WORM_SMALL.SMA
Worm:Win32/Agent (Microsoft); W32/Xiquitir.ow!p2p (McAfee); W32.SillyP2P (Symantec); P2P-Worm.Win32.Small.p, P2P-Worm.Win32.Small.p (Kaspersky); Worm.Win32.Xiquitir.ow (v) (Sunbelt); Worm.Generic.322426 (FSecure)
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Worm
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This worm arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
653,400 bytes
EXE
01 Oct 2011
Arrival Details
This worm arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This worm creates the following folders:
- %System Root%/WINDOWS/Intelx386
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
Autostart Technique
This worm adds the following registry entries to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
VMIntel386 = "%Windows%\Intelx386\VMIntel386.exe 256mb 32bit"
Dropping Routine
This worm drops the following files:
- %System Root%/WINDOWS/Intelx386/Winamp 5.0 (full version).exe
- %System Root%/WINDOWS/Intelx386/Winamp 3 (full version).exe
- %System Root%/WINDOWS/Intelx386/Winamp 3.5 (full version).exe
- %System Root%/WINDOWS/Intelx386/Update Photoshop 7.0 to Photoshop 9.16 (It´s Work!).exe
- %System Root%/WINDOWS/Intelx386/Update Photoshop 8.0 to Photoshop 9.5 (It´s Work!).exe
- %System Root%/WINDOWS/Intelx386/WinAce 3.85 (with Serial).exe
- %System Root%/WINDOWS/Intelx386/Download Accelerator Plus (DAP) (full version with serial).exe
- %System Root%/WINDOWS/Intelx386/RealOne Player (Full version).exe
- %System Root%/WINDOWS/Intelx386/BsPlayer v3.exe
- %System Root%/WINDOWS/Intelx386/WinRar v6.11 (with crack).exe
- %System Root%/WINDOWS/Intelx386/WinRar 4 (with crack).exe
- %System Root%/WINDOWS/Intelx386/ContaWin 2000 (full version).exe
- %System Root%/WINDOWS/Intelx386/WinZip 9.exe
- %System Root%/WINDOWS/Intelx386/DivX 7.2 freeware.exe
- %System Root%/WINDOWS/Intelx386/3D Studio R8 (It's Work!!).exe
- %System Root%/WINDOWS/Intelx386/VirtualDub 2.1.4.exe
- %System Root%/WINDOWS/Intelx386/MSN messenger 6.3.exe
- %System Root%/WINDOWS/Intelx386/Hacha Profesional Edition.exe
- %System Root%/WINDOWS/Intelx386/Simpsons pack guiones (Temporada 2004).exe
- %System Root%/WINDOWS/Intelx386/Mazinkaiser pack fondos de escritorio.exe
- %System Root%/WINDOWS/Intelx386/Mazinkaiser comics pack.exe
- %System Root%/WINDOWS/Intelx386/Juegos JAVA para NOKIA.exe
- %System Root%/WINDOWS/Intelx386/Capitulos ineditos de DragonBall Z jamas emitidos.exe
- %System Root%/WINDOWS/Intelx386/Pack Tonos y Logos para Nokia.exe
- %System Root%/WINDOWS/Intelx386/Nero 7.5.1.0 (cracked!).exe
- %System Root%/WINDOWS/Intelx386/Pack Photoshop CS 8 plugins.exe
- %System Root%/WINDOWS/Intelx386/3D Movie Maker.exe
- %System Root%/WINDOWS/Intelx386/Silent Hill.exe
- %System Root%/WINDOWS/Intelx386/PSEmu.exe
- %System Root%/WINDOWS/Intelx386/RM2GBA.exe
- %System Root%/WINDOWS/Intelx386/WAV2MP3.exe
- %System Root%/WINDOWS/Intelx386/GBAEmu.exe
- %System Root%/WINDOWS/Intelx386/GameCube Emulator.exe
- %System Root%/WINDOWS/Intelx386/Pack 50 Juegos PS2.exe
- %System Root%/WINDOWS/Intelx386/Pack 25 Juegos GameCube.exe
- %System Root%/WINDOWS/Intelx386/Resident Evil for GameCube.exe
- %System Root%/WINDOWS/Intelx386/Visual Basic 6.exe
- %System Root%/WINDOWS/Intelx386/Visual C.exe
- %System Root%/WINDOWS/Intelx386/Visual Studio (full).exe
- %System Root%/WINDOWS/Intelx386/mugen (full).exe
- %System Root%/WINDOWS/Intelx386/Fuck my fat ass.avi.exe
- %System Root%/WINDOWS/Intelx386/German extreme violation.mpg.exe
- %System Root%/WINDOWS/Intelx386/Sexo con una menor.exe
- %System Root%/WINDOWS/Intelx386/Pedofilia pack 37 pics.exe
- %System Root%/WINDOWS/Intelx386/Follada brutal coño roto.exe
- %System Root%/WINDOWS/Intelx386/Lolita Pack 20 Pics.exe
- %System Root%/WINDOWS/Intelx386/Puta come mierda.exe
- %System Root%/WINDOWS/Intelx386/Solo para Maricas.exe
- %System Root%/WINDOWS/Intelx386/No lo Descargues.exe
- %System Root%/WINDOWS/Intelx386/Dont Download.exe
- %System Root%/WINDOWS/Intelx386/humor.exe
- %System Root%/WINDOWS/Intelx386/Dont Touch.exe
- %System Root%/WINDOWS/Intelx386/Hentai.exe
- %System Root%/WINDOWS/Intelx386/Matrix Wallpapers.exe
- %System Root%/WINDOWS/Intelx386/Terminator 3 Wallpapers.exe
- %System Root%/WINDOWS/Intelx386/Hentai Evangelion Poker.exe
- %System Root%/WINDOWS/Intelx386/Shinchan screen saver.scr
- %System Root%/WINDOWS/Intelx386/Hentai Shizuka clit.exe
- %System Root%/WINDOWS/Intelx386/a pelo.exe
- %System Root%/WINDOWS/Intelx386/Chenoa en cueros.exe
- %System Root%/WINDOWS/Intelx386/WinAmp skings and plugins.exe
- %System Root%/WINDOWS/Intelx386/FlashGet Max acceleration (Experimental).exe
- %System Root%/WINDOWS/Intelx386/VMIntel386.exe
- %System Root%/WINDOWS/Intelx386/Pack sex very hot nude young girl porn erotic private pussy rape clitoris suck chicas fotos culos tetas coños mamadas corridas sister hermana amigas friends lesbianas mujeres desnudas putas guarras hentai.exe
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
This report is generated via an automated analysis system.
SOLUTION
9.200
Step 1
Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.
Step 2
Restart in Safe Mode
Step 3
Delete this registry value
Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- VMIntel386="%Windows%\Intelx386\VMIntel386.exe 256mb 32bit"
Step 4
Search and delete this folder
Step 5
Search and delete these files
- %System Root%/WINDOWS/Intelx386/Winamp 5.0 (full version).exe
- %System Root%/WINDOWS/Intelx386/Winamp 3 (full version).exe
- %System Root%/WINDOWS/Intelx386/Winamp 3.5 (full version).exe
- %System Root%/WINDOWS/Intelx386/Update Photoshop 7.0 to Photoshop 9.16 (It´s Work!).exe
- %System Root%/WINDOWS/Intelx386/Update Photoshop 8.0 to Photoshop 9.5 (It´s Work!).exe
- %System Root%/WINDOWS/Intelx386/WinAce 3.85 (with Serial).exe
- %System Root%/WINDOWS/Intelx386/Download Accelerator Plus (DAP) (full version with serial).exe
- %System Root%/WINDOWS/Intelx386/RealOne Player (Full version).exe
- %System Root%/WINDOWS/Intelx386/BsPlayer v3.exe
- %System Root%/WINDOWS/Intelx386/WinRar v6.11 (with crack).exe
- %System Root%/WINDOWS/Intelx386/WinRar 4 (with crack).exe
- %System Root%/WINDOWS/Intelx386/ContaWin 2000 (full version).exe
- %System Root%/WINDOWS/Intelx386/WinZip 9.exe
- %System Root%/WINDOWS/Intelx386/DivX 7.2 freeware.exe
- %System Root%/WINDOWS/Intelx386/3D Studio R8 (It's Work!!).exe
- %System Root%/WINDOWS/Intelx386/VirtualDub 2.1.4.exe
- %System Root%/WINDOWS/Intelx386/MSN messenger 6.3.exe
- %System Root%/WINDOWS/Intelx386/Hacha Profesional Edition.exe
- %System Root%/WINDOWS/Intelx386/Simpsons pack guiones (Temporada 2004).exe
- %System Root%/WINDOWS/Intelx386/Mazinkaiser pack fondos de escritorio.exe
- %System Root%/WINDOWS/Intelx386/Mazinkaiser comics pack.exe
- %System Root%/WINDOWS/Intelx386/Juegos JAVA para NOKIA.exe
- %System Root%/WINDOWS/Intelx386/Capitulos ineditos de DragonBall Z jamas emitidos.exe
- %System Root%/WINDOWS/Intelx386/Pack Tonos y Logos para Nokia.exe
- %System Root%/WINDOWS/Intelx386/Nero 7.5.1.0 (cracked!).exe
- %System Root%/WINDOWS/Intelx386/Pack Photoshop CS 8 plugins.exe
- %System Root%/WINDOWS/Intelx386/3D Movie Maker.exe
- %System Root%/WINDOWS/Intelx386/Silent Hill.exe
- %System Root%/WINDOWS/Intelx386/PSEmu.exe
- %System Root%/WINDOWS/Intelx386/RM2GBA.exe
- %System Root%/WINDOWS/Intelx386/WAV2MP3.exe
- %System Root%/WINDOWS/Intelx386/GBAEmu.exe
- %System Root%/WINDOWS/Intelx386/GameCube Emulator.exe
- %System Root%/WINDOWS/Intelx386/Pack 50 Juegos PS2.exe
- %System Root%/WINDOWS/Intelx386/Pack 25 Juegos GameCube.exe
- %System Root%/WINDOWS/Intelx386/Resident Evil for GameCube.exe
- %System Root%/WINDOWS/Intelx386/Visual Basic 6.exe
- %System Root%/WINDOWS/Intelx386/Visual C.exe
- %System Root%/WINDOWS/Intelx386/Visual Studio (full).exe
- %System Root%/WINDOWS/Intelx386/mugen (full).exe
- %System Root%/WINDOWS/Intelx386/Fuck my fat ass.avi.exe
- %System Root%/WINDOWS/Intelx386/German extreme violation.mpg.exe
- %System Root%/WINDOWS/Intelx386/Sexo con una menor.exe
- %System Root%/WINDOWS/Intelx386/Pedofilia pack 37 pics.exe
- %System Root%/WINDOWS/Intelx386/Follada brutal coño roto.exe
- %System Root%/WINDOWS/Intelx386/Lolita Pack 20 Pics.exe
- %System Root%/WINDOWS/Intelx386/Puta come mierda.exe
- %System Root%/WINDOWS/Intelx386/Solo para Maricas.exe
- %System Root%/WINDOWS/Intelx386/No lo Descargues.exe
- %System Root%/WINDOWS/Intelx386/Dont Download.exe
- %System Root%/WINDOWS/Intelx386/humor.exe
- %System Root%/WINDOWS/Intelx386/Dont Touch.exe
- %System Root%/WINDOWS/Intelx386/Hentai.exe
- %System Root%/WINDOWS/Intelx386/Matrix Wallpapers.exe
- %System Root%/WINDOWS/Intelx386/Terminator 3 Wallpapers.exe
- %System Root%/WINDOWS/Intelx386/Hentai Evangelion Poker.exe
- %System Root%/WINDOWS/Intelx386/Shinchan screen saver.scr
- %System Root%/WINDOWS/Intelx386/Hentai Shizuka clit.exe
- %System Root%/WINDOWS/Intelx386/a pelo.exe
- %System Root%/WINDOWS/Intelx386/Chenoa en cueros.exe
- %System Root%/WINDOWS/Intelx386/WinAmp
Step 6
Restart in normal mode and scan your computer with your Trend Micro product for files detected as WORM_SMALL.SMA. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Did this description help? Tell us how we did.