This malware does nothing except propagate itself. It is capable of propagating by contaminating CDs burned on an infected system with copies of its infectious code.
Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.
During installation, the malware creates a decrypted copy of itself as %temp% \[Random].tmp. This file is detected as Worm.VBS.Agent.w. It then executes this decrypted copy, using the following command:
Next, the malware creates the following files:
The first file contains zero bytes. The file %temp%\auto.exe is actually the autorun file for the decrypted copy of the malware, and it is this particular file that is detected as Trojan:JS/Agent.JP.The malware attempts to create a copy of itself in the following Alternate Data Stream file:
It also creates a copy of itself in the following folder:
This malware is capable of propagating through infected CD ROM discs. To do so, the malware creates the following files:
The first file is also detected as Trojan:JS/Agent.JP, while the second file is the autorun file for the first. Subsequently, all CDs burned on the infected system will be contaminated with these files.The file %ApplicationData%\Microsoft\CD Burning\autorun.inf contains the following data:
This same data is also present in the %temp%\auto.exe file.
The malware makes a number of modifications to the registry to facilitate its propagation. Some interesting changes it makes include disabling the Registry Editor by creating the following registry entries:
Also, the malware checks whether the day of the month is "1"; if so, it creates the following registries:
And then creates the following file:
Note: v.doc is normal file.
The malware checks whether the date is April 1; if so, it runs the file %temp%\v.doc, using the following command three times:
The command allows the malware to print the file under notepad.exe process. The printed file should look like this:
The malware then takes a number of actions involving:
First, it drops the following files to these locations:
Notes: thumb.db is a copy of the malware; autorun.inf is the malware's autorun file; Microsoft.lnk is a shortcut link to "[drive]:\thumb.db".The shortcut file link text is named after the folder name.If the date is April 1, it also drops:
It may also create one of the following shortcut file links "[drive]:\thumb.db" to these locations:
Creates these keys:
Deletes these keys:
Date Created: -
Date Last Modified: -