| Detection added |
May 26 2007 12:58 GMT |
| Update released |
May 26 2007 14:44 GMT |
| Description added |
Jun 01 2007 |
| Behavior |
Virus |
This file virus is a Windows PE EXE file. The file is 380 416 bytes in size.
It is written in Delphi.
Installation
When launched, the virus copies its executable file as follows:
%System%\config\csrss.exe
%WinDir%\media\arona.exe
It also creates the following file:
%System%\logon.bat
When this file is run, it will launch a copy of the virus:
%System%\config\csrss.exe
In order to ensure that the virus is launched automatically when the system
is rebooted, it adds a link to its executable file to the system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Worms" = "%System%\logon.bat"
The virus also creates the following files:
%System%\config\autorun.inf
h:\autorun.inf
f:\autorun.inf
i:\autorun.inf
g:\autorun.inf
k:\autorun.inf
l:\autorun.inf
o:\autorun.inf
j:\autorun.inf
These files will be launched each time the user opens the corresponding hard
disk partition using Windows Explorer. When one of these files is run, it will
launch a copy of the virus: %System%\config\csrss.exe.
The virus modifies values of the following system registry keys:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
DisableTaskMgr = 1
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
NoFolderOptions = 1
It also searches the hard disk partitions listed below for files with an ".mp3"
extension:
d:\
c:\
e:\
f:\
g:\
h:\
These files wil then be deleted.
If your computer does not have an up-to-date antivirus, or does not have an
antivirus solution at all, follow the instructions below to delete the malicious
program:
- Use Task
Manager to terminate the virus process.
- Delete the original virus file (the location will depend on how
the program originally penetrated the victim machine).
- Delete the following parameters from the system registry (see
What
is a system registry and how do I use it for details on how to edit the registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
DisableTaskMgr = 1
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
NoFolderOptions = 1
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Worms" = "%System%\logon.bat"
- Delete the following files:
%System%\config\csrss.exe
%WinDir%\media\arona.exe
%System%\logon.bat
%System%\config\autorun.inf
h:\autorun.inf
f:\autorun.inf
i:\autorun.inf
g:\autorun.inf
k:\autorun.inf
l:\autorun.inf
o:\autorun.inf
j:\autorun.inf
- Update your antivirus databases and perform a full scan of the
computer (download a trial version of Kaspersky Anti-Virus).