Home > Support > Global Security Advisor 

Virus Detail

Win32.Chisyne.F

Date Published:
26 Apr 2005

Last Updated:
27 Apr 2005

Threat Assessment

Overall Risk:   Very Low
Wild:  Low
Destructiveness:  Medium
Pervasiveness:  None

Characteristics

Type : Trojan

Category : Win32

Also known as:  Downloader-ZM (McAfee)

Immediate Protection Info

 
SignatureProductRemoval Instructions
11.x/9096
eTrust Antivirus v7/8* (Vet Engine)
6.2x/9096
eTrust EZ Antivirus 6.2x
6.3x/9096
eTrust EZ Antivirus 6.3x
6.4x/9096
eTrust EZ Antivirus 6.4x
7.x/9096
eTrust EZ Antivirus 7.x
10.6x/9096
Vet Anti-Virus 10.6x
 
 
 

Description

Win32.Chisyne.F is a trojan that downloads and executes files from the Internet.

Back to top

Method of Infection

When executed, Win32.Chisyne.F drops the DLL "req.dll" into the %System% folder. The trojan sets this DLL as a hidden file and modifies security settings so that it cannot be changed. This DLL performs the rest of the trojan's functionality.


The trojan hooks this DLL into the Explorer.exe process so that it can hide it's presence. The trojan also sets the following registry values so that the DLL is loaded each time the affected user logs into Windows:
 
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\req\DllName = %System%\reg.dll
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\req\Asynchronous 1
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\req\Impersonate = 0
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\req\Logon = "Logon"
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\req\Logoff = "Logoff"


Note: '%System%' is a variable location. The malware determines the location of the current System folder by querying the operating system. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; and for XP is C:\Windows\System32.


The trojan also installs itself as a Browser Helper Object so that it runs everytime Internet Explorer is executed:


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}
HKCR\CLSID\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}\InprocServer32\(Default) = "C:\WINDOWS\System32\req.dll"
HKCR\CLSID\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}\InprocServer32\ThreadingModel = "Both"


Back to top

Payload

Downloads and Executes Arbitrary Files

The trojans primary function is to download and execute files from the domain "ushuistov.net". The trojan downloads a file from this domain and saves it to "%System%\psc.exe".


Analysis by Amir Fouda


Back to top

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All

Security Resources

 
 
Page Tools