Win32.Virtob.{2,3,4}.Gen( Generic.Virtob.1, Win32.Virut, W32/Virut, Virus.Win32.Virut, Virus:Win32/Virut, W32.Virut, W32/Vetor )
SYMPTOMS:
TECHNICAL DESCRIPTION: This virus is a polymorphic, memory-resident file-infector, with backdoor behaviour. The author spreads it by posting it as a crack for different applications or games, on several forums. He also uses a "pay-per-install" affiliate program, hosted at exerevenue.com, but the executable he pretends users have to run to earn cash is the virus itself. Once executed, it injects itself into WINLOGON, creates a new thread in that process, and passes the execution control to the host file. It also hooks the following functions in each running process (in NTDLL module):
It infects EXE and SCR files, using different infection techniques:
The virus is able to avoid emulators and virtual machines. To ensure there's only one instance of it running in the system, it creates an event with one of the following names:
It avoids infecting files that containg the following strings:
It tries to connect to some IRC server, and join a certain channel. The IRC server can be:
Once it joins the channel, it waits for commands that instruct it to download several files from Internet, and then execute them. One of these files is a second component of the virus (it is detected as Win32.Virtob.Dld.?). It downloads other files (other downloaders), and infects HTM, PHP and ASP files found on all fixed and removable drives, and also on network shares, by inserting an IFRAME right before the BODY tag. The IFRAME contains MPack, an exploit kit that includes:
By infecting ASP, HTM and PHP scripts on every infected machine, it is possible to infect scripts that serve webpages, so the potential of spreading is bigger (it is actually acting like a worm). Some versions have a piece of a Friedrich Nietzsche's poem. Usually this is:
or:
It is possible that some versions are detected by BitDefender with names like:
Note: there are a lot of versions that contain bugs, so not all the described behavior actually works as expected. Removal instructions: Please let BitDefender disinfect your files. Please note that there are versions of Virtob that contain bugs, so it is possible that misinfected files can't be disinfected. ANALYZED BY: Raul TOSA, BitDefender virus researcher |