Alerts
Moderators: Moderator, Global Moderator
Alerts
[color=\"#41121C\"]Please post virus alerts only in this section. Include a link to "more info" if you have it, the source you got the alert from, and a link to legitimate removal tools.[/color]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
[color=\"#41121C\"][b]Originally Posted On GraphixGround by Trinity on May 2 2004[/b]
[b]W32.Sasser.B.Worm[/b]
This is a version of the Sasser worm, and has been given a Level 4 threat rating from Symantec.
Symantec Virus Information:[/color]
[quote]W32.Sasser.B.Worm is a variant of W32.Sasser.Worm. It attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin MS04-011, and spreads by scanning randomly-chosen IP addresses for vulnerable systems.
--------------------------------------------------------------------------------
Notes:
The MD5 hash value for this worm is 0x1A2C0E6130850F8FD9B9B5309413CD00.
Symantec Security Response has developed a removal tool to clean the infections of W32.Sasser.B.Worm.
Block TCP ports 5554, 9996 and 445 at the perimeter firewall and install the appropriate Microsoft patch (MS04-011) to prevent remote exploitation of the vulnerability.
--------------------------------------------------------------------------------
Security Response is upgrading W32.Sasser.B.Worm to a Category 4 from a Category 3 based on increased rate of submissions.
Also Known As: WORM_SASSER.B [Trend], W32/Sasser.worm.b [McAfee]
Variants: W32.Sasser.Worm
Type: Worm
Infection Length: 15872 bytes
Systems Affected: Windows 2000, Windows Server 2003, Windows XP
Virus Definitions (Intelligent Updater) *
May 01, 2004
Virus Definitions (LiveUpdate™) **
May 01, 2004
*
Intelligent Updater definitions are released daily, but require manual download and installation.
Click here to download manually.
**
LiveUpdate virus definitions are usually released every Wednesday.
Click here for instructions on using LiveUpdate.
Wild:
Number of infections: More than 1000
Number of sites: More than 10
Geographical distribution: Medium
Threat containment: Easy
Removal: Moderate
Threat Metrics
Wild:
High
Damage:
Low
Distribution:
High
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Causes significant degradation in performance
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP 445, 5554, 9996
Shared drives: n/a
Target of infection: Unpatched systems vulnerable to LSASS exploit - MS04-011
When W32.Sasser.B.Worm runs, it does the following:
Attempts to create a mutex called Jobaka3 and exits if the attempt fails. This ensures that no more than one instance of the worm can run on the computer at any time.
Copies itself as %Windir%\avserve2.exe.
--------------------------------------------------------------------------------
Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
--------------------------------------------------------------------------------
Adds the value:
"avserve2.exe"="%Windir%\avserve2.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Uses the AbortSystemShutdown API to hinder attempts to shut down or restart the computer.
Starts an FTP server on TCP port 5554. This server is used to spread the worm to other hosts.
Attempts to connect to randomly-generated IP addresses on TCP port 445. If a connection is made to a computer, the worm sends shellcode to that computer which may cause it to run a remote shell on TCP port 9996. The worm then uses the shell to cause the computer to connect back to the FTP server on port 5554 and retrieve a copy of the worm. This copy will have a name consisting of 4 or 5 digits followed by _up.exe (eg 74354_up.exe).[/quote]
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html\"]Link To Full Virus Info[/url]
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html\"]Link To Symantec Removal Tool[/url]
[b]W32.Sasser.B.Worm[/b]
This is a version of the Sasser worm, and has been given a Level 4 threat rating from Symantec.
Symantec Virus Information:[/color]
[quote]W32.Sasser.B.Worm is a variant of W32.Sasser.Worm. It attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin MS04-011, and spreads by scanning randomly-chosen IP addresses for vulnerable systems.
--------------------------------------------------------------------------------
Notes:
The MD5 hash value for this worm is 0x1A2C0E6130850F8FD9B9B5309413CD00.
Symantec Security Response has developed a removal tool to clean the infections of W32.Sasser.B.Worm.
Block TCP ports 5554, 9996 and 445 at the perimeter firewall and install the appropriate Microsoft patch (MS04-011) to prevent remote exploitation of the vulnerability.
--------------------------------------------------------------------------------
Security Response is upgrading W32.Sasser.B.Worm to a Category 4 from a Category 3 based on increased rate of submissions.
Also Known As: WORM_SASSER.B [Trend], W32/Sasser.worm.b [McAfee]
Variants: W32.Sasser.Worm
Type: Worm
Infection Length: 15872 bytes
Systems Affected: Windows 2000, Windows Server 2003, Windows XP
Virus Definitions (Intelligent Updater) *
May 01, 2004
Virus Definitions (LiveUpdate™) **
May 01, 2004
*
Intelligent Updater definitions are released daily, but require manual download and installation.
Click here to download manually.
**
LiveUpdate virus definitions are usually released every Wednesday.
Click here for instructions on using LiveUpdate.
Wild:
Number of infections: More than 1000
Number of sites: More than 10
Geographical distribution: Medium
Threat containment: Easy
Removal: Moderate
Threat Metrics
Wild:
High
Damage:
Low
Distribution:
High
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Causes significant degradation in performance
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP 445, 5554, 9996
Shared drives: n/a
Target of infection: Unpatched systems vulnerable to LSASS exploit - MS04-011
When W32.Sasser.B.Worm runs, it does the following:
Attempts to create a mutex called Jobaka3 and exits if the attempt fails. This ensures that no more than one instance of the worm can run on the computer at any time.
Copies itself as %Windir%\avserve2.exe.
--------------------------------------------------------------------------------
Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
--------------------------------------------------------------------------------
Adds the value:
"avserve2.exe"="%Windir%\avserve2.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Uses the AbortSystemShutdown API to hinder attempts to shut down or restart the computer.
Starts an FTP server on TCP port 5554. This server is used to spread the worm to other hosts.
Attempts to connect to randomly-generated IP addresses on TCP port 445. If a connection is made to a computer, the worm sends shellcode to that computer which may cause it to run a remote shell on TCP port 9996. The worm then uses the shell to cause the computer to connect back to the FTP server on port 5554 and retrieve a copy of the worm. This copy will have a name consisting of 4 or 5 digits followed by _up.exe (eg 74354_up.exe).[/quote]
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html\"]Link To Full Virus Info[/url]
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html\"]Link To Symantec Removal Tool[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Adware.NDotNet
Last Updated on: February 05, 2004 09:43:24 AM
Type: Adware
Version: 3.8
Publisher: NewDotNet
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX
Removal: Low
Damage: Low
This threat can be detected only by Symantec products that support expanded threats. For more information on expanded threats, please go here.
Behavior
Adware.NDotNet is an adware program that displays advertisements based on keywords. This adware component works as a Browser Helper Object.
Symptoms
Your Symantec antivirus program detects Adware.NDotNet.
Transmission
This adware component must be manually installed or installed as a component of another program that you install.
File names:
Newdotnet3_88.dkk
Nnezt388.exe
When Adware.NDotNet is installed, it performs the following actions:
Creates the folder, C:\Program Files\NewDotNet, and copies files into it.
Adds the value:
"New.net Startup"="rundll32 C:\Progra~1\Newdot~1\Newdot~1.dll, NewDotNetStartup"
to the following registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Creates the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\Uninstall\New.net
HKEY_LOCAL_MACHINE\SOFTWARE\New.net
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2
\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004
HKEY_CLASSES_ROOT\CLSID\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E
HKEY_CLASSES_ROOT\Tldctl2.URLLink
HKEY_CLASSES_ROOT\Tldctl2.URLLink.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Tldctl2.URLLink
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Tldctl2.URLLink.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\Explorer\Browser Helper Objects\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}
Attempts to automatically update itself.
--------------------------------------------------------------------------------
Notes:
Adware.NDotNet runs as a Browser Helper Object, which means that the adware component receives information regarding all the actions inside Internet Explorer. This Browser Helper Object requires Internet Explorer 4.0 or later to function.
This adware component appears to track Internet usage habits, but without using any identification parameters. It does not appear to track personally identifiable information.
--------------------------------------------------------------------------------
This adware program must be manually installed. However, there are several known programs that have Adware.NDotNet within them and that install it as the program itself is installed.
--------------------------------------------------------------------------------
Note: Removing this adware component from the system will likely cause the program that installed it to not function as intended. The uninstaller generally identifies the programs that will not work after uninstallation.
--------------------------------------------------------------------------------
The following instructions pertain to all Symantec antivirus products that support Expanded Threat detection.
Update the definitions.
Uninstall New.net using the Add/Remove Programs utility in Control Panel.
Run a full system scan, and delete all files that are detected as Adware.NDotNet.
For specific details on each of these steps, read the following instructions.
1. Updating the definitions
To obtain the most recent definitions, start your Symantec program and run LiveUpdate.
2. Uninstalling the Adware
Do one of the following:
On the Windows 98 taskbar:
Click Start > Settings > Control Panel.
In the Control Panel window, double-click Add/Remove Programs.
On the Windows Me taskbar:
Click Start > Settings > Control Panel.
In the Control Panel window, double-click Add/Remove Programs.
If you do not see the Add/Remove Programs icon, click "...view all Control Panel options."
On the Windows 2000 taskbar:
By default, Windows 2000 is set up the same as Windows 98. In that case, follow the Windows 98 instructions. Otherwise, click Start > Settings > Control Panel, and then click Add/Remove Programs.
On the Windows XP taskbar:
Click Start > Control Panel.
In the Control Panel window, double-click Add or Remove Programs.
Click New.net Domains 3.88.
--------------------------------------------------------------------------------
Note: You may need to use the scroll bar to view the entire list.
--------------------------------------------------------------------------------
Click Add/Remove, Change/Remove, or Remove (depending on the operating system). Follow the prompts.
3. Scanning for and deleting the files
Start your Symantec antivirus program, and run a full system scan.
If any files are detected as Adware.NDotNet, click Delete.
--------------------------------------------------------------------------------
Notes:
If your Symantec antivirus product reports that it cannot delete a detected file, write down the path and file name. Then use Windows Explorer to locate and delete the file.
If you ran the Add/Remove programs applet as described in the previous section, it is possible that all files were removed; therefore, none will be detected.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/adware.ndotnet.html\"]Symantec[/url].
Last Updated on: February 05, 2004 09:43:24 AM
Type: Adware
Version: 3.8
Publisher: NewDotNet
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX
Removal: Low
Damage: Low
This threat can be detected only by Symantec products that support expanded threats. For more information on expanded threats, please go here.
Behavior
Adware.NDotNet is an adware program that displays advertisements based on keywords. This adware component works as a Browser Helper Object.
Symptoms
Your Symantec antivirus program detects Adware.NDotNet.
Transmission
This adware component must be manually installed or installed as a component of another program that you install.
File names:
Newdotnet3_88.dkk
Nnezt388.exe
When Adware.NDotNet is installed, it performs the following actions:
Creates the folder, C:\Program Files\NewDotNet, and copies files into it.
Adds the value:
"New.net Startup"="rundll32 C:\Progra~1\Newdot~1\Newdot~1.dll, NewDotNetStartup"
to the following registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Creates the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\Uninstall\New.net
HKEY_LOCAL_MACHINE\SOFTWARE\New.net
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2
\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004
HKEY_CLASSES_ROOT\CLSID\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E
HKEY_CLASSES_ROOT\Tldctl2.URLLink
HKEY_CLASSES_ROOT\Tldctl2.URLLink.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Tldctl2.URLLink
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Tldctl2.URLLink.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\Explorer\Browser Helper Objects\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}
Attempts to automatically update itself.
--------------------------------------------------------------------------------
Notes:
Adware.NDotNet runs as a Browser Helper Object, which means that the adware component receives information regarding all the actions inside Internet Explorer. This Browser Helper Object requires Internet Explorer 4.0 or later to function.
This adware component appears to track Internet usage habits, but without using any identification parameters. It does not appear to track personally identifiable information.
--------------------------------------------------------------------------------
This adware program must be manually installed. However, there are several known programs that have Adware.NDotNet within them and that install it as the program itself is installed.
--------------------------------------------------------------------------------
Note: Removing this adware component from the system will likely cause the program that installed it to not function as intended. The uninstaller generally identifies the programs that will not work after uninstallation.
--------------------------------------------------------------------------------
The following instructions pertain to all Symantec antivirus products that support Expanded Threat detection.
Update the definitions.
Uninstall New.net using the Add/Remove Programs utility in Control Panel.
Run a full system scan, and delete all files that are detected as Adware.NDotNet.
For specific details on each of these steps, read the following instructions.
1. Updating the definitions
To obtain the most recent definitions, start your Symantec program and run LiveUpdate.
2. Uninstalling the Adware
Do one of the following:
On the Windows 98 taskbar:
Click Start > Settings > Control Panel.
In the Control Panel window, double-click Add/Remove Programs.
On the Windows Me taskbar:
Click Start > Settings > Control Panel.
In the Control Panel window, double-click Add/Remove Programs.
If you do not see the Add/Remove Programs icon, click "...view all Control Panel options."
On the Windows 2000 taskbar:
By default, Windows 2000 is set up the same as Windows 98. In that case, follow the Windows 98 instructions. Otherwise, click Start > Settings > Control Panel, and then click Add/Remove Programs.
On the Windows XP taskbar:
Click Start > Control Panel.
In the Control Panel window, double-click Add or Remove Programs.
Click New.net Domains 3.88.
--------------------------------------------------------------------------------
Note: You may need to use the scroll bar to view the entire list.
--------------------------------------------------------------------------------
Click Add/Remove, Change/Remove, or Remove (depending on the operating system). Follow the prompts.
3. Scanning for and deleting the files
Start your Symantec antivirus program, and run a full system scan.
If any files are detected as Adware.NDotNet, click Delete.
--------------------------------------------------------------------------------
Notes:
If your Symantec antivirus product reports that it cannot delete a detected file, write down the path and file name. Then use Windows Explorer to locate and delete the file.
If you ran the Add/Remove programs applet as described in the previous section, it is possible that all files were removed; therefore, none will be detected.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/adware.ndotnet.html\"]Symantec[/url].

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
July 5 2005
W32.Evaman@mm is a mass-mailing worm that spreads to addresses found at the website email.people.yahoo.com. This worm arrives as an attachment with a .exe or .scr extension. Note: Symantec Consumer products that support Worm Blocking functionality automatically detect this threat as it attempts to spread.
Type: Worm
Infection Length: 14,848 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x
When W32.Evaman@mm is executed, it does the following:
May launch Notepad.exe the first time it is executed.
Creates the registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Wintasks
Copies itself as %System%\wintasks.exe.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"wintasks.exe"="%System%\wintasks.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Selects an smtp server from the following hardcoded list:
smtp.rcn.com
outgoing.verizon.net
smtp.comcast.net
mail.mindspring.com
smtp.email.msn.com
smtpauth.earthlink.net
smtp-server.nc.rr.com
smtp1.attglobal.net
mailhost.att.net
mail.optonline.net
mail.peoplepc.com
smtpout.bellatlantic.net
mail.verio.net
smtp.netzero.net
smtp.prodigy.net
The worm uses the first server that it successfully connects to. If it is unable to connect to any of these servers, the worm queries the registry key
HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\SMTP Server
to find a mail server.
Generates random queries to email.people.yahoo.com, and collects email addresses from the search results.
Sends itself to the addresses that it finds with a spoofed From address. The message has the following characteristics:
Subject: one of the following:
Delivery Status (Failure)
failed transaction
failure delivery
mail failure
returned mail
server error
Attachment: the attachment has the form <first part>.<last part>,
where <first part> is one of:
body
message
email
returned
text
document
and <last part> is one of:
scr
txt.scr
html.scr
outlook.scrtxt.exe
Message: one of the following:
This is an automatically generated Delivery Status Notification.
Delivery to last recipient failed.
Email returned as attachment text file.
Message from Mail Delivery Server.
Unable to deliver message to last recipient.
Email returned as text file.
Email returned by the server as ASCII Text mail file.
To read the email download the included attachment.
Mail Server Notice:
Last email sent could not reach intented destination.
Email returned as ASCII text file.
The last email sent by this account could not reach intended destination.
Email has been returned as text file attachment.
Mail Delivery Status Notification:
Message returned by server. Message returned as text file attachment.
[url=\"http://www.sarc.com/avcenter/venc/data/w32.evaman@mm.html#removalinstructions\"]Symantec Removal Instructions & Further Information[/url]
[url=\"http://vil.nai.com/vil/content/v_126563.htm\"]McAfee[/url]
[url=\"http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39513\"]Computer Associates[/url]
W32.Evaman@mm is a mass-mailing worm that spreads to addresses found at the website email.people.yahoo.com. This worm arrives as an attachment with a .exe or .scr extension. Note: Symantec Consumer products that support Worm Blocking functionality automatically detect this threat as it attempts to spread.
Type: Worm
Infection Length: 14,848 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x
When W32.Evaman@mm is executed, it does the following:
May launch Notepad.exe the first time it is executed.
Creates the registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Wintasks
Copies itself as %System%\wintasks.exe.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"wintasks.exe"="%System%\wintasks.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Selects an smtp server from the following hardcoded list:
smtp.rcn.com
outgoing.verizon.net
smtp.comcast.net
mail.mindspring.com
smtp.email.msn.com
smtpauth.earthlink.net
smtp-server.nc.rr.com
smtp1.attglobal.net
mailhost.att.net
mail.optonline.net
mail.peoplepc.com
smtpout.bellatlantic.net
mail.verio.net
smtp.netzero.net
smtp.prodigy.net
The worm uses the first server that it successfully connects to. If it is unable to connect to any of these servers, the worm queries the registry key
HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\SMTP Server
to find a mail server.
Generates random queries to email.people.yahoo.com, and collects email addresses from the search results.
Sends itself to the addresses that it finds with a spoofed From address. The message has the following characteristics:
Subject: one of the following:
Delivery Status (Failure)
failed transaction
failure delivery
mail failure
returned mail
server error
Attachment: the attachment has the form <first part>.<last part>,
where <first part> is one of:
body
message
returned
text
document
and <last part> is one of:
scr
txt.scr
html.scr
outlook.scrtxt.exe
Message: one of the following:
This is an automatically generated Delivery Status Notification.
Delivery to last recipient failed.
Email returned as attachment text file.
Message from Mail Delivery Server.
Unable to deliver message to last recipient.
Email returned as text file.
Email returned by the server as ASCII Text mail file.
To read the email download the included attachment.
Mail Server Notice:
Last email sent could not reach intented destination.
Email returned as ASCII text file.
The last email sent by this account could not reach intended destination.
Email has been returned as text file attachment.
Mail Delivery Status Notification:
Message returned by server. Message returned as text file attachment.
[url=\"http://www.sarc.com/avcenter/venc/data/w32.evaman@mm.html#removalinstructions\"]Symantec Removal Instructions & Further Information[/url]
[url=\"http://vil.nai.com/vil/content/v_126563.htm\"]McAfee[/url]
[url=\"http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39513\"]Computer Associates[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Lovgate.AB@mm is mass-mailing worm that also spreads through open network shares. Once a system is infected, it can be accessed by a remote attacker. The email will have a variable subject and a file attachment with an .exe, .pif, .scr,.com,. rar or .zip file extension.The worm also infects other Windows executable(.exe) files
Type: Worm
Infection Length: 183,296
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 64-bit (AMD64), Windows 64-bit (IA64)
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Wild:
Low
Damage:
Low
Distribution:
High
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Attempts to reply to incoming email messages
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates processes belonging to various antivirus programs.
Distribution
Subject of email: Varies
Name of attachment: Varies with .exe, .pif, .scr, .com, or .rar as the extension
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: Copies itself to network-shared folders
Target of infection: n/a
When W32.Lovgate.AB@mm runs, it performs the following actions:
Copies itself as the following files:
%Windir%\SYSTRA.EXE
%System%\hxdef.exe
%System%\IEXPLORE.EXE
%System%\RAVMOND.exe
%System%\internet.exe
%System%\svch0st.exe
%System%\kernel66.dll ( With attributes set to Read Only, Hidden, and System)
Notes:
%Windir% is a variable: The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
%System% is a variable: The worm locates the System folder and copies itself to that location. By default, this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following files:
%System%\ODBC16.dll (53,248 bytes)
%System%\msjdbc11.dll (53,248 bytes)
%System%\MSSIGN30.DLL (53,248 bytes)
%System%\WIN32VXD.DLL (53,248 bytes)
which are identical backdoor components of the worm.
Creates a file named AUTORUN.INF in the root folder of all the drives, except the CD-ROM drives, and copies itself as COMMAND.EXE into that folder.
Adds the values:
"NetworkAssociates Inc" = "internet.exe"
"Hardware Profile" = "%system%\hxdef.exe"
"Program In Windows" = "%system%\IEXPLORE.EXE"
"Microsoft NetMeeting Associates, Inc." = NetMeeting.exe"
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXEMSSIGN30.DLL ondll_reg"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLLondll_reg"
"Shell Extension" = "%system%\spollsv.exe"
"S0undMan" = "%system%\svch0st.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
so the worm runs when you start Windows.
Adds the values:
"SystemTra"="%Windir%\SysTra.EXE"
"COM+ Event System"="DRWTSN16.EXE"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
so that the worm runs as a service when you start Windows.
On Windows NT/2000/XP, adds the value:
"run"="RAVMOND.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\
Creates a service, "Windows Management Protocol v.0 (experimental)", which is mapped to "Rundll32.exe msjdbc11.dll ondll_server."
Creates the service, "_reg", which is mapped to "Rundll32.exe msjdbc11.dll ondll_server".
Terminates all the processes that contains any of the following strings:
Duba
NAV
kill
RavMon.exe
Rfw.exe
Gate
McAfee
Symantec
SkyNet
rising
Copies itself to all the network-shared folders and subfolders as any of the following:
WinRAR.exe
Internet Explorer.bat
Documents and Settings.txt.exe
Microsoft Office.exe
Windows Media Player.zip.exe
Support Tools.exe
WindowsUpdate.pif
Cain.pif
MSDN.ZIP.pif
autoexec.bat
findpass.exe
client.exe
i386.exe
winhlp32.exe
xcopy.exe
mmc.exe
Creates a .zip file in the root folder of all drives, unless the drive letter is A or B.
Filename: (One of the following)
letter
bak
WORK
install
Extension: (One of the following)
.RAR
.ZIP
Scans all the computers on the local network, using the following passwords to attempt to log on as "Guest", "Admin" or"Administrator."
Guest
Administrator
zxcv
yxcv
xxx
win
test123
test
temp123
temp
sybase
super
sex
secret
pwd
pw123
Password
owner
oracle
mypc123
mypc
mypass123
mypass
love
login
Login
Internet
home
godblessyou
god
enable
database
computer
alpha
admin123
Admin
abcd
aaa
88888888
2600
2004
2003
123asd
123abc
123456789
1234567
123123
121212
11111111
110
007
00000000
000000
pass
54321
12345
password
passwd
server
sql
!@#$%^&*
!@#$%^&
!@#$%^
!@#$%
asdfgh
asdf
!@#$
1234
111
root
abc123
12345678
abcdefg
abcdef
abc
888888
666666
111111
admin
administrator
guest
654321
123456
321
123
If the worm successfully logs on to the remote computer, it will attempt to copy itself as:
\\<remote computer name>\admin$\system32\NetManager.exe
and to start the file as the service, "Windows Management NetWork Service Extensions"
It will also create a network share named "Media".
Replies to all the incoming email messages when they arrive in the mailbox of certain MAPI-compliant email clients, such as Microsoft Outlook.
If the original email is:
Subject: <subject>
From: <someone>@<somewhere.com>
Message: <original message body>
the worm will attempt to send the following email:
Subject: Re: <subject>
To: <someone>@<somewhere.com>
Message:
'<someone>' wrote:
====
> <original message body>
>
====
<sender's domain> account auto-reply:
followed by one of the following:
If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about,don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;
... ... more look to the attachment.
> Get your FREE <sender's domain>now! <
Attachment: (One of the following)
the hardcore game-.pif
Sex in Office.rm.scr
Deutsch BloodPatch!.exe
s3msong.MP3.pif
Me_nude.AVI.pif
How to Crack all gamez.exe
Macromedia Flash.scr
SETUP.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
DSL Modem Uncapper.rar.exe
joke.pif
Britney spears nude.exe.txt.exe
I am For u.doc.exe
Retrieves email addresses on the infected machine and sends an email with the following properties:
Subject: (One of the following)
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error
Message: (One of the following)
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.
The message contains Unicode characters and has been sent as a binary attachment.
Mail failed. For further assistance, please contact!
Extension: (One of the following)
.exe
.scr
.pif
.com
.rar
Opens a backdoor on a random port.
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Reverse the changes made to the registry.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and repair files detected as W32.Lovgate.AB@mm.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.ab@mm.html\"]Symantec Full Information[/url]
Type: Worm
Infection Length: 183,296
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 64-bit (AMD64), Windows 64-bit (IA64)
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Wild:
Low
Damage:
Low
Distribution:
High
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Attempts to reply to incoming email messages
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates processes belonging to various antivirus programs.
Distribution
Subject of email: Varies
Name of attachment: Varies with .exe, .pif, .scr, .com, or .rar as the extension
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: Copies itself to network-shared folders
Target of infection: n/a
When W32.Lovgate.AB@mm runs, it performs the following actions:
Copies itself as the following files:
%Windir%\SYSTRA.EXE
%System%\hxdef.exe
%System%\IEXPLORE.EXE
%System%\RAVMOND.exe
%System%\internet.exe
%System%\svch0st.exe
%System%\kernel66.dll ( With attributes set to Read Only, Hidden, and System)
Notes:
%Windir% is a variable: The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
%System% is a variable: The worm locates the System folder and copies itself to that location. By default, this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following files:
%System%\ODBC16.dll (53,248 bytes)
%System%\msjdbc11.dll (53,248 bytes)
%System%\MSSIGN30.DLL (53,248 bytes)
%System%\WIN32VXD.DLL (53,248 bytes)
which are identical backdoor components of the worm.
Creates a file named AUTORUN.INF in the root folder of all the drives, except the CD-ROM drives, and copies itself as COMMAND.EXE into that folder.
Adds the values:
"NetworkAssociates Inc" = "internet.exe"
"Hardware Profile" = "%system%\hxdef.exe"
"Program In Windows" = "%system%\IEXPLORE.EXE"
"Microsoft NetMeeting Associates, Inc." = NetMeeting.exe"
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXEMSSIGN30.DLL ondll_reg"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLLondll_reg"
"Shell Extension" = "%system%\spollsv.exe"
"S0undMan" = "%system%\svch0st.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
so the worm runs when you start Windows.
Adds the values:
"SystemTra"="%Windir%\SysTra.EXE"
"COM+ Event System"="DRWTSN16.EXE"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
so that the worm runs as a service when you start Windows.
On Windows NT/2000/XP, adds the value:
"run"="RAVMOND.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\
Creates a service, "Windows Management Protocol v.0 (experimental)", which is mapped to "Rundll32.exe msjdbc11.dll ondll_server."
Creates the service, "_reg", which is mapped to "Rundll32.exe msjdbc11.dll ondll_server".
Terminates all the processes that contains any of the following strings:
Duba
NAV
kill
RavMon.exe
Rfw.exe
Gate
McAfee
Symantec
SkyNet
rising
Copies itself to all the network-shared folders and subfolders as any of the following:
WinRAR.exe
Internet Explorer.bat
Documents and Settings.txt.exe
Microsoft Office.exe
Windows Media Player.zip.exe
Support Tools.exe
WindowsUpdate.pif
Cain.pif
MSDN.ZIP.pif
autoexec.bat
findpass.exe
client.exe
i386.exe
winhlp32.exe
xcopy.exe
mmc.exe
Creates a .zip file in the root folder of all drives, unless the drive letter is A or B.
Filename: (One of the following)
letter
bak
WORK
install
Extension: (One of the following)
.RAR
.ZIP
Scans all the computers on the local network, using the following passwords to attempt to log on as "Guest", "Admin" or"Administrator."
Guest
Administrator
zxcv
yxcv
xxx
win
test123
test
temp123
temp
sybase
super
sex
secret
pwd
pw123
Password
owner
oracle
mypc123
mypc
mypass123
mypass
love
login
Login
Internet
home
godblessyou
god
enable
database
computer
alpha
admin123
Admin
abcd
aaa
88888888
2600
2004
2003
123asd
123abc
123456789
1234567
123123
121212
11111111
110
007
00000000
000000
pass
54321
12345
password
passwd
server
sql
!@#$%^&*
!@#$%^&
!@#$%^
!@#$%
asdfgh
asdf
!@#$
1234
111
root
abc123
12345678
abcdefg
abcdef
abc
888888
666666
111111
admin
administrator
guest
654321
123456
321
123
If the worm successfully logs on to the remote computer, it will attempt to copy itself as:
\\<remote computer name>\admin$\system32\NetManager.exe
and to start the file as the service, "Windows Management NetWork Service Extensions"
It will also create a network share named "Media".
Replies to all the incoming email messages when they arrive in the mailbox of certain MAPI-compliant email clients, such as Microsoft Outlook.
If the original email is:
Subject: <subject>
From: <someone>@<somewhere.com>
Message: <original message body>
the worm will attempt to send the following email:
Subject: Re: <subject>
To: <someone>@<somewhere.com>
Message:
'<someone>' wrote:
====
> <original message body>
>
====
<sender's domain> account auto-reply:
followed by one of the following:
If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about,don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;
... ... more look to the attachment.
> Get your FREE <sender's domain>now! <
Attachment: (One of the following)
the hardcore game-.pif
Sex in Office.rm.scr
Deutsch BloodPatch!.exe
s3msong.MP3.pif
Me_nude.AVI.pif
How to Crack all gamez.exe
Macromedia Flash.scr
SETUP.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
DSL Modem Uncapper.rar.exe
joke.pif
Britney spears nude.exe.txt.exe
I am For u.doc.exe
Retrieves email addresses on the infected machine and sends an email with the following properties:
Subject: (One of the following)
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error
Message: (One of the following)
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.
The message contains Unicode characters and has been sent as a binary attachment.
Mail failed. For further assistance, please contact!
Extension: (One of the following)
.exe
.scr
.pif
.com
.rar
Opens a backdoor on a random port.
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Reverse the changes made to the registry.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and repair files detected as W32.Lovgate.AB@mm.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.ab@mm.html\"]Symantec Full Information[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.Ecure.C
Discovered on: July 07, 2004
Last Updated on: July 07, 2004 01:51:34 PM
Trojan.Ecure.C is a Trojan horse that modifies the Hosts file and the Internet Explorer home page.
Variants: Trojan.Ecure
Type: Trojan Horse
Infection Length: 5,632 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Wild:
Low
Damage:
Low
Distribution:
Low
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: Modifies the Hosts file.
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.Ecure.C is executed, it performs the following actions:
Creates the file, %Windir%\secure.html.
Note: %Windir% is a variable. The Trojan locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
Modifies the values:
"Local Page"="%Windir%\secure.html"
"Start Page"="%Windir%\secure.html"
"Default_Page_URL"="%Windows%\secure.html"
to the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
which change the Internet Explorer home page to %Windir%\secure.html.
Adds the following entries to the Hosts file:
127.0.0.1 ruworld.com
127.0.0.1 maxxxhosters.com
127.0.0.1 therealsearch.com
127.0.0.1 thumbest-traffic.com
127.0.0.1 600pics.com
127.0.0.1 tonser.4-counter.com
127.0.0.1 free.sinpussy.com
127.0.0.1 hightcalldialer.com
127.0.0.1 bestpornnews.com
127.0.0.1 thumberland.com
127.0.0.1 greg-search.com
127.0.0.1 connect.online-dialer.com
127.0.0.1 0190-dialer.com
127.0.0.1 approvedlinks.com
127.0.0.1 download.buxomatic.com
127.0.0.1 dia.4-counter.com
127.0.0.1 vse-moe.biz
127.0.0.1 crue.global-counter.com
127.0.0.1 line-plus.com
127.0.0.1 porno-links.biz
127.0.0.1 download.tntdialer.com
127.0.0.1 freelivesex.org
127.0.0.1 free3xmatures.com
127.0.0.1 bestpics.net
127.0.0.1 dikai.com
127.0.0.1 world-search.biz
127.0.0.1 1-se.com
127.0.0.1 58q.com
127.0.0.1 aifind.cc
127.0.0.1 aifind.info
127.0.0.1 allneedsearch.com
127.0.0.1 auto.ie.searchforge.com
127.0.0.1 awebfind.biz
127.0.0.1 best.royalsearch.net
127.0.0.1 cracks.am
127.0.0.1 default-homepage-network.com
127.0.0.1 find.microgirls.com
127.0.0.1 find4u.net
127.0.0.1 freshvideogals.com
127.0.0.1 i-lookup.com
127.0.0.1 ie-search.com
127.0.0.1 in.webcounter.cc
127.0.0.1 itseasy.us
127.0.0.1 just.find-itnow.com
127.0.0.1 link.startmake.com
127.0.0.1 mysearchnow.com
127.0.0.1 nativehardcore.com
127.0.0.1 qwertysearch123.biz
127.0.0.1 search.ieplugin.com
127.0.0.1 search.psn.cn
127.0.0.1 searchbar.findthewebsiteyouneed.com
127.0.0.1 searchcentrix.com
127.0.0.1 searchmyrequest.com
127.0.0.1 super-spider.com
127.0.0.1 t.rack.cc
127.0.0.1 teen-biz.com
127.0.0.1 teenhqpics.com
127.0.0.1 tits.hardcore4ever.net
127.0.0.1 webcoolsearch.com
127.0.0.1 wmmse.com
127.0.0.1 008i.com
127.0.0.1 2fastsearch.net
127.0.0.1 8095.com
127.0.0.1 alfa-search.com
127.0.0.1 boredlife.com
127.0.0.1 couldnotfind.com
127.0.0.1 cracks.am
127.0.0.1 daum.net
127.0.0.1 dreamwiz.com
127.0.0.1 find-itnow.com
127.0.0.1 find4u.net
127.0.0.1 firstbookmark.com
127.0.0.1 gajai.com
127.0.0.1 hand-book.com
127.0.0.1 hao123.com
127.0.0.1 hotsearchbox.com
127.0.0.1 hotwebsearch.com
127.0.0.1 hugesearch.net
127.0.0.1 iquicksearch.com
127.0.0.1 lookfor.cc
127.0.0.1 naver.com
127.0.0.1 nkvd.us
127.0.0.1 novafuck.com
127.0.0.1 ohcorea.com
127.0.0.1 omega-search.com
127.0.0.1 onet.pl
127.0.0.1 power-search.info
127.0.0.1 rightfinder.net
127.0.0.1 search-1.net
127.0.0.1 search-and-go.com
127.0.0.1 search-dot.com
127.0.0.1 search-space.com
127.0.0.1 searchforge.com
127.0.0.1 searching-the-net.com
127.0.0.1 searchv.com
127.0.0.1 searchxl.com
127.0.0.1 seznam.cz
127.0.0.1 slotch.com
127.0.0.1 spidersearch.com
127.0.0.1 startium.com
127.0.0.1 ttjj.com
127.0.0.1 viewpornkey.com
127.0.0.1 wazzupnet.com
127.0.0.1 websearch.com
127.0.0.1 windowws.cc
127.0.0.1 xgmm.com
127.0.0.1 xwebsearch.biz
127.0.0.1 yourbookmarks.ws
127.0.0.1 collections.inhost.info
127.0.0.1 collections.inhost2.info
127.0.0.1 www.ruworld.com
127.0.0.1 www.maxxxhosters.com
127.0.0.1 www.therealsearch.com
127.0.0.1 www.thumbest-traffic.com
127.0.0.1 www.600pics.com
127.0.0.1 www.hightcalldialer.com
127.0.0.1 www.bestpornnews.com
127.0.0.1 www.thumberland.com
127.0.0.1 www.greg-search.com
127.0.0.1 www.0190-dialer.com
127.0.0.1 www.approvedlinks.com
127.0.0.1 www.vse-moe.biz
127.0.0.1 www.line-plus.com
127.0.0.1 www.porno-links.biz
127.0.0.1 www.freelivesex.org
127.0.0.1 www.free3xmatures.com
127.0.0.1 www.bestpics.net
127.0.0.1 www.dikai.com
127.0.0.1 www.world-search.biz
127.0.0.1 www.1-se.com
127.0.0.1 www.58q.com
127.0.0.1 www.aifind.cc
127.0.0.1 www.aifind.info
127.0.0.1 www.allneedsearch.com
127.0.0.1 www.awebfind.biz
127.0.0.1 www.cracks.am
127.0.0.1 www.default-homepage-network.com
127.0.0.1 www.find4u.net
127.0.0.1 www.freshvideogals.com
127.0.0.1 www.i-lookup.com
127.0.0.1 www.ie-search.com
127.0.0.1 www.itseasy.us
127.0.0.1 www.mysearchnow.com
127.0.0.1 www.nativehardcore.com
127.0.0.1 www.qwertysearch123.biz
127.0.0.1 www.searchcentrix.com
127.0.0.1 www.searchmyrequest.com
127.0.0.1 www.super-spider.com
127.0.0.1 www.teen-biz.com
127.0.0.1 www.teenhqpics.com
127.0.0.1 www.webcoolsearch.com
127.0.0.1 www.wmmse.com
127.0.0.1 www.008i.com
127.0.0.1 www.2fastsearch.net
127.0.0.1 www.8095.com
127.0.0.1 www.alfa-search.com
127.0.0.1 www.boredlife.com
127.0.0.1 www.couldnotfind.com
127.0.0.1 www.cracks.am
127.0.0.1 www.daum.net
127.0.0.1 www.dreamwiz.com
127.0.0.1 www.find-itnow.com
127.0.0.1 www.find4u.net
127.0.0.1 www.firstbookmark.com
127.0.0.1 www.gajai.com
127.0.0.1 www.hand-book.com
127.0.0.1 www.hao123.com
127.0.0.1 www.hotsearchbox.com
127.0.0.1 www.hotwebsearch.com
127.0.0.1 www.hugesearch.net
127.0.0.1 www.iquicksearch.com
127.0.0.1 www.lookfor.cc
127.0.0.1 www.naver.com
127.0.0.1 www.nkvd.us
127.0.0.1 www.novafuck.com
127.0.0.1 www.ohcorea.com
127.0.0.1 www.omega-search.com
127.0.0.1 www.onet.pl
127.0.0.1 www.power-search.info
127.0.0.1 www.rightfinder.net
127.0.0.1 www.search-1.net
127.0.0.1 www.search-and-go.com
127.0.0.1 www.search-dot.com
127.0.0.1 www.search-space.com
127.0.0.1 www.searchforge.com
127.0.0.1 www.searching-the-net.com
127.0.0.1 www.searchv.com
127.0.0.1 www.searchxl.com
127.0.0.1 www.seznam.cz
127.0.0.1 www.slotch.com
127.0.0.1 www.spidersearch.com
127.0.0.1 www.startium.com
127.0.0.1 www.ttjj.com
127.0.0.1 www.viewpornkey.com
127.0.0.1 www.wazzupnet.com
127.0.0.1 www.websearch.com
127.0.0.1 www.windowws.cc
127.0.0.1 www.xgmm.com
127.0.0.1 www.xwebsearch.biz
127.0.0.1 www.yourbookmarks.ws
127.0.0.1 thehun.com
127.0.0.1 www.thehun.com
127.0.0.1 thehun.net
127.0.0.1 www.thehun.net
127.0.0.1 www.yahoo.com
127.0.0.1 yahoo.com
127.0.0.1 www.google.com
127.0.0.1 google.com
127.0.0.1 www.altavista.com
127.0.0.1 altavista.com
127.0.0.1 search.microsoft.com
127.0.0.1 search.msn.com
127.0.0.1 www.msn.com
127.0.0.1 msn.com
127.0.0.1 www.search.com
127.0.0.1 search.com
127.0.0.1 www.teoma.com
127.0.0.1 teoma.com
127.0.0.1 www.alltheweb.com
127.0.0.1 alltheweb.com
127.0.0.1 www.wisenut.com
127.0.0.1 wisenut.com
127.0.0.1 www.dmoz.org
127.0.0.1 dmoz.org
127.0.0.1 www.excite.com
127.0.0.1 excite.com
127.0.0.1 www.lycos.com
127.0.0.1 lycos.com
127.0.0.1 www.hotbot.com
127.0.0.1 hotbot.com
127.0.0.1 www.casino.com
127.0.0.1 casino.com
so that these URLs are redirected to %Windir%\secure.html.
Deletes the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Key2
Attempts to stop the following processes:
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
loadclean.exe
loader.exe
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
runddl.exe
serve.exe
UPDATE.EXE
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Ecure.C.
Reverse the changes that were made to the registry.
Reset the Internet Explorer home page.
Delete the added lines from the Windows Hosts file.
4. To reverse the changes that were made to the registry
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run. (The Run dialog box appears.)
Type regedit
and then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
In the right pane, modifiy the following values:
Windows 95/98/Me:
"Local Page"="C:\WINDOWS\SYSTEM\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?
prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?
prd=ie&pver=6&ar=msnhome"
Windows NT/2000/XP:
"Local Page"="%SystemRoot%\system32\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?
prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?
prd=ie&pver=6&ar=msnhome"
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
In the right pane, modify the following values: (on all OSes)
"Local Page"="C:\WINDOWS\SYSTEM\blank.htm"
"Start Page"="file:///C:/WINDOWS/WEB/Start.htm"
5. To delete the added lines from the Windows Hosts file
Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.
Follow the instructions for your operating system:
Windows 95/98/Me/NT/2000
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
In the "Named" or "Search for..." box, type:
hosts
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file, except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
Windows XP
Click Start > Search.
Click All files and folders.
In the "All or part of the file name" box, type:
hosts
Verify that "Look in" is set to "Local Hard Drives" or to (C:).
Click More advanced options.
Check Search system folders.
Check Search subfolders.
Click Search.
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.ecure.c.html\"]Symantec Full Information[/url]
Discovered on: July 07, 2004
Last Updated on: July 07, 2004 01:51:34 PM
Trojan.Ecure.C is a Trojan horse that modifies the Hosts file and the Internet Explorer home page.
Variants: Trojan.Ecure
Type: Trojan Horse
Infection Length: 5,632 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Wild:
Low
Damage:
Low
Distribution:
Low
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: Modifies the Hosts file.
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.Ecure.C is executed, it performs the following actions:
Creates the file, %Windir%\secure.html.
Note: %Windir% is a variable. The Trojan locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
Modifies the values:
"Local Page"="%Windir%\secure.html"
"Start Page"="%Windir%\secure.html"
"Default_Page_URL"="%Windows%\secure.html"
to the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
which change the Internet Explorer home page to %Windir%\secure.html.
Adds the following entries to the Hosts file:
127.0.0.1 ruworld.com
127.0.0.1 maxxxhosters.com
127.0.0.1 therealsearch.com
127.0.0.1 thumbest-traffic.com
127.0.0.1 600pics.com
127.0.0.1 tonser.4-counter.com
127.0.0.1 free.sinpussy.com
127.0.0.1 hightcalldialer.com
127.0.0.1 bestpornnews.com
127.0.0.1 thumberland.com
127.0.0.1 greg-search.com
127.0.0.1 connect.online-dialer.com
127.0.0.1 0190-dialer.com
127.0.0.1 approvedlinks.com
127.0.0.1 download.buxomatic.com
127.0.0.1 dia.4-counter.com
127.0.0.1 vse-moe.biz
127.0.0.1 crue.global-counter.com
127.0.0.1 line-plus.com
127.0.0.1 porno-links.biz
127.0.0.1 download.tntdialer.com
127.0.0.1 freelivesex.org
127.0.0.1 free3xmatures.com
127.0.0.1 bestpics.net
127.0.0.1 dikai.com
127.0.0.1 world-search.biz
127.0.0.1 1-se.com
127.0.0.1 58q.com
127.0.0.1 aifind.cc
127.0.0.1 aifind.info
127.0.0.1 allneedsearch.com
127.0.0.1 auto.ie.searchforge.com
127.0.0.1 awebfind.biz
127.0.0.1 best.royalsearch.net
127.0.0.1 cracks.am
127.0.0.1 default-homepage-network.com
127.0.0.1 find.microgirls.com
127.0.0.1 find4u.net
127.0.0.1 freshvideogals.com
127.0.0.1 i-lookup.com
127.0.0.1 ie-search.com
127.0.0.1 in.webcounter.cc
127.0.0.1 itseasy.us
127.0.0.1 just.find-itnow.com
127.0.0.1 link.startmake.com
127.0.0.1 mysearchnow.com
127.0.0.1 nativehardcore.com
127.0.0.1 qwertysearch123.biz
127.0.0.1 search.ieplugin.com
127.0.0.1 search.psn.cn
127.0.0.1 searchbar.findthewebsiteyouneed.com
127.0.0.1 searchcentrix.com
127.0.0.1 searchmyrequest.com
127.0.0.1 super-spider.com
127.0.0.1 t.rack.cc
127.0.0.1 teen-biz.com
127.0.0.1 teenhqpics.com
127.0.0.1 tits.hardcore4ever.net
127.0.0.1 webcoolsearch.com
127.0.0.1 wmmse.com
127.0.0.1 008i.com
127.0.0.1 2fastsearch.net
127.0.0.1 8095.com
127.0.0.1 alfa-search.com
127.0.0.1 boredlife.com
127.0.0.1 couldnotfind.com
127.0.0.1 cracks.am
127.0.0.1 daum.net
127.0.0.1 dreamwiz.com
127.0.0.1 find-itnow.com
127.0.0.1 find4u.net
127.0.0.1 firstbookmark.com
127.0.0.1 gajai.com
127.0.0.1 hand-book.com
127.0.0.1 hao123.com
127.0.0.1 hotsearchbox.com
127.0.0.1 hotwebsearch.com
127.0.0.1 hugesearch.net
127.0.0.1 iquicksearch.com
127.0.0.1 lookfor.cc
127.0.0.1 naver.com
127.0.0.1 nkvd.us
127.0.0.1 novafuck.com
127.0.0.1 ohcorea.com
127.0.0.1 omega-search.com
127.0.0.1 onet.pl
127.0.0.1 power-search.info
127.0.0.1 rightfinder.net
127.0.0.1 search-1.net
127.0.0.1 search-and-go.com
127.0.0.1 search-dot.com
127.0.0.1 search-space.com
127.0.0.1 searchforge.com
127.0.0.1 searching-the-net.com
127.0.0.1 searchv.com
127.0.0.1 searchxl.com
127.0.0.1 seznam.cz
127.0.0.1 slotch.com
127.0.0.1 spidersearch.com
127.0.0.1 startium.com
127.0.0.1 ttjj.com
127.0.0.1 viewpornkey.com
127.0.0.1 wazzupnet.com
127.0.0.1 websearch.com
127.0.0.1 windowws.cc
127.0.0.1 xgmm.com
127.0.0.1 xwebsearch.biz
127.0.0.1 yourbookmarks.ws
127.0.0.1 collections.inhost.info
127.0.0.1 collections.inhost2.info
127.0.0.1 www.ruworld.com
127.0.0.1 www.maxxxhosters.com
127.0.0.1 www.therealsearch.com
127.0.0.1 www.thumbest-traffic.com
127.0.0.1 www.600pics.com
127.0.0.1 www.hightcalldialer.com
127.0.0.1 www.bestpornnews.com
127.0.0.1 www.thumberland.com
127.0.0.1 www.greg-search.com
127.0.0.1 www.0190-dialer.com
127.0.0.1 www.approvedlinks.com
127.0.0.1 www.vse-moe.biz
127.0.0.1 www.line-plus.com
127.0.0.1 www.porno-links.biz
127.0.0.1 www.freelivesex.org
127.0.0.1 www.free3xmatures.com
127.0.0.1 www.bestpics.net
127.0.0.1 www.dikai.com
127.0.0.1 www.world-search.biz
127.0.0.1 www.1-se.com
127.0.0.1 www.58q.com
127.0.0.1 www.aifind.cc
127.0.0.1 www.aifind.info
127.0.0.1 www.allneedsearch.com
127.0.0.1 www.awebfind.biz
127.0.0.1 www.cracks.am
127.0.0.1 www.default-homepage-network.com
127.0.0.1 www.find4u.net
127.0.0.1 www.freshvideogals.com
127.0.0.1 www.i-lookup.com
127.0.0.1 www.ie-search.com
127.0.0.1 www.itseasy.us
127.0.0.1 www.mysearchnow.com
127.0.0.1 www.nativehardcore.com
127.0.0.1 www.qwertysearch123.biz
127.0.0.1 www.searchcentrix.com
127.0.0.1 www.searchmyrequest.com
127.0.0.1 www.super-spider.com
127.0.0.1 www.teen-biz.com
127.0.0.1 www.teenhqpics.com
127.0.0.1 www.webcoolsearch.com
127.0.0.1 www.wmmse.com
127.0.0.1 www.008i.com
127.0.0.1 www.2fastsearch.net
127.0.0.1 www.8095.com
127.0.0.1 www.alfa-search.com
127.0.0.1 www.boredlife.com
127.0.0.1 www.couldnotfind.com
127.0.0.1 www.cracks.am
127.0.0.1 www.daum.net
127.0.0.1 www.dreamwiz.com
127.0.0.1 www.find-itnow.com
127.0.0.1 www.find4u.net
127.0.0.1 www.firstbookmark.com
127.0.0.1 www.gajai.com
127.0.0.1 www.hand-book.com
127.0.0.1 www.hao123.com
127.0.0.1 www.hotsearchbox.com
127.0.0.1 www.hotwebsearch.com
127.0.0.1 www.hugesearch.net
127.0.0.1 www.iquicksearch.com
127.0.0.1 www.lookfor.cc
127.0.0.1 www.naver.com
127.0.0.1 www.nkvd.us
127.0.0.1 www.novafuck.com
127.0.0.1 www.ohcorea.com
127.0.0.1 www.omega-search.com
127.0.0.1 www.onet.pl
127.0.0.1 www.power-search.info
127.0.0.1 www.rightfinder.net
127.0.0.1 www.search-1.net
127.0.0.1 www.search-and-go.com
127.0.0.1 www.search-dot.com
127.0.0.1 www.search-space.com
127.0.0.1 www.searchforge.com
127.0.0.1 www.searching-the-net.com
127.0.0.1 www.searchv.com
127.0.0.1 www.searchxl.com
127.0.0.1 www.seznam.cz
127.0.0.1 www.slotch.com
127.0.0.1 www.spidersearch.com
127.0.0.1 www.startium.com
127.0.0.1 www.ttjj.com
127.0.0.1 www.viewpornkey.com
127.0.0.1 www.wazzupnet.com
127.0.0.1 www.websearch.com
127.0.0.1 www.windowws.cc
127.0.0.1 www.xgmm.com
127.0.0.1 www.xwebsearch.biz
127.0.0.1 www.yourbookmarks.ws
127.0.0.1 thehun.com
127.0.0.1 www.thehun.com
127.0.0.1 thehun.net
127.0.0.1 www.thehun.net
127.0.0.1 www.yahoo.com
127.0.0.1 yahoo.com
127.0.0.1 www.google.com
127.0.0.1 google.com
127.0.0.1 www.altavista.com
127.0.0.1 altavista.com
127.0.0.1 search.microsoft.com
127.0.0.1 search.msn.com
127.0.0.1 www.msn.com
127.0.0.1 msn.com
127.0.0.1 www.search.com
127.0.0.1 search.com
127.0.0.1 www.teoma.com
127.0.0.1 teoma.com
127.0.0.1 www.alltheweb.com
127.0.0.1 alltheweb.com
127.0.0.1 www.wisenut.com
127.0.0.1 wisenut.com
127.0.0.1 www.dmoz.org
127.0.0.1 dmoz.org
127.0.0.1 www.excite.com
127.0.0.1 excite.com
127.0.0.1 www.lycos.com
127.0.0.1 lycos.com
127.0.0.1 www.hotbot.com
127.0.0.1 hotbot.com
127.0.0.1 www.casino.com
127.0.0.1 casino.com
so that these URLs are redirected to %Windir%\secure.html.
Deletes the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Key2
Attempts to stop the following processes:
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
loadclean.exe
loader.exe
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
runddl.exe
serve.exe
UPDATE.EXE
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Ecure.C.
Reverse the changes that were made to the registry.
Reset the Internet Explorer home page.
Delete the added lines from the Windows Hosts file.
4. To reverse the changes that were made to the registry
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run. (The Run dialog box appears.)
Type regedit
and then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
In the right pane, modifiy the following values:
Windows 95/98/Me:
"Local Page"="C:\WINDOWS\SYSTEM\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?
prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?
prd=ie&pver=6&ar=msnhome"
Windows NT/2000/XP:
"Local Page"="%SystemRoot%\system32\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?
prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?
prd=ie&pver=6&ar=msnhome"
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
In the right pane, modify the following values: (on all OSes)
"Local Page"="C:\WINDOWS\SYSTEM\blank.htm"
"Start Page"="file:///C:/WINDOWS/WEB/Start.htm"
5. To delete the added lines from the Windows Hosts file
Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.
Follow the instructions for your operating system:
Windows 95/98/Me/NT/2000
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
In the "Named" or "Search for..." box, type:
hosts
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file, except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
Windows XP
Click Start > Search.
Click All files and folders.
In the "All or part of the file name" box, type:
hosts
Verify that "Look in" is set to "Local Hard Drives" or to (C:).
Click More advanced options.
Check Search system folders.
Check Search subfolders.
Click Search.
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.ecure.c.html\"]Symantec Full Information[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.Ecure.B
Discovered on: July 06, 2004
Last Updated on: July 07, 2004 09:50:34 AM
Trojan.Ecure.B is a Trojan horse that modifies the Hosts file and the Internet Explorer home page.
Infection Length: 4,096
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Trojan.Ecure.B
Discovered on: July 06, 2004
Last Updated on: July 07, 2004 09:50:34 AM
Trojan.Ecure.B is a Trojan horse that modifies the Hosts file and the Internet Explorer home page.
Infection Length: 4,096
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Virus Definitions (Intelligent Updater) *
July 07, 2004
Virus Definitions (LiveUpdate™) **
July 07, 2004
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Wild:
Low
Damage:
Low
Distribution:
Low
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.Ecure.B is excuted, it performs the following actions:
Creates the file, %Windir%\Secure.html.
Note: %Windir% is a variable. The Trojan locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
Modifies these values to what is shown here:
"Local Page"="%Windir%\secure.html"
"Start Page"="%Windir%\secure.html"
"Default_Page_URL"="%Windir%\secure.html"
in the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
Adds the following entries to the Hosts file:
127.0.0.1 thehun.com
127.0.0.1 www.thehun.com
127.0.0.1 thehun.net
127.0.0.1 www.thehun.net
127.0.0.1 www.yahoo.com
127.0.0.1 yahoo.com
127.0.0.1 www.google.com
127.0.0.1 google.com
127.0.0.1 www.altavista.com
127.0.0.1 altavista.com
127.0.0.1 search.microsoft.com
127.0.0.1 search.msn.com
127.0.0.1 www.msn.com
127.0.0.1 msn.com
127.0.0.1 www.search.com
127.0.0.1 search.com
127.0.0.1 www.teoma.com
127.0.0.1 teoma.com
127.0.0.1 www.alltheweb.com
127.0.0.1 alltheweb.com
127.0.0.1 www.wisenut.com
127.0.0.1 wisenut.com
127.0.0.1 www.dmoz.org
127.0.0.1 dmoz.org
127.0.0.1 www.excite.com
127.0.0.1 excite.com
127.0.0.1 www.lycos.com
127.0.0.1 lycos.com
127.0.0.1 www.hotbot.com
127.0.0.1 hotbot.com
127.0.0.1 www.casino.com
127.0.0.1 casino.com
so that these URLs are redirected to %Windir%\secure.html.
Deletes the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Key2
Attempts to stop the following processes:
serve.exe
loadclean.exe
loader.exe
runddl.exe
MCUPDATE.EXE
CFIAUDIT.EXE
AVXQUAR.EXE
AUTOUPDATE.EXE
AUTOTRACE.EXE
AUTODOWN.EXE
AUPDATE.EXE
NUPGRADE.EXE
UPDATE.EXE
ICSUPP95.EXE
ICSSUPPNT.EXE
DRWEBUPW.EXE
LUALL.EXE
AVPUPD.EXE
AVWUPD32.EXE
ATUPDATER.EXE
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Ecure.B.
Reset the Internet Explorer home page.
Delete the added lines from the Windows Hosts file.
5. To reset the Internet Explorer home page
Start Microsoft Internet Explorer.
Connect to the Internet, and then go to the page that you want to set as your home page.
Click Tools > Internet Options.
In the Home page section of the General tab, click Use Current > OK.
For additional information, or if this procedure does not work, read the Microsoft® Knowledge Base article, "Home Page Setting Changes Unexpectedly, or You Cannot Change Your Home Page Setting, Article ID 320159."
6. To delete the added lines from the Windows Hosts file
Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.
Follow the instructions for your operating system:
Windows 95/98/Me/NT/2000
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
In the "Named" or "Search for..." box, type:
hosts
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the Always use this program to open this program check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file, except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
Windows XP
Click Start > Search.
Click All files and folders.
In the "All or part of the file name" box, type:
hosts
Verify that "Look in" is set to "Local Hard Drives" or to (C:).
Click More advanced options.
Check Search system folders.
Check Search subfolders.
Click Search.
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the Always use this program to open this program check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.ecure.b.html\"]Symantec Full Information[/url]
Discovered on: July 06, 2004
Last Updated on: July 07, 2004 09:50:34 AM
Trojan.Ecure.B is a Trojan horse that modifies the Hosts file and the Internet Explorer home page.
Infection Length: 4,096
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Trojan.Ecure.B
Discovered on: July 06, 2004
Last Updated on: July 07, 2004 09:50:34 AM
Trojan.Ecure.B is a Trojan horse that modifies the Hosts file and the Internet Explorer home page.
Infection Length: 4,096
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Virus Definitions (Intelligent Updater) *
July 07, 2004
Virus Definitions (LiveUpdate™) **
July 07, 2004
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Wild:
Low
Damage:
Low
Distribution:
Low
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.Ecure.B is excuted, it performs the following actions:
Creates the file, %Windir%\Secure.html.
Note: %Windir% is a variable. The Trojan locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
Modifies these values to what is shown here:
"Local Page"="%Windir%\secure.html"
"Start Page"="%Windir%\secure.html"
"Default_Page_URL"="%Windir%\secure.html"
in the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
Adds the following entries to the Hosts file:
127.0.0.1 thehun.com
127.0.0.1 www.thehun.com
127.0.0.1 thehun.net
127.0.0.1 www.thehun.net
127.0.0.1 www.yahoo.com
127.0.0.1 yahoo.com
127.0.0.1 www.google.com
127.0.0.1 google.com
127.0.0.1 www.altavista.com
127.0.0.1 altavista.com
127.0.0.1 search.microsoft.com
127.0.0.1 search.msn.com
127.0.0.1 www.msn.com
127.0.0.1 msn.com
127.0.0.1 www.search.com
127.0.0.1 search.com
127.0.0.1 www.teoma.com
127.0.0.1 teoma.com
127.0.0.1 www.alltheweb.com
127.0.0.1 alltheweb.com
127.0.0.1 www.wisenut.com
127.0.0.1 wisenut.com
127.0.0.1 www.dmoz.org
127.0.0.1 dmoz.org
127.0.0.1 www.excite.com
127.0.0.1 excite.com
127.0.0.1 www.lycos.com
127.0.0.1 lycos.com
127.0.0.1 www.hotbot.com
127.0.0.1 hotbot.com
127.0.0.1 www.casino.com
127.0.0.1 casino.com
so that these URLs are redirected to %Windir%\secure.html.
Deletes the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Key2
Attempts to stop the following processes:
serve.exe
loadclean.exe
loader.exe
runddl.exe
MCUPDATE.EXE
CFIAUDIT.EXE
AVXQUAR.EXE
AUTOUPDATE.EXE
AUTOTRACE.EXE
AUTODOWN.EXE
AUPDATE.EXE
NUPGRADE.EXE
UPDATE.EXE
ICSUPP95.EXE
ICSSUPPNT.EXE
DRWEBUPW.EXE
LUALL.EXE
AVPUPD.EXE
AVWUPD32.EXE
ATUPDATER.EXE
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Ecure.B.
Reset the Internet Explorer home page.
Delete the added lines from the Windows Hosts file.
5. To reset the Internet Explorer home page
Start Microsoft Internet Explorer.
Connect to the Internet, and then go to the page that you want to set as your home page.
Click Tools > Internet Options.
In the Home page section of the General tab, click Use Current > OK.
For additional information, or if this procedure does not work, read the Microsoft® Knowledge Base article, "Home Page Setting Changes Unexpectedly, or You Cannot Change Your Home Page Setting, Article ID 320159."
6. To delete the added lines from the Windows Hosts file
Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.
Follow the instructions for your operating system:
Windows 95/98/Me/NT/2000
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
In the "Named" or "Search for..." box, type:
hosts
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the Always use this program to open this program check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file, except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
Windows XP
Click Start > Search.
Click All files and folders.
In the "All or part of the file name" box, type:
hosts
Verify that "Look in" is set to "Local Hard Drives" or to (C:).
Click More advanced options.
Check Search system folders.
Check Search subfolders.
Click Search.
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the Always use this program to open this program check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.ecure.b.html\"]Symantec Full Information[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Backdoor.Berbew.H
Discovered on: July 08, 2004
Last Updated on: July 09, 2004 11:50:41 AM
Backdoor.Berbew.H is a minor variant of Backdoor.Berbew.G. It attempts to steal cached passwords and may display fake windows to gather confidential information.
Infection Length: 46,592 (exe), 6,657 (dll)
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Backdoor.Berbew.H
Discovered on: July 08, 2004
Last Updated on: July 09, 2004 11:50:41 AM
Backdoor.Berbew.H is a minor variant of Backdoor.Berbew.G. It attempts to steal cached passwords and may display fake windows to gather confidential information.
Infection Length: 46,592 (exe), 6,657 (dll)
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Attempts to steal cached passwords and may display fake windows to gather confidential information. Sends collected information to a predetermined URL.
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Backdoor.Berbew.H is executed, it performs the following actions:
Creates a mutex, "QueenKarton_11", which ensures that only one instance of the Trojan runs simultaneously.
Creates the files:
%System%\<8 random characters>.exe, or
%System%\<6 random characters>32.exe
Note: %System% is a variable. The Trojan locates the System folder and copies the files to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates several <8 random characters>.htm files in the %Temp% folder.
Opens the <8 random characters>.htm files in Internet Explorer. Some of the files may access a predetermined URL at the domain, tat-neftbank.ru.
Adds the value:
"(Default)" = "<8 random characters>.dll"
"ThreadingModel" = "Apartment"
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{79FEACFF-FFCE-815E-A900-316290B5B738}\InProcServer32
Adds the value:
"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Adds the value:
"QueenKarton" = 0xb
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft
Modifies the value:
"1601" = "0"
to the registry key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\5
Modifies the value:
"GlobalUserOffline" = "0"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Adds the value:
"BrowseNewProcess" = "yes"
to the registry key:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
Collects passwords from the infected computer and intercepts data entered into forms in Internet Explorer.
May create the following files in the %System% folder to save this password information and any downloaded configuration data:
dnkkq.dll
kkq32.vxd
kkq32.dll
Rtdx1<number>.dat
The stolen information is passed to the attacker by sending HTTP query strings. Configuration data may also be uploaded through the Web to a predetermined URL, at the domain, tat-neftbank.ru.
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Berbew.H.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CLASSES_ROOT\CLSID\{79FEACFF-FFCE-815E-A900-316290B5B738}\InProcServer32
In the left pane, delete the subkeys:
"(Default)" = "%System%/<8 random characters>.dll"
"ThreadingModel" = "Apartment"
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
In the right pane, delete the value:
"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft
In the right pane, delete the value:
"QueenKarton" = 0xc
Exit the Registry Editor.
[url=\"http://www.symantec.com/avcenter/venc/data/backdoor.berbew.h.html\"]Symantec Source[/url]
Discovered on: July 08, 2004
Last Updated on: July 09, 2004 11:50:41 AM
Backdoor.Berbew.H is a minor variant of Backdoor.Berbew.G. It attempts to steal cached passwords and may display fake windows to gather confidential information.
Infection Length: 46,592 (exe), 6,657 (dll)
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Backdoor.Berbew.H
Discovered on: July 08, 2004
Last Updated on: July 09, 2004 11:50:41 AM
Backdoor.Berbew.H is a minor variant of Backdoor.Berbew.G. It attempts to steal cached passwords and may display fake windows to gather confidential information.
Infection Length: 46,592 (exe), 6,657 (dll)
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Attempts to steal cached passwords and may display fake windows to gather confidential information. Sends collected information to a predetermined URL.
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Backdoor.Berbew.H is executed, it performs the following actions:
Creates a mutex, "QueenKarton_11", which ensures that only one instance of the Trojan runs simultaneously.
Creates the files:
%System%\<8 random characters>.exe, or
%System%\<6 random characters>32.exe
Note: %System% is a variable. The Trojan locates the System folder and copies the files to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates several <8 random characters>.htm files in the %Temp% folder.
Opens the <8 random characters>.htm files in Internet Explorer. Some of the files may access a predetermined URL at the domain, tat-neftbank.ru.
Adds the value:
"(Default)" = "<8 random characters>.dll"
"ThreadingModel" = "Apartment"
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{79FEACFF-FFCE-815E-A900-316290B5B738}\InProcServer32
Adds the value:
"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Adds the value:
"QueenKarton" = 0xb
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft
Modifies the value:
"1601" = "0"
to the registry key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\5
Modifies the value:
"GlobalUserOffline" = "0"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Adds the value:
"BrowseNewProcess" = "yes"
to the registry key:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
Collects passwords from the infected computer and intercepts data entered into forms in Internet Explorer.
May create the following files in the %System% folder to save this password information and any downloaded configuration data:
dnkkq.dll
kkq32.vxd
kkq32.dll
Rtdx1<number>.dat
The stolen information is passed to the attacker by sending HTTP query strings. Configuration data may also be uploaded through the Web to a predetermined URL, at the domain, tat-neftbank.ru.
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Berbew.H.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CLASSES_ROOT\CLSID\{79FEACFF-FFCE-815E-A900-316290B5B738}\InProcServer32
In the left pane, delete the subkeys:
"(Default)" = "%System%/<8 random characters>.dll"
"ThreadingModel" = "Apartment"
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
In the right pane, delete the value:
"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft
In the right pane, delete the value:
"QueenKarton" = 0xc
Exit the Registry Editor.
[url=\"http://www.symantec.com/avcenter/venc/data/backdoor.berbew.h.html\"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
VBS.Gaggle.E@mm
Discovered on: July 08, 2004
Last Updated on: July 09, 2004 10:46:40 AM
VBS.Gaggle.E is a variant of VBS.Gaggle.D. It is a mass-mailing worm that overwrites several files. This worm can infect the following file types:
.vbs
.vbe
.js
.jse
.hta
.htm
.html
.php
.shtm
.shtml
.phtm
.phtml
.mht
.mhtml
.plg
.htx
The worm retrieves the email addresses from the files that have .hta, .htm, .html, .php, .shtm, .shtml, .phtm, .phtml, .mht, .mhtml, .plg, or .htx extensions. Then, it uses its own SMTP engine to send email to all the email addresses that it finds. The worm can also spread through ICQ, and some file-sharing networks.
The From field of the email is spoofed, the subject line and message vary, and the attachment is Filezip.zip.
Also Known As: I-Worm.Gedza [Kaspersky], VBS/Gedza.A [F-Prot]
Variants: VBS.Gaggle.B@mm, VBS.Gaggle.C, VBS.Gaggle.D
Type: Worm
Infection Length: Varies, about 260k, 30,721 bytes, 17,409 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Moderate
Threat Metrics
Wild:
Low
Damage:
Medium
Distribution:
High
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to all the email addresses that it collects from the local system.
Deletes files: n/a
Modifies files: Overwrites .vbs, .vbe, .js, .jse, .hta, .htm, .html, .php, .shtm, .shtml, .phtm, .phtml, .mht, .mhtml, .plg, and .htx files with itself.
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: Varies
Name of attachment: Filezip.zip
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: Generates random IP addresses and attempts to copy itself to those IP addresses. Spreads through various file-sharing networks.
Target of infection: n/a
When VBS.Gaggle.E runs, it does the following:
Creates copies of itself in the %System% folder as some of these file names:
File.vbs
Gedzac.vbs
Israfel.vbs
pubprn.vbs
Kernel32.win
Mouse_configurator.win
Winmgd.win
Backup.vbs
Template.htm (A .html file containing the worm.)
Filezip.zip (A .zip archive of the worm.)
Notes:
%System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
The worm may insert some garbage data into the files, so that the size of the files vary.
Creates the following files in the %System% folder:
Regsrv.exe: 17,409 bytes. Detected as Trojan.KillAV.
Sendi.exe: 30,721 bytes. A component of the worm.
Pkzip.exe: A legitimate program.
AvrilLavigne.jpg: 12,549 bytes. A .jpg file.
C:\Estigma.hta: 354 bytes. A harmless .html file.
iwn.dat
iw.dat.
ixn.dat
ix.dat
Note: The worm attempts to use the .dat files to infect the Microsoft Word and Excel files.
Adds the values:
"Kernel32"="%System%\Kernel32.win"
"Israfel"="%System%\Israfel.vbs"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Modifies the default value to:
"(Default)"="GEDZAC"
in the registry keys:
HKEY_CLASSES_ROOT\regfile\shell\open\command
HKEY_CLASSES_ROOT\keyfile\shell\open\command
Modifies the value to:
"Timeout"="0"
in the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Scripting Host\Settings
Modifies the value to:
"DisableRegistryTools"="1"
in the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Policies\System
HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\
Policies\System
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Policies\System
Copies %comshell% to all the hard drives as \inetpub\scripts\israfel.exe.
Note: %Comshell% is a variable. The worm locates the default command shell. For example, this can be command.com or cmd.exe.
Creates an iisroot.asp file in the \inetpub\wwwroot folder and its subfolders. This file is not viral by itself.
Modifies the following line to the [boot] section of the System.ini file:
shell=Explorer.exe %System%\winmgd.win
so that the worm runs when you start Windows 95/98/Me.
Modifies the following line to the [windows] section of the Win.ini file:
run=%System%\mouse_configurator.win
so that the worm runs when you start Windows 95/98/Me.
If the date of the system clock is the third day of the month, the .html file, C:\Estigma.hta, will be displayed. This file only contains text.
If the date of the system clock is the 19th day of the month, the following message will be displayed:
19/12/2003 - Saludos a Cienciano Campeon 2003 de la Copa Sudamericana
If the date of the system clock is the 11th day of the month, the following message will be displayed:
Luego del alevoso ataque de eeuu y sus aliados
contra Iraq, aun tiene bush el descaro de decir
que lo hizo por libertar al pueblo o por la
democracia, como si eso le interesara, solo le
interesa tener gobiernos titeres y el petroleo
(investiguen sobre su dizque reconstruccion
de Iraq), desde los 90 que se pretendia derrocar
al gobierno de Iraq, quien le dio el derecho de decidir que
gobiernos deben ser derrocados o no, acaso
se cree el policia del mundo, una de las frases
favoritas del Asesino de bush, es el 'origen
del mal' el es eso.
Y para terminar otra de sus frases 'que Dios bendiga a los eeuu' ojala lo haga
porque lo van a nesecitar, porque algun
dia eeuu pagara por querer decirle al
mundo como tiene que vivir
(Mensage en contra del Gobierno de eeuu, no del pueblo)"
If the date of the system clock is the 26th day of the month, the following message will be displayed:
"Soy una ballena de color azúl mi espalda sopla y tu ves esa fuente
de agua limpia aún. Nuestra casa abierta, era el ancho mar
Viajábamos en paz, sin manchas de petróleo que evitar
Busco un sitio puro donde descansar no hay muchas como yo
me tengo que cuidar de ti. Nubes blancas, cielo transparente
y el humano compartiendo con otros, un sueño que quizás ya no regrese
pues ya es tarde para todos nosotros
Soy el cóndor majestuoso del Per? mi cuello gira y t?br> me miras con ojos de luz. Busco un sitio alto donde recordar
que hubo un tiempo mejor, pues como yo no quedan más
Si tus hijos te preguntan cómo fui, no s?que les dirás, me tuve que alejar de ti
Cordilleras blancas dominando, todo ser que se alimenta del rúŒ
hombres en aldeas cultivando, sin decirle al campo dame lo que es múŒ
Estás equivocado, no sabes dónde vas
guanacos, osos panda, renos, águilas, delfines y todo lo demás
Estás equivocado no sabes dónde vas
un espúitu ronda por la selva llorando lo que fue el jaguar
bienvenido al mundo del hombre construúo con detergentes y también con alquitrán
Soy una ballena de color azúl mi espalda sopla y t?br> ves esa fuente de agua limpia aún
(Cancion perteneciente a 'Los Nosequien y Los Nosecuantos')
El 26 de Abril es el dú} de la Tierra, protegela"
If the date of the system clock is the 29th of the month, the worm will open the Web page, www.arvil-lavigne.com.
Retrieves the shared folder of SoulSeek by querying the following registry key:
HKEY_CURRENT_USER\Software\SoulSeek\InstallPath
Copies %System%\Filezip.zip, to the following folders, if the folders exist:
C:\My Downloads
C:\My Shared Folder
C:\Program Files\appleJuice\incoming
C:\Program Files\BearShare\Shared
C:\Program Files\eDonkey2000\incoming
C:\Program Files\Gnucleus\Downloads
C:\Program Files\Grokster\My Grokster
C:\Program Files\ICQ\shared files
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA Lite\My Shared Folder
C:\Program Files\KMD\My Shared Folder
C:\Program Files\LimeWire\Shared
C:\Program Files\Morpheus\MyShared Folder
C:\Program Files\Overnet\incoming
C:\Program Files\Shareaza\Downloads
C:\Program Files\Swaptor\Download
C:\Program Files\WinMX\My Shared Folder
C:\Program Files\Tesla\Files
C:\Program Files\XoloX\Downloads
C:\Program Files\Rapigator\Share
C:\Archivos de programa\appleJuice\incoming
C:\Archivos de programa\BearShare\Shared
C:\Archivos de programa\eDonkey2000\incoming
C:\Archivos de programa\Gnucleus\Downloads
C:\Archivos de programa\Grokster\My Grokster
C:\Archivos de programa\ICQ\shared files
C:\Archivos de programa\KaZaA\My Shared Folder
C:\Archivos de programa\KaZaA Lite\My Shared Folder
C:\Archivos de programa\KMD\My Shared Folder
C:\Archivos de programa\LimeWire\Shared
C:\Archivos de programa\Morpheus\MyShared Folder
C:\Archivos de programa\Overnet\incoming
C:\Archivos de programa\Shareaza\Downloads
C:\Archivos de programa\Swaptor\Download
C:\Archivos de programa\WinMX\My Shared Folder
C:\Archivos de programa\Tesla\Files
C:\Archivos de programa\XoloX\Downloads
C:\Archivos de programa\Rapigator\Share
<The shared folder of SoulSeek>
as the following file names:
ACDSee 5.5.zip
AOL Instant Messenger.zip
AVP Antivirus Pro Key Crack.zip
Age of Empires 2 crack.zip
Ana Kournikova Sex Video.zip
Animated Screen 7.0b.zip
AquaNox2 Crack.zip
Audiograbber 2.05.zip
BabeFest 2003 ScreenSaver 1.5.zip
Babylon 3.50b reg_crack.zip
Battlefield1942_bloodpatch.zip
Battlefield1942_keygen.zip
Britney Spears Sex Video.zip
Buffy Vampire Slayer Movie.zip
Business Card Designer Plus 7.9.zip
Clone CD 5.0.0.3 (crack).zip
Clone CD 5.0.0.3.zip
Coffee Cup Free zip 7.0b.zip
Cool Edit Pro v2.55.zip
Crack Passwords Mail.zip
Credit Card Numbers generator(incl Visa,MasterCard,...).zip
Cristina Aguilera Sex Video.zip
DVD Copy Plus v5.0.zip
DVD Region-Free 2.3.zip
Diablo 2 Crack.zip
DirectDVD 5.0.zip
DirectX Buster (all versions).zip
DirectX InfoTool.zip
DivX Video Bundle 6.5.zip
Download Accelerator Plus 6.1.zip
Edonkey2000-Speed me up scotty.zip
FIFA2003 crack.zip
Final Fantasy VII XP Patch 1.5.zip
Flash MX crack (trial).zip
FlashGet 1.5.zip
FreeRAM XP Pro 1.9.zip
GTA 3 Crack.zip
GTA 3 Serial.zip
Game Cube Real Emulator.zip
GetRight 5.0a.zip
Global DiVX Player 3.0.zip
Gothic2 licence.zip
Guitar Chords Library 5.5.zip
Hentai Anime Girls Movie.zip
Hitman_2_no_cd_crack.zip
Hot Babes XXX Screen Saver.zip
HotGirls.zip
Hotmail Hacker 2003-Xss Exploit.zip
ICQ Pro 2003a.zip
ICQ Pro 2003b (new beta).zip
IrfanView 4.5.zip
Jenifer Lopez Sex Video.zip
KaZaA Hack 2.5.0.zip
KaZaA Speedup 3.6.zip
Kazaa SDK + Xbit speedUp for 2.xx.zip
Links 2003 Golf game (crack).zip
Living Waterfalls 1.3.zip
MSN Messenger 5.2.zip
Mafia_crack.zip
Matrix Movie.zip
Matrix Screensaver 1.5.zip
Mcafee Antivirus Scan Crack.zip
MediaPlayer Update.zip
Microsoft KeyGenerator-Allmost all microsoft stuff.zip
NBA2003_crack.zip
NHL 2003 crack.zip
Need 4 Speed crack.zip
Nero Burning ROM crack.zip
Netbios Nuker 2003.zip
Netfast 1.8.zip
Network Cable e ADSL Speed 2.0.5.zip
Nimo CodecPack (new) 8.0.zip
Norton Anvirus Key Crack.zip
PS2 PlayStation Simulator.zip
PalTalk 5.01b.zip
Panda Antivirus Titanium Crack.zip
Pop-Up Stopper 3.5.zip
Popup Defender 6.5.zip
Quick Time Key Crack.zip
QuickTime_Pro_Crack.zip
Sakura Card Captor Movie.zip
Screen saver christina aguilera naked.zip
Screen saver christina aguilera.zip
Security-2003-Update.zip
Serials 2003 v.8.0 Full.zip
Sex Live Simulator.zip
Sex Passwords.zip
SmartFTP 2.0.0.zip
SmartRipper v2.7.zip
Space Invaders 1978.zip
Spiderman Movie.zip
Splinter_Cell_Crack.zip
Starcraft serial.zip
Start Wars Trilogy Movies.zip
Steinberg_WaveLab_5_crack.zip
Stripping MP3 dancer+crack.zip
Thalia Sex Video.zip
Trillian 0.85 (free).zip
TweakAll 3.8.zip
UT2003_bloodpatch.zip
UT2003_keygen.zip
UT2003_no cd (crack).zip
UT2003_patch.zip
Unreal2_bloodpatch.zip
Unreal2_crack.zip
VB6.zip
Virtua Girl (Full).zip
VirtualSex.zip
Visual Basic 6.0 Msdn Plugin.zip
Visual basic 6.zip
WarCraft_3_crack.zip
WinOnCD 4 PE_crack.zip
WinRar 3.xx Password Cracker.zip
WinZip 9.0b.zip
WinZipped Visual C++ Tutorial.zip
Winamp 3.8.zip
WindowBlinds 4.0.zip
Windows XP complete + serial.zip
Windows Xp Exploit.zip
Winzip KeyGenerator Crack.zip
XNuker 2003 2.93b.zip
Yahoo Messenger 6.0.zip
Zelda Classic 2.00.zip
aol cracker.zip
aol password cracker.zip
cable modem ultility pack.zip
counter-strike.zip
delphi.zip
divx pro.zip
divx_pro.zip
hotmail_hack.zip
iMesh 3.6.zip
iMesh 3.7b (beta).zip
mIRC 6.40.zip
macromedia dreamweaver key generator.zip
mp3Trim PRO 2.5.zip
pamela_anderson.zip
play station emulator.zip
serials2000.zip
subseven.zip
virtua girl - adriana.zip
virtua girl - bailey short skirt.zip
warcraft 3 crack.zip
warcraft 3 serials.zip
winamp plugin pack.zip
winzip full version key generator.zip
Creates the following files in the %Temp% folder:
imh.dat
iml.dat
imv.dat
Notes:
%Temp% is a variable. The worm locates the temporary folder and copies itself to that location. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
These files are not viral by themselves. The worm retrieves the email addresses from the Microsoft Outlook Address Book and from the files with .hta, .htm, .html, .php, .shtm, .shtml, .phtm, .phtml, .mht, .mhtml, .plg, or .htx extensions. Then, it saves the email addresses to these files.
Overwrites the .vbs, .vbe, .js, .jse, .hta, .htm, .html, .php, .shtm, .shtml, .phtm, .phtml, .mht, .mhtml, .plg, and .htx files with itself.
Generates random IP addresses and attempts to connect to the IP addresses using the following user names and passwords:
<blank>
<CR/LF>
<ComputerName>
<UserName>
name
%null%
%username%
%username%12
%username%123
%username%1234
123
1234
12345
123456
1234567
12345678
654321
54321
1
111
11111
111111
11111111
000000
00000000
22
5201314
88888888
888888
passwd
password
sql
database
admin
test
server
computer
secret
oracle
sybase
root
Internet
super
user
manager
security
public
private
default
1234qwer
123qwe
abcd
abc123
123abc
abc
123asd
asdf
asdfgh
KKKKKKK
!@#$
!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
!@#$%^&*(
!@#$%^&*()
intel
Copies itself to the remote computer as autorun.vbs. Then, it overwrites the autoexec.bat file with the line:
@win \autoexec.vbs
Adds the line:
run=autorun.vbs
to the [windows] section of the file, Win.ini, on the remote computer.
Overwrites all the .vbs files on drive A with itself. If it does not find any .vbs files on drive A, it will copy itself as one of the following:
A:\Israfel.vbs
A:\Document.txt.vbs
A:\Image.jpg.vbs
A:\Loreley.jpg.vbs
A:\Vigilancia.txt.vbs
Uses its email component, sendi.exe, to send itself to all the email addresses that it finds.
The worm uses the current user's SMTP server or one of the following servers to spread itself:
mx1.latinmail.com
mx1.hotmail.com
The email has the following characteristics:
From: The sender's name is randomly selected from a list that the worm carries.
Attachment: Filezip.zip
Subject: Subject line is randomly selected from the list that the worm carries.
Message: The message body is randomly selected from the list that the worm carries.
It may begin with one of the following texts:
=============================Mcaffe Virus Scan=============================
Resultado del Anßlisis: Mensaje y Adjunto libre de virus
===========================================================================
=============================Mcaffe Virus Scan=============================
Result gives the Analysis: Message and Added free he gives virus
===========================================================================
For example, the subject and the message can be one of the following:
Subject: Postal Animada
Message:
Ha recibido una postal desde esta direccion
para verla descarguela antes de 7 dias de recibido este e-mail
Un Servicio de FreeCards
Subject: Cartoons
Message:
Nuestra pagina de Cartoons viene recargada
mira este que se titula: El inofensivo pajarito
Subject: Free ScreenSaver
Message: Mira este screensaver, y si te gusta, visita nuestra page
/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
Subject: FordWare
Message: Sabes lo que es el FordWare?, entonces mira este
Subject: Espero te guste
Message: Mira la postal =)
Subject: Esta es buena
Message: Haber que te parece a ti?
Subject: Aviso Importante
Message:
Debido a la nueva politica del servidor, se pide a los usuarios
completar el nuevo registro a fin de poder conservar sus cuentas de correo
Subject: Sexo Tantrico
Message:
Conoces el sexo tantrico?
Tantra: Antigua disciplina oriental para mejorar el rendimiento sexual
Aprendelo y nota la diferencia.
Subject: Significado de los nombres
Message: Quieres saber el significao de tu nombre, o apellido o de donde proviene?
Subject: Manual Seduccion
Message: Quieres conquistar una pareja?, prueba con estos consejos
Subject: ilusiones
Message: Mira la foto adjunta 20 segundos y veras algo
Subject: Hi
Message: Te envio las imagenes que pediste, bye
Subject: Help me
Message: please open file
Subject: Mail Return System
Message: El correo no pudo ser enviado a uno o mßs destinatarios.
Subject: Fotos en tu email
Message: XXX Todo Vale XXX
Sends email to the attacker. The email may contain the stolen information and email addresses that the worm finds on an infected computer.
Creates the following registry keys:
HKEY_LOCAL_MACHINE\Software\GEDZAC LABS\Israfel\Parent
HKEY_LOCAL_MACHINE\Software\GEDZAC LABS\VBS.Israfel\Info
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Do one of the following:
Windows 95/98/Me: Restart the computer in Safe mode.
Windows NT/2000/XP: End the malicious process.
Run a full system scan and delete all the files detected as VBS.Gaggle.E.
Reverse the changes made to the registry.
Remove the text from the Windows 95/98/Me Win.ini file.
Remove the text from the Windows 95/98/Me System.ini file.
To reverse the changes made to the registry
Click Start > Run.
Type notepad c:\repair.reg
Then click OK.
When prompted for confirmation, click Yes. (The Notepad text editor opens.)
Type, or copy and paste, the following lines into the Notepad text editor. If you type them, they must be typed exactly as shown here:
REGEDIT4
[HKEY_CLASSES_ROOT\regfile\shell\open\command]
@="regedit.exe \"%1\""
[-HKEY_CLASSES_ROOT\keyfile]
[HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings]
"Timeout"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Scripting Host\Settings]
"Timeout"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=-
[HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Policies\System]
"DisableRegistryTools"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Kernel32"=-
"Israfel"=-
Click the File menu > Exit. Click Yes when you are prompted to save the changes.
Do one of the following:
Windows NT/2000/XP: This completes the removal. Restart the computer in Normal mode. For instructions, read the section on returning to Normal mode in the document, "How to start the computer in Safe Mode."
Windows 95/98/Me: Go on to the next section.
6. To remove the text from the Windows 95/98/Me Win.ini file
If you are running Windows 95/98/Me, follow these steps:
The function you perform depends on your operating system:
Windows 95/98: Go to step B.
Windows Me: If you are running Windows Me, the Windows Me file-protection process may have made a backup copy of the Win.ini file that you need to edit. If this backup copy exists, it will be in the C:\Windows\Recent folder. Symantec recommends that you delete this file before continuing with the steps in this section. To do this:
Start Windows Explorer.
Browse to and select the C:\Windows\Recent folder.
In the right pane, select the Win.ini file and delete it. The Win.ini file will be regenerated when you save your changes to it in step F.
Click Start > Run.
Type the following, and then click OK.
edit c:\windows\win.ini
(The MS-DOS Editor opens.)
Note: If Windows is installed in a different location, make the appropriate path substitution.
In the [windows] section of the file, look for a line similar to:
run=%System%\mouse_configurator.win
If this line exists, select the text. Be sure that you do not select any other text, and then press Delete.
Click File > Save.
Click File > Exit.
7. To remove the text from the Windows 95/98/Me System.ini file
Note for Windows Me users only: Due to the file-protection process in Windows Me, a backup copy of System.ini exists in the C:\Windows\Recent folder. Symantec recommends that you delete this file before continuing with the steps in this section. To do this using Windows Explorer, go to C:\Windows\Recent, and in the right pane select the System.ini file and delete it. The System.ini file will be recreated in C:\Windows\Recent when you save your changes to System.ini in C:\Windows.
Click Start > Run.
Type the following:
edit c:\windows\System.ini
And then click OK. (The MS-DOS Editor opens.)
Note: If Windows is installed in a different location, make the appropriate path substitution.
In the [boot] section of the file, look for an entry similar to:
shell=Explorer.exe %System%\winmgd.win
If this line exists, replace it with the following text:
shell=Explorer.exe
Click File > Save.
Click File > Exit.
This completes the removal. Restart the computer in Normal mode
[url=\"http://www.symantec.com/avcenter/venc/data/vbs.gaggle.e@mm.html\"]Symantec Source[/url]
Discovered on: July 08, 2004
Last Updated on: July 09, 2004 10:46:40 AM
VBS.Gaggle.E is a variant of VBS.Gaggle.D. It is a mass-mailing worm that overwrites several files. This worm can infect the following file types:
.vbs
.vbe
.js
.jse
.hta
.htm
.html
.php
.shtm
.shtml
.phtm
.phtml
.mht
.mhtml
.plg
.htx
The worm retrieves the email addresses from the files that have .hta, .htm, .html, .php, .shtm, .shtml, .phtm, .phtml, .mht, .mhtml, .plg, or .htx extensions. Then, it uses its own SMTP engine to send email to all the email addresses that it finds. The worm can also spread through ICQ, and some file-sharing networks.
The From field of the email is spoofed, the subject line and message vary, and the attachment is Filezip.zip.
Also Known As: I-Worm.Gedza [Kaspersky], VBS/Gedza.A [F-Prot]
Variants: VBS.Gaggle.B@mm, VBS.Gaggle.C, VBS.Gaggle.D
Type: Worm
Infection Length: Varies, about 260k, 30,721 bytes, 17,409 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Moderate
Threat Metrics
Wild:
Low
Damage:
Medium
Distribution:
High
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to all the email addresses that it collects from the local system.
Deletes files: n/a
Modifies files: Overwrites .vbs, .vbe, .js, .jse, .hta, .htm, .html, .php, .shtm, .shtml, .phtm, .phtml, .mht, .mhtml, .plg, and .htx files with itself.
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: Varies
Name of attachment: Filezip.zip
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: Generates random IP addresses and attempts to copy itself to those IP addresses. Spreads through various file-sharing networks.
Target of infection: n/a
When VBS.Gaggle.E runs, it does the following:
Creates copies of itself in the %System% folder as some of these file names:
File.vbs
Gedzac.vbs
Israfel.vbs
pubprn.vbs
Kernel32.win
Mouse_configurator.win
Winmgd.win
Backup.vbs
Template.htm (A .html file containing the worm.)
Filezip.zip (A .zip archive of the worm.)
Notes:
%System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
The worm may insert some garbage data into the files, so that the size of the files vary.
Creates the following files in the %System% folder:
Regsrv.exe: 17,409 bytes. Detected as Trojan.KillAV.
Sendi.exe: 30,721 bytes. A component of the worm.
Pkzip.exe: A legitimate program.
AvrilLavigne.jpg: 12,549 bytes. A .jpg file.
C:\Estigma.hta: 354 bytes. A harmless .html file.
iwn.dat
iw.dat.
ixn.dat
ix.dat
Note: The worm attempts to use the .dat files to infect the Microsoft Word and Excel files.
Adds the values:
"Kernel32"="%System%\Kernel32.win"
"Israfel"="%System%\Israfel.vbs"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Modifies the default value to:
"(Default)"="GEDZAC"
in the registry keys:
HKEY_CLASSES_ROOT\regfile\shell\open\command
HKEY_CLASSES_ROOT\keyfile\shell\open\command
Modifies the value to:
"Timeout"="0"
in the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Scripting Host\Settings
Modifies the value to:
"DisableRegistryTools"="1"
in the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Policies\System
HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\
Policies\System
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Policies\System
Copies %comshell% to all the hard drives as \inetpub\scripts\israfel.exe.
Note: %Comshell% is a variable. The worm locates the default command shell. For example, this can be command.com or cmd.exe.
Creates an iisroot.asp file in the \inetpub\wwwroot folder and its subfolders. This file is not viral by itself.
Modifies the following line to the [boot] section of the System.ini file:
shell=Explorer.exe %System%\winmgd.win
so that the worm runs when you start Windows 95/98/Me.
Modifies the following line to the [windows] section of the Win.ini file:
run=%System%\mouse_configurator.win
so that the worm runs when you start Windows 95/98/Me.
If the date of the system clock is the third day of the month, the .html file, C:\Estigma.hta, will be displayed. This file only contains text.
If the date of the system clock is the 19th day of the month, the following message will be displayed:
19/12/2003 - Saludos a Cienciano Campeon 2003 de la Copa Sudamericana
If the date of the system clock is the 11th day of the month, the following message will be displayed:
Luego del alevoso ataque de eeuu y sus aliados
contra Iraq, aun tiene bush el descaro de decir
que lo hizo por libertar al pueblo o por la
democracia, como si eso le interesara, solo le
interesa tener gobiernos titeres y el petroleo
(investiguen sobre su dizque reconstruccion
de Iraq), desde los 90 que se pretendia derrocar
al gobierno de Iraq, quien le dio el derecho de decidir que
gobiernos deben ser derrocados o no, acaso
se cree el policia del mundo, una de las frases
favoritas del Asesino de bush, es el 'origen
del mal' el es eso.
Y para terminar otra de sus frases 'que Dios bendiga a los eeuu' ojala lo haga
porque lo van a nesecitar, porque algun
dia eeuu pagara por querer decirle al
mundo como tiene que vivir
(Mensage en contra del Gobierno de eeuu, no del pueblo)"
If the date of the system clock is the 26th day of the month, the following message will be displayed:
"Soy una ballena de color azúl mi espalda sopla y tu ves esa fuente
de agua limpia aún. Nuestra casa abierta, era el ancho mar
Viajábamos en paz, sin manchas de petróleo que evitar
Busco un sitio puro donde descansar no hay muchas como yo
me tengo que cuidar de ti. Nubes blancas, cielo transparente
y el humano compartiendo con otros, un sueño que quizás ya no regrese
pues ya es tarde para todos nosotros
Soy el cóndor majestuoso del Per? mi cuello gira y t?br> me miras con ojos de luz. Busco un sitio alto donde recordar
que hubo un tiempo mejor, pues como yo no quedan más
Si tus hijos te preguntan cómo fui, no s?que les dirás, me tuve que alejar de ti
Cordilleras blancas dominando, todo ser que se alimenta del rúŒ
hombres en aldeas cultivando, sin decirle al campo dame lo que es múŒ
Estás equivocado, no sabes dónde vas
guanacos, osos panda, renos, águilas, delfines y todo lo demás
Estás equivocado no sabes dónde vas
un espúitu ronda por la selva llorando lo que fue el jaguar
bienvenido al mundo del hombre construúo con detergentes y también con alquitrán
Soy una ballena de color azúl mi espalda sopla y t?br> ves esa fuente de agua limpia aún
(Cancion perteneciente a 'Los Nosequien y Los Nosecuantos')
El 26 de Abril es el dú} de la Tierra, protegela"
If the date of the system clock is the 29th of the month, the worm will open the Web page, www.arvil-lavigne.com.
Retrieves the shared folder of SoulSeek by querying the following registry key:
HKEY_CURRENT_USER\Software\SoulSeek\InstallPath
Copies %System%\Filezip.zip, to the following folders, if the folders exist:
C:\My Downloads
C:\My Shared Folder
C:\Program Files\appleJuice\incoming
C:\Program Files\BearShare\Shared
C:\Program Files\eDonkey2000\incoming
C:\Program Files\Gnucleus\Downloads
C:\Program Files\Grokster\My Grokster
C:\Program Files\ICQ\shared files
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA Lite\My Shared Folder
C:\Program Files\KMD\My Shared Folder
C:\Program Files\LimeWire\Shared
C:\Program Files\Morpheus\MyShared Folder
C:\Program Files\Overnet\incoming
C:\Program Files\Shareaza\Downloads
C:\Program Files\Swaptor\Download
C:\Program Files\WinMX\My Shared Folder
C:\Program Files\Tesla\Files
C:\Program Files\XoloX\Downloads
C:\Program Files\Rapigator\Share
C:\Archivos de programa\appleJuice\incoming
C:\Archivos de programa\BearShare\Shared
C:\Archivos de programa\eDonkey2000\incoming
C:\Archivos de programa\Gnucleus\Downloads
C:\Archivos de programa\Grokster\My Grokster
C:\Archivos de programa\ICQ\shared files
C:\Archivos de programa\KaZaA\My Shared Folder
C:\Archivos de programa\KaZaA Lite\My Shared Folder
C:\Archivos de programa\KMD\My Shared Folder
C:\Archivos de programa\LimeWire\Shared
C:\Archivos de programa\Morpheus\MyShared Folder
C:\Archivos de programa\Overnet\incoming
C:\Archivos de programa\Shareaza\Downloads
C:\Archivos de programa\Swaptor\Download
C:\Archivos de programa\WinMX\My Shared Folder
C:\Archivos de programa\Tesla\Files
C:\Archivos de programa\XoloX\Downloads
C:\Archivos de programa\Rapigator\Share
<The shared folder of SoulSeek>
as the following file names:
ACDSee 5.5.zip
AOL Instant Messenger.zip
AVP Antivirus Pro Key Crack.zip
Age of Empires 2 crack.zip
Ana Kournikova Sex Video.zip
Animated Screen 7.0b.zip
AquaNox2 Crack.zip
Audiograbber 2.05.zip
BabeFest 2003 ScreenSaver 1.5.zip
Babylon 3.50b reg_crack.zip
Battlefield1942_bloodpatch.zip
Battlefield1942_keygen.zip
Britney Spears Sex Video.zip
Buffy Vampire Slayer Movie.zip
Business Card Designer Plus 7.9.zip
Clone CD 5.0.0.3 (crack).zip
Clone CD 5.0.0.3.zip
Coffee Cup Free zip 7.0b.zip
Cool Edit Pro v2.55.zip
Crack Passwords Mail.zip
Credit Card Numbers generator(incl Visa,MasterCard,...).zip
Cristina Aguilera Sex Video.zip
DVD Copy Plus v5.0.zip
DVD Region-Free 2.3.zip
Diablo 2 Crack.zip
DirectDVD 5.0.zip
DirectX Buster (all versions).zip
DirectX InfoTool.zip
DivX Video Bundle 6.5.zip
Download Accelerator Plus 6.1.zip
Edonkey2000-Speed me up scotty.zip
FIFA2003 crack.zip
Final Fantasy VII XP Patch 1.5.zip
Flash MX crack (trial).zip
FlashGet 1.5.zip
FreeRAM XP Pro 1.9.zip
GTA 3 Crack.zip
GTA 3 Serial.zip
Game Cube Real Emulator.zip
GetRight 5.0a.zip
Global DiVX Player 3.0.zip
Gothic2 licence.zip
Guitar Chords Library 5.5.zip
Hentai Anime Girls Movie.zip
Hitman_2_no_cd_crack.zip
Hot Babes XXX Screen Saver.zip
HotGirls.zip
Hotmail Hacker 2003-Xss Exploit.zip
ICQ Pro 2003a.zip
ICQ Pro 2003b (new beta).zip
IrfanView 4.5.zip
Jenifer Lopez Sex Video.zip
KaZaA Hack 2.5.0.zip
KaZaA Speedup 3.6.zip
Kazaa SDK + Xbit speedUp for 2.xx.zip
Links 2003 Golf game (crack).zip
Living Waterfalls 1.3.zip
MSN Messenger 5.2.zip
Mafia_crack.zip
Matrix Movie.zip
Matrix Screensaver 1.5.zip
Mcafee Antivirus Scan Crack.zip
MediaPlayer Update.zip
Microsoft KeyGenerator-Allmost all microsoft stuff.zip
NBA2003_crack.zip
NHL 2003 crack.zip
Need 4 Speed crack.zip
Nero Burning ROM crack.zip
Netbios Nuker 2003.zip
Netfast 1.8.zip
Network Cable e ADSL Speed 2.0.5.zip
Nimo CodecPack (new) 8.0.zip
Norton Anvirus Key Crack.zip
PS2 PlayStation Simulator.zip
PalTalk 5.01b.zip
Panda Antivirus Titanium Crack.zip
Pop-Up Stopper 3.5.zip
Popup Defender 6.5.zip
Quick Time Key Crack.zip
QuickTime_Pro_Crack.zip
Sakura Card Captor Movie.zip
Screen saver christina aguilera naked.zip
Screen saver christina aguilera.zip
Security-2003-Update.zip
Serials 2003 v.8.0 Full.zip
Sex Live Simulator.zip
Sex Passwords.zip
SmartFTP 2.0.0.zip
SmartRipper v2.7.zip
Space Invaders 1978.zip
Spiderman Movie.zip
Splinter_Cell_Crack.zip
Starcraft serial.zip
Start Wars Trilogy Movies.zip
Steinberg_WaveLab_5_crack.zip
Stripping MP3 dancer+crack.zip
Thalia Sex Video.zip
Trillian 0.85 (free).zip
TweakAll 3.8.zip
UT2003_bloodpatch.zip
UT2003_keygen.zip
UT2003_no cd (crack).zip
UT2003_patch.zip
Unreal2_bloodpatch.zip
Unreal2_crack.zip
VB6.zip
Virtua Girl (Full).zip
VirtualSex.zip
Visual Basic 6.0 Msdn Plugin.zip
Visual basic 6.zip
WarCraft_3_crack.zip
WinOnCD 4 PE_crack.zip
WinRar 3.xx Password Cracker.zip
WinZip 9.0b.zip
WinZipped Visual C++ Tutorial.zip
Winamp 3.8.zip
WindowBlinds 4.0.zip
Windows XP complete + serial.zip
Windows Xp Exploit.zip
Winzip KeyGenerator Crack.zip
XNuker 2003 2.93b.zip
Yahoo Messenger 6.0.zip
Zelda Classic 2.00.zip
aol cracker.zip
aol password cracker.zip
cable modem ultility pack.zip
counter-strike.zip
delphi.zip
divx pro.zip
divx_pro.zip
hotmail_hack.zip
iMesh 3.6.zip
iMesh 3.7b (beta).zip
mIRC 6.40.zip
macromedia dreamweaver key generator.zip
mp3Trim PRO 2.5.zip
pamela_anderson.zip
play station emulator.zip
serials2000.zip
subseven.zip
virtua girl - adriana.zip
virtua girl - bailey short skirt.zip
warcraft 3 crack.zip
warcraft 3 serials.zip
winamp plugin pack.zip
winzip full version key generator.zip
Creates the following files in the %Temp% folder:
imh.dat
iml.dat
imv.dat
Notes:
%Temp% is a variable. The worm locates the temporary folder and copies itself to that location. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
These files are not viral by themselves. The worm retrieves the email addresses from the Microsoft Outlook Address Book and from the files with .hta, .htm, .html, .php, .shtm, .shtml, .phtm, .phtml, .mht, .mhtml, .plg, or .htx extensions. Then, it saves the email addresses to these files.
Overwrites the .vbs, .vbe, .js, .jse, .hta, .htm, .html, .php, .shtm, .shtml, .phtm, .phtml, .mht, .mhtml, .plg, and .htx files with itself.
Generates random IP addresses and attempts to connect to the IP addresses using the following user names and passwords:
<blank>
<CR/LF>
<ComputerName>
<UserName>
name
%null%
%username%
%username%12
%username%123
%username%1234
123
1234
12345
123456
1234567
12345678
654321
54321
1
111
11111
111111
11111111
000000
00000000
22
5201314
88888888
888888
passwd
password
sql
database
admin
test
server
computer
secret
oracle
sybase
root
Internet
super
user
manager
security
public
private
default
1234qwer
123qwe
abcd
abc123
123abc
abc
123asd
asdf
asdfgh
KKKKKKK
!@#$
!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
!@#$%^&*(
!@#$%^&*()
intel
Copies itself to the remote computer as autorun.vbs. Then, it overwrites the autoexec.bat file with the line:
@win \autoexec.vbs
Adds the line:
run=autorun.vbs
to the [windows] section of the file, Win.ini, on the remote computer.
Overwrites all the .vbs files on drive A with itself. If it does not find any .vbs files on drive A, it will copy itself as one of the following:
A:\Israfel.vbs
A:\Document.txt.vbs
A:\Image.jpg.vbs
A:\Loreley.jpg.vbs
A:\Vigilancia.txt.vbs
Uses its email component, sendi.exe, to send itself to all the email addresses that it finds.
The worm uses the current user's SMTP server or one of the following servers to spread itself:
mx1.latinmail.com
mx1.hotmail.com
The email has the following characteristics:
From: The sender's name is randomly selected from a list that the worm carries.
Attachment: Filezip.zip
Subject: Subject line is randomly selected from the list that the worm carries.
Message: The message body is randomly selected from the list that the worm carries.
It may begin with one of the following texts:
=============================Mcaffe Virus Scan=============================
Resultado del Anßlisis: Mensaje y Adjunto libre de virus
===========================================================================
=============================Mcaffe Virus Scan=============================
Result gives the Analysis: Message and Added free he gives virus
===========================================================================
For example, the subject and the message can be one of the following:
Subject: Postal Animada
Message:
Ha recibido una postal desde esta direccion
para verla descarguela antes de 7 dias de recibido este e-mail
Un Servicio de FreeCards
Subject: Cartoons
Message:
Nuestra pagina de Cartoons viene recargada
mira este que se titula: El inofensivo pajarito
Subject: Free ScreenSaver
Message: Mira este screensaver, y si te gusta, visita nuestra page
Subject: FordWare
Message: Sabes lo que es el FordWare?, entonces mira este
Subject: Espero te guste
Message: Mira la postal =)
Subject: Esta es buena
Message: Haber que te parece a ti?
Subject: Aviso Importante
Message:
Debido a la nueva politica del servidor, se pide a los usuarios
completar el nuevo registro a fin de poder conservar sus cuentas de correo
Subject: Sexo Tantrico
Message:
Conoces el sexo tantrico?
Tantra: Antigua disciplina oriental para mejorar el rendimiento sexual
Aprendelo y nota la diferencia.
Subject: Significado de los nombres
Message: Quieres saber el significao de tu nombre, o apellido o de donde proviene?
Subject: Manual Seduccion
Message: Quieres conquistar una pareja?, prueba con estos consejos
Subject: ilusiones
Message: Mira la foto adjunta 20 segundos y veras algo
Subject: Hi
Message: Te envio las imagenes que pediste, bye
Subject: Help me
Message: please open file
Subject: Mail Return System
Message: El correo no pudo ser enviado a uno o mßs destinatarios.
Subject: Fotos en tu email
Message: XXX Todo Vale XXX
Sends email to the attacker. The email may contain the stolen information and email addresses that the worm finds on an infected computer.
Creates the following registry keys:
HKEY_LOCAL_MACHINE\Software\GEDZAC LABS\Israfel\Parent
HKEY_LOCAL_MACHINE\Software\GEDZAC LABS\VBS.Israfel\Info
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Do one of the following:
Windows 95/98/Me: Restart the computer in Safe mode.
Windows NT/2000/XP: End the malicious process.
Run a full system scan and delete all the files detected as VBS.Gaggle.E.
Reverse the changes made to the registry.
Remove the text from the Windows 95/98/Me Win.ini file.
Remove the text from the Windows 95/98/Me System.ini file.
To reverse the changes made to the registry
Click Start > Run.
Type notepad c:\repair.reg
Then click OK.
When prompted for confirmation, click Yes. (The Notepad text editor opens.)
Type, or copy and paste, the following lines into the Notepad text editor. If you type them, they must be typed exactly as shown here:
REGEDIT4
[HKEY_CLASSES_ROOT\regfile\shell\open\command]
@="regedit.exe \"%1\""
[-HKEY_CLASSES_ROOT\keyfile]
[HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings]
"Timeout"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Scripting Host\Settings]
"Timeout"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=-
[HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Policies\System]
"DisableRegistryTools"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Kernel32"=-
"Israfel"=-
Click the File menu > Exit. Click Yes when you are prompted to save the changes.
Do one of the following:
Windows NT/2000/XP: This completes the removal. Restart the computer in Normal mode. For instructions, read the section on returning to Normal mode in the document, "How to start the computer in Safe Mode."
Windows 95/98/Me: Go on to the next section.
6. To remove the text from the Windows 95/98/Me Win.ini file
If you are running Windows 95/98/Me, follow these steps:
The function you perform depends on your operating system:
Windows 95/98: Go to step B.
Windows Me: If you are running Windows Me, the Windows Me file-protection process may have made a backup copy of the Win.ini file that you need to edit. If this backup copy exists, it will be in the C:\Windows\Recent folder. Symantec recommends that you delete this file before continuing with the steps in this section. To do this:
Start Windows Explorer.
Browse to and select the C:\Windows\Recent folder.
In the right pane, select the Win.ini file and delete it. The Win.ini file will be regenerated when you save your changes to it in step F.
Click Start > Run.
Type the following, and then click OK.
edit c:\windows\win.ini
(The MS-DOS Editor opens.)
Note: If Windows is installed in a different location, make the appropriate path substitution.
In the [windows] section of the file, look for a line similar to:
run=%System%\mouse_configurator.win
If this line exists, select the text. Be sure that you do not select any other text, and then press Delete.
Click File > Save.
Click File > Exit.
7. To remove the text from the Windows 95/98/Me System.ini file
Note for Windows Me users only: Due to the file-protection process in Windows Me, a backup copy of System.ini exists in the C:\Windows\Recent folder. Symantec recommends that you delete this file before continuing with the steps in this section. To do this using Windows Explorer, go to C:\Windows\Recent, and in the right pane select the System.ini file and delete it. The System.ini file will be recreated in C:\Windows\Recent when you save your changes to System.ini in C:\Windows.
Click Start > Run.
Type the following:
edit c:\windows\System.ini
And then click OK. (The MS-DOS Editor opens.)
Note: If Windows is installed in a different location, make the appropriate path substitution.
In the [boot] section of the file, look for an entry similar to:
shell=Explorer.exe %System%\winmgd.win
If this line exists, replace it with the following text:
shell=Explorer.exe
Click File > Save.
Click File > Exit.
This completes the removal. Restart the computer in Normal mode
[url=\"http://www.symantec.com/avcenter/venc/data/vbs.gaggle.e@mm.html\"]Symantec Source[/url]
Last edited by Tami on Fri Jul 09, 2004 7:52 pm, edited 1 time in total.

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Korgo.X
Discovered on: July 09, 2004
Last Updated on: July 09, 2004 12:17:46 PM
W32.Korgo.X is a worm that attempts to propagate by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011) on TCP port 445.
This variant also attempts to download and execute a file from a remote Web site.
Variants: W32.Korgo.W
Type: Worm
Infection Length: 9,359 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT
W32.Korgo.X
Discovered on: July 09, 2004
Last Updated on: July 09, 2004 12:17:46 PM
W32.Korgo.X is a worm that attempts to propagate by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011) on TCP port 445.
This variant also attempts to download and execute a file from a remote Web site.
Variants: W32.Korgo.W
Type: Worm
Infection Length: 9,359 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Network propagation routines may degrade overall network performance.
Causes system instability: n/a
Releases confidential info: Backdoor functionality allows unauthorized access.
Compromises security settings: Backdoor functionality may compromise security settings.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 445 and a random port.
Shared drives: n/a
Target of infection: Unpatched computers vulnerable to the Microsoft LSASS Windows exploit.
When W32.Korgo.X is executed, it performs the following actions:
Deletes the file, ftpupd.exe, from the folder in which the worm was executed.
Creates the following mutexes to ensure that only one instance of the worm is executed on the computer:
u8
u9
u10
u10x
u11
u11x
u12
u12x
u13
u13i
u13x
u14
u14x
u15
u15x
u16
u16x
u17
u17x
u18
u18x
u19
u19x
u20
u20x
Deletes the values:
"Windows Security Manager"
"Disk Defragmenter"
"System Restore Service"
"Bot Loader"
"SysTray"
"WinUpdate"
"Windows Update Service"
"avserve.exe"
"avserve2.exeUpdate Service"
"MS Config v13"
"Windows Update"
from the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Copies itself as %System%\<random filename>.exe.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the values:
"Client"="1"
"ID"="<random value>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
Adds one of the following values:
"System Update"="%System%\<random filename>.exe"
"Cryptographic Service"="%System%\<random filename>.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Attempts to inject a function into Explorer.exe as a thread.
If successful, this threat will continue to run in the Explorer.exe process. All the actions described in the next step will appear to be done by Explorer.exe, and the worm will not show when viewing the process list in the Windows Task Manager.
If unsuccessful, the worm will continue to run as its own process.
Opens a random TCP port, which the worm uses to send itself.
Attempts to connect and update itself from one of the following HTTP servers:
adult-empire.com
asechka.ru
citi-bank.ru
color-bank.ru
crutop.nu
fethard.biz
filesearch.ru
kavkaz.tv
kidos-bank.ru
konfiskat.org
master-x.com
mazafaka.ru
parex-bank.ru
roboxchange.com
www.redline.ru
xware.cjb.net
Attempts to exploit the LSASS Windows vulnerability on TCP port 445 (described in Microsoft Security Bulletin MS04-011), against random IP addresses. If the worm successfully finds a vulnerable computer, the computer will attempt to reconnect to the infected computer to download the worm.
Before you begin:
[b]If you are running Windows 2000 or XP, and have not yet done so, you must patch for the vulnerability.[/b] [url=\"http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx\"]Microsoft Security Bulletin MS04-011[/url] describes this process. If you do not, it is likely that your computer will continue to be re-infected.
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Korgo.X.
Reverse the changes made to the registry.
To reverse the changes made to the registry
--------------------------------------------------------------------------------
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"System Update"="%System%\<random filename>.exe"
"Cryptographic Service"="%System%\<random filename>.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
In the right pane, delete the values, if they exist:
"Client"="1"
"ID" = "<random value>"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://www.symantec.com/avcenter/venc/data/w32.korgo.x.html\"]Symantec Source[/url]
Discovered on: July 09, 2004
Last Updated on: July 09, 2004 12:17:46 PM
W32.Korgo.X is a worm that attempts to propagate by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011) on TCP port 445.
This variant also attempts to download and execute a file from a remote Web site.
Variants: W32.Korgo.W
Type: Worm
Infection Length: 9,359 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT
W32.Korgo.X
Discovered on: July 09, 2004
Last Updated on: July 09, 2004 12:17:46 PM
W32.Korgo.X is a worm that attempts to propagate by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011) on TCP port 445.
This variant also attempts to download and execute a file from a remote Web site.
Variants: W32.Korgo.W
Type: Worm
Infection Length: 9,359 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Network propagation routines may degrade overall network performance.
Causes system instability: n/a
Releases confidential info: Backdoor functionality allows unauthorized access.
Compromises security settings: Backdoor functionality may compromise security settings.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 445 and a random port.
Shared drives: n/a
Target of infection: Unpatched computers vulnerable to the Microsoft LSASS Windows exploit.
When W32.Korgo.X is executed, it performs the following actions:
Deletes the file, ftpupd.exe, from the folder in which the worm was executed.
Creates the following mutexes to ensure that only one instance of the worm is executed on the computer:
u8
u9
u10
u10x
u11
u11x
u12
u12x
u13
u13i
u13x
u14
u14x
u15
u15x
u16
u16x
u17
u17x
u18
u18x
u19
u19x
u20
u20x
Deletes the values:
"Windows Security Manager"
"Disk Defragmenter"
"System Restore Service"
"Bot Loader"
"SysTray"
"WinUpdate"
"Windows Update Service"
"avserve.exe"
"avserve2.exeUpdate Service"
"MS Config v13"
"Windows Update"
from the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Copies itself as %System%\<random filename>.exe.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the values:
"Client"="1"
"ID"="<random value>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
Adds one of the following values:
"System Update"="%System%\<random filename>.exe"
"Cryptographic Service"="%System%\<random filename>.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Attempts to inject a function into Explorer.exe as a thread.
If successful, this threat will continue to run in the Explorer.exe process. All the actions described in the next step will appear to be done by Explorer.exe, and the worm will not show when viewing the process list in the Windows Task Manager.
If unsuccessful, the worm will continue to run as its own process.
Opens a random TCP port, which the worm uses to send itself.
Attempts to connect and update itself from one of the following HTTP servers:
adult-empire.com
asechka.ru
citi-bank.ru
color-bank.ru
crutop.nu
fethard.biz
filesearch.ru
kavkaz.tv
kidos-bank.ru
konfiskat.org
master-x.com
mazafaka.ru
parex-bank.ru
roboxchange.com
www.redline.ru
xware.cjb.net
Attempts to exploit the LSASS Windows vulnerability on TCP port 445 (described in Microsoft Security Bulletin MS04-011), against random IP addresses. If the worm successfully finds a vulnerable computer, the computer will attempt to reconnect to the infected computer to download the worm.
Before you begin:
[b]If you are running Windows 2000 or XP, and have not yet done so, you must patch for the vulnerability.[/b] [url=\"http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx\"]Microsoft Security Bulletin MS04-011[/url] describes this process. If you do not, it is likely that your computer will continue to be re-infected.
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Korgo.X.
Reverse the changes made to the registry.
To reverse the changes made to the registry
--------------------------------------------------------------------------------
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"System Update"="%System%\<random filename>.exe"
"Cryptographic Service"="%System%\<random filename>.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
In the right pane, delete the values, if they exist:
"Client"="1"
"ID" = "<random value>"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://www.symantec.com/avcenter/venc/data/w32.korgo.x.html\"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Microsoft teams have confirmed a report of a security issue known as Download.Ject affecting customers using Microsoft Internet Explorer, a component of Microsoft Windows.
Important Users of Windows XP Service Pack 2 Release Candidate 2 (Windows XP SP2 RC2) are not at risk.
Microsoft has released a configuration change for Windows XP, Windows 2000, Windows Server 2003, Windows Millennium Edition, Windows 98, and Windows 98 Second Edition to address this issue. Microsoft strongly encourages users to apply this configuration change immediately to help protect their computers.
Install Critical Updates
Go to the [url=\"http://windowsupdate.microsoft.com/\"]Windows Update Web Site[/url] to install the configuration update and any other critical updates that are available.
Check for Infection
To determine if the malicious code is on your computer, search for the following files:
kk32.dll
surf.dat
Steps for users of Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003:
On the taskbar at the bottom of your screen, click Start, and then click Run.
In the Run box, type: cmd and then click OK.
At the command prompt, type:
dir /a /s /b %systemdrive%\kk32.dll
and then press the ENTER key to search your computer.
If the file is present, the file path is displayed. If the file is not present, a message is displayed that the system cannot find the path.
At the command prompt, type:
dir /a /s /b %systemdrive%\surf.dat
and then press the ENTER key to search your computer.
If the file is present, the file path is displayed. If the file is not present, a message is displayed that the system cannot find the path.
If either of these files is present, your computer may be infected. You can find tools to clean your computer and obtain up-to-date antivirus protection from the following software vendors participating in the Microsoft Virus Information Alliance:
Symantec
F-Secure
Trend Micro
Network Associates
Computer Associates
Important Users of Windows XP Service Pack 2 Release Candidate 2 (Windows XP SP2 RC2) are not at risk.
Microsoft has released a configuration change for Windows XP, Windows 2000, Windows Server 2003, Windows Millennium Edition, Windows 98, and Windows 98 Second Edition to address this issue. Microsoft strongly encourages users to apply this configuration change immediately to help protect their computers.
Install Critical Updates
Go to the [url=\"http://windowsupdate.microsoft.com/\"]Windows Update Web Site[/url] to install the configuration update and any other critical updates that are available.
Check for Infection
To determine if the malicious code is on your computer, search for the following files:
kk32.dll
surf.dat
Steps for users of Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003:
On the taskbar at the bottom of your screen, click Start, and then click Run.
In the Run box, type: cmd and then click OK.
At the command prompt, type:
dir /a /s /b %systemdrive%\kk32.dll
and then press the ENTER key to search your computer.
If the file is present, the file path is displayed. If the file is not present, a message is displayed that the system cannot find the path.
At the command prompt, type:
dir /a /s /b %systemdrive%\surf.dat
and then press the ENTER key to search your computer.
If the file is present, the file path is displayed. If the file is not present, a message is displayed that the system cannot find the path.
If either of these files is present, your computer may be infected. You can find tools to clean your computer and obtain up-to-date antivirus protection from the following software vendors participating in the Microsoft Virus Information Alliance:
Symantec
F-Secure
Trend Micro
Network Associates
Computer Associates

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Hardoc@mm
Discovered on: July 10, 2004
Last Updated on: July 12, 2004 03:15:57 PM
W32.Hardoc@mm is a mass-mailing worm that sends itself to email addresses found in .html files and the Windows address book on the infected computer. This worm uses the Incorrect MIME Header vulnerability (described in Microsoft Security Bulletin MS01-020) to allow the automatic execution of the attachment on an unpatched computer.
The email has the following characteristics:
Subject: (One of the following)
Re:
Fw:
Power Point
Body: !!! Power Point !!!
Attachment: PowerPoint.scr
Type: Worm
Infection Length: 5120 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x
W32.Hardoc@mm
Discovered on: July 10, 2004
Last Updated on: July 12, 2004 03:15:57 PM
W32.Hardoc@mm is a mass-mailing worm that sends itself to email addresses found in .html files and the Windows address book on the infected computer. This worm uses the Incorrect MIME Header vulnerability (described in Microsoft Security Bulletin MS01-020) to allow the automatic execution of the attachment on an unpatched computer.
The email has the following characteristics:
Subject: (One of the following)
Re:
Fw:
Power Point
Body: !!! Power Point !!!
Attachment: PowerPoint.scr
Type: Worm
Infection Length: 5120 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Attempts to email itself to addresses found in html files and wab files.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: "Re:" or "Fw:" or "Power Point"
Name of attachment: PowerPoint.scr
Size of attachment: 5120 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Hardoc@mm is executed, it does the following:
Displays a fake error message with the following text:
Error
Not Enought Memory [b]<<<NOTE THE TYPO[/b]
Copies itself as %System%\WINRE16.EXE.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"Windows Explorer-3212"="%System%\WINRE16.EXE"
to the registry key:
HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run
so that the worm runs when you start Windows.
Collects email addresses from .html files and the Windows address book.
Attempts to email itself out using its own SMTP engine.
The email has the following characteristics:
From: (spoofed)
Subject: one of the following:
Re:
Fw:
Power Point
Body:
!!! Power Point !!!
Attachment: PowerPoint.scr
Removal:
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Hardoc@mm.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run
In the right pane, delete the value:
"Windows Explorer-3212"="%System%\WINRE16.EXE"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.hardoc@mm.html\"]Symantec Source[/url]
Discovered on: July 10, 2004
Last Updated on: July 12, 2004 03:15:57 PM
W32.Hardoc@mm is a mass-mailing worm that sends itself to email addresses found in .html files and the Windows address book on the infected computer. This worm uses the Incorrect MIME Header vulnerability (described in Microsoft Security Bulletin MS01-020) to allow the automatic execution of the attachment on an unpatched computer.
The email has the following characteristics:
Subject: (One of the following)
Re:
Fw:
Power Point
Body: !!! Power Point !!!
Attachment: PowerPoint.scr
Type: Worm
Infection Length: 5120 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x
W32.Hardoc@mm
Discovered on: July 10, 2004
Last Updated on: July 12, 2004 03:15:57 PM
W32.Hardoc@mm is a mass-mailing worm that sends itself to email addresses found in .html files and the Windows address book on the infected computer. This worm uses the Incorrect MIME Header vulnerability (described in Microsoft Security Bulletin MS01-020) to allow the automatic execution of the attachment on an unpatched computer.
The email has the following characteristics:
Subject: (One of the following)
Re:
Fw:
Power Point
Body: !!! Power Point !!!
Attachment: PowerPoint.scr
Type: Worm
Infection Length: 5120 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Attempts to email itself to addresses found in html files and wab files.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: "Re:" or "Fw:" or "Power Point"
Name of attachment: PowerPoint.scr
Size of attachment: 5120 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Hardoc@mm is executed, it does the following:
Displays a fake error message with the following text:
Error
Not Enought Memory [b]<<<NOTE THE TYPO[/b]
Copies itself as %System%\WINRE16.EXE.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"Windows Explorer-3212"="%System%\WINRE16.EXE"
to the registry key:
HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run
so that the worm runs when you start Windows.
Collects email addresses from .html files and the Windows address book.
Attempts to email itself out using its own SMTP engine.
The email has the following characteristics:
From: (spoofed)
Subject: one of the following:
Re:
Fw:
Power Point
Body:
!!! Power Point !!!
Attachment: PowerPoint.scr
Removal:
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Hardoc@mm.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run
In the right pane, delete the value:
"Windows Explorer-3212"="%System%\WINRE16.EXE"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.hardoc@mm.html\"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Lemoor.A
Discovered on: July 11, 2004
Last Updated on: July 12, 2004 03:15:22 PM
W32.Lemoor.A is a worm that spreads by exploiting a vulnerability in the FTP server component of the W32.Sasser family of worms.
The worm is written in Assembler and packed with FSG.
Also Known As: Worm.Win32.Lemoor.a [KAV]
Type: Worm
Infection Length: About 1,900 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003
W32.Lemoor.A
Discovered on: July 11, 2004
Last Updated on: July 12, 2004 03:15:22 PM
W32.Lemoor.A is a worm that spreads by exploiting a vulnerability in the FTP server component of the W32.Sasser family of worms.
The worm is written in Assembler and packed with FSG.
Also Known As: Worm.Win32.Lemoor.a [KAV]
Type: Worm
Infection Length: About 1,900 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Network propagation routines may degrade overall network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: Random port
Shared drives: n/a
Target of infection: Unpatched computers vulnerable to the Microsoft LSASS Windows exploit and infected with W32.Sasser.Worm or its variants.
Technical Details
When W32.Lemoor.A is executed, it performs the following actions:
Adds the one of the following values:
"[Ephemeral 2.3] by TreeHugger, " = <path to worm>
"[Ephemeral 2.4] by TreeHugger, " = <path to worm>
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Creates an overlapped socket for intercepting SMB packets from W32.Sasser variants, in order to attack other hosts.
Retrieves the IP addresses of infected computers from the data it intercepts from W32.Sasser variants.
Connects to the IP addresses and submits a special request that exploits a vulnerability in the FTP server that is hosted by W32.Sasser variants.
If the worm successfully exploits the vulnerability, it launches a command shell on the remote computer, using a random port number.
Using the command shell, the worm uploads itself to the remote computer.
Note: Before sending a copy of itself, the worm attempts to avoid detection by patching its section name with random bytes.
Removal Instructions:
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lemoor.A.
Reverse the changes made to the registry.
To Remove Registry Entries:
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the following values, if present:
"[Ephemeral 2.3] by TreeHugger, " = <path to worm>
"[Ephemeral 2.4] by TreeHugger, " = <path to worm>
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lemoor.a.html\"]Symantec Source[/url]
Discovered on: July 11, 2004
Last Updated on: July 12, 2004 03:15:22 PM
W32.Lemoor.A is a worm that spreads by exploiting a vulnerability in the FTP server component of the W32.Sasser family of worms.
The worm is written in Assembler and packed with FSG.
Also Known As: Worm.Win32.Lemoor.a [KAV]
Type: Worm
Infection Length: About 1,900 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003
W32.Lemoor.A
Discovered on: July 11, 2004
Last Updated on: July 12, 2004 03:15:22 PM
W32.Lemoor.A is a worm that spreads by exploiting a vulnerability in the FTP server component of the W32.Sasser family of worms.
The worm is written in Assembler and packed with FSG.
Also Known As: Worm.Win32.Lemoor.a [KAV]
Type: Worm
Infection Length: About 1,900 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003
Wild:
Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Network propagation routines may degrade overall network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: Random port
Shared drives: n/a
Target of infection: Unpatched computers vulnerable to the Microsoft LSASS Windows exploit and infected with W32.Sasser.Worm or its variants.
Technical Details
When W32.Lemoor.A is executed, it performs the following actions:
Adds the one of the following values:
"[Ephemeral 2.3] by TreeHugger, " = <path to worm>
"[Ephemeral 2.4] by TreeHugger, " = <path to worm>
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Creates an overlapped socket for intercepting SMB packets from W32.Sasser variants, in order to attack other hosts.
Retrieves the IP addresses of infected computers from the data it intercepts from W32.Sasser variants.
Connects to the IP addresses and submits a special request that exploits a vulnerability in the FTP server that is hosted by W32.Sasser variants.
If the worm successfully exploits the vulnerability, it launches a command shell on the remote computer, using a random port number.
Using the command shell, the worm uploads itself to the remote computer.
Note: Before sending a copy of itself, the worm attempts to avoid detection by patching its section name with random bytes.
Removal Instructions:
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lemoor.A.
Reverse the changes made to the registry.
To Remove Registry Entries:
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the following values, if present:
"[Ephemeral 2.3] by TreeHugger, " = <path to worm>
"[Ephemeral 2.4] by TreeHugger, " = <path to worm>
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lemoor.a.html\"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32/Agobot-KM
Aliases:
Backdoor.Agobot.ty, W32/Gaobot.worm.gen.f virus
Type: Win32 worm
Detection
A virus identity (IDE) file which provides protection is available now from the Latest virus identities section, and will be incorporated into the August 2004 (3.84) release of Sophos Anti-Virus.
Description
W32/Agobot-KM is a network worm that spreads to other computers by exploiting network services with either weak passwords or unpatched vulnerabilities.
In order to run automatically when Windows starts up W32/Agobot-KM copies itself to the file MSVSRV32.EXE in the Windows system folder and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\msvsrv32
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\msvsrv32
W32/Agobot-KM runs continuously in the background, allowing a remote intruder to access and control the computer via IRC channels.
W32/Agobot-KM modifies the Windows HOSTS file to redirect several AV and security-related websites to 127.0.0.1
Recovery
Please follow the instructions for removing worms.
Replace the Hosts file from a backup or edit it in Notepad to remove the changes that the worm has made.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\msvsrv32
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\msvsrv32
and delete them if they exist.
Close the registry editor.
[url=\"http://www.sophos.com/virusinfo/analyses/w32agobotkm.html\"]Sophos Source[/url]
Aliases:
Backdoor.Agobot.ty, W32/Gaobot.worm.gen.f virus
Type: Win32 worm
Detection
A virus identity (IDE) file which provides protection is available now from the Latest virus identities section, and will be incorporated into the August 2004 (3.84) release of Sophos Anti-Virus.
Description
W32/Agobot-KM is a network worm that spreads to other computers by exploiting network services with either weak passwords or unpatched vulnerabilities.
In order to run automatically when Windows starts up W32/Agobot-KM copies itself to the file MSVSRV32.EXE in the Windows system folder and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\msvsrv32
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\msvsrv32
W32/Agobot-KM runs continuously in the background, allowing a remote intruder to access and control the computer via IRC channels.
W32/Agobot-KM modifies the Windows HOSTS file to redirect several AV and security-related websites to 127.0.0.1
Recovery
Please follow the instructions for removing worms.
Replace the Hosts file from a backup or edit it in Notepad to remove the changes that the worm has made.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\msvsrv32
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\msvsrv32
and delete them if they exist.
Close the registry editor.
[url=\"http://www.sophos.com/virusinfo/analyses/w32agobotkm.html\"]Sophos Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]

