Selected viruses, spyware, and other threats: sorted alphabetically
Short descriptionWin32/Bogoj.B is a worm that spreads via removable media. The file is run-time compressed using Astrum SFX .
InstallationWhen executed, the worm drops the following files in the %windir% folder:
The following file is dropped in the %temp% folder:
- lsass.exe (77824 B)
- nerodigit16.inf (20480 B)
- services.exe (53248 B)
- uninstlv16.exe (32768 B)
In order to be executed on every system start, the worm sets the following Registry entry:
- errir.exe (20480 B)
The following Registry entries are created:
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed
"StubPath" = "%windir%\uninstlv16.exe"
The worm displays a fake error message:
"Directory" = "%program_files%\torn"
"Version" = "1.00"
"Uninstaller" = "%windir%\torn uninstaller.exe"
Spreading on removable mediaThe worm creates the following folders:
The following file is dropped in the same folder:
The worm creates the following file:
Thus, the worm ensures it is started each time infected media is inserted into the computer.
Information stealingWin32/Bogoj.B is a worm that steals passwords and other sensitive information. The data is saved in the following file:
The worm is able to log keystrokes. The worm can send the information to a remote machine. The worm contains a list of (1) URLs. The HTTP protocol is used.
Other informationThe worm encrypts files on local disks. The extension of the encrypted files is changed to:
The worm deletes the original file. It avoids files which contain any of the following strings in their path:
It avoids files with the following extensions:
- \Program Files\
- \Users\All Users\Microsoft\
When searching the drives, the worm creates the following file in every folder visited:
It contains the following text:
- read this.txt
The worm creates the following files:
- As you probably already noticed, your files on this Pc/laptop are
- That means you cant use them before you decrypt them.
- Decrypthing these files without password and proper software is
- Im the only person in the world who has password and software you
need to decrypt your files.