This virus is received in an email message as follows:<br>
<br>
Subject : photos<br>
Body : LOL!;))))<br>
Attachment : photos_arc.exe<br>
<br>
When the attachment is run, the virus copies itself to the WINDOWS (%WinDir%) directory as rasor38a.dll , and to the SYSTEM (%SysDir%) directory as winpsd.exe . <br>
<br>
The virus creates the following registry key values:<br>
<br>
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\<br>
Explorer\ComDlg32 <br>
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\<br>
Explorer\ComDlg32 <br>
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\<br>
Run "winpsd" = C:\WINDOWS\System32\winpsd.exe <br>
The virus downloads a backdoor component from 2 different websites:<br>
<br>
www.richcolour.com <br>
zenandjuice.com <br>
The backdoor component is detected as BackDoor-CHR with the specified DAT files.<br>