My Bitdefender
  • 0 Shopping Cart


Facebook Twitter Google Plus


~110 kB
(Peed, Zhelatin, Nuwar, Peacomm)


Computer slow-downs
Increased network activity.
Presence of the specified files and registry entries.

Removal instructions:

Please let BitDefender disinfect your files.

Analyzed By

Dan Anton, virus researcher

Technical Description:

When started, the malware copies itself to the following location:

It creates the following registry entry:
HKCU\Microsoft\Windows\CurrentVersion\Run\"[malware_name]" = "%windows%\[malware_name].exe"

A few examples of [malware_name] are:

It synchronizes the current computer time by executing the following commands:
w32tm.exe /config /synffromflags:manual /,
w32tm.exe /config /update

The malware adds itself as a Windows Firewall exception by executing the following command:
netsh firewall set allowedprogram %windows%\[malware_name].exe

The virus registers the compromised computer as a peer in its malware network and uses a randomly chosen UDP port to communicate with the other peers. It also sends to its network an unique ID for the compromised computer from the registry key:

It drops a list of the initial peers to the configuration file:
The malware updates this list by communicating with url-s like:

The malware also has backdoor capabilities and can perform actions like:
- send spam emails by using its SMTP engine
- send system information from the compromised computer
- download and execute other malware
- update itself

It searches email addresses from files with the following extensions:

It does not send spam emails to email addresses that contain the following strings:

Examples of sent emails:

Subject: Well done 4th!
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

American Independence Day http://69.251.[hide]/

Subject: Amazing Independence Day show
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Stars and Strips forever http://68.90.195.

Some of sent emails' subjects are:

Amazing firework 2008
Amazing Independence Day salute
Amazing Independence Day show
America for You and Me
America the Beautiful
American Independence Day
Bright and joyful Fourth of July
Celebrate Independence
Celebrate the spirit of America
Celebrate with Pride
Celebrating Fourth of July
Celebrating the Glory of our Nation
Celebrating the spirit of our Country
Celebrations have already begun
Fabulous Independence Day firework
God bless America
Happy Birthday, America!
Happy Fourth of July
Happy Independence Day
Home of the Brave
Independence Day firework broke all records
Just You
Light up the sky
Long Live America
Proud to be an American
S America the Beautiful
S Happy Fourth of July
S Stars and Strips forever
Sparkling Celebration of Independence Day
Spectacular fireworks show
Stars and Strips forever
Super 4th!
The best firework you've ever seen
The best of 4th of July Salute
Time for Fireworks
Well done 4th!
You Stay In My Heart

Some of the ip-s used in the email body: