My Bitdefender
  • 0 Shopping Cart


Facebook Twitter Google Plus


~524 kbytes
( Win32/Autoit.BO Trojan:Win32/Malagent Worm/Autoit.OJ)


The following process is running: MsRun32.exe

The following files will be found on an infected computer:
%SYSTEMDIRECTORY%\MsRun32.exe (524 K)
%WINDIR%\MsRun32.exe (524 K)

%SYSTEMDIRECTORY%\autorun.ini with the following configuration:
Shellexe cute=MsRun32.exe

The following registry entry will be found:
"MSN Messengger" = %SYSTEMDIRECTORY%\MsRun32.exe

Removal instructions:

Please let BitDefender disinfect your files.

Analyzed By

Robert Szasz, virus researcher

Technical Description:

This worm is an AutoIt compiled script that has a word document icon in order to trigger the user to run it.
If run, it will perform the following actions:

- creates the following copies of itself:

- add/modify the following registry keys:

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe MsRun32.exe

"MSN Messengger" = C:\WINDOWS\system32\MsRun32.exe

    -with these 2 entries adds itself to startup.

"DisableRegistryTools" = 1
"DisableTaskMgr" = 1

    -disable registry tools and the task manager.

"NofolderOptions" = 1

    -disable the access to Tools | Folder Options in Windows Explorer

"CheckedValue" = 0


    - Spreads via shared drives by checking the values within the following registry subkey:
"shared" = \True_Love.exe
    Then copies itself in the root of the found shared drives with the name MsRun32 and copies autorun.ini too.
    Then copies itself as True_Love.exe to the last entry.
- creates a file named autorun.ini in %SYSTEMDIRECTORY% in order to spread itself on removable drives too(with the name True_Love.exe)

- kills processes with the following name:
    "System Configuration"
    "Windows Task"
- spreads over Yahoo Messengers with the following messages:
    "see this comedy joke click on this link[...]5"
    "Ha ha ha click on link to laugh ...[...]5"
    "what a joke ......[...]5"
    "nice one see this ....[...]5"
    "what a joke to see[...]5"
    "what a joke ......[...]5"
    "nice to listen ..........[...]5"
    "what is this ? ......see[...]5"
    "i am busy you click on a link and see ...[...]5"
    "what is this ? ......see[...]5"