TROJ_VUNDO.BBF
Trojan:Win32/Vundo.gen!AI (Microsoft); Packed.Win32.Mondera.b (Kaspersky); Trojan.Vundo (Symantec); Vundo.gen.o (McAfee)
Windows

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
92,725 bytes
DLL
No
08 Apr 2009
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
CPM{8 random alphanumeric characters} = "Rundll32.exe "{malware path}\{malware name}",a"
Other System Modifications
This Trojan adds the following registry keys:
HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}
HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\
InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InprocServer32
It adds the following registry entries:
HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\
InprocServer32
@ = "{malware path}\{malware name}"
HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\
InprocServer32
ThreadingModel = "Both"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InprocServer32
@ = "{malware path}\{malware name}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InprocServer32
ThreadingModel = "Both"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
SharedTaskScheduler
{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} = "STS"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\ShellServiceObjectDelayLoad
SSODL = "{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Windows
LoadAppInit_DLLs = "1"