Home / malwarePDF  

Viking.DE


First posted on 01 March 2007.
Source: SecurityHome

Aliases :

Viking.DE is also known as Worm.Win32.Viking.de, Win32/Viking.CH.

Explanation :

Viking.DE, a variant of Viking, is a virus that it infects executable files on all available drives and has network spreading capabilities. The virus copies itself into the Windows directory and drops a DLL that downloads and runs files from a website. Viking.DE has a payload - it kills processes belonging to anti-virus and security software.

cription

Installation to the System

The first time an infected file is run on a clean system, the virus activates and drops the following files into the main Windows directory:


The .DLL component is then injected into the EXPLORER.EXE process. The virus also creates a subfolder named UNINSTALL in the main Windows folder and then drops a file named RUNDL132.EXE at that location. The virus creates a startup value for that dropped file in Windows Registry:


Where %WinDir% represents the main Windows folder (usualy C:Windows).

Viking.DE also adds the following registry entry as a part of its installation:


The virus creates the following text files where it writes some information related to its activities:



Infection of Files

Viking.DE is a prepending virus that searches for .EXE files on all available fixed hard drives and infects them by writing its body before the original file's body. In order for the host file to be run correctly, Viking.DE creates a backup copy of itself in the current directory as [filename].exe.exe and then drops and executes the original file as [filename].exe. After that, it deletes the uninfected original file and renames the backup file with the original filename. Viking.DE is able to do this with the help of a temporary batch file that it creates in the system's designated temporary folder as $$ad.bat.

Viking.DE virus avoids infecting files with the following strings in their paths or filenames:



Network Spreading Capabilities

The virus also attempts to propagate via network shares by copying itself to the following shared folders:


- with the following accounts:



Payload

As a part of the payload, the virus stops the following service:


- and terminates the following processes related to several anti-virus products:


The DLL component of Viking.DE virus attempts to download and execute files from Internet.

Last update 01 March 2007

 

TOP

Malware :

Family: