Content
Generic PWS.y!6F939359
- Type
- Trojan
- SubType
- Password Stealer
- Discovery Date
- 11/05/2008
- Length
- 31232
- Minimum DAT
- 5426 (11/06/2008)
- Updated DAT
- 5427 (11/07/2008)
- Minimum Engine
- 5.2.00
- Description Added
- 11/05/2008
- Description Modified
- 11/06/2008 2:28 AM (PT)
Risk Assessment
- Corporate User
- Low-Profiled
- Home User
- Low-Profiled
Tab Navigation
Characteristics
| File Property | Property Value |
|---|---|
| FileName | adobe_flash9.exe |
| McAfee Detection | Generic PWS.y |
| Length | 31,232 bytes |
| CRC | 6f939359 |
| MD5 | 47C86509A78DC1EDB42F2964BEA86306 |
| SHA1 | d3e810f43e77d6963018eccdcbbb3b0464288b1d |
Other Common Detection Aliases
| Company Name | Detection Name |
|---|---|
| Avast | Win32:Agent-LVZ [Rtk] |
| AVG (GriSoft) | Agent.AJAY |
| Avira | TR/Crypt.XDR.Gen |
| Nod32 | Win32/PSW.Papras.AA |
| Frisk | W32/Downloader.C.gen!Eldorado |
| Ikarus | Trojan-PWS.Games.C |
| Microsoft | TrojanSpy:Win32/Ursnif.gen!D |
| Sophos | Mal/Heuri-E |
| Symantec | Infostealer |
| Trend Micro | Possible_Crypt |
| VBA | ~Embedded.Rootkit.Win32.Agent.ex |
AvertŪ Labs has observed the following system activities:
| Activity | Risk Level |
|---|---|
| Enumerates open windows |
Medium |
| Enumerates running processes |
Medium |
| Program often suspends itself |
Medium |
| Uses shared memory of other processes |
Low |
| Writes executable in the windows folder |
Low |
| Creates registry keys and data values to persist on OS reboot |
Informational |
| Performs a shell execute of downloaded or existing files |
Informational |
Other detections that have been observed.
| FileName | McAfee Supported |
|---|---|
| %WINDIR%\new_drv.sys |
Generic Rootkit.d |
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
Generic PWS.y!6F939359 has been know to speard via spam email. A snippet from the email is provided below
"From: "President election results"
Subject: A new president, a new congress ...
Barack Obama Elected 44th President of United States
Barack Obama, unknown to most Americans just four years ago, will become the 44th president and the first African-American president of the United States.
Watch His amazing speech at November 5! ...... "
The email tells the user that they require Adobe Flash to view the video which requires a download. The download drops "adobe_flash9.exe". On execution, the trojan drops a Rootkit component which is used to hide the running process. The hidden process steals user information and relays it back to a server.
The following files have been added to the system:
The following registry elements have been created:
- k1 = 671634
- k2 = 339167
- version = 50
The following registry elements have been changed:
- ttool = %WINDIR%\9129837.exe
The following Services were added:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv
- ImagePath = %WINDIR%\new_drv.sys
- DisplayName = "!!!!"
The applications created the following network connection(s):
- hxxp://91.203.93.57/cgi-bin/[Removed]
Symptoms
This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Method of Infection
This trojan spreads via spammed email.
Removal
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
-- Update November 5, 2008 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://voices.washingtonpost.com/securityfix/2008/11/malware_piggybacks_on_obama_wi.html
--
This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include e-mail, malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.
Characteristics
Characteristics -
| File Property | Property Value |
|---|---|
| FileName | adobe_flash9.exe |
| McAfee Detection | Generic PWS.y |
| Length | 31,232 bytes |
| CRC | 6f939359 |
| MD5 | 47C86509A78DC1EDB42F2964BEA86306 |
| SHA1 | d3e810f43e77d6963018eccdcbbb3b0464288b1d |
Other Common Detection Aliases
| Company Name | Detection Name |
|---|---|
| Avast | Win32:Agent-LVZ [Rtk] |
| AVG (GriSoft) | Agent.AJAY |
| Avira | TR/Crypt.XDR.Gen |
| Nod32 | Win32/PSW.Papras.AA |
| Frisk | W32/Downloader.C.gen!Eldorado |
| Ikarus | Trojan-PWS.Games.C |
| Microsoft | TrojanSpy:Win32/Ursnif.gen!D |
| Sophos | Mal/Heuri-E |
| Symantec | Infostealer |
| Trend Micro | Possible_Crypt |
| VBA | ~Embedded.Rootkit.Win32.Agent.ex |
AvertŪ Labs has observed the following system activities:
| Activity | Risk Level |
|---|---|
| Enumerates open windows |
Medium |
| Enumerates running processes |
Medium |
| Program often suspends itself |
Medium |
| Uses shared memory of other processes |
Low |
| Writes executable in the windows folder |
Low |
| Creates registry keys and data values to persist on OS reboot |
Informational |
| Performs a shell execute of downloaded or existing files |
Informational |
Other detections that have been observed.
| FileName | McAfee Supported |
|---|---|
| %WINDIR%\new_drv.sys |
Generic Rootkit.d |
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
Generic PWS.y!6F939359 has been know to speard via spam email. A snippet from the email is provided below
"From: "President election results"
Subject: A new president, a new congress ...
Barack Obama Elected 44th President of United States
Barack Obama, unknown to most Americans just four years ago, will become the 44th president and the first African-American president of the United States.
Watch His amazing speech at November 5! ...... "
The email tells the user that they require Adobe Flash to view the video which requires a download. The download drops "adobe_flash9.exe". On execution, the trojan drops a Rootkit component which is used to hide the running process. The hidden process steals user information and relays it back to a server.
The following files have been added to the system:
The following registry elements have been created:
- k1 = 671634
- k2 = 339167
- version = 50
The following registry elements have been changed:
- ttool = %WINDIR%\9129837.exe
The following Services were added:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv
- ImagePath = %WINDIR%\new_drv.sys
- DisplayName = "!!!!"
The applications created the following network connection(s):
- hxxp://91.203.93.57/cgi-bin/[Removed]
Symptoms
Symptoms -
This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Method of Infection
Method of Infection -
This trojan spreads via spammed email.
Removal -
Removal -
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A