1. Home
  2. Computing & Technology
  3. Antivirus Software
Mary Landesman
Mary's Antivirus Software Blog

By Mary Landesman, About.com Guide to Antivirus Software

Private Detective Scare is Storm Trojan

Saturday November 17, 2007
A malicious Trojan is being sent in email claiming the recipient is being spied on and that the password-protected .rar attachment to the message is proof of a previously recorded conversation. The .rar contains an executable file that masquerades as an MP3 music file. In reality, the file is a disguised variant of the Zhelatin family of malware (commonly referred to as the "Storm worm").

The email message body sent by this variant of Zhelatin appears as follows:

I am working in a private detective agency. I can't say my name. I'm warning you that i'm going to overhear your telephone line. Do you want to know who paid for shadowing you? Wait for my next message.

P.S. Of course, you don't believe me. But i think that the record of your yesterday's telephone conversation will change your point. The record is in archive. The password is 123qwe

According to PC Tools ThreatExpert, this latest variant creates a file named "kernelwind32.exe" in the Windows system folder (usually C:\Windows\System32). The registry is modified to load this copy when Windows starts, as follows:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
System = "<path to system folder>\kernelwind32.exe"

A file named "kernelw.sys" is also dropped to the Windows system folder. This file is a kernel mode rootkit that hides itself and other files and processes associated with the infection. The Trojan also modifies the registry to prevent access to the Windows Task Manager.

Rootkit enabled malware is extremely common these days. To bolster your virus protection, use one or more of these free rootkit detectors to scan your system.

Comments
July 16, 2009 at 5:47 am
(1) georg says:

Sounds interesting!

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Explore Antivirus Software
About.com Special Features

Holiday Central

What to eat, where to go, fun things to do and how to save money on the perfect gifts. More >

Family Tech Center

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

  1. Home
  2. Computing & Technology
  3. Antivirus Software

©2009 About.com, a part of The New York Times Company.

All rights reserved.