Short description
Win32/Zimuse.B is a worm that overwrites MBR (Master Boot Record) of all available drives with its own data. The file is run-time compressed using PECompact .
Installation
When executed, the worm creates the following files:
- %system%driversMstart.sys (13100 B)
- %system%driversMseu.sys (18188 B)
- %system%mseus.exe (69632 B)
- %system%tokset.dll (228352 B)
- %system%ainf.inf (41 B)
- %system%driversMstart.sys (13100 B)
- %system%driversMseu.sys (18188 B)
- %system%mseus.exe (69632 B)
- %system%tokset.dll (228352 B)
- %system%ainf.inf (41 B)
- %programfiles%DumpDump.exe (28672 B)
- %temp%Mseu.ini (225 B)
- %temp%mseus.ini (328 B)
- %temp%Instdrv.exe (44552 B)
- %temp%Dump.ini (275 B)
- %temp%Regini.exe (68880 B)
- %systemdrive%IQTESTIqtest.exe (97424 B)
- %systemdrive%IQTESTReadme.txt (73 B)
Installs the following system drivers (path, name):
- %system%driversMstart.sys, MSTART
- %system%driversMseu.sys, MSEU
In order to be executed on every system start, the worm sets the following Registry entry:
- [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows
CurrentVersionRun]
"Dump" = "%programfiles%DumpDump.exe"
The following Registry entries are created:
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetEnumRoot
LEGACY_MSTART 000Control]
"*NewlyCreated*" = 0
"ActiveService" = "MSTART"
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetEnumRoot
LEGACY_MSTART 000]
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetEnumRoot
LEGACY_MSTART 000Control]
"*NewlyCreated*" = 0
"ActiveService" = "MSTART"
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetEnumRoot
LEGACY_MSTART 000]
"Service" = "MSTART"
"Legacy" = 1
"ConfigFlags" = 0
"Class" = "LegacyDriver"
"ClassGUID" = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc" = "MSTART"
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetEnumRoot
LEGACY_MSTART]
"NextInstance" = 1
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMseu]
"Type" = 1
"Start" = 2
"ErrorControl" = 1
"Tag" = 1
"Group" = "Extended base"
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMSTART
Enum]
"0" = "RootLEGACY_MSTART 000"
"Count" = 1
"NextInstance" = 1
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMSTART
Security]
"Security" = "%hex_str%"
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMSTART]
"Type" = 1
"Start" = 3
"ErrorControl" = 1
"ImagePath" = "%system%driversMSTART.SYS"
"DisplayName" = "MSTART"
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices
UnzipService]
"Type" = 272
"Start" = 2
"ImagePath" = "%system%Mseus.exe"
"ErrorControl" = 0
"DisplayName" = "Self extract service"
"ObjectName" = "LocalSystem"
"Description" = "Self extract archive decrypt"
"ft1" = %datetime1%
"ft2" = %datetime2%
A string with variable content is used instead of %datetime1-2% .
Spreading
If the current system date and time matches certain conditions, the worm will copy itself into the root folders of the following drives A:, B:, C:, D:, E:, F:, G:, H:, I:, J:, K: using the following name:
The following file is dropped in the same folder:
Thus, the worm ensures it is started each time infected media is inserted into the computer.
Payload information
If the current system date and time matches certain conditions, the worm overwrites the MBR (Master Boot Record) of available drives with its own data.
Example :
The worm displays the following message:
Other information
The worm may delete the following files:
- C:BOOT.INI
- C:NTDETECT.COM
- C:NTLDR
- C:HYBERFILE.SYS
- C:BOOTMGR
- C:BOOT.INI
- C:NTDETECT.COM
- C:NTLDR
- C:HYBERFILE.SYS
- C:BOOTMGR
- C:BOOTMGR.BAK
- C:BOOTSECT
- C:BOOTSECT.BAK
- C:System Volume Information*.*
- D:System Volume Information*.*
- E:System Volume Information*.*
- F:System Volume Information*.*
- G:System Volume Information*.*
- H:System Volume Information*.*
- I:System Volume Information*.*
- J:System Volume Information*.*
- C:Documents and SettingsAdministratorMy Documents*.*
- D:Documents and SettingsAdministratorMy Documents*.*
- E:Documents and SettingsAdministratorMy Documents*.*
- F:Documents and SettingsAdministratorMy Documents*.*
- G:Documents and SettingsAdministratorMy Documents*.*
- H:Documents and SettingsAdministratorMy Documents*.*
- I:Documents and SettingsAdministratorMy Documents*.*
- J:Documents and SettingsAdministratorMy Documents*.*
- C:UsersAdministrator*.*
- D:UsersAdministrator*.*
- E:UsersAdministrator*.*
- F:UsersAdministrator*.*
- G:UsersAdministrator*.*
- H:UsersAdministrator*.*
- I:UsersAdministrator*.*
- J:UsersAdministrator*.*
- C:Documents and Settings*.*
- D:Documents and Settings*.*
- E:Documents and Settings*.*
- F:Documents and Settings*.*
- G:Documents and Settings*.*
- H:Documents and Settings*.*
- I:Documents and Settings*.*
- J:Documents and Settings*.*
- C:Users*.*
- D:Users*.*
- E:Users*.*
- F:Users*.*
- G:Users*.*
- H:Users*.*
- I:Users*.*
- J:Users*.*
- %systemroot%system32drivers*.*
- %systemroot%system32CONFIG*.*
- %systemroot%system32*.*