Win32/Derusbi [Threat Name] go to Threat

Win32/Derusbi.C [Threat Variant Name]

Category trojan
Size 65816 B
Detection created Oct 30, 2012
Detection database version 7642
Aliases TR/Derusbi.C (Avira)
  Trojan.Win32.Agentb.aoni (Kaspersky)
  Infostealer.Derusbi (Symantec)
Short description

The trojan serves as a backdoor. It can be controlled remotely. The trojan is usually a part of other malware.

Installation

When executed, the trojan copies itself into the following location:

  • %windir%\­system32\­msusb%variable1%.hlp

The trojan registers itself as a system service using the following name:

  • wuauserv

The following Registry entries are set:

  • [HKEY_LOCAL_MACHINE\­SYSTEM\­CurrentControlSet\­Services\­wuauserv]
    • "Type" = 32
    • "Start" = 2
    • "ErrorControl" = 0
    • "DisplayName" = "Automatic Updates"
    • "ObjectName" = "LocalSystem"
    • "ImagePath" = "%systemroot%\­System32\­svchost.exe -k netsvcs"
  • [HKEY_LOCAL_MACHINE\­SYSTEM\­CurrentControlSet\­Services\­wuauserv\­Parameters]
    • "Security" = %variable2%
    • "ServiceDll" = "%windir%\­system32\­msusb%variable1%.hlp"

This causes the trojan to be executed on every system start.


A string with variable content is used instead of %variable1-2% .


The trojan creates the following file:

  • %system%\­Drivers\­{93144EB0-8E3E-4591-B307-8EEBFE7DB28F}.sys (21016 B, Win32/Derusbi.F)

The following Registry entries are set:

  • [HKEY_LOCAL_MACHINE\­System\­CurrentControlSet\­Services\­{93144EB0-8E3E-4591-B307-8EEBFE7DB28F}]
    • "Type" = 1
    • "ErrorControl" = 0
    • "Start" = 3
    • "ImagePath" = "%system%\­Drivers\­{93144EB0-8E3E-4591-B307-8EEBFE7DB28F}.sys"

Installs the following system drivers (path, name):

  • %system%\­Drivers\­{93144EB0-8E3E-4591-B307-8EEBFE7DB28F}.sys, {93144EB0-8E3E-4591-B307-8EEBFE7DB28F}

After the installation is complete, the trojan deletes the original executable file.

Other information

The trojan acquires data and commands from a remote computer or the Internet.


It listens on TCP port 40051 .


It can execute the following operations:

  • download files from a remote computer and/or the Internet
  • run executable files
  • update itself to a newer version
  • uninstall itself
  • send requested files
  • send the list of disk devices and their type to a remote computer
  • send the list of files on a specific drive to a remote computer
  • various file system operations
  • execute shell commands

The trojan hides its presence in the system.

Please enable Javascript to ensure correct displaying of this content and refresh this page.