Content

Generic PWS.y!6F939359

Type
Trojan
SubType
Password Stealer
Discovery Date
11/05/2008
Length
31232
Minimum DAT
5426 (11/06/2008)
Updated DAT
5427 (11/07/2008)
Minimum Engine
5.2.00
Description Added
11/05/2008
Description Modified
11/06/2008 2:28 AM (PT)
Risk Assessment
Corporate User
Low-Profiled
Home User
Low-Profiled

Tab Navigation

Characteristics

File Property Property Value
FileName adobe_flash9.exe
McAfee Detection Generic PWS.y
Length 31,232 bytes
CRC 6f939359
MD5 47C86509A78DC1EDB42F2964BEA86306
SHA1 d3e810f43e77d6963018eccdcbbb3b0464288b1d

Other Common Detection Aliases

Company Name Detection Name
Avast Win32:Agent-LVZ [Rtk]
AVG (GriSoft) Agent.AJAY
Avira TR/Crypt.XDR.Gen
Nod32 Win32/PSW.Papras.AA
Frisk W32/Downloader.C.gen!Eldorado
Ikarus Trojan-PWS.Games.C
Microsoft TrojanSpy:Win32/Ursnif.gen!D
Sophos Mal/Heuri-E
Symantec Infostealer
Trend Micro Possible_Crypt
VBA ~Embedded.Rootkit.Win32.Agent.ex

AvertŪ Labs has observed the following system activities:

Activity Risk Level
Enumerates open windows
Medium
Enumerates running processes
Medium
Program often suspends itself
Medium
Uses shared memory of other processes
Low
Writes executable in the windows folder
Low
Creates registry keys and data values to persist on OS reboot
Informational
Performs a shell execute of downloaded or existing files
Informational

Other detections that have been observed.

FileName McAfee Supported
%WINDIR%\new_drv.sys
Generic Rootkit.d

System Changes

These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files

Generic PWS.y!6F939359 has been know to speard via spam email. A snippet from the email is provided below

"From: "President election results"
Subject: A new president, a new congress ...
Barack Obama Elected 44th President of United States

Barack Obama, unknown to most Americans just four years ago, will become the 44th president and the first African-American president of the United States.
Watch His amazing speech at November 5! ...... "

The email tells the user that they require Adobe Flash to view the video which requires a download. The download drops "adobe_flash9.exe". On execution, the trojan drops a Rootkit component which is used to hide the running process. The hidden process steals user information and relays it back to a server.

The following files have been added to the system:

  • %WINDIR%\9129837.exe
  • %WINDIR%\new_drv.sys

    The following registry elements have been created:

  • hkey_users\s-1-5-21-1202660629-602609370-839522115-500\software\microsoft\inetdata\
    • k1 = 671634
    • k2 = 339167
    • version = 50

    The following registry elements have been changed:

  • hkey_users\s-1-5-21-1202660629-602609370-839522115-500\software\microsoft\windows\currentversion\run\
    • ttool = %WINDIR%\9129837.exe

    The following Services were added:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv

    • ImagePath =   %WINDIR%\new_drv.sys
    • DisplayName =  "!!!!"
  • The applications created the following network connection(s):

  • http
    • hxxp://91.203.93.57/cgi-bin/[Removed]

    Symptoms

    This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

    Method of Infection

    This trojan spreads via spammed email.

    Removal

    All Users:
    Use current engine and DAT files for detection and removal.

    Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

    Additional Windows ME/XP removal considerations

    Variants

    Variants

      N/A

    All Information

    Overview -

    -- Update November 5, 2008 --
    The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
    http://voices.washingtonpost.com/securityfix/2008/11/malware_piggybacks_on_obama_wi.html

    --

    This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include e-mail, malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

    Characteristics

    Characteristics -

    File Property Property Value
    FileName adobe_flash9.exe
    McAfee Detection Generic PWS.y
    Length 31,232 bytes
    CRC 6f939359
    MD5 47C86509A78DC1EDB42F2964BEA86306
    SHA1 d3e810f43e77d6963018eccdcbbb3b0464288b1d

    Other Common Detection Aliases

    Company Name Detection Name
    Avast Win32:Agent-LVZ [Rtk]
    AVG (GriSoft) Agent.AJAY
    Avira TR/Crypt.XDR.Gen
    Nod32 Win32/PSW.Papras.AA
    Frisk W32/Downloader.C.gen!Eldorado
    Ikarus Trojan-PWS.Games.C
    Microsoft TrojanSpy:Win32/Ursnif.gen!D
    Sophos Mal/Heuri-E
    Symantec Infostealer
    Trend Micro Possible_Crypt
    VBA ~Embedded.Rootkit.Win32.Agent.ex

    AvertŪ Labs has observed the following system activities:

    Activity Risk Level
    Enumerates open windows
    Medium
    Enumerates running processes
    Medium
    Program often suspends itself
    Medium
    Uses shared memory of other processes
    Low
    Writes executable in the windows folder
    Low
    Creates registry keys and data values to persist on OS reboot
    Informational
    Performs a shell execute of downloaded or existing files
    Informational

    Other detections that have been observed.

    FileName McAfee Supported
    %WINDIR%\new_drv.sys
    Generic Rootkit.d

    System Changes

    These are general defaults for typical path variables. (Although they may differ, these examples are common.):
    %WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
    %SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
    %ProgramFiles% = \Program Files

    Generic PWS.y!6F939359 has been know to speard via spam email. A snippet from the email is provided below

    "From: "President election results"
    Subject: A new president, a new congress ...
    Barack Obama Elected 44th President of United States

    Barack Obama, unknown to most Americans just four years ago, will become the 44th president and the first African-American president of the United States.
    Watch His amazing speech at November 5! ...... "

    The email tells the user that they require Adobe Flash to view the video which requires a download. The download drops "adobe_flash9.exe". On execution, the trojan drops a Rootkit component which is used to hide the running process. The hidden process steals user information and relays it back to a server.

    The following files have been added to the system:

  • %WINDIR%\9129837.exe
  • %WINDIR%\new_drv.sys

    The following registry elements have been created:

  • hkey_users\s-1-5-21-1202660629-602609370-839522115-500\software\microsoft\inetdata\
    • k1 = 671634
    • k2 = 339167
    • version = 50

    The following registry elements have been changed:

  • hkey_users\s-1-5-21-1202660629-602609370-839522115-500\software\microsoft\windows\currentversion\run\
    • ttool = %WINDIR%\9129837.exe

    The following Services were added:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv

    • ImagePath =   %WINDIR%\new_drv.sys
    • DisplayName =  "!!!!"
  • The applications created the following network connection(s):

  • http
    • hxxp://91.203.93.57/cgi-bin/[Removed]

    Symptoms

    Symptoms -

    This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

    Method of Infection

    Method of Infection -

    This trojan spreads via spammed email.

    Removal -

    Removal -

    All Users:
    Use current engine and DAT files for detection and removal.

    Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

    Additional Windows ME/XP removal considerations

    Variants

    Variants -

      N/A