Affected OS: Win NT-based
File size: 25 600 bytes
Packed by: -
- Can be installed by various malicious downloaders and installers.
- When launched injects its code in the alternative data stream (ADS) into %systemroot%\system32\svchost.exe.
- In order to be launched at Windows start-up it registers the copy of %systemroot%\system32\svchost.exe as a service:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FCI\
ImagePath = %systemroot%\system32\svchost.exe:ext.exe
The displayed service name is FCI. - Adds the infected %systemroot%\system32\svchost.exe to the list of trusted applications of the Windows firewall .
- Connects to a remote server and initiates spamming.
1. Disconnect an infected machine from the local area network and/or the Internet. Disable the System Restore service.
2. Use an uninfected machine to download the Dr.Web CureIt!utility and place it on a removable media.
3. Boot Windows in the safe mode (F8 at start-up) and scan the infected computer using Dr.Web CureIt!. Apply “Cure” to all infected objects.