Alerts

Moderators: Moderator, Global Moderator

Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

PWSteal.Likmet.A

Discovered on: July 05, 2004
Last Updated on: July 06, 2004 11:43:35 AM


PWSteal.Likmet.A is a Trojan horse that displays a fake MSN Messenger logon window and steals the password provided.

Type: Trojan Horse
Infection Length: 1,098,248 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX


Virus Definitions (Intelligent Updater) *

July 05, 2004

Virus Definitions (LiveUpdate™) **

July 05, 2004


*

Intelligent Updater definitions are released daily, but require manual download and installation.
Click here to download manually.

**

LiveUpdate virus definitions are usually released every Wednesday.
Click here for instructions on using LiveUpdate.



Wild:
Geographical distribution: Low
Threat containment: Easy
Removal: Easy

Threat Metrics

Wild:Low
Damage:Low
Distribution:Low

Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Steals MSN Messenger passwords.
Compromises security settings: n/a

Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 88
Shared drives: n/a
Target of infection: MSN Messenger

It has been reported that this Trojan is sent through MSN Messenger as a file named "Net Echo.exe".

When PWSteal.Likmet.A is executed, it performs the following actions:

Displays a fake error message window which reads:

MSN Echo Runtime error 429 Not enough memory

Opens a backdoor on TCP port 88.

Creates a fake MSN messenger logon window when an attacker connects to this backdoor

Sends the login information that the user types into this window back to the attacker, using the back door.

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as PWSteal.Likmet.A.

If any files are detected as infected with PWSteal.Likmet.A, click Delete.

Note: If your Symantec antivirus product reports that it cannot delete an infected file, Windows may be using the file. To fix this, run the scan in Safe mode. For instructions, read the document, "How to start the computer in Safe Mode." Once you have restarted in Safe mode, run the scan again.

When all the infected files have been deleted, restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.likmet.a.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Troj/Padodo-Fam

Aliases: Backdoor.AXJ, Berbew, Webber

Type: Trojan

Troj/Padodo-Fam is a family of proxy and backdoor Trojans with password
stealing funtionality.
When first run the Trojans copy themselves to the Windows system folder
with a random filename and an extension of EXE and drop a library DLL to
the system folder with a random filename and an extension of DLL.

The DLL is registered as a COM object creating registry entries similar
to the following:

HKCR\CLSID\(79FEACFF-FFCE-815E-A900-316290B5B738)
\InProcServer32\

HKCR\CLSID\(79FEACFF-FFCE-815E-A900-316290B5B738)
\InProcServer32\@ = <pathname of dropped DLL>

HKCR\CLSID\(79FEACFF-FFCE-815E-A900-316290B5B738)
\InProcServer32\ThreadingModel = "Apartment"

The following registry entry is created to load the DLL on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad\Web Event Logger =
(79FEACFF-FFCE-815E-A900-316290B5B738)

The DLL component launches the Trojan executable which then runs
continuously in the background allowing unauthorised access and control
of the computer from a remote network location.

Log files may be created in the system folder to store stolen passwords.

The Trojans provide a proxy server on a random port which allows data to
be routed through the computer. The proxy can be used to bypass access
restrictions, to hide the IP address of the source computer and to forward
spam email.

Following installation the Trojans try to send notification messages to
remote locations with details of the computer's IP address and access
ports.

Follow the Trojan Removal Instructions in Pinned Topics

[url=\"http://www.sophos.com\"]Sophos[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Beagle.AA@mm
Discovered on: July 12, 2004
Last Updated on: July 13, 2004 11:01:47 AM

W32.Beagle.AA@mm is a mass-mailing worm that uses its own SMTP engine to spread through email and opens a backdoor on TCP port 1234.

The worm is functionally similar to W32.Beagle.X@mm and is packed with FSG.

Type: Worm
Infection Length: 15 KB

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Allows unauthorized remote access to a compromised host.
Distribution

Subject of email: varies
Name of attachment: varies
Size of attachment: varies
Ports: Opens backdoor on TCP port 1234
Shared drives: n/a
Target of infection: n/a


When W32.Beagle.AA@mm runs, it performs the following actions:


Displays the error message image:

"Can't Find A Viewer Associated With The File!"

Creates seven mutexes with the following names, which prevent some variants of W32.Netsky@mm from running:

MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_

Deletes any values that contain the following strings:

"My AV"
"Zone Labs Client Ex"
"9XHtProtect"
"Antivirus"
"Special Firewall Service"
"service"
"Tiny AV"
"ICQNet"
"HtProtect"
"NetDy"
"Jammer2nd"
"FirewallSvr"
"MsInfo"
"SysMonXP"
"EasyAV"
"PandaAVEngine"
"Norton Antivirus AV"
"KasperskyAVEng"
"SkynetsRevenge"
"ICQ Net"

from the keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Creates the following files:

%System%\loader_name.exe
%System%\loader_name.exeopen (A copy of the worm with randomly appended data.)

Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Drops the file, %System%\loader_name.exeopenopen. This file will be a .zip file, .vbs file, .cpl file, .hta file, or the worm itself. One of the following actions will occur, depending on the file type:

If the file is a .zip file, it will contain two randomly named files. One will be a .exe file and the other will be a text file with a .sys, .dat, .idx, .vxd, .vid, or .dll extension.
If the file is a .vbs file and is executed, it will drop a file named vss_2.exe into the current folder.
If the file is a .cpl file and is executed, it will drop a file named cplstub.exe into the %Windir% folder.
If the file is a .hta file and is executed, it will drop a file named qwrk.exe into the current folder.


Drops the file, %System%\loader_name.exeopenopenopen. If the file Gdiplus.dll is present on the computer, this file will be a .jpg or .gif. Otherwise it will be a .bmp file.


Adds the value:

"reg_key" = "%System%\loader_name.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


If the system date is after January 25, 2005, the worm will exit from memory and delete its registry value, as well as the key:

HKEY_CURRENT_USER\SOFTWARE\base_reg_path


Opens a backdoor on TCP port 1234, which allows the infected computer to be used as an email relay.


Attempts to create copies of itself in any folder that contains the characters "shar". The files will have the following file names:

Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral, /censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> cool, awesome!!.exe
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe


Searches for the email addresses in files that have the following extensions:

.wab
.txt
.msg
.htm
.shtm
.stm
.xml
.dbx
.mbx
.mdx
.eml
.nch
.mmf
.ods
.cfg
.asp
.php
.pl
.wsh
.adb
.tbb
.sht
.xls
.oft
.uin
.cgi
.mht
.dhtm
.jsp


Uses its own SMTP engine to send email messages to any addresses found. The email may have the following characteristics:

From: <spoofed>

Subject: (One of the following)
Re: Msg reply
Re: Hello
Re: Yahoo!
Re: Thank you!
Re: Thanks /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
RE: Text message
Re: Document
Incoming message
Re: Incoming Message
RE: Incoming Msg
RE: Message Notify
Notification
Changes..
Update
Fax Message
Protected message
RE: Protected message
Forum notify
Site changes
Re: Hi
Encrypted document


Body: If the attachment is a .zip file, then the body will contain one of the following messages:

For security reasons attached file is password protected. The password is
For security purposes the attached file is password protected. Password --
Note: Use password
Attached file is protected with the password for security reasons. Password is
In order to read the attach you have to use the following password:
Archive password:
Password
Password:

followed by a copy of the image file dropped as loader_name.exeopenopen.


If the attachment is not a .zip file, the body will be one of the following,

Read the attach.
Your file is attached.
More info is in attach
See attach.
Please, have a look at the attached file.
Your document is attached.
Please, read the document.
Attach tells everything.
Attached file tells everything.
Check attached file for details.
Check attached file.
Pay attention at the attach.
See the attached file for details.
Message is in attach
Here is the file.


Attachment: (One of the following)
Information
Details
text_document
Updates
Readme
Document
Info
MoreInfo
Message


Attachment extension: (One of the following)
.hta
.vbs
.exe
.scr
.com
.cpl
.zip

Removal:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AA@mm.
Delete the value that was added to the registry.

To delete the value from the registry

WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"reg_key" = "%System%\loader_name.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.aa@mm.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Lovgate.AD@mm
Discovered on: July 13, 2004
Last Updated on: July 13, 2004 02:15:13 PM

W32.Lovgate.AD@mm is mass-mailing worm that spreads using the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026) and through open network shares.

The worm infects executable files and allows unauthorized remote access to the infected computer.

Type: Worm
Infection Length: 125,440 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Attempts to reply to incoming email messages. Gathers email addresses from the infected computer and emails itself to them.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates the processes of security and antivirus applications.
Distribution

Subject of email: Varies
Name of attachment: Randomly generated, with a .bat, .exe, .pif or .scr file extension.
Size of attachment: 125,440 bytes
Time stamp of attachment: n/a
Ports: Random port.
Shared drives: Copies itself to network shared folders.
Target of infection: n/a


When W32.Lovgate.AD@mm is executed, it performs the following actions:


Copies itself as the following:

%Windir%\SYSTRA.EXE
%System%\hxdef.exe
%System%\IEXPLORE.EXE
%System%\RAVMOND.exe
%System%\realsched.exe
%System%\vptray.exe
%System%\kernel66.dll (With attributes set to Read Only, Hidden, and System)
C:\COMMAND.EXE
C:\AUTORUN.INF
%System%\ODBC16.dll (A component of the backdoor. 53,248 bytes)
%System%\msjdbc11.dll (A component of the backdoor. 53,248 bytes)
%System%\MSSIGN30.DLL (A component of the backdoor. 53,248 bytes)
%System%\LMMIB20.DLL (A component of the backdoor. 53,248 bytes)

Notes:
%Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
%System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the values:

"WinHelp" = "%system%\realsched.exe"
"Hardware Profile" = "%system%\hxdef.exe"
"Program In Windows" = "%system%\IEXPLORE.EXE"
"Microsoft NetMeeting Associates, Inc." = "NetMeeting.exe"
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg"
"Shell Extension" = "%system%\spollsv.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Adds the values:

"SystemTra" = "%Windor%\SysTra.EXE"
"COM++ System" = "suchost.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\runServices

which starts the worm when Windows starts.


Adds the value:

"run"="RAVMOND.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows

which starts the worm when Windows starts.


Modifies the value:

"(Default)"="vptray.exe %1"

in the registry keys:

HKEY_CLASSES_ROOT\txtfile\shell\open\command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command

so that the worm will run each time a .txt file is opened.


Creates the following services:

Display name: _reg
ImagePath: Rundll32.exe msjdbc11.dll ondll_server
Startup: automatic

Display name: Windows Management Protocol v.0 (experimental)
Description: Windows Advanced Server. Performs scheduled scans for LANguard.
ImagePath: Rundll32.exe msjdbc11.dll ondll_server
Startup: automatic


Terminates any processes with the following strings in their names:

KV
KAV
Duba
NAV
kill
RavMon.exe
Rfw.exe
Gate
McAfee
Symantec
SkyNet
rising


Attempts to propagate to other computers by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026).


Scans computers attached to the same local network as the infected computer, attempting to authenticate to the admin$ share. The worm uses "Guest", "Admin", or "Administrator" for a username, combined with the following passwords:

!@#$
!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
000000
00000000
007
110
111
111111
11111111
121212
123
123123
1234
12345
123456
1234567
12345678
123456789
123abc
123asd
2003
2004
2600
321
54321
654321
666666
888888
88888888
aaa
abc
abc123
abcd
abcdef
abcdefg
Admin
admin
admin123
Administrator
administrator
alpha
asdf
asdfgh
computer
database
enable
god
godblessyou
Guest
guest
home
Internet
login
Login
love
mypass
mypass123
mypc
mypc123
oracle
owner
pass
passwd
Password
password
pw123
pwd
root
secret
server
sex
sql
super
sybase
temp
temp123
test
test123
win
xxx
yxcv
zxcv


If the worm successfully authenticates to a remote computer, it will attempt to create the following copy of itself as \\<remote computer>\admin$\system32\NetManager32.exe.


Creates a service on the remote computer named "Windows Management NetWork Service Extensions" and a share named "Media".


May copy itself to shared drives using one or more of the following names:

WinRAR.exe
Internet Explorer.bat
Documents and Settings.txt.exe
Microsoft Office.exe
Windows Media Player.zip.exe
Support Tools.exe
WindowsUpdate.pif
Cain.pif
MSDN.ZIP.pif
autoexec.bat
findpass.exe
client.exe
i386.exe
winhlp32.exe
xcopy.exe
mmc.exe


Opens a backdoor on a random port.


Replies to any email messages that arrive in the inbox of certain MAPI-compliant email clients, such as Microsoft Outlook.

For example, if the incoming email has the following properties:

Subject: <subject>
Message: <original message body>

The reply will be formatted as follows:

Subject: Re: <subject>

Message:
<original message body>
<domain name> auto-reply:
If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about,don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;
... ... more look to the attachment.

> Get your FREE <domain name> Mail now! <

Attachment: (One of the following)
the hardcore game-.pif
Sex in Office.rm.scr
Deutsch BloodPatch!.exe
s3msong.MP3.pif
Me_nude.AVI.pif
How to Crack all gamez.exe
Macromedia Flash.scr
SETUP.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
DSL Modem Uncapper.rar.exe
joke.pif
Britney spears nude.exe.txt.exe
I am For u.doc.exe


May gather email addresses on the infected computer and send an email with the following properties:

Subject: (One of the following)
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error

Message: (One of the following)
Mail failed. For further assistance, please contact!
The message contains Unicode characters and has been sent as a binary attachment.
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.

Attachment: (Randomly constructed, with one of the following extensions)
.exe
.scr
.pif
.com
.rar


Infects .exe files by doing the following to a host file:

Prepending a copy of the dropped file, suchost.exe.
Appending a copy of the original worm.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lovgate.AD@mm.
Reverse the changes made to the registry

To reverse the changes made to the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.


Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the values:

"WinHelp" = "%system%\realsched.exe"
"Hardware Profile" = "%system%\hxdef.exe"
"Program In Windows" = "%system%\IEXPLORE.EXE"
"Microsoft NetMeeting Associates, Inc." = "NetMeeting.exe"
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg"
"Shell Extension" = "%system%\spollsv.exe"


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\runServices


In the right pane, delete the values:

"SystemTra" = "%Windor%\SysTra.EXE"
"COM++ System" = "suchost.exe"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows


In the right pane, delete the value:

"run"="RAVMOND.exe"


Navigate to the keys:

HKEY_CLASSES_ROOT\txtfile\shell\open\command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command


In the right pane, restore the value:

"(Default)" = "%SystemRoot%\system32\NOTEPAD.EXE %1"

or to the location of your default text editor.


Exit the Registry Editor.


Restart the computer in Normal mode

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.ad@mm.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Lovgate.AC@mm
Discovered on: July 13, 2004
Last Updated on: July 13, 2004 03:00:25 PM

W32.Lovgate.AC@mm is mass-mailing worm that spreads using the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026) and through open network shares.

The worm infects executable files and allows unauthorized remote access to the infected computer.

Type: Worm
Infection Length: 131,072 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Microsoft IIS, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Attempts to reply to incoming email messages. Gathers email addresses from the infected computer and emails itself to them.
Deletes files: n/a
Modifies files: Renames .exe files to .zmx
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates the processes of security and antivirus applications.
Distribution

Subject of email: Varies
Name of attachment: Randomly generated, with a .bat, .exe, .pif or .scr file extension.
Size of attachment: 125,440 bytes
Time stamp of attachment: n/a
Ports: TCP port 6000
Shared drives: Copies itself to network shared folders.
Target of infection: Copies itself to Kazaa shared folder.


When W32.Lovgate.AC@mm is executed, it performs the following actions:


Creates the following files:

%Windir%\CDPlay.exe
%System%\iexplore.exe
%System%\RAVMOND.exe
%System%\WinHelp.exe
%System%\Update_OB.exe
%System%\TkBellExe.exe
%System%\hxdef.exe
%System%\Kernel66.dll, which is a hidden file.

Notes:
%Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
%System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates a file named CDROM.COM in the root folder of all drives, except CD-ROM drives. The file attributes are set to system, hidden, and read_only.


Creates an autorun.inf file on each drive with the lines:

[Autorun]
open="C:\cdrom.com" /StartExplorer


Creates an archive containing a copy of the worm with the following format in the root folder of all drives, unless the drive letter is A or B:

<filename>.<ext>

Where <filename> may be one of the following:
Bakeup
Tools
email

and <ext> is one of the following:
RAR
ZIP


Adds the values:

"Winhelp" = "%system%\TkBellExe.exe..."
"Hardware Profile" = "%system%\hxdef.exe..."
"Program in Windows"="%system%\IEXPLORE.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Adds the values:

"COM++ System" = "exploier.exe..."
"SystemTra" = "%windows%\CDPlay.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\runServices

which starts the worm when Windows starts.


Adds the value:

"run"="RAVMOND.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows

which starts the worm when Windows starts.


Modifies the value:

(Default) = "Update_OB.exe %1..."

in the registry keys:

HKEY_CLASSES_ROOT\txtfile\shell\open\command

so that the worm will run each time a .txt file is opened.


Stops the following services:

Rising Realtime Monitor Service
Symantec AntiVirus Server
Symantec AntiVirus Client


Terminates any processes with the following strings in their names:

rising
SkyNet
Symantec
McAfee
Gate
Rfw.exe
RavMon.exe
kill
NAV
Duba
KAV


Scans all the drives on the infected computer. If the drive type is removable, mapped, or the drive type is fixed with a drive letter greater than E, it does the following:

Attempts to rename the extensions of all .exe files to .zmx.
Sets the attributes on these files to hidden and system.
Copies itself as the original file name.


Injects a process-watching procedure, as a thread, into either Explorer.exe or Taskmgr.exe. If this thread detects that the worm process has stopped, it will attempt to launch %System%\Iexplore.exe.


Listens on TCP port 6000.


Steals information from an infected computer and stores it in the file, C:\Netlog.txt. The worm then emails the stolen information to the hacker.


Determines the location of the Kazaa shared folder from the registry.


Creates a copy of itself in the Kazaa shared folder as one of the following (with a .bat, .exe, .pif, or .scr file extension):

wrar320sc
REALONE
BlackIcePCPSetup_creak
Passware5.3
word_pass_creak
HEROSOFT
orcard_original_creak
rainbowcrack-1.1-win
W32Dasm
setup
<random file name>


Scans computers attached to the same local network as the infected computer, attempting to authenticate to the administrative shares. The worm uses "Administrator" for a username, combined with the following passwords:

!@#$
!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
000000
00000000
007
110
111
111111
11111111
121212
123
123123
1234
12345
123456
1234567
12345678
123456789
123abc
123asd
2003
2004
2600
321
54321
654321
666666
888888
88888888
aaa
abc
abc123
abcd
abcdef
abcdefg
Admin
admin
admin123
Administrator
administrator
alpha
asdf
asdfgh
computer
database
enable
god
godblessyou
Guest
guest
home
Internet
login
Login
love
mypass
mypass123
mypc
mypc123
oracle
owner
pass
passwd
Password
password
pw123
pwd
root
secret
server
sex
sql
super
sybase
temp
temp123
test
test123
win
xxx
yxcv
zxcv


If the worm successfully authenticates to a remote computer, it will attempt to create the following copy of itself as \\<remote computer name>\admin$\system32\NetManager.exe.


It will then start the file as the service, "Windows Management NetWork Service Extensions" which is mapped to "NetManager.exe -exe_start."


Creates a network share named "Media", which is mapped to %Windir%\Media.


Copies itself to all network shared folders using one or more of the following names:

WinRAR.exe
Internet Explorer.bat
Documents and Settings.txt.exe
Microsoft Office.exe
Windows Media Player.zip.exe
Support Tools.exe
WindowsUpdate.pif
Cain.pif
MSDN.ZIP.pif
autoexec.bat
findpass.exe
client.exe
i386.exe
winhlp32.exe
xcopy.exe
mmc.exe


Replies to any email messages that arrive in the inbox of certain MAPI-compliant email clients, such as Microsoft Outlook.

For example, if the incoming email has the following properties:

Subject: <subject>
Message: <original message body>

The worm will attempt to reply with the following:

Subject: Re: <subject>
Message:
'<sender>' wrote:
====
> <original message body>
====

<domain.com> account auto-reply:

If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about,don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;
... ... more look to the attachment.

> Get your FREE <domain.com> account now! <

Attachment: (One of the following)
the hardcore game-.pif
Sex in Office.rm.scr
Deutsch BloodPatch!.exe
s3msong.MP3.pif
Me_nude.AVI.pif
How to Crack all gamez.exe
Macromedia Flash.scr
SETUP.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
DSL Modem Uncapper.rar.exe
joke.pif
Britney spears nude.exe.txt.exe
I am For u.doc.exe


Retrieves email addresses from the Windows address book and from files with the following extensions:

.txt
.pl
.wab
.adb
.tbb
.dbx
.asp
.php
.sht
.htm

under the following folders:

%Windir%\Local Settings
\documents and settings\&lt;current user&gt;\local settings
\Temporary Internet Files


The worm also uses its own SMTP engine to send itself to the email addresses found.

The email has the following characteristics:

Subject: (One of the following)
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error

Message: (One of the following)
pass
Mail failed. For further assistance, please contact!
The message contains Unicode characters and has been sent as a binary attachment.
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.

Attachment: (One of the following)
document
readme
doc
text
file
data
test
message
body

with one of the following extensions:
.bat
.cmd
.exe
.pif
.scr


Attempts to find .exe files. If successful, the worm creates a viral file in %System%\win~.uuu and prepends this file to the .exe file.


Disable System Restore (Windows Me/XP).
Update the virus definitions.
Reverse the changes made to the registry.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lovgate.Z@mm.
Rename the .zmx files to the .exe files.

[b]To reverse the changes made to the registry[/b]

Before continuing, Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. For instructions, read the document, "How to make a backup of the Windows registry."

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the values:

"Winhelp" = "%system%\TkBellExe.exe..."
"Hardware Profile" = "%system%\hxdef.exe..."
"Program in Windows"="%system%\IEXPLORE.exe"


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices


In the right pane, delete the values:

"COM++ System" = "exploier.exe..."
"SystemTra" = "%windows%\CDPlay.exe"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows


In the right pane, delete the value:

"run"="RAVMOND.exe"


Navigate to the following keys:

HKEY_CLASSES_ROOT\txtfile\shell\open\command\
HKEY_LOCAL_MACHINE\Software\Classes\txtfile\shell\open\command


In the right pane, restore the value:

"(Default)" = "%SystemRoot%\system32\NOTEPAD.EXE %1"

or to the location of your default text editor.


Exit the Registry Editor.

[b]To rename the .zmx files to the .exe files[/b]

As W32.Lovgate.Z@mm modifies the .exe files, correct this for relevant programs to function correctly.

Follow the instructions for your operating system:

Windows 98/Me/2000

On the Windows desktop, click the Start button > Find or Search > Files or Folders.
In the Search Results window, set "Look in" to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Check Include subfolders.
In the Named or Search for... box, type, or copy and paste, the following:

*.zmx


Click Find Now or Search Now.


Windows XP

On the Windows desktop, click the Start button > Search.
Click All files and folders.
In the "All or part of the file name box," type, or copy and paste, the following:

*.zmx


Verify that "Look in" is set to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Click More advanced options.
Select Search system folders.
Select Search subfolders.
Select Search hidden files and folders.
Click Search.


For every file that is found, right click it, select Rename, and then change the .zmx extension to .exe.


Repeat step 6 for every removable, mapped, or fixed drive type with a drive letter greater than E.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.ac@mm.html\"]Symantec Source[/url]
Last edited by Tami on Tue Jul 13, 2004 4:43 pm, edited 1 time in total.
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32/Rbot-DP
Win32 worm


W32/Rbot-DP is an IRC backdoor Trojan with spreading capability. W32/Rbot-DP copies itself into the Windows system folder and sets the following registry entries to run itself automatically when Windows starts up
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft DirectX
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft DirectX
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Microsoft DirectX

W32/Rbot-DP logs onto a predefined IRC server and waits for backdoor commands. When receives the appropriate backdoor command W32/Rbot-DP will attempt to spread to other computers.

Scan your computer with your anti virus software, remove worm, edit your registry:

Locate the HKEY_LOCAL_MACHINE entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

and remove any reference to any file you deleted.

Each user has a registry area named HKEY_USERS\[code number indicating user]\. For each user locate the entry:

HKU\[code number]\Software\Microsoft\Windows\
CurrentVersion\Run\

and remove any reference to any file you deleted.

Close the registry editor

[url=\"http://www.sophos.com/virusinfo/analyses/w32rbotdp.html\"]Sophos Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32/Rbot-DL
Aliases: Backdoor.Rbot.gen, W32/Sdbot.worm.gen.k, WORM_RBOT.W
Win32 worm

W32/Rbot-DL is a network worm and backdoor Trojan for the Windows platform.
W32/Rbot-DL allows a malicious user remote access to an infected computer.
The worm copies itself to a file named winsyst.exe in the Windows system
folder and creates the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Update = winsyst.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Update = winsyst.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Update = winsyst.exe.

W32/Rbot-DL spreads using a variety of techniques including exploiting weak passwords on computers and SQL servers, exploiting operating system vulnerabilities (including DCOM-RPC, LSASS, WebDAV and UPNP) and using backdoors opened by other worms or Trojans.

W32/Rbot-DL can be controlled by a remote attacker over IRC channels.

Patches for the operating system vulnerabilities exploited by W32/Rbot-DL can
be obtained from Microsoft at:
MS04-011
MS03-026
MS03-007
MS01-059

Use your anti-virus software to remove the worm, then edit your registry:

Locate the HKEY_LOCAL_MACHINE entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

and remove any reference to any file you deleted.

Each user has a registry area named HKEY_USERS\[code number indicating user]\. For each user locate the entry:

HKU\[code number]\Software\Microsoft\Windows\
CurrentVersion\Run\

and remove any reference to any file you deleted.

Close the registry editor.

[url=\"http://www.sophos.com/virusinfo/analyses/w32rbotdl.html\"]Sophos Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Atak@mm
Discovered on: July 13, 2004
Updated on: July 15, 2004 12:13:27 PM

W32.Atak@mm is a mass-mailing worm that spreads by sending itself to email addresses gathered from the infected computer.


The email has the following characteristics:

Subject:

Read the Result!
Important Data!

Attachment:
A .zip file that includes a copy of the worm.


Also Known As: Win32/Atak.A [Panda], W32/Atak@MM [McAfee], I-Worm.Atak.a [Kaspersky]

Type: Worm
Infection Length: 15,917 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Yes
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: Read the Result! -or- Important Data!
Name of attachment: A .zip file containing a copy of the worm.
Size of attachment: 15,917 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When W32.Atak@mm is executed, it performs the following actions:


Copies itself as %System%\hint.exe.

Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates a mutex named "SloperMtx" to ensure that only one instance of the worm is executed on the computer.


On NT based system, the worm will add the value:

"load"="%System%\hint.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows

On 9x system, it will adds the following line to the [windows] section of Win.ini file:

"load"="%System%\hint.exe"

Scans the following locations:

Default windows address book
"%Windir%\Temporary Internet Files"
"%USERPROFILE%\Local Settings\Temporary Internet Files"
Disk A
Disk C to Z(only if it's a fixed or ram disk)

and attempts to get email addresses from the files who extension is one of the following:

txt
eml
nch
mbx
htm
log
ods
mht
sht
php
cgi
asp
jsp
uin
dbx
msg
vbs
cfg
xml
html
tbb
adb
pl
wab

Sends itself out to email addresses is finds on the infected computer.

The email has the following characteristics:

From: (start with one of the following string)

kevin
huck
george
mike
andrew

Subject:

Read the Result!
Important Data!

Message:
Authorized Researcher Only.

Attachment:
A .zip file that includes a copy of the worm. The filename is constructed as: <random 3-7 lower-case characters>.zip.
the filename of the embedded file inside the zip file is constructed as: <random 3-7 lower-case characters>.<"gif" or "jpg"><70 blank space>.<exe>

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Atak@mm.
Delete the value that was added to the registry.
[b]Edit the Win.ini file. <<added July 15/04[/b]

To delete the value from the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows


In the right pane, delete the value:

"load"="%System%\hint.exe"


Exit the Registry Editor.

[b]Edit the Win.ini file

If you are running Windows 95/98/Me, follow these steps:

The function you perform depends on your operating system:

Windows 95/98: Go to step B.

Windows Me: If you are running Windows Me, the Windows Me file-protection process may have made a backup copy of the Win.ini file that you need to edit. If this backup copy exists, it will be in the C:\Windows\Recent folder. Symantec recommends that you delete this file before continuing with the steps in this section. To do this:

Start Windows Explorer.
Browse to and select the C:\Windows\Recent folder.
In the right pane, select the Win.ini file and delete it. The Win.ini file will be regenerated when you save your changes to it in step F.


Click Start > Run.
Type the following:

edit c:\windows\win.ini

and then click OK.

(The MS-DOS Editor opens.)

NOTE: If Windows is installed in a different location, make the appropriate path substitution.


In the [windows] section of the file, look for a line similar to:

load=%System%\hint.exe


If this line exists, delete everything to the right of load=


Click File > Save.
Click File > Exit.[/b]


[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.atak@mm.html\"]Symantec Source[/url]
Last edited by Tami on Sun Jul 18, 2004 12:32 pm, edited 1 time in total.
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Trojan.Cargao
Discovered on: July 14, 2004
Last Updated on: July 14, 2004 03:40:54 PM


Trojan.Cargao is a Trojan horse that sends emails to all contacts it finds in Windows address book. It also downloads executable files and executes them.

Type: Worm
Infection Length: 309,289 bytes, 105,472 bytes, 131,072 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Yes
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: Ol [recipient name], Entrega para voc - oCarteiro.com Cart Diverss e muito mais!
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When Trojan.Cargao is executed, it performs the following actions:


Creates the following files:

%Temp%\appconn.exe (105,472 bytes)
%Temp%\cartao.exe (176,640 bytes)

Note: %Temp% is a variable. The Trojan locates the temporary folder and copies itself to that location. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).


Contacts the domain, ocarteiro.hostdotnet.com.br, and attempts to download the following files:

applrpc.exe
applrpc.dll
appconn.exe
winssl.exe

and saves them to C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS.


Connects to one of the following domains and opens a Web page:

www.hostdotnet.com.br
www.10s.com.br


Adds the value:

"appconn"="C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS\appconn.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs when Windows starts.


Sends emails to all contacts it finds in the Windows address book.

The email has the following characteristics:

Subject:
Ol [recipient name], Entrega para voc - oCarteiro.com Cart
Diverss e muito mais!

Message:
The message is in HTML and contains many links.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Do one of the following:
Windows 95/98/Me: Restart the computer in Safe mode.
Windows NT/2000/XP: End the malicious process.
Run a full system scan and delete all the files detected as Trojan.Cargao.
Reverse the changes made to the registry.

To reverse the changes made to the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.


Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"appconn"="C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS\appconn.exe"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.cargao.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Trojan.Foron
Discovered on: July 13, 2004
Last Updated on: July 14, 2004 03:41:48 PM


Trojan.Foron is a browser helper object that attempts to steal system information and send it to a remote attacker. It also can act as a backdoor program.

Type: Trojan Horse
Infection Length: 1,234

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Attempts to steal system and personal information
Compromises security settings: Allows unauthorized remote access
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When Trojan.Foron is executed, it performs the following actions:


Creates the following registry keys:

HKEY_CLASSES_ROOT\Html.mmHKCR\Html.mm.1HKCR\CLSID\{B49DA3DF-E569-423d-BDEA-8F89128E8107}
HKEY_CLASSES_ROOT\TypeLib\{BAF91296-5246-458E-BB13-0E14E64BCD28}
HKEY_CLASSES_ROOT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{B49DA3DF-E569-423d-BDEA-8F89128E8107}


Executes one of the following files to act as a backdoor:

command.com
cmd.exe

Note: The Trojan may need the following files in order to function properly:

msrascfg.ini
mskeboard.dll
mssysmsg.dll
mstword.dll


Monitors any packet movement through the infected computer.


Collects the following information:

OS version
Computer Name
Registered User Name
Registered Organization Name
RAM
Cached password


Sends collected information to the attacker when receives a certain command.

Removal Instructions

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Foron.
Delete the value that was added to the registry.

To delete the value from the registry

Click Start, and then click Run. (The Run dialog box appears.)
Type regedit

Then click OK. (The Registry Editor opens.)


Navigate to the key:

HKEY_CLASSES_ROOT\CLSID\{B49DA3DF-E569-423d-BDEA-8F89128E8107}\InprocServer32\(Default)


In the right pane, delete files associated with the above key.


Delete the subkeys:

HKEY_CLASSES_ROOT\Html.mmHKCR\Html.mm.1HKCR\CLSID\{B49DA3DF-E569-423d-BDEA-8F89128E8107}
HKEY_CLASSES_ROOT\TypeLib\{BAF91296-5246-458E-BB13-0E14E64BCD28}
HKEY_CLASSES_ROOT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{B49DA3DF-E569-423d-BDEA-8F89128E8107}


Exit the Registry Editor

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.foron.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Backdoor.Xebiz
Discovered on: July 13, 2004
Last Updated on: July 14, 2004 03:41:36 PM

Backdoor.Xebiz is a Backdoor Trojan horse that allows a remote attacker to perform various actions on a compromised computer.

Also Known As: BackDoor-CGT [McAfee], Xebiz.A [Panda], Troj/Xebix.A [Sophos], Trojan.Win32.Genme.a [Kaspersky]

Type: Trojan Horse
Infection Length: 15,360 bytes, 3,072 bytes



Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: May modify the system files to ensure that it is run.
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: A attacker can access confidential information on a compromised computer.
Compromises security settings: Allows unauthorized access to an infected computer.
Distribution

Subject of email: Varies.
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


A large scale spamming of messages contained a link to a Web page hosting the backdoor. Following the link downloads the file Links.HTA, which in turn downloads and executes the Trojan as ss.exe.

When Backdoor.Xebiz is executed, it performs the following actions:


Copies itself as %System%\ss.exe.

Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the following files:

ss.dat - backup copy of Backdoor.Xebiz xored with 0x20 (15,360 bytes)
dss.dll - launches Backdoor.Xebiz (3,072 bytes)
dssa.dll - restores Backdoor.Xebiz from a backup (3,072 bytes)


Adds the value:

"ss"="{<newly created CLSID>}"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad

so that the Trojan runs when you start Windows.


Adds the value:

"(Default)"="dssa.dll"

to the registry key:

HKEY_CLASSES_ROOT\CLSID\{<CLSID from step 3>}\InProcServer32

so that the Trojan runs when you start Windows.


Opens a backdoor on a random TCP port and sends a notification to the attacker, which contains the port number and IP address of the infected computer.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Xebiz.
Reverse the changes made to the registry.


To reverse the changes made to the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.


Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad


In the right pane, delete the value:

"ss"="{<CLSID from step 3>}"


Navigate to the key:

HKEY_CLASSES_ROOT\CLSID\{<CLSID from step 3>}\InProcServer32


In the right pane, delete the value:

"(Default)"="dssa.dll"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.xebiz.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Backdoor.Doster
Discovered on: July 15, 2004
Last Updated on: July 16, 2004 12:32:10 PM

Backdoor.Doster is a Backdoor Trojan horse that attempts to give an attacker access to your computer. It also modifies the Hosts file.

Type: Worm

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Allows unauthorized remote access
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When Backdoor.Doster is executed, it performs the following actions:


Creates the file %Windir%\hosts.


Notes:
If this file already exists in this location, which is the default location of Windows 95/98/Me, the Trojan will overwrite the existing file.
%Windir% is a variable. By default, this is C:\Windows or C:\Winnt.


Locates the default Hosts file if it is not in %Windir% and overwrites it with the dropped hosts file. This causes any traffic going to the following URLs to be redirected to the local computer:

127.0.0.1 thehun.com
127.0.0.1 www.thehun.com
127.0.0.1 thehun.net
127.0.0.1 www.thehun.net
127.0.0.1 www.yahoo.com
127.0.0.1 yahoo.com
127.0.0.1 www.google.com
127.0.0.1 google.com
127.0.0.1 www.altavista.com
127.0.0.1 altavista.com
127.0.0.1 search.microsoft.com
127.0.0.1 search.msn.com
127.0.0.1 www.msn.com
127.0.0.1 msn.com
127.0.0.1 www.search.com
127.0.0.1 search.com
127.0.0.1 www.teoma.com
127.0.0.1 teoma.com
127.0.0.1 www.alltheweb.com
127.0.0.1 alltheweb.com
127.0.0.1 www.wisenut.com
127.0.0.1 wisenut.com
127.0.0.1 www.dmoz.org
127.0.0.1 dmoz.org
127.0.0.1 www.excite.com
127.0.0.1 excite.com
127.0.0.1 www.lycos.com
127.0.0.1 lycos.com
127.0.0.1 www.hotbot.com
127.0.0.1 hotbot.com
127.0.0.1 www.casino.com
127.0.0.1 casino.com


Adds the value:

"Explorer"="%System%\explorer.exe"

to the registry entry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that it is executed every time Windows starts.

Notes:
%System% is a variable. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Due to bugs in the code, the Trojan does not copy the Trojan file, Explorer.exe file, to the %System% folder. If it performed this action, this Explorer.exe file would contain functionality to open a backdoor on TCP port 80.

Removal Instructions

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Doster.
Delete the value that was added to the registry.

To delete the value from the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Explorer" = "%System%\explorer.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.doster.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Beagle.AB@mm
Discovered on: July 15, 2004
Last Updated on: July 15, 2004 05:20:45 PM

W32.Beagle.AB@mm is a mass-mailing worm that uses its own SMTP engine to spread through email and opens a backdoor on TCP port 1080. The email will have a variable subject and a file attachment. The attachment will have a .com, .cpl, .exe, .hta, .scr, .vbs, or .zip file extension.

The worm is packed with UPX.

Notes:

Virus definitions dated prior to July 15, 2004 may detect this as Bloodhound.Packed.
Virus definitions greater than version 60715av (extended version 7/15/2004 rev. 48) are required to detect this as W32.Beagle.AB@mm.


Also Known As: W32/Bagle.af@MM [McAfee], WORM_BAGLE.AF [Trend]

Type: Worm
Infection Length: Varies

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends email to addresses collected from the compromised host.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates processes associated with various security related programs. Allows unauthorized remote access to a compromised host.
Distribution

Subject of email: Varies
Name of attachment: Varies with a .com, .cpl, .exe, .scr, or .zip file extension.
Size of attachment: Varies
Time stamp of attachment: n/a
Ports: TCP 1080
Shared drives: n/a
Target of infection: n/a


When W32.Beagle.AB@mm runs, it performs the following actions:


Creates seven mutexes with the following names, which prevent some variants of W32.Netsky@mm from running:

MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_

Deletes any values that contain the following strings:

"My AV"
"Zone Labs Client Ex"
"9XHtProtect"
"Antivirus"
"Special Firewall Service"
"service"
"Tiny AV"
"ICQNet"
"HtProtect"
"NetDy"
"Jammer2nd"
"FirewallSvr"
"MsInfo"
"SysMonXP"
"EasyAV"
"PandaAVEngine"
"Norton Antivirus AV"
"KasperskyAVEng"
"SkynetsRevenge"
"ICQ Net"

from the keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Creates the following files:

%System%\sysxp.exe
%System%\sysxp.exeopen (A copy of the worm with randomly appended data.)

Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Drops the file, %System%\sysxp.exeopenopen. This file will be a .zip file or .cpl file:

If the file is a .zip file, it will contain two randomly named files. One will be a .exe file and the other will be a text file with a .sys, .dat, .idx, .vxd, .vid, or .dll extension.
If the file is a .cpl file and is executed, it will drop a file named cplstub.exe into the %Windir% folder.

Drops the file, %System%\sysxp.exeopenopenopen. If the file Gdiplus.dll is present on the computer, this file will be a .jpg or .gif. Otherwise it will be a .bmp file.


Drops the file, %System%\sysxp.exeopenopenopenopen, which is not viral by itself.

Adds the value:

"key" = "%System%\sysxp.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


If the system date is after January 25, 2005, the worm will exit from memory and delete its registry value, as well as the key:

HKEY_CURRENT_USER\SOFTWARE\base_path


Opens a backdoor on TCP port 1080, which allows the infected computer to be used as an email relay.


Contacts a .php script at each of the following domains:

[url=\"http://www.bmgs.bund.de\"]http://www.bmgs.bund.de[/url]
[url=\"http://www.gtz.de\"]http://www.gtz.de[/url]
[url=\"http://www.dwelle.de\"]http://www.dwelle.de[/url]
[url=\"http://www.monster.de\"]http://www.monster.de[/url]
[url=\"http://www.regtp.de\"]http://www.regtp.de[/url]
[url=\"http://www.stufenlos-regelbar.de\"]http://www.stufenlos-regelbar.de[/url]
[url=\"http://www.rapz-records.de\"]http://www.rapz-records.de[/url]
[url=\"http://abtacha.wirebrain.de\"]http://abtacha.wirebrain.de[/url]
[url=\"http://die-cliquee.de\"]http://die-cliquee.de[/url]
[url=\"http://www.gantke-net.de\"]http://www.gantke-net.de[/url]
[url=\"http://www.dar-fantasy.de\"]http://www.dar-fantasy.de[/url]
[url=\"http://www.mdirk.de\"]http://www.mdirk.de[/url]
[url=\"http://www.calistyler.de\"]http://www.calistyler.de[/url]
[url=\"http://tripod.de\"]http://tripod.de[/url]
[url=\"http://sgi1.rz.rwth-aachen.de\"]http://sgi1.rz.rwth-aachen.de[/url]
[url=\"http://www.sysserver1.de\"]http://www.sysserver1.de[/url]
[url=\"http://www.vwschubert.de\"]http://www.vwschubert.de[/url]
[url=\"http://ronnyackermann.de\"]http://ronnyackermann.de[/url]
[url=\"http://www.destatis.de\"]http://www.destatis.de[/url]
[url=\"http://www.berlinonline.de\"]http://www.berlinonline.de[/url]
[url=\"http://www.meinestadt.de\"]http://www.meinestadt.de[/url]
[url=\"http://obechmann.de\"]http://obechmann.de[/url]
[url=\"http://www.stepstone.de\"]http://www.stepstone.de[/url]
[url=\"http://www.degruyter.de\"]http://www.degruyter.de[/url]
[url=\"http://www.lufthansa.de\"]http://www.lufthansa.de[/url]
[url=\"http://www.duden.de\"]http://www.duden.de[/url]
[url=\"http://www.pcwelt.de\"]http://www.pcwelt.de[/url]
[url=\"http://www.astronomie.de\"]http://www.astronomie.de[/url]
[url=\"http://www.abacho.de\"]http://www.abacho.de[/url]
[url=\"http://www.bundesliga.de\"]http://www.bundesliga.de[/url]
[url=\"http://www.expo2000.de\"]http://www.expo2000.de[/url]
[url=\"http://knecht.cs.uni-magdeburg.de\"]http://knecht.cs.uni-magdeburg.de[/url]
[url=\"http://www.murczak.de\"]http://www.murczak.de[/url]
[url=\"http://www.murczak.de\"]http://www.murczak.de[/url]
[url=\"http://www.lupo18t.de\"]http://www.lupo18t.de[/url]
[url=\"http://www.hosteurope.de\"]http://www.hosteurope.de[/url]
[url=\"http://login.rz.fh-augsburg.de\"]http://login.rz.fh-augsburg.de[/url]
[url=\"http://www.hannobunz.de\"]http://www.hannobunz.de[/url]
[url=\"http://dfk-crew.clanintern.de\"]http://dfk-crew.clanintern.de[/url]
[url=\"http://www.empire-show.de\"]http://www.empire-show.de[/url]
[url=\"http://www.atlantis-show.de\"]http://www.atlantis-show.de[/url]
[url=\"http://www.superstar-nord.de\"]http://www.superstar-nord.de[/url]
[url=\"http://www.lords-of-havoc.de\"]http://www.lords-of-havoc.de[/url]
[url=\"http://deepiceman.de\"]http://deepiceman.de[/url]
[url=\"http://www.atlas-hannover.de\"]http://www.atlas-hannover.de[/url]
[url=\"http://begros.de\"]http://begros.de[/url]
[url=\"http://www.h-p-i.de\"]http://www.h-p-i.de[/url]
[url=\"http://www.szakos.de\"]http://www.szakos.de[/url]
[url=\"http://www.king-alp.de\"]http://www.king-alp.de[/url]
[url=\"http://people-ftp.freenet.de\"]http://people-ftp.freenet.de[/url]
[url=\"http://www.stuttgart.de\"]http://www.stuttgart.de[/url]
[url=\"http://www.eumetsat.de\"]http://www.eumetsat.de[/url]
[url=\"http://www.gutenberg2000.de\"]http://www.gutenberg2000.de[/url]
[url=\"http://www.heidelberg.de\"]http://www.heidelberg.de[/url]
[url=\"http://www.tu-muenchen.de\"]http://www.tu-muenchen.de[/url]
[url=\"http://www.studentenwerke.de\"]http://www.studentenwerke.de[/url]
[url=\"http://www.stellenmarkt.de\"]http://www.stellenmarkt.de[/url]
[url=\"http://zille.cs.uni-magdeburg.de\"]http://zille.cs.uni-magdeburg.de[/url]
[url=\"http://www.mupad.de\"]http://www.mupad.de[/url]
[url=\"http://www.gelbeseiten.de\"]http://www.gelbeseiten.de[/url]
[url=\"http://www.klug-suchen.de\"]http://www.klug-suchen.de[/url]
[url=\"http://www.niedersachsen.de\"]http://www.niedersachsen.de[/url]
[url=\"http://www.frankfurter-buchmesse.de\"]http://www.frankfurter-buchmesse.de[/url]
[url=\"http://www.freiburg.de\"]http://www.freiburg.de[/url]
[url=\"http://www.messe-duesseldorf.de\"]http://www.messe-duesseldorf.de[/url]
[url=\"http://www.beck.de\"]http://www.beck.de[/url]
[url=\"http://zeus05.de\"]http://zeus05.de[/url]
[url=\"http://www.europarl.de\"]http://www.europarl.de[/url]
[url=\"http://www.onlinereviewguide.com\"]http://www.onlinereviewguide.com[/url]
[url=\"http://www.krebsinformation.de\"]http://www.krebsinformation.de[/url]
[url=\"http://www.brigitte.de\"]http://www.brigitte.de[/url]
[url=\"http://www.webhits.de\"]http://www.webhits.de[/url]
[url=\"http://www.kabel1.de\"]http://www.kabel1.de[/url]
[url=\"http://www.saarland.de\"]http://www.saarland.de[/url]
[url=\"http://www.renewables2004.de\"]http://www.renewables2004.de[/url]
[url=\"http://www.awi-bremerhaven.de\"]http://www.awi-bremerhaven.de[/url]
[url=\"http://www.uni-tuebingen.de\"]http://www.uni-tuebingen.de[/url]
[url=\"http://www.frankfurt-airport.de\"]http://www.frankfurt-airport.de[/url]
[url=\"http://people-ftp.freenet.de\"]http://people-ftp.freenet.de[/url]
[url=\"http://people-ftp.freenet.de\"]http://people-ftp.freenet.de[/url]
[url=\"http://www.szakos.de\"]http://www.szakos.de[/url]
[url=\"http://www.king-alp.de\"]http://www.king-alp.de[/url]
[url=\"http://niematec.de\"]http://niematec.de[/url]
[url=\"http://symbit.de\"]http://symbit.de[/url]
[url=\"http://pe-data.de\"]http://pe-data.de[/url]
[url=\"http://web154.essen082.server4free.de\"]http://web154.essen082.server4free.de[/url]
[url=\"http://web216.berlin240.server4free.de\"]http://web216.berlin240.server4free.de[/url]
[url=\"http://edwinf.surfplanet.de\"]http://edwinf.surfplanet.de[/url]
[url=\"http://www.stricker-doerpen.de\"]http://www.stricker-doerpen.de[/url]
[url=\"http://www.helmholtz.de\"]http://www.helmholtz.de[/url]
[url=\"http://www.staedtetag.de\"]http://www.staedtetag.de[/url]
[url=\"http://www.tu-dresden.de\"]http://www.tu-dresden.de[/url]
[url=\"http://www.immobilienscout24.de\"]http://www.immobilienscout24.de[/url]
[url=\"http://www.karlsruhe.de\"]http://www.karlsruhe.de[/url]
[url=\"http://www.citypopulation.de\"]http://www.citypopulation.de[/url]
[url=\"http://www.schulen-ans-netz.de\"]http://www.schulen-ans-netz.de[/url]
[url=\"http://www.fernuni-hagen.de\"]http://www.fernuni-hagen.de[/url]
[url=\"http://www.stifterverband.de\"]http://www.stifterverband.de[/url]
[url=\"http://www.wissenschaft-online.de\"]http://www.wissenschaft-online.de[/url]
[url=\"http://www.nuernbergmesse.de\"]http://www.nuernbergmesse.de[/url]
[url=\"http://www.dortmund.de\"]http://www.dortmund.de[/url]
[url=\"http://www.uni-marburg.de\"]http://www.uni-marburg.de[/url]
[url=\"http://www.anwaltverein.de/\"]http://www.anwaltverein.de/[/url]
[url=\"http://www.math-net.de\"]http://www.math-net.de[/url]
[url=\"http://www.finanznachrichten.de\"]http://www.finanznachrichten.de[/url]
[url=\"http://www.uni-bremen.de\"]http://www.uni-bremen.de[/url]
[url=\"http://www.tu-darmstadt.de\"]http://www.tu-darmstadt.de[/url]
[url=\"http://www.aachen.de\"]http://www.aachen.de[/url]
[url=\"http://www.dasding.de\"]http://www.dasding.de[/url]
[url=\"http://www.messe-muenchen.de\"]http://www.messe-muenchen.de[/url]
[url=\"http://www.uni-duisburg-essen.de\"]http://www.uni-duisburg-essen.de[/url]
[url=\"http://www.photokina.de\"]http://www.photokina.de[/url]
[url=\"http://www.umweltbundesamt.de\"]http://www.umweltbundesamt.de[/url]
[url=\"http://www.jugendherberge.de\"]http://www.jugendherberge.de[/url]
[url=\"http://www.bitburger.de\"]http://www.bitburger.de[/url]
[url=\"http://www.munich-airport.de\"]http://www.munich-airport.de[/url]
[url=\"http://www.uni-mannheim.de\"]http://www.uni-mannheim.de[/url]
[url=\"http://www.uni-frankfurt.de\"]http://www.uni-frankfurt.de[/url]
[url=\"http://www.ruhr-uni-bochum.de\"]http://www.ruhr-uni-bochum.de[/url]
[url=\"http://www.medicine-worldwide.de\"]http://www.medicine-worldwide.de[/url]
[url=\"http://www.firstgate.de\"]http://www.firstgate.de[/url]
[url=\"http://www.kompetenznetze.de\"]http://www.kompetenznetze.de[/url]
[url=\"http://www.uni-jena.de\"]http://www.uni-jena.de[/url]
[url=\"http://www.testdaf.de\"]http://www.testdaf.de[/url]
[url=\"http://www.kalenderblatt.de\"]http://www.kalenderblatt.de[/url]
[url=\"http://www.baden-wuerttemberg.de\"]http://www.baden-wuerttemberg.de[/url]
[url=\"http://www.saarbruecken.de\"]http://www.saarbruecken.de[/url]
[url=\"http://www.kompetenzz.de\"]http://www.kompetenzz.de[/url]
[url=\"http://www.aquarius.geomar.de\"]http://www.aquarius.geomar.de[/url]
[url=\"http://www.uni-duesseldorf.de\"]http://www.uni-duesseldorf.de[/url]
[url=\"http://www.urlaubstage.de\"]http://www.urlaubstage.de[/url]
[url=\"http://www.wiley-vch.de\"]http://www.wiley-vch.de[/url]
[url=\"http://www.mohr.de\"]http://www.mohr.de[/url]
[url=\"http://www.bessy.de\"]http://www.bessy.de[/url]
[url=\"http://www.bayerninfo.de\"]http://www.bayerninfo.de[/url]
[url=\"http://www.uni-osnabrueck.de\"]http://www.uni-osnabrueck.de[/url]
[url=\"http://www.stuttgarter-zeitung.de\"]http://www.stuttgarter-zeitung.de[/url]
[url=\"http://www.mathguide.de\"]http://www.mathguide.de[/url]
[url=\"http://www.blk-bonn.de/\"]http://www.blk-bonn.de/[/url]
[url=\"http://www.slowfood.de\"]http://www.slowfood.de[/url]
[url=\"http://www.schaubuehne.de\"]http://www.schaubuehne.de[/url]
[url=\"http://www.unibw-muenchen.de\"]http://www.unibw-muenchen.de[/url]


Terminates processes with the following names:

OUTPOST.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NVARCH16.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
CLEANPC.EXE
AVprotect9x.exe
CMGRDIAN.EXE
CMON016.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
ICSSUPPNT.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
DRWATSON.EXE
ENT.EXE
ESCANH95.EXE
AVXQUAR.EXE
ESCANHNT.EXE
ESCANV95.EXE
AVPUPD.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
AUTODOWN.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
ATUPDATER.EXE
AUPDATE.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
AUTOUPDATE.EXE
CFINET.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
AUTOTRACE.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
CFIAUDIT.EXE
LUCOMSERVER.EXE
AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATWATCH.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVSYNMGR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
DRWEBUPW.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
AVLTMAIN.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
AVWUPD32.EXE
NUPGRADE.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
CFINET32.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMON016.EXE
CPD.EXE
CFGWIZ.EXE
CFIADMIN.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDT32.EXE
REGEDIT.EXE
UPDATE.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
LUALL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
CFIAUDIT.EXE
CFINET.EXE
ICSUPP95.EXE
MCUPDATE.EXE
CFINET32.EXE
CLEAN.EXE
CLEANER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
ZAUINST.EXE
ZONALM2601.EXE


Attempts to create copies of itself in any folder that contains the characters "shar". The files will have the following file names:

Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral, /censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> cool, awesome!!.exe
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe


Searches for the email addresses in files that have the following extensions:

.wab
.txt
.msg
.htm
.shtm
.stm
.xml
.dbx
.mbx
.mdx
.eml
.nch
.mmf
.ods
.cfg
.asp
.php
.pl
.wsh
.adb
.tbb
.sht
.xls
.oft
.uin
.cgi
.mht
.dhtm
.jsp


Uses its own SMTP engine to send email messages to any addresses found. The email may have the following characteristics:

From: <spoofed>

Subject: (One of the following)
Re: Msg reply
Re: Hello
Re: Yahoo!
Re: Thank you!
Re: Thanks /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
RE: Text message
Re: Document
Incoming message
Re: Incoming Message
RE: Incoming Msg
RE: Message Notify
Notification
Changes..
Update
Fax Message
Protected message
RE: Protected message
Forum notify
Site changes
Re: Hi
Encrypted document


Body: If the attachment is a .zip file, then the body will contain one of the following messages:

For security reasons attached file is password protected. The password is
For security purposes the attached file is password protected. Password --
Note: Use password
Attached file is protected with the password for security reasons. Password is
In order to read the attach you have to use the following password:
Archive password:
Password
Password:

followed by a copy of the image file dropped as sysxp.exeopenopenopen.


If the attachment is not a .zip file, the body will be one of the following,

Read the attach.
Your file is attached.
More info is in attach
See attach.
Please, have a look at the attached file.
Your document is attached.
Please, read the document.
Attach tells everything.
Attached file tells everything.
Check attached file for details.
Check attached file.
Pay attention at the attach.
See the attached file for details.
Message is in attach
Here is the file.


Attachment: (One of the following)
Information
Details
text_document
Updates
Readme
Document
Info
MoreInfo
Message


Attachment extension: (One of the following)
.exe
.scr
.com
.cpl
.zip

Removal Instructions

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AB@mm.
Delete the value that was added to the registry.
Delete the following files manually,
%system%\sysxp.exeopenopenopen
%system%\sysxp.exeopenopenopen

To delete the value from the registry

WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"key" = "%System%\sysxp.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ab@mm.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

PWSteal.Refest

PWSteal.Refest is a Trojan Horse that installs itself as a BHO (Browser Helper Object) for Internet Explorer and steals online banking information when it is submitted in web forms.



Type: Trojan Horse
Infection Length: 81,920 (.exe), 45,056 (.dll)



Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Steals banking information.
Compromises security settings: n/a
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


PWSteal.Refest does the following when it is executed:

Creates a dll file in the %System% directory. This file has a random name with up to 8 lower-case characters, e.g., "abcde.dll" or "qrstuvwx.dll". The file is 45056 bytes in length.

Note: %System% is a variable. The Trojan locates the System folder and creates a dll in that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

Installs the dll as a Browser Helper Object, so that it is loaded every time Internet Explorer starts. To do this, it creates the following registry keys:

HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{<random clsid>}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{<random clsid>}

and sets the value

(Default) = %System%\<random name>.dll

in the registry key

HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{<random clsid>}\InProcServer32.

The {<random clsid>} is a random value of the form, {########-####-####-####-############}, for example, {380b99b4-5f7d-7791-b8ef-499d848499e6}.


The dll monitors outgoing https connections to the following websites:

.anz.com
.bendigobank.com.au
.citibank.com
.citibank.de
.commbank.com.au
.dab-bank.com
.deutsche-bank.de
.e-gold.com
.hsbc.com.au
.hsbc.com.hk
.online-banking.standardchartered.com.hk
.sparkasse-banking.de
.stgeorge.com.au
banking.lbbw.de
banking.mashreqbank.com
banknetpower.net
barclays.co.uk
cd.citibank.co.ae
cibconline.cibc.com
citibank.com.au
dit-online.de
easyweb.tdcanadatrust.com
ebank.uae.hsbc.com
ekocbank.kocbank.com.tr
hercules.pamukbank.com.tr
internetsube.akbank.com.tr
lloydstsb.co.uk
national.com.au
nbd.ae
online-banking.standardchartered.ae
online.nbad.com
pbg1.edc.citiaccess.com
standardchartered.com
suncorpmetway.com.au
westpac.com.au
www.alahlionline.com
www.almubasher.com.sa
www.arabi-online.com
www.cbdonline.ae
www.citibank.com.hk
www.dahsing.com
www.ebank.iba.com.hk
www.privatebank.citibank.com.sg
www.sabbnet.com
www.samba.com
www.scotiaonline.scotiabank.com
www.unb.com
www1.bmo.com
www1.royalbank.com


When Internet Explorer makes an HTTP POST request to one of these domains (for example, when the user submits a web form at a bank site), the Trojan also sends the information to a cgi script at www.refestltd.com.

Removal Instructions

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Close all Internet Explorer windows.
Run a full system scan and delete all the files detected as PWSteal.Refest.
Optional: delete the value that was added to the registry.

Optional: deleting the keys from the registry

WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Note: If you do not feel comfortable modifying the registry as described below, it is safe to skip this step.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Classes\CLSID


Search for the name of the dll that was detected in step 4. If you find an entry of the form:

(Default) = %System%\<filename>.dll

in the registry key

HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{<random clsid>}\InProcServer32

then make note of the <random clsid> value, and delete the entire key

HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{<random clsid>}.


Navigate to and delete the key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{<random clsid>}

Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.refest.html\"]Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Lovgate.Y@mm
Discovered on: July 01, 2004
Last Updated on: July 14, 2004 12:03:22 PM

W32.Lovgate.Y@mm is a mass-mailing worm that also propagates through open network shares. It allows an attacker to access your computer. The email will have a variable subject and a file attachment with a .bat, .cmd, .exe, .pif, .scr, or .zip file extension.

W32.Lovgate.Y@mm spreads through the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135.


Note: Symantec Security Response has developed a removal tool to clean the infections of W32.Lovgate.Y@mm.


Also Known As: I-Worm.Lovgate.ae [Kaspersky], W32/Lovgate.ad@MM [McAfee]

Type: Worm
Infection Length: 152,064 bytes



Systems Affected: Windows 2000, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to all the contacts of the Windows Address Book and the Outlook Address Book, and to the email addresses that it finds from the files with extension .txt, .pl, .wab, .adb, .tbb, .dbx, .asp, .php, .sht, and .htm.
Deletes files: n/a
Modifies files: Renames .exe files to .zmx.
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates processes belonging to various antivirus programs.
Distribution

Subject of email: Varies
Name of attachment: Varies with .bat, .cmd, .exe, .pif, .scr, or .zip as the extension.
Size of attachment: 152,064 bytes
Time stamp of attachment: n/a
Ports: TCP 6000
Shared drives: Copies itself to network-shared folders.
Target of infection: Copies itself to KaZaA-shared folder.


When W32.Lovgate.Y@mm runs, it does the following:


Copies itself as the following files:

%Windir%\Systra.exe
%System%\iexplore.exe
%System%\RAVMOND.exe
%System%\WinHelp.exe
%System%\Kernel66.dll


Notes:
%Windir% is a variable: The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
%System% is a variable: The worm locates the System folder and copies itself to that location. By default, this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the following files:

%System%\ODBC16.dll
%System%\msjdbc11.dll
%System%\MSSIGN30.DLL
%System%\LMMIB20.DLL
%System%\TkBell.exe
%System%\Update_0B.exe
%Windir%\svchost.exe

Note: These files are all the same. They are backdoor components of the worm, each 53,760 bytes in size.


Creates and executes the file %System%\NetMeeting.exe (61,440 bytes). This file is detected as W32.Lovgate.R@mm.

When the file runs, it does the following:

Copies itself as %System%\spollsv.exe.


Adds the value:

"Shell Extension" = "%system%\spollsv.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so the worm runs when you start Windows.


Attempts to create %System%\a in other systems using the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability. This file is an FTP script that is used to get hxdef.exe from the infected system.


May create these files in the %System% folder.
results.txt
win2k.txt
winxp.txt

These files are not viral by themselves, and as such, are not detected.


Adds the values:

"Program in Windows"="%system%\iexplore.exe"
"Protected Storage"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"WinHelp"="%system%\WinHelp.exe"
"Hardware Profile" = "%system%\hxdef.exe..."
"Program in Windows"="%system%\IEXPLORE.exe"
"Microsoft NetMeeting Associates, Inc."="NetMeeting.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you start Windows.


Adds the values:

"SystemTra"="%Windir%\SysTra.exe"
"COM++ System" = "svchost.exe..."

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices

so that the worm runs as a service when you start Windows 95/98/Me.


Adds the value:

"run"="RAVMOND.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\

so that the worm runs when you start Windows NT/2000/XP.



Adds the following line to the [Windows] section of the Win.ini file:

run=ravmond.exe


Creates a network share, "Media," which is mapped to "%Windir%\Media." It copies itself to all the network-shared folders using one or more of the following names:

Thank you.doc.exe
3D Flash Animator.rar.bat
SWF Browser2.93.txt.exe
Download.exe
Panda Crack.zip.exe
WinRAR V3.2.0 Beta 2.exe
Swish2.00.pif
AAdobe Photoshop7.0 creak.pif
You_Life.JPG.pif
CloneCD crack.exe
WinZip v9.0 Beta Build 5480 crack.exe
Real-DRAW PRO v3.10.exe
Star Wars Downloader.exe
HyperSnap-DX v5.20.01.exe
Adobe Photoshop6.0.zip.exe
HyperSnap-DX v4.51.01.exe


Creates two files named AUTORUN.INF and COMMAND.EXE in the root folder of all the drives, except for the CD-ROM drives.


Creates an archive file named <filename>.<ext> in the root folder of all the drives, unless the drive letter is A or B.

<filename> will be one of the following:

WORK
setup
Important
bak
letter
pass

and <ext> is one of the following:

RAR
ZIP

This zip file contains a copy of the worm with the file name <filename>.<ext>.

<filename> is one of the following:

WORK
setup
Important
book
email
PassWord

and <ext> is one of the following:

.exe
.com
.pif
.scr


Creates the service, "Windows Management Protocol v.0 (experimental)," which is mapped to "Rundll32.exe msjdbc11.dll ondll_server".


Creates the service "_reg" that is mapped to "Rundll32.exe msjdbc11.dll ondll_server".


Terminates all the processes that contain any of the following strings:

KV
KAV
Duba
NAV
kill
RavMon.exe
Rfw.exe
Gate
McAfee
Symantec
SkyNet
rising


Scans all the drives. If the drive type is removable, mapped, or if the drive type is fixed with a drive letter greater than E, it does the following on all the drives found:

Attempts to rename the extension on all .exe files to .zmx.
Sets the attributes to Hidden and System on these files.
Copies itself as the original file name.


Injects a process-watching procedure as a thread into either Explorer.exe or Taskmgr.exe. This thread will attempt to launch %System32%\Iexplore.exe if it detects that the worm process is stopped.


Listens on port 6000. The backdoor procedures steal the information of a compromised system and stores it in the file, C:\Netlog.txt. Then, the worm emails the stolen information to the hacker.


Finds the location of the KaZaA-shared folder in the system registry. Then, it creates a copy of itself in the KaZaA-shared folder as one of the following (with a .bat, .exe, .pif, or .scr file extension):

wrar320sc
REALONE
BlackIcePCPSetup_creak
Passware5.3
word_pass_creak
HEROSOFT
orcard_original_creak
rainbowcrack-1.1-win
W32Dasm
setup
<random file name>


Scans all the computers on the local network and attempts to log on as an Administrator using the following passwords:

Guest
Administrator
zxcv
yxcv
xxx
win
test123
test
temp123
temp
sybase
super
sex
secret
pwd
pw123
Password
owner
oracle
mypc123
mypc
mypass123
mypass
love
login
Login
Internet
home
godblessyou
god
enable
database
computer
alpha
admin123
Admin
abcd
aaa
88888888
2600
2003
2002
123asd
123abc
123456789
1234567
123123
121212
11111111
110
007
00000000
000000
pass
54321
12345
password
passwd
server
sql
!@#$%^&*
!@#$%^&
!@#$%^
!@#$%
asdfgh
asdf
!@#$
1234
111
root
abc123
12345678
abcdefg
abcdef
abc
888888
666666
111111
admin
administrator
guest
654321
123456
321
123


If the worm successfully logs on to the remote computer, it will attempt to copy itself as:

\\<remote computer name>\admin$\system32\NetManager.exe

and to start the file as the service, "Windows Management NetWork Service Extensions", which is mapped to "NetManager.exe -exe_start".


Retrieves the email addresses from the files with .txt, .pl, .wab, .adb, .tbb, .dbx, .asp, .php, .sht, and .htm file extensions in the following folders:

%Windir%\Local Settings
\Documents and Settings\<current user>\local settings
Temporary Internet Files folder


Retrieves the email addresses from the Windows Address Book files.


Uses its own SMTP engine to send itself to the email addresses that it finds.

The email has the following characteristics:

Subject: (One of the following)
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error

Message: (One of the following)
pass
Mail failed. For further assistance, please contact!
The message contains Unicode characters and has been sent as a binary attachment.
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.

Attachment: (One of the following)
document
readme
doc
text
file
data
test
message
body

with one of the following file extensions:

.bat
.cmd
.exe
.pif
.scr


Replies to all the incoming messages when they arrive in the mailbox of certain MAPI-compliant email clients, including Microsoft Outlook.


If the original email is:

Subject: <subject>
From: <sender>@<domain.com>
Message: <original message body>

the worm will attempt to send the following email:

Subject: Re: <subject>
To: <sender>@<domain.com>

Message:
'<sender>' wrote:
====
> <original message body>
====

<domain.com> account auto-reply:

If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about,don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;
... ... more look to the attachment.


> Get your FREE <domain.com> account now! <

Attachment: (One of the following)
the hardcore game-.pif
Sex in Office.rm.scr
Deutsch BloodPatch!.exe
s3msong.MP3.pif
Me_nude.AVI.pif
How to Crack all gamez.exe
Macromedia Flash.scr
SETUP.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
DSL Modem Uncapper.rar.exe
joke.pif
Britney spears nude.exe.txt.exe
I am For u.doc.exe

Removal using the W32.HLLW.Lovgate [url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate.removal.tool.html\"]Removal Tool[/url]
Symantec Security Response has created a removal tool to clean the infections of W32.Lovgate.Y@mm.This is the easiest way to remove this threat.


The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Reverse the changes made to the registry.
Reverse the changes made to the Win.ini file (Windows 95/98/Me only).
Run a full system scan and delete all the files detected as W32.Lovgate.Y@mm.
Rename the .zmx files to the .exe files.

To reverse the changes made to the registry

Before continuing, Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. For instructions, read the document, "How to make a backup of the Windows registry."

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the values:

"Winhelp" = "%system%\TkBellExe.exe..."
"Hardware Profile" = "%system%\hxdef.exe..."
"Program in Windows"="%system%\IEXPLORE.exe"
"Microsoft NetMeeting Associates, Inc." = "NetMeeting.exe"
"Protected Storage"="RUNDLL32.exe MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"WinHelp"="%system%\WinHelp.exe"
"Shell Extension" = "%system%\spollsv.exe"


Do one of the following:
If you are using Windows NT/2000/XP, skip to step h.
If you are using Windows 95/98/Me, proceed with step f.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices


In the right pane, delete the values:

"SystemTra"="%Windir%\SysTra.exe"
"COM++ System" = "svchost.exe..."

When you have deleted these values, proceed with step j.


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows


In the right pane, delete the value:

"run"="RAVMOND.exe"


Navigate to the key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services


In the left hand pane, delete the subkeys:

_reg

Windows Management Protocol v.0(experimental


Exit the Registry Editor.


Do one of the following:
If you are using Windows NT/2000/XP, skip to section 6, "To scan for and delete the infected files."
If you are using Windows 95/98/Me, proceed with section 5.



5. To reverse the changes made to the Win.ini file
If you are running Windows 95/98/Me, follow these steps:

The function you perform depends on your operating system:
Windows 95/98: Go to step B.
Windows Me: If you are running Windows Me, the Windows Me file-protection process may have made a backup copy of the Win.ini file that you need to edit. If this backup copy exists, it will be in the C:\Windows\Recent folder. Symantec recommends that you delete this file before continuing with the steps in this section. To do this:
Start Windows Explorer.
Browse to and select the C:\Windows\Recent folder.
In the right pane, select the Win.ini file and delete it. The Win.ini file will be regenerated when you save your changes to it in step F.


Click Start > Run.
Type the following:

edit c:\windows\win.ini

and then click OK.

(The MS-DOS Editor opens.)

Note: If Windows is installed in a different location, make the appropriate path substitution.


In the [windows] section of the file, look for a line similar to:

run=ravmond.exe


If this line exists, delete everything to the right of run=


Click File > Save.
Click File > Exit.

To scan for and delete the infected files
Start your Symantec antivirus program and make sure that it is configured to scan all the files.
For Norton AntiVirus consumer products: Read the document, "How to configure Norton AntiVirus to scan all files."
For Symantec AntiVirus Enterprise products: Read the document, "How to verify that a Symantec Corporate antivirus product is set to scan all files."
Run a full system scan.
If any files are detected as infected with W32.Lovgate.W@mm, click Delete.
Restart the computer in Normal mode. For instructions, read the section on returning to Normal mode in the document, "How to start the computer in Safe Mode."


7. To rename the .zmx files to the .exe files
As W32.HLLW.Lovgate.Y@mm renames many .exe files, rename them to the correct extension for them to work.

Follow the instructions for your operating system:

Windows 98/Me/2000

On the Windows desktop, click the Start button > Find or Search > Files or Folders.
In the Search Results window, set "Look in" to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Check Include subfolders.
In the "Named" or "Search for..." box, type, or copy and paste, the following:

*.zmx


Click Find Now or Search Now.


Windows XP

On the Windows desktop, click the Start button > Search.
Click All files and folders.
In the All or part of the file name box, type, or copy and paste, the following:

*.zmx


Verify that "Look in" is set to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Click More advanced options.
Select Search system folders.
Select Search subfolders.
Select Search hidden files and folders.
Click Search.


For every file that is found, right click it, select Rename, and then change the .zmx extension to .exe.


Repeat step 6 for every removable, mapped, or fixed drive type with a drive letter greater than E

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.y@mm.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”