Home Malware Programs Worms Sygyp

Sygyp

Posted: March 28, 2006

Sygyp, also known as Gypsy, is an Internet worm that spreads by e-mail via messages with infected executable attachments and through network shares. The user can accidentally infect a PC by opening malicious e-mail attachment or running infected, but purportedly useful file.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 asistant_alert.exe
    2 exploit_patcher_v1.0.0.exe
    3 fwall32.reg
    4 googleearthsetup.exe
    5 netalert_v2.4.exe
    6 netwatch_v1.0.3.exe
    7 ntfs32.reg
    8 oe32.reg
    9 reg32.reg
    10 regverif32.exe
    11 sec32.reg
    12 sys32.reg
    13 w32info.reg

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERIdentities[CurrentUserID]SoftwareMicrosoftOutlookExpress[Version]DontShowDialogsCompactDoNotAskAgain=1HKEY_CURRENT_USERIdentities[CurrentUserID]SoftwareMicrosoftOutlookExpress[Version]DontShowDialogsDeleteThreadWarning=6HKEY_CURRENT_USERIdentities[CurrentUserID]SoftwareMicrosoftOutlookExpress[Version]DontShowDialogsMailEmptySubjectWarning=1HKEY_CURRENT_USERIdentities[CurrentUserID]SoftwareMicrosoftOutlookExpress[Version]DontShowDialogsSendMailWarning=1HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableRegistryTools=1HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskmgr=1HKEY_LOCAL_MACHINESOFTWAREGypsyW32.GypsyHKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurityCenterAntiVirusDisableNotify=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurityCenterAntiVirusOverride=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurityCenterFirewallDisableNotify=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurityCenterFirewallOverride=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurityCenterUpdatesDisableNotify=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunHKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLSAcrashonauditfail=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLSAforceguest=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLSAlimitblankpassworduse=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0egvfy32
Loading...