Alerts
Moderators: Moderator, Global Moderator
Alerts
W64.Shruggle.1318
Discovered on: August 20, 2004
Last Updated on: August 24, 2004 09:06:24 AM
W64.Shruggle.1318 is a direct-action file infector, similar to W64.Rugrat.3344, which infects AMD64 Windows Portable Executable (PE) files. It is a fairly simple proof-of-concept virus; however, it is the first known virus to attack 64-bit Windows executables on AMD64 systems.
The virus is written in AMD64 assembly code.
Type: Virus
Infection Length: 1318 bytes
Systems Affected: Windows 64-bit (AMD64)
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 2000, Windows 3.x, Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Technical Details:
When W64.Shruggle.1318 is executed, it searches 64-bit executable files that are in same folder, and all subfolders, as the one from which the virus was executed. When it finds a 64-bit executable file, the virus appends itself to the file, including .dll files.
Note: The virus does not infect 32-bit Portable Executable files, and it will not run natively on 32-bit Windows platforms. However, it can be run on a 32-bit computer that is using 64-bit simulation software.
Removal Instructions:
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Update the virus definitions.
Run a full system scan, and delete all of the files that are detected as W64.Shruggle.1318.
Additional information:
The virus uses a small number of Win64 APIs from the following three libraries:
Ntdll.dll
Sfc_os.dll
Kernel32.dll
From Ntdll.dll, the virus uses the following functions:
LdrGetDllHandle()
RtlAddVectoredExceptionHandler()
RtlRemoveVectoredExceptionHandler()
The virus supports vectored exception handling to avoid crashing during infections.
The SfcIsFileProtected() function of Sfc_os.dll is used to avoid infecting executables that are protected by the System File Checker (SFC).
The following sixteen functions are used from Kernel32.dll to implement a standard file infection of a AMD64 Portable Executable image:
CreateFileMappingA()
CreateFileW()
CloseHandle()
FindFirstFileW()
FindNextFileW
FindClose()
GetFullPathNameW()
GetTickCount()
GlobalAlloc()
GlobalFree()
LoadLibraryA()
MapViewOfFile()
SetCurrentDirectoryW()
SetFileAttributesW()
SetFileTime()
UnmapViewOfFile()
The virus carries the following string, which is never displayed, within itself:
Shrug - roy g biv
The file infection routine is standard. The last section of the executable is marked as executable, the virus body is inserted into the last section, and a random number of bytes are appended to the end of the virus body.
The virus author is also the author of a number of other proof-of-concept viruses. These are collected under the name [url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.chiton.gen.html\"]W32.Chiton.gen[/url].
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w64.shruggle.1318.html\"]source[/url]
Discovered on: August 20, 2004
Last Updated on: August 24, 2004 09:06:24 AM
W64.Shruggle.1318 is a direct-action file infector, similar to W64.Rugrat.3344, which infects AMD64 Windows Portable Executable (PE) files. It is a fairly simple proof-of-concept virus; however, it is the first known virus to attack 64-bit Windows executables on AMD64 systems.
The virus is written in AMD64 assembly code.
Type: Virus
Infection Length: 1318 bytes
Systems Affected: Windows 64-bit (AMD64)
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 2000, Windows 3.x, Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Technical Details:
When W64.Shruggle.1318 is executed, it searches 64-bit executable files that are in same folder, and all subfolders, as the one from which the virus was executed. When it finds a 64-bit executable file, the virus appends itself to the file, including .dll files.
Note: The virus does not infect 32-bit Portable Executable files, and it will not run natively on 32-bit Windows platforms. However, it can be run on a 32-bit computer that is using 64-bit simulation software.
Removal Instructions:
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Update the virus definitions.
Run a full system scan, and delete all of the files that are detected as W64.Shruggle.1318.
Additional information:
The virus uses a small number of Win64 APIs from the following three libraries:
Ntdll.dll
Sfc_os.dll
Kernel32.dll
From Ntdll.dll, the virus uses the following functions:
LdrGetDllHandle()
RtlAddVectoredExceptionHandler()
RtlRemoveVectoredExceptionHandler()
The virus supports vectored exception handling to avoid crashing during infections.
The SfcIsFileProtected() function of Sfc_os.dll is used to avoid infecting executables that are protected by the System File Checker (SFC).
The following sixteen functions are used from Kernel32.dll to implement a standard file infection of a AMD64 Portable Executable image:
CreateFileMappingA()
CreateFileW()
CloseHandle()
FindFirstFileW()
FindNextFileW
FindClose()
GetFullPathNameW()
GetTickCount()
GlobalAlloc()
GlobalFree()
LoadLibraryA()
MapViewOfFile()
SetCurrentDirectoryW()
SetFileAttributesW()
SetFileTime()
UnmapViewOfFile()
The virus carries the following string, which is never displayed, within itself:
Shrug - roy g biv
The file infection routine is standard. The last section of the executable is marked as executable, the virus body is inserted into the last section, and a random number of bytes are appended to the end of the virus body.
The virus author is also the author of a number of other proof-of-concept viruses. These are collected under the name [url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.chiton.gen.html\"]W32.Chiton.gen[/url].
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w64.shruggle.1318.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
[b]Trojan.Mitglieder.O
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 04:44:15 PM [/b]
Trojan.Mitglieder.O is a Trojan horse that allows an infected computer to be used as an email relay.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: Linux, Macintosh OS X, Novell Netware, OS/2, UNIX
When Trojan.Mitglieder.O runs, it does the following:
Copies itself as the following files:
%System%\foõ.exe
%System%\norat.exe
%System%\winerdir.exe.
Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds a value:
"ssgrate.exe"="%System%\winerdir.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\WindowsCurrentVersion\Run
so that the worm runs when you restart Windows.
Adds the values:
"port" = "0x000097e3"
"uid" = "[random number]"
"wdrn" = "0x00000001"
to the registry key:
HKEY_CURRENT_USER\Software\DateTime8
Attempts to injects itself as a thread into the Explorer.exe process.
Opens and listens on TCP port 28883.
Note: This functionality is usually employed to send unsolicited commercial email.
Terminates the following processes:
AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET.EXE
CFINET32.EXE
CFINET32.EXE
CLEAN.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMGRDIAN.EXE
CMON016.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
Drvddll.exe
drvsys.exe
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE
Attempts to run a PHP script on one of the following domains, passing details about the infected host to the Web server:
artesproduction.com
avistrade.ru
bernlocher.de
blackwidow.nsk.ru
comdat.de
dabigbadboy.de
die-cliquee.de
egogo.ru
gaz-service.ru
gnet30.gamesnet.de
hannes-wacker.de
investexpo.ru
komtel.spb.ru
mc-figga.de
mir-auto.ru
mir-vesov.ru
monomah-city.ru
multi-gaming.com
partiyazerna.1gb.ru
plastikp.ru
prizmapr.ru
promco.ru
pvcps.ru
rdwufa.ru
roszvetmet.com
schiffsparty.de
service6.valuehost.ru
shop-of-innovations.de
sound-cell.de
st-agnes.de
stroyindustry.ru
tpoint.ru
unbound.de
vladzernoproduct.ru
web298.server7.webplus24.de
www.13tw22rigobert.de
www.admlaw.ru
www.deadlygames.de
www.emil-zittau.de
www.etype.hostingcity.net
www.eurostretch.ru
www.ferienwohnung-in-masuren.de
www.gasterixx.de
www.gay-traffic.de
www.hhc-online.de
www.komandor.ru
www.levada.ru
www.lowenbrau.ru
www.metzgerei-gebhart.de
www.mirage.ru
www.ordendeslichts.de
www.progame.de
www.psnr.ru
www.thomas-we.de
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Mitglieder.N.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the following key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"ssgrate.exe"="%System%\winerdir.exe"
Navigate to the key:
HKEY_CURRENT_USER\Software\DateTime8
In the right pane, delete the values:
"port" = "0x000097e3"
"uid" = "[random number]"
"wdrn" = "0x00000001"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.mitglieder.o.html\"]Source[/url]
[b]Trojan.Mitglieder.N
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 04:44:42 PM [/b]
Trojan.Mitglieder.N is a Trojan horse that allows an infected computer to be used as an email relay.
Also Known As: W32/Bagle.ak!proxy [McAfee]
Type: Trojan Horse
Infection Length: 17,920 bytes, 1,536 bytes, 26,112 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When Trojan.Mitglieder.N runs, it does the following:
Copies itself as the following files:
%System%\fi?.exe
%System%\nopat.exe
%System%\sysdoor.exe.
Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds a value:
"ssgrate.exe"="%System%\sysdoor.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\WindowsCurrentVersion\Run
so that the Trojan runs when you restart Windows.
Adds the values:
"port" = "0x000070d2"
"uid" = "[random number]"
"wdrn" = "0x00000001"
to the registry key:
HKEY_CURRENT_USER\Software\DateTime8
Attempts to injects itself as a thread into the Explorer.exe process.
Opens and listens on TCP port 28882.
Note: This functionality is usually employed to send unsolicited commercial email.
Terminates the following processes:
AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET.EXE
CFINET32.EXE
CFINET32.EXE
CLEAN.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMGRDIAN.EXE
CMON016.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
Drvddll.exe
drvsys.exe
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE
Attempts to run a PHP script on one of the following domains, passing details about the infected host to the Web server:
artesproduction.com
avistrade.ru
bernlocher.de
blackwidow.nsk.ru
comdat.de
dabigbadboy.de
die-cliquee.de
egogo.ru
gaz-service.ru
gnet30.gamesnet.de
hannes-wacker.de
investexpo.ru
komtel.spb.ru
mc-figga.de
mir-auto.ru
mir-vesov.ru
monomah-city.ru
multi-gaming.com
partiyazerna.1gb.ru
plastikp.ru
prizmapr.ru
promco.ru
pvcps.ru
rdwufa.ru
roszvetmet.com
schiffsparty.de
service6.valuehost.ru
shop-of-innovations.de
sound-cell.de
st-agnes.de
stroyindustry.ru
tpoint.ru
unbound.de
vladzernoproduct.ru
web298.server7.webplus24.de
www.13tw22rigobert.de
www.admlaw.ru
www.deadlygames.de
www.emil-zittau.de
www.etype.hostingcity.net
www.eurostretch.ru
www.ferienwohnung-in-masuren.de
www.gasterixx.de
www.gay-traffic.de
www.hhc-online.de
www.komandor.ru
www.levada.ru
www.lowenbrau.ru
www.metzgerei-gebhart.de
www.mirage.ru
www.ordendeslichts.de
www.progame.de
www.psnr.ru
www.thomas-we.de
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Mitglieder.N.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the following key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"ssgrate.exe"="%System%\sysdoor.exe"
Navigate to the key:
HKEY_CURRENT_USER\Software\DateTime8\
In the right pane, delete the values:
"port" = "0x000070d2"
"uid" = "[random number]"
"wdrn" = "0x00000001"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.mitglieder.n.html\"]Source[/url]
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 04:44:15 PM [/b]
Trojan.Mitglieder.O is a Trojan horse that allows an infected computer to be used as an email relay.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: Linux, Macintosh OS X, Novell Netware, OS/2, UNIX
When Trojan.Mitglieder.O runs, it does the following:
Copies itself as the following files:
%System%\foõ.exe
%System%\norat.exe
%System%\winerdir.exe.
Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds a value:
"ssgrate.exe"="%System%\winerdir.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\WindowsCurrentVersion\Run
so that the worm runs when you restart Windows.
Adds the values:
"port" = "0x000097e3"
"uid" = "[random number]"
"wdrn" = "0x00000001"
to the registry key:
HKEY_CURRENT_USER\Software\DateTime8
Attempts to injects itself as a thread into the Explorer.exe process.
Opens and listens on TCP port 28883.
Note: This functionality is usually employed to send unsolicited commercial email.
Terminates the following processes:
AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET.EXE
CFINET32.EXE
CFINET32.EXE
CLEAN.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMGRDIAN.EXE
CMON016.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
Drvddll.exe
drvsys.exe
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE
Attempts to run a PHP script on one of the following domains, passing details about the infected host to the Web server:
artesproduction.com
avistrade.ru
bernlocher.de
blackwidow.nsk.ru
comdat.de
dabigbadboy.de
die-cliquee.de
egogo.ru
gaz-service.ru
gnet30.gamesnet.de
hannes-wacker.de
investexpo.ru
komtel.spb.ru
mc-figga.de
mir-auto.ru
mir-vesov.ru
monomah-city.ru
multi-gaming.com
partiyazerna.1gb.ru
plastikp.ru
prizmapr.ru
promco.ru
pvcps.ru
rdwufa.ru
roszvetmet.com
schiffsparty.de
service6.valuehost.ru
shop-of-innovations.de
sound-cell.de
st-agnes.de
stroyindustry.ru
tpoint.ru
unbound.de
vladzernoproduct.ru
web298.server7.webplus24.de
www.13tw22rigobert.de
www.admlaw.ru
www.deadlygames.de
www.emil-zittau.de
www.etype.hostingcity.net
www.eurostretch.ru
www.ferienwohnung-in-masuren.de
www.gasterixx.de
www.gay-traffic.de
www.hhc-online.de
www.komandor.ru
www.levada.ru
www.lowenbrau.ru
www.metzgerei-gebhart.de
www.mirage.ru
www.ordendeslichts.de
www.progame.de
www.psnr.ru
www.thomas-we.de
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Mitglieder.N.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the following key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"ssgrate.exe"="%System%\winerdir.exe"
Navigate to the key:
HKEY_CURRENT_USER\Software\DateTime8
In the right pane, delete the values:
"port" = "0x000097e3"
"uid" = "[random number]"
"wdrn" = "0x00000001"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.mitglieder.o.html\"]Source[/url]
[b]Trojan.Mitglieder.N
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 04:44:42 PM [/b]
Trojan.Mitglieder.N is a Trojan horse that allows an infected computer to be used as an email relay.
Also Known As: W32/Bagle.ak!proxy [McAfee]
Type: Trojan Horse
Infection Length: 17,920 bytes, 1,536 bytes, 26,112 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When Trojan.Mitglieder.N runs, it does the following:
Copies itself as the following files:
%System%\fi?.exe
%System%\nopat.exe
%System%\sysdoor.exe.
Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds a value:
"ssgrate.exe"="%System%\sysdoor.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\WindowsCurrentVersion\Run
so that the Trojan runs when you restart Windows.
Adds the values:
"port" = "0x000070d2"
"uid" = "[random number]"
"wdrn" = "0x00000001"
to the registry key:
HKEY_CURRENT_USER\Software\DateTime8
Attempts to injects itself as a thread into the Explorer.exe process.
Opens and listens on TCP port 28882.
Note: This functionality is usually employed to send unsolicited commercial email.
Terminates the following processes:
AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET.EXE
CFINET32.EXE
CFINET32.EXE
CLEAN.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMGRDIAN.EXE
CMON016.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
Drvddll.exe
drvsys.exe
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE
Attempts to run a PHP script on one of the following domains, passing details about the infected host to the Web server:
artesproduction.com
avistrade.ru
bernlocher.de
blackwidow.nsk.ru
comdat.de
dabigbadboy.de
die-cliquee.de
egogo.ru
gaz-service.ru
gnet30.gamesnet.de
hannes-wacker.de
investexpo.ru
komtel.spb.ru
mc-figga.de
mir-auto.ru
mir-vesov.ru
monomah-city.ru
multi-gaming.com
partiyazerna.1gb.ru
plastikp.ru
prizmapr.ru
promco.ru
pvcps.ru
rdwufa.ru
roszvetmet.com
schiffsparty.de
service6.valuehost.ru
shop-of-innovations.de
sound-cell.de
st-agnes.de
stroyindustry.ru
tpoint.ru
unbound.de
vladzernoproduct.ru
web298.server7.webplus24.de
www.13tw22rigobert.de
www.admlaw.ru
www.deadlygames.de
www.emil-zittau.de
www.etype.hostingcity.net
www.eurostretch.ru
www.ferienwohnung-in-masuren.de
www.gasterixx.de
www.gay-traffic.de
www.hhc-online.de
www.komandor.ru
www.levada.ru
www.lowenbrau.ru
www.metzgerei-gebhart.de
www.mirage.ru
www.ordendeslichts.de
www.progame.de
www.psnr.ru
www.thomas-we.de
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Mitglieder.N.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the following key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"ssgrate.exe"="%System%\sysdoor.exe"
Navigate to the key:
HKEY_CURRENT_USER\Software\DateTime8\
In the right pane, delete the values:
"port" = "0x000070d2"
"uid" = "[random number]"
"wdrn" = "0x00000001"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.mitglieder.n.html\"]Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Sasser.G
Discovered on: August 23, 2004
Last Updated on: August 24, 2004 04:53:59 PM
W32.Sasser.G is a variant of [url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.html\"]W32.Sasser.Worm[/url] that attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin [url=\"http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx\"]MS04-011[/url]. The worm spreads by scanning random IP addresses and drops [url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.ac@mm.html\"]W32.Netsky.AC@mm[/url].
Variants: W32.Sasser.Worm
Type: Worm
Infection Length: 58,880 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003
Technical Details:
When W32.Sasser.G runs, it does the following:
Attempts to create mutexes named "PinaasoSky" and "Jobaka3", exiting if it fails. This ensures that no more than one instance of the worm can run on a computer at any time.
Copies itself as one of the following files:
%Windir%\avserve3.exe.
%Windir%\wserver.exe
Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
Drops and executes the following files:
%Windir%\skynet.cpl
%Windir%\comp.cpl
Note: These files are detected as W32.Netsky.AC@mm.
Adds one of the following values:
"avserve3.exe"="%Windir%\avserv3.exe"
"wserver"="%Windir%\wserver.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Prevents any attempts to shut down or restart the computer.
Starts an FTP server on TCP port 5554. This server is used to spread the worm to other hosts.
Retrieves the IP addresses of the infected computer.
Generates a second IP address, based on one of the IP addresses retrieved from the infected computer.
Connects to the generated IP address on TCP port 445 to determine whether a remote computer is online.
If a connection is made to a remote computer, the worm will send shell code to it, which may cause it to open a remote shell on TCP port 9996.
Uses the shell on the remote computer to reconnect to the infected computer's FTP server and retrieve a copy of the worm. This copy will have a name consisting of four or five numbers, followed by _up.exe. For example, 74354_up.exe.
Creates a file at C:\win2.log that contains the IP address of the computer that the worm most recently attempted to infect, as well as the number of infected computers.
Note: The Lsass.exe process will crash after the worm exploits the Windows LSASS vulnerability. Windows will display the alert and shut down the system in one minute.
Removal Instructions:
Before you begin:
If you are running Windows 2000 or XP, and have not yet done so, you must patch for the vulnerability described in Microsoft Security Bulletin MS04-011. If you do not, it is likely that your computer will continue to be reinfected.
What to do if the computer shuts down before you can patch or get the tool
This threat can cause Windows to keep shutting down and restarting. This can prevent you from installing the Microsoft patch or downloading the tool described below.
--------------------------------------------------------------------------------
Notes:
You may have to try this several times, as you only have about 20 seconds to do steps 3 to 6.
This will not work on Windows 2000.
--------------------------------------------------------------------------------
To prevent the shut down, do the following:
Disconnect the computer from the network/Internet connection. (Disconnect the cable if necessary.)
Restart the computer.
As soon as Windows opens and you see the Windows desktop, click Start > Run.
Type:
cmd
and press Enter.
Type:
shutdown -i
and press Enter.
In the Remote Shutdown Dialog that opens, do the following:
Click Add, type your computer name into the Add Computers dialog box, and then click OK.
In the "Display warning for" field, type 9999.
Type the following text in the Comment box:
Delay Lsass.exe shutdown.
Click OK.
Reconnect the network/Internet connection.
Connect to the Internet, and get the patch. Then continue with the steps described below.
When you have patched your computer and removed the threat, you can re-enable the 20 second default warning if you wish.
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
End the malicious process (Windows NT/2000/XP).
Disable System Restore (Windows XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Sasser.G.
Reverse the change made to the registry.
For details on each of these steps, read the following instructions.
1. To end the malicious process
On Windows NT/2000/XP computers, you must first end the malicious process. Follow these instructions:
Press Ctrl+Alt+Delete once.
Click Task Manager.
Click the Processes tab.
Double-click the Image Name column header to alphabetically sort the processes.
Scroll through the list and look for the following processes:
napatch.exe
any process with a name consisting of four or five numbers, followed by _up.exe (for example, 74354_up.exe).
If you find any such process, click it, and then click End Process.
Exit the Task Manager.
To Edit The Registry:
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values, if present:
"avserve3.exe"="%Windir%\avserve3.exe"
"wserver"="%Windir%\wserver.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.g.html\"]source[/url]
Discovered on: August 23, 2004
Last Updated on: August 24, 2004 04:53:59 PM
W32.Sasser.G is a variant of [url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.html\"]W32.Sasser.Worm[/url] that attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin [url=\"http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx\"]MS04-011[/url]. The worm spreads by scanning random IP addresses and drops [url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.ac@mm.html\"]W32.Netsky.AC@mm[/url].
Variants: W32.Sasser.Worm
Type: Worm
Infection Length: 58,880 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003
Technical Details:
When W32.Sasser.G runs, it does the following:
Attempts to create mutexes named "PinaasoSky" and "Jobaka3", exiting if it fails. This ensures that no more than one instance of the worm can run on a computer at any time.
Copies itself as one of the following files:
%Windir%\avserve3.exe.
%Windir%\wserver.exe
Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
Drops and executes the following files:
%Windir%\skynet.cpl
%Windir%\comp.cpl
Note: These files are detected as W32.Netsky.AC@mm.
Adds one of the following values:
"avserve3.exe"="%Windir%\avserv3.exe"
"wserver"="%Windir%\wserver.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Prevents any attempts to shut down or restart the computer.
Starts an FTP server on TCP port 5554. This server is used to spread the worm to other hosts.
Retrieves the IP addresses of the infected computer.
Generates a second IP address, based on one of the IP addresses retrieved from the infected computer.
Connects to the generated IP address on TCP port 445 to determine whether a remote computer is online.
If a connection is made to a remote computer, the worm will send shell code to it, which may cause it to open a remote shell on TCP port 9996.
Uses the shell on the remote computer to reconnect to the infected computer's FTP server and retrieve a copy of the worm. This copy will have a name consisting of four or five numbers, followed by _up.exe. For example, 74354_up.exe.
Creates a file at C:\win2.log that contains the IP address of the computer that the worm most recently attempted to infect, as well as the number of infected computers.
Note: The Lsass.exe process will crash after the worm exploits the Windows LSASS vulnerability. Windows will display the alert and shut down the system in one minute.
Removal Instructions:
Before you begin:
If you are running Windows 2000 or XP, and have not yet done so, you must patch for the vulnerability described in Microsoft Security Bulletin MS04-011. If you do not, it is likely that your computer will continue to be reinfected.
What to do if the computer shuts down before you can patch or get the tool
This threat can cause Windows to keep shutting down and restarting. This can prevent you from installing the Microsoft patch or downloading the tool described below.
--------------------------------------------------------------------------------
Notes:
You may have to try this several times, as you only have about 20 seconds to do steps 3 to 6.
This will not work on Windows 2000.
--------------------------------------------------------------------------------
To prevent the shut down, do the following:
Disconnect the computer from the network/Internet connection. (Disconnect the cable if necessary.)
Restart the computer.
As soon as Windows opens and you see the Windows desktop, click Start > Run.
Type:
cmd
and press Enter.
Type:
shutdown -i
and press Enter.
In the Remote Shutdown Dialog that opens, do the following:
Click Add, type your computer name into the Add Computers dialog box, and then click OK.
In the "Display warning for" field, type 9999.
Type the following text in the Comment box:
Delay Lsass.exe shutdown.
Click OK.
Reconnect the network/Internet connection.
Connect to the Internet, and get the patch. Then continue with the steps described below.
When you have patched your computer and removed the threat, you can re-enable the 20 second default warning if you wish.
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
End the malicious process (Windows NT/2000/XP).
Disable System Restore (Windows XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Sasser.G.
Reverse the change made to the registry.
For details on each of these steps, read the following instructions.
1. To end the malicious process
On Windows NT/2000/XP computers, you must first end the malicious process. Follow these instructions:
Press Ctrl+Alt+Delete once.
Click Task Manager.
Click the Processes tab.
Double-click the Image Name column header to alphabetically sort the processes.
Scroll through the list and look for the following processes:
napatch.exe
any process with a name consisting of four or five numbers, followed by _up.exe (for example, 74354_up.exe).
If you find any such process, click it, and then click End Process.
Exit the Task Manager.
To Edit The Registry:
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values, if present:
"avserve3.exe"="%Windir%\avserve3.exe"
"wserver"="%Windir%\wserver.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.g.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Backdoor.Berbew.J
Discovered on: August 24, 2004
Last Updated on: August 25, 2004 03:09:02 PM
Backdoor.Berbew.J is a Trojan horse program that attempts to steal cached passwords from an infected computer. It may also display fake windows to gather confidential information from the user.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When the Trojan is executed, it performs the following actions:
Creates a mutex named "Engel_12", which ensures that only one instance of the Trojan is running on the infected computer at one time.
Drops the following files:
%System%\[8 random characters].exe
%System%\[8 random characters].dll
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following files, which are used for saving password information and any downloaded configuration data for the Trojan:
%System%\Engl32.dat
%System%\Rtdx1[random number].htm
%System%\engl32.vxd
%System%\Rtdx1[random number].dat
%System%\ccct32.dat
Creates several .htm files in the %Temp% directory, named [8 random characters].htm. The Trojan may then open these files in Internet Explorer.
Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
Adds the value:
"WebEvent Logger"="{79ECA078-17FF-726B-E811-213280E5C831}"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
so that the Trojan starts when Windows starts.
Creates the following registry key:
HKEY_CLASSES_ROOT\CLSID\{79ECA078-17FF-726B-E811-213280E5C831}
which causes %System%\[8 random characters].dll to be called as a browser help object by Internet Explorer.
Adds the value:
"MGR" = "D-REPORTS-[8 random letters]"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\IE4
to prevent Internet Explorer from asking users if they are sure that they want to submit unencrypted form data.
Adds the value:
"1601"="0x0"
to the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
to prevent Internet Explorer from asking users if they are sure that they want to submit unencrypted form data.
Adds the value:
"GlobalUserOffline" = "0x0"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
to prevent Internet Explorer from asking users if they wish to work offline, when using Internet Explorer and not connected to the Internet.
Adds the value:
"BrowseNewProcess" = "Yes"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
to enable Windows Explorer to access the Internet.
Adds the value:
"AutoSuggest" = "Yes"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AutoComplete
to disable autocomplete in Internet Explorer.
Adds the value:
"Use FormSuggest" = "Yes"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main
to disable autocomplete in Internet Explorer.
Adds the value:
"FormSuggest Passwords" = "Yes"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main
to disable autocomplete in Internet Explorer.
Adds the value:
"FormSuggest PW Ask" = "Yes"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main
to disable autocomplete in Internet Explorer.
Opens the following:
a rootshell on TCP port 23232.
an FTP server on TCP port 32121.
backdoors on TCP ports 12065 and 28253.
Collects passwords from the infected computer and intercepts data entered into forms in Internet Explorer.
Sends the information gathered to a remote attacker.
Uploads configuration data through the web to a URL in the domain pidorasam.net .
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
To restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Berbew.J.
To restore the Internet Security settings:
Start Internet Explorer.
b. Click Tools, click Internet Options, and then click the Security tab.
c. Set the desired level for every zone. (The easiest way to do this is to click Default Level for each one.)
Delete the value that was added to the registry:
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
In the right pane, delete the value:
"Web Event Logger"="{79ECA078-17FF-726B-E811-213280E5C831}"
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\IE4
In the right pane, delete the value:
"MGR" = "D-REPORTS-[8 random letters]"
Navigate to the key:
HKEY_CLASSES_ROOT\CLSID\{79ECA078-17FF-726B-E811-213280E5C831}
delete the key.
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.berbew.j.html\"]source[/url]
Discovered on: August 24, 2004
Last Updated on: August 25, 2004 03:09:02 PM
Backdoor.Berbew.J is a Trojan horse program that attempts to steal cached passwords from an infected computer. It may also display fake windows to gather confidential information from the user.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When the Trojan is executed, it performs the following actions:
Creates a mutex named "Engel_12", which ensures that only one instance of the Trojan is running on the infected computer at one time.
Drops the following files:
%System%\[8 random characters].exe
%System%\[8 random characters].dll
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following files, which are used for saving password information and any downloaded configuration data for the Trojan:
%System%\Engl32.dat
%System%\Rtdx1[random number].htm
%System%\engl32.vxd
%System%\Rtdx1[random number].dat
%System%\ccct32.dat
Creates several .htm files in the %Temp% directory, named [8 random characters].htm. The Trojan may then open these files in Internet Explorer.
Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
Adds the value:
"WebEvent Logger"="{79ECA078-17FF-726B-E811-213280E5C831}"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
so that the Trojan starts when Windows starts.
Creates the following registry key:
HKEY_CLASSES_ROOT\CLSID\{79ECA078-17FF-726B-E811-213280E5C831}
which causes %System%\[8 random characters].dll to be called as a browser help object by Internet Explorer.
Adds the value:
"MGR" = "D-REPORTS-[8 random letters]"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\IE4
to prevent Internet Explorer from asking users if they are sure that they want to submit unencrypted form data.
Adds the value:
"1601"="0x0"
to the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
to prevent Internet Explorer from asking users if they are sure that they want to submit unencrypted form data.
Adds the value:
"GlobalUserOffline" = "0x0"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
to prevent Internet Explorer from asking users if they wish to work offline, when using Internet Explorer and not connected to the Internet.
Adds the value:
"BrowseNewProcess" = "Yes"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
to enable Windows Explorer to access the Internet.
Adds the value:
"AutoSuggest" = "Yes"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AutoComplete
to disable autocomplete in Internet Explorer.
Adds the value:
"Use FormSuggest" = "Yes"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main
to disable autocomplete in Internet Explorer.
Adds the value:
"FormSuggest Passwords" = "Yes"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main
to disable autocomplete in Internet Explorer.
Adds the value:
"FormSuggest PW Ask" = "Yes"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main
to disable autocomplete in Internet Explorer.
Opens the following:
a rootshell on TCP port 23232.
an FTP server on TCP port 32121.
backdoors on TCP ports 12065 and 28253.
Collects passwords from the infected computer and intercepts data entered into forms in Internet Explorer.
Sends the information gathered to a remote attacker.
Uploads configuration data through the web to a URL in the domain pidorasam.net .
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
To restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Berbew.J.
To restore the Internet Security settings:
Start Internet Explorer.
b. Click Tools, click Internet Options, and then click the Security tab.
c. Set the desired level for every zone. (The easiest way to do this is to click Default Level for each one.)
Delete the value that was added to the registry:
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
In the right pane, delete the value:
"Web Event Logger"="{79ECA078-17FF-726B-E811-213280E5C831}"
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\IE4
In the right pane, delete the value:
"MGR" = "D-REPORTS-[8 random letters]"
Navigate to the key:
HKEY_CLASSES_ROOT\CLSID\{79ECA078-17FF-726B-E811-213280E5C831}
delete the key.
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.berbew.j.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
VBS.Voodoo.C
Discovered on: August 24, 2004
Last Updated on: August 26, 2004 10:06:25 AM
VBS.Voodoo.C is a virus written in Visual Basic Script (VBS). It prepends itself to the files that have .asp, .htm, .hta, .htx, .html, and .htt file extensions.
Also Known As: VBS.Voodoo.B [Kaspersky], VBS/Reality [McAfee]
Variants: VBS.Voodoo.A
Type: Virus
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Technical Details:
When VBS.Voodoo.C is executed, it performs the following actions:
Modifies the value:
"1201"=0
in the registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
so that the security protection that Microsoft Internet Explorer provides is lowered to a level that is less safe.
Infects .asp, .htm, .hta, .htx, .html, and .htt (html template) files that are located in:
The same folder as the virus.
The parent folder of the currently infecting folder, and recursively up to the root folder.
The following locations:
C:\My Documents
C:\Windows\Desktop
C:\Inetpub\wwwroot
May add the value:
"RegisteredOwner"="BLASTER"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RegisteredOwner
May create the following entry in your Internet Explorer Favorites list:
Blaster.URL: http:/ /www.coderz.net
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as VBS.Voodoo.C.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/vbs.voodoo.c.html\"]source[/url]
Discovered on: August 24, 2004
Last Updated on: August 26, 2004 10:06:25 AM
VBS.Voodoo.C is a virus written in Visual Basic Script (VBS). It prepends itself to the files that have .asp, .htm, .hta, .htx, .html, and .htt file extensions.
Also Known As: VBS.Voodoo.B [Kaspersky], VBS/Reality [McAfee]
Variants: VBS.Voodoo.A
Type: Virus
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Technical Details:
When VBS.Voodoo.C is executed, it performs the following actions:
Modifies the value:
"1201"=0
in the registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
so that the security protection that Microsoft Internet Explorer provides is lowered to a level that is less safe.
Infects .asp, .htm, .hta, .htx, .html, and .htt (html template) files that are located in:
The same folder as the virus.
The parent folder of the currently infecting folder, and recursively up to the root folder.
The following locations:
C:\My Documents
C:\Windows\Desktop
C:\Inetpub\wwwroot
May add the value:
"RegisteredOwner"="BLASTER"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RegisteredOwner
May create the following entry in your Internet Explorer Favorites list:
Blaster.URL: http:/ /www.coderz.net
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as VBS.Voodoo.C.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/vbs.voodoo.c.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Tiniresu
Discovered on: August 24, 2004
Last Updated on: August 26, 2004 07:28:46 AM
W32.Tiniresu is a virus that infects the Userinit.exe file and downloads and executes a file from a remote location.
Type: Virus
Infection Length: 48,132 Bytes
Systems Affected: Windows 2000, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98
Technical Details:
When W32.Tiniresu is executed, it performs the following actions:
Locates %System%\Userinit.exe, and if the file is less than 25,600 bytes long, infects it by prepending 48,128 bytes and appending four extra bytes at the end of the file.
Note: %System% is a variable that refers to the System folder. By default, this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Opens backdoor ports and sends the infected system's IP address and backdoor port numbers to the following addresses:
brtblrvn.hopto.org
brtblrvn.no-ip.info
dlzdvlnj.hopto.org
dlzdvlnj.no-ip.info
hzlhpzxb.hopto.org
hzlhpzxb.no-ip.info
jtrjztpx.hopto.org
jtrjztpx.no-ip.info
lnxljnht.hopto.org
lnxljnht.no-ip.info
nhdnthzp.hopto.org
nhdnthzp.no-ip.info
pbjpdbrl.hopto.org
pbjpdbrl.no-ip.info
rvprnvjh.hopto.org
rvprnvjh.no-ip.info
tpvtxpbd.hopto.org
tpvtxpbd.no-ip.info
vjbvhjtz.hopto.org
vjbvhjtz.no-ip.info
xdhxrdlv.hopto.org
xdhxrdlv.no-ip.info
zxnzbxdr.hopto.org
zxnzbxdr.no-ip.info
Note: no-ip.info and hopto.org are dynamic DNS sites.
Retrieves and executes a file from a remote location.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as W32.Tiniresu.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.tiniresu.html\"]source[/url]
Discovered on: August 24, 2004
Last Updated on: August 26, 2004 07:28:46 AM
W32.Tiniresu is a virus that infects the Userinit.exe file and downloads and executes a file from a remote location.
Type: Virus
Infection Length: 48,132 Bytes
Systems Affected: Windows 2000, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98
Technical Details:
When W32.Tiniresu is executed, it performs the following actions:
Locates %System%\Userinit.exe, and if the file is less than 25,600 bytes long, infects it by prepending 48,128 bytes and appending four extra bytes at the end of the file.
Note: %System% is a variable that refers to the System folder. By default, this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Opens backdoor ports and sends the infected system's IP address and backdoor port numbers to the following addresses:
brtblrvn.hopto.org
brtblrvn.no-ip.info
dlzdvlnj.hopto.org
dlzdvlnj.no-ip.info
hzlhpzxb.hopto.org
hzlhpzxb.no-ip.info
jtrjztpx.hopto.org
jtrjztpx.no-ip.info
lnxljnht.hopto.org
lnxljnht.no-ip.info
nhdnthzp.hopto.org
nhdnthzp.no-ip.info
pbjpdbrl.hopto.org
pbjpdbrl.no-ip.info
rvprnvjh.hopto.org
rvprnvjh.no-ip.info
tpvtxpbd.hopto.org
tpvtxpbd.no-ip.info
vjbvhjtz.hopto.org
vjbvhjtz.no-ip.info
xdhxrdlv.hopto.org
xdhxrdlv.no-ip.info
zxnzbxdr.hopto.org
zxnzbxdr.no-ip.info
Note: no-ip.info and hopto.org are dynamic DNS sites.
Retrieves and executes a file from a remote location.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as W32.Tiniresu.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.tiniresu.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Lovgate.AO@mm
Discovered on: August 25, 2004
Last Updated on: August 26, 2004 10:09:36 AM
W32.Lovgate.AO@mm is a mass-mailing worm that propagates through open network shares and prepends itself to .exe files.
The email has a variable subject and attachment name, with a .bat, .cmd, .com, .exe, .pif, .scr, or.zip file extension.
Also Known As: I-Worm.LovGate.ah [Kaspersky]
Type: Worm
Infection Length: varies
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x
Technical Details:
When W32.Lovgate.AO@mm is run, it does the following:
Creates a network share, named JAVA, which is mapped to %Windir%\JAVA.
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Copies itself to all the network shares using one or more of the following names:
Daemon Tools v3.41.exe
EnterNet 500 V1.5 RC1.exe
Flash2X Flash Hunter v1.1.2.pif
FoxMail V5.0.500.0.exe
Microsoft Office.exe
Minilyrics_Std_2.7.233.pif
Serv-U FTP Server 4.1.exe
Support Tools.exe
WINISO 5.3.exe
WinGate V5.0.10 Build.exe
Winamp skin_FinalFantasy.exe
Windows 2000 sp4.ZIP.exe
Windows Media Player.zip.exe
autoexec.bat
eMule-0.42e-VeryCD0407Install.exe
i386.exe
Creates the following files:
%Windir%\Office.exe
%Windir%\Video.EXE
%System%\IEXPLORE.EXE
%System%\Kernel66.dll (A hidden file.)
%System%\TkBellExe.exe
%System%\Update_OB.exe
%System%\hxdef.exe
%System%\iexplorer.exe
%System%\real.exe
Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following files:
%System%\Lmmib20.dll
%System%\MSSIGN30.DLL
%System%\ODBC16.dll
%System%\msjdbc11.dll
which make up the worm's backdoor component.
Creates the file, upDate.exe, in the root folder of all the drives, except for CD-ROM drives. The file attributes of this file are set to System, Hidden, and Read-only.
Drops a file named %System%\WinPatch.dll.
Creates and starts the following services:
_reg
Windows Management Protocol v.0(experimental)
Overwrites the autorun.inf file on each drive with the following:
[AUTORUN]
Open="C:\upDate.exe" /StartExplorer
Creates an archive containing a copy of the worm with the following format in the root folder of all the drives, unless the drive letter is A or B:
<filename>.RAR
where <filename> may be one of the following:
Bakeup
ghost
email
Adds the values:
"Microsoft Inc." = "iexplorer.exe..."
"Program In Windows" = "%System%\IEXPLORE.EXE"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"WinHelp" = "%System%\TkBellExe.exe..."
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that it executes every time Windows starts.
Adds the values:
"Installed shell32.dll" = "Office.exe..."
"SystemTra" = "C:\WINDOWS\Video.EXE"
"Soft Profile Inc" = "%System%\hxdef.exe..."
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices
so that it executes every time Windows 95/98/Me starts.
Adds the value:
"run" = "real.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
Adds the value:
"(Default)" = "Update_OB.exe %1..."
to the registry key:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
so that the worm runs each time a .txt file is opened.
Stops the following services:
Rising Realtime Monitor Service
Symantec AntiVirus Client
Symantec AntiVirus Server
Terminates any processes with the following strings in their names:
Duba
Gate
KAV
KV
McAfee
NAV
RavMon.exe
Rfw.exe
SkyNet
Symantec
kill
rising
Injects a process-watching procedure as a thread into either Explorer.exe or Taskmgr.exe. This thread will attempt to launch %System%\Iexplore.exe if it detects that the worm's process has stopped.
The worm will then listen on TCP port 6060. The backdoor procedures steal information of an infected computer and stores it in the file, C:\Netlog.txt. The worm then emails the stolen information to the hacker.
Extracts the location of the KaZaA-shared folder from the registry. Then, it copies itself to the folder as one of the following:
BlackIcePCPSetup_creak
HEROSOFT
Passware5.3
REALONE
W32Dasm
orcard_original_creak
rainbowcrack-1.1-win
setup
word_pass_creak
wrar320sc
<random file name>
with a .bat, .exe, .pif, or .scr file extension.
Scans all the computers attached to the same network segment as the infected computer. The worm will attempt to authenticate to administrative shares on systems that are found, using "Administrator" as a user name, combined with the following passwords:
!@#$
!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
000000
00000000
007
110
111
111111
11111111
121212
123
123123
1234
12345
123456
1234567
12345678
123456789
123abc
123asd
2003
2004
2600
321
54321
654321
666666
888888
88888888
Admin
Administrator
Guest
Internet
Login
Password
aaa
abc
abc123
abcd
abcdef
abcdefg
admin
admin123
administrator
alpha
asdf
asdfgh
computer
database
enable
god
godblessyou
guest
home
login
love
mypass
mypass123
mypc
mypc123
oracle
owner
pass
passwd
password
pw123
pwd
root
secret
server
sex
sql
super
sybase
temp
temp123
test
test123
win
yxcv
zxcv
zzz
If the worm successfully authenticates to a remote system, it will attempt to copy itself as:
\\<remote computer name>\admin$\system32\TelePhone.exe
Starts the file as the service, "NetWork Associates Inc."
Replies to any messages that arrive in the mailbox of certain MAPI-compliant email clients, such as Microsoft Outlook.
For example, if the incoming email has the following properties:
Subject: <subject>
From: <sender>@<domain.com>
Message: <original message body>
the worm will attempt to send the following email:
Subject: Re: <subject>
To: <sender>@<domain.com>
Message:
'<sender>' wrote:
====
> <original message body>
====
<domain.com> account auto-reply:
... ... more details,look to the attachment.
> Get your FREE <domain.com> account now! <
Attachment: (One of the following)
Butterfly Garden.scr
FlashFXP.exe
HyperSnap-DX v5.rar.exe
Industry Giant II.exe
MSN Messenger.exe
MacroMedia.pif
Macromedia Flash.scr
Matrix Reloaded 3D.exe
MyIE.AVI.pif
Photoshop.EXE
Shakira.zip.exe
StarWars2 - CloneAttack.rm.scr
WindowsXP Creak.exe
dreamweaver MX (crack).exe
joke.exe
s3msong.MP3.pif
Retrieves the email addresses on the infected machine and sends an email with the following properties. The From field may be spoofed.
Subject: (One of the following)
Delivery Status Notification (Delay)
Error
Hi
Mail Transaction Failed
Test
<blank>
Message: (One of the following)
Delivery to the following recipient has failed:
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.
Mail failed. For further assistance, Please contact!
THIS IS A WARNING MESSAGE ONLY.
The message contains Uniocode characters and has been sent as a binary attachment.
This is an automatically generated Delivery Status Notification
YOU DO NOT NEED TO RESEND YOUR MESSAGE.
<blank>
Attachment: (One of the following)
Body
Doc
Document
File
Message
Readme
Test
Text
data
<random>
Extension: (One of the following)
.bat
.cmd
.com
.exe
.pif
.scr
.zip
Searches the hard disk for .exe files. When it finds one, it creates a viral file, %System%\temp.uuu, and prepends this file to the .exe file. These files will be detected as W32.Lovgate.AO@mm!inf.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Reverse the changes made to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values:
"Microsoft Inc." = "iexplorer.exe..."
"Program In Windows" = "%System%\IEXPLORE.EXE"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"WinHelp" = "%system%\TkBellExe.exe..."
If you are using Windows 95/98/Me, navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices
In the right pane, delete the values:
"SystemTra" = "C:\WINDOWS\Video.EXE"
"Soft Profile Inc" = "%System%\hxdef.exe..."
"Installed shell32.dll" = "Office.exe..."
If you are using Windows NT/2000/XP, navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
In the right pane, delete the value:
"run" = "real.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
In the right pane, delete the subkeys:
_reg
Windows Management Protocol v.0(experimental)
Navigate to the key:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
In the right pane, change the value to:
Windows 95/98/Me:
"(Default)"="WINDOWS\NOTEPAD.EXE %1"
Windows NT/2000/XP:
"(Default)"="%SystemRoot%\system32\NOTEPAD.EXE %1"
Exit the Registry Editor.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lovgate.AO@mm.
Repair those detected as W32.Lovgate.AO@mm!inf.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.ao@mm.html\"]source[/url]
Discovered on: August 25, 2004
Last Updated on: August 26, 2004 10:09:36 AM
W32.Lovgate.AO@mm is a mass-mailing worm that propagates through open network shares and prepends itself to .exe files.
The email has a variable subject and attachment name, with a .bat, .cmd, .com, .exe, .pif, .scr, or.zip file extension.
Also Known As: I-Worm.LovGate.ah [Kaspersky]
Type: Worm
Infection Length: varies
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x
Technical Details:
When W32.Lovgate.AO@mm is run, it does the following:
Creates a network share, named JAVA, which is mapped to %Windir%\JAVA.
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Copies itself to all the network shares using one or more of the following names:
Daemon Tools v3.41.exe
EnterNet 500 V1.5 RC1.exe
Flash2X Flash Hunter v1.1.2.pif
FoxMail V5.0.500.0.exe
Microsoft Office.exe
Minilyrics_Std_2.7.233.pif
Serv-U FTP Server 4.1.exe
Support Tools.exe
WINISO 5.3.exe
WinGate V5.0.10 Build.exe
Winamp skin_FinalFantasy.exe
Windows 2000 sp4.ZIP.exe
Windows Media Player.zip.exe
autoexec.bat
eMule-0.42e-VeryCD0407Install.exe
i386.exe
Creates the following files:
%Windir%\Office.exe
%Windir%\Video.EXE
%System%\IEXPLORE.EXE
%System%\Kernel66.dll (A hidden file.)
%System%\TkBellExe.exe
%System%\Update_OB.exe
%System%\hxdef.exe
%System%\iexplorer.exe
%System%\real.exe
Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following files:
%System%\Lmmib20.dll
%System%\MSSIGN30.DLL
%System%\ODBC16.dll
%System%\msjdbc11.dll
which make up the worm's backdoor component.
Creates the file, upDate.exe, in the root folder of all the drives, except for CD-ROM drives. The file attributes of this file are set to System, Hidden, and Read-only.
Drops a file named %System%\WinPatch.dll.
Creates and starts the following services:
_reg
Windows Management Protocol v.0(experimental)
Overwrites the autorun.inf file on each drive with the following:
[AUTORUN]
Open="C:\upDate.exe" /StartExplorer
Creates an archive containing a copy of the worm with the following format in the root folder of all the drives, unless the drive letter is A or B:
<filename>.RAR
where <filename> may be one of the following:
Bakeup
ghost
Adds the values:
"Microsoft Inc." = "iexplorer.exe..."
"Program In Windows" = "%System%\IEXPLORE.EXE"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"WinHelp" = "%System%\TkBellExe.exe..."
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that it executes every time Windows starts.
Adds the values:
"Installed shell32.dll" = "Office.exe..."
"SystemTra" = "C:\WINDOWS\Video.EXE"
"Soft Profile Inc" = "%System%\hxdef.exe..."
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices
so that it executes every time Windows 95/98/Me starts.
Adds the value:
"run" = "real.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
Adds the value:
"(Default)" = "Update_OB.exe %1..."
to the registry key:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
so that the worm runs each time a .txt file is opened.
Stops the following services:
Rising Realtime Monitor Service
Symantec AntiVirus Client
Symantec AntiVirus Server
Terminates any processes with the following strings in their names:
Duba
Gate
KAV
KV
McAfee
NAV
RavMon.exe
Rfw.exe
SkyNet
Symantec
kill
rising
Injects a process-watching procedure as a thread into either Explorer.exe or Taskmgr.exe. This thread will attempt to launch %System%\Iexplore.exe if it detects that the worm's process has stopped.
The worm will then listen on TCP port 6060. The backdoor procedures steal information of an infected computer and stores it in the file, C:\Netlog.txt. The worm then emails the stolen information to the hacker.
Extracts the location of the KaZaA-shared folder from the registry. Then, it copies itself to the folder as one of the following:
BlackIcePCPSetup_creak
HEROSOFT
Passware5.3
REALONE
W32Dasm
orcard_original_creak
rainbowcrack-1.1-win
setup
word_pass_creak
wrar320sc
<random file name>
with a .bat, .exe, .pif, or .scr file extension.
Scans all the computers attached to the same network segment as the infected computer. The worm will attempt to authenticate to administrative shares on systems that are found, using "Administrator" as a user name, combined with the following passwords:
!@#$
!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
000000
00000000
007
110
111
111111
11111111
121212
123
123123
1234
12345
123456
1234567
12345678
123456789
123abc
123asd
2003
2004
2600
321
54321
654321
666666
888888
88888888
Admin
Administrator
Guest
Internet
Login
Password
aaa
abc
abc123
abcd
abcdef
abcdefg
admin
admin123
administrator
alpha
asdf
asdfgh
computer
database
enable
god
godblessyou
guest
home
login
love
mypass
mypass123
mypc
mypc123
oracle
owner
pass
passwd
password
pw123
pwd
root
secret
server
sex
sql
super
sybase
temp
temp123
test
test123
win
yxcv
zxcv
zzz
If the worm successfully authenticates to a remote system, it will attempt to copy itself as:
\\<remote computer name>\admin$\system32\TelePhone.exe
Starts the file as the service, "NetWork Associates Inc."
Replies to any messages that arrive in the mailbox of certain MAPI-compliant email clients, such as Microsoft Outlook.
For example, if the incoming email has the following properties:
Subject: <subject>
From: <sender>@<domain.com>
Message: <original message body>
the worm will attempt to send the following email:
Subject: Re: <subject>
To: <sender>@<domain.com>
Message:
'<sender>' wrote:
====
> <original message body>
====
<domain.com> account auto-reply:
... ... more details,look to the attachment.
> Get your FREE <domain.com> account now! <
Attachment: (One of the following)
Butterfly Garden.scr
FlashFXP.exe
HyperSnap-DX v5.rar.exe
Industry Giant II.exe
MSN Messenger.exe
MacroMedia.pif
Macromedia Flash.scr
Matrix Reloaded 3D.exe
MyIE.AVI.pif
Photoshop.EXE
Shakira.zip.exe
StarWars2 - CloneAttack.rm.scr
WindowsXP Creak.exe
dreamweaver MX (crack).exe
joke.exe
s3msong.MP3.pif
Retrieves the email addresses on the infected machine and sends an email with the following properties. The From field may be spoofed.
Subject: (One of the following)
Delivery Status Notification (Delay)
Error
Hi
Mail Transaction Failed
Test
<blank>
Message: (One of the following)
Delivery to the following recipient has failed:
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.
Mail failed. For further assistance, Please contact!
THIS IS A WARNING MESSAGE ONLY.
The message contains Uniocode characters and has been sent as a binary attachment.
This is an automatically generated Delivery Status Notification
YOU DO NOT NEED TO RESEND YOUR MESSAGE.
<blank>
Attachment: (One of the following)
Body
Doc
Document
File
Message
Readme
Test
Text
data
<random>
Extension: (One of the following)
.bat
.cmd
.com
.exe
.pif
.scr
.zip
Searches the hard disk for .exe files. When it finds one, it creates a viral file, %System%\temp.uuu, and prepends this file to the .exe file. These files will be detected as W32.Lovgate.AO@mm!inf.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Reverse the changes made to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values:
"Microsoft Inc." = "iexplorer.exe..."
"Program In Windows" = "%System%\IEXPLORE.EXE"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"WinHelp" = "%system%\TkBellExe.exe..."
If you are using Windows 95/98/Me, navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices
In the right pane, delete the values:
"SystemTra" = "C:\WINDOWS\Video.EXE"
"Soft Profile Inc" = "%System%\hxdef.exe..."
"Installed shell32.dll" = "Office.exe..."
If you are using Windows NT/2000/XP, navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
In the right pane, delete the value:
"run" = "real.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
In the right pane, delete the subkeys:
_reg
Windows Management Protocol v.0(experimental)
Navigate to the key:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
In the right pane, change the value to:
Windows 95/98/Me:
"(Default)"="WINDOWS\NOTEPAD.EXE %1"
Windows NT/2000/XP:
"(Default)"="%SystemRoot%\system32\NOTEPAD.EXE %1"
Exit the Registry Editor.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lovgate.AO@mm.
Repair those detected as W32.Lovgate.AO@mm!inf.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.ao@mm.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Scane
Discovered on: August 26, 2004
Last Updated on: August 27, 2004 04:11:26 PM
W32.Scane is a worm that attempts to spread by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability.
Type: Worm
Infection Length: 71,416 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT
Technical Details:
When W32.Scane executes, it does the following:
May copy itself as %System%\servicec.exe
Note: %System% is a variable that refers to the System folder. By default this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the values:
"WinLsass"="%System%\servicec.exe" or
"WinLsass"="<path to original threat file>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the W32.Scane runs when you start Windows.
Creates multiple threads that attempt to connect to a random block of IP addresses by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability on TCP port 445. If successful, the remote system attempts to download a copy of the worm from the host.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restarting the computer in Safe mode or VGA mode
Run a full system scan and delete all the files detected as W32.Scane.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete either of the following values:
"WinLsass"="%System%\servicec.exe"
"WinLsass"="<path to original threat file>"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.scane.html\"]source[/url]
Discovered on: August 26, 2004
Last Updated on: August 27, 2004 04:11:26 PM
W32.Scane is a worm that attempts to spread by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability.
Type: Worm
Infection Length: 71,416 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT
Technical Details:
When W32.Scane executes, it does the following:
May copy itself as %System%\servicec.exe
Note: %System% is a variable that refers to the System folder. By default this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the values:
"WinLsass"="%System%\servicec.exe" or
"WinLsass"="<path to original threat file>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the W32.Scane runs when you start Windows.
Creates multiple threads that attempt to connect to a random block of IP addresses by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability on TCP port 445. If successful, the remote system attempts to download a copy of the worm from the host.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restarting the computer in Safe mode or VGA mode
Run a full system scan and delete all the files detected as W32.Scane.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete either of the following values:
"WinLsass"="%System%\servicec.exe"
"WinLsass"="<path to original threat file>"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.scane.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Spybot.DAZ
Discovered on: August 27, 2004
Last Updated on: August 28, 2004 10:58:19 AM
W32.Spybot.DAZ is a worm that spreads through IRC, network shares, exploits, and computers that are infected with common backdoor Trojan horses.
Type: Worm
Systems Affected: Windows 2000, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details
When W32.Spybot.DAZ is executed, it does the following:
Copies itself as %System%\mvsc.exe
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"Microsoft Update" = "mvsc.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Note: The name of the value may change if an attacker sends a command to change it.
Modifies the value:
"EnableDCOM" = "N"
in the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM
Modifies the value:
"restrictanonymous" = "1"
in the registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
Scans for other computers on the network, attempting to connect to shared resources using a predetermined list of usernames and passwords. If successful, the worm will attempt to copy itself to the remote computer.
Connects to a remote IRC server on TCP port 6667 and listens for commands, including any of following:
Download and execute files.
Scan the network for server with running backdoor trojan horses.
List, stop, and start processes.
Launch Denial of Service (DoS) attacks.
Steal system information and send it to the attacker.
Log keystrokes to a file in the %System% folder.
Open a backdoor port.
Control the file system (Delete, create, and list files).
Perform port redirection.
Flush DNS server.
Creates a log file, named c:\debug.txt, containing information about the IRC servers the worm is connected to.
May spread by exploiting the following vulnerabilities:
The DCOM RPC Vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135.
The Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011).
The vulnerabilities in the Microsoft SQL Server 2000 or MSDE 2000 audit (described in Microsoft Security Bulletin MS02-061) using UDP port 1434.
The WebDav Vulnerability (described in Microsoft Security Bulletin MS03-007) using TCP port 80.
The UPnP NOTIFY Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS01-059).
The Workstation Service Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-049) using TCP port 445. Windows XP users are protected against this vulnerability if the patch in Microsoft Security Bulletin MS03-043 has been applied. Windows 2000 users must apply the patch in Microsoft Security Bulletin MS03-049.
May steal CD keys and passwords for the following games:
Battlefield 1942
Battlefield 1942 (Road To Rome)
Battlefield 1942 (Secret Weapons of WWII)
Battlfield Vietnam
Black and White
Chrome
Command and Conquer: Generals
Command and Conquer: Red Alert
Command and Conquer: Red Alert 2
Command and Conquer: Tiberian Sun
Counter-Strike
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden & Dangerous 2
IGI 2: Covert Strike
Industry Giant 2
James Bond 007: Nightfire
Legends of Might and Magic
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
Need For Speed Hot Pursuit 2
Need For Speed: Underground
Neverwinter Nights
Neverwinter Nights (Hordes of the Underdark)
Neverwinter Nights (Shadows of Undrentide)
NHL 2002
NHL 2003
NOX
Rainbow Six III RavenShield
Shogun: Total War: Warlord Edition
Soldier of Fortune II - Double Helix
Soldiers Of Anarchy
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Spybot.DAZ
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the following keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Microsoft Update" = "mvsc.exe"
Exit the Registry Editor
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.daz.html\"]source[/url]
Discovered on: August 27, 2004
Last Updated on: August 28, 2004 10:58:19 AM
W32.Spybot.DAZ is a worm that spreads through IRC, network shares, exploits, and computers that are infected with common backdoor Trojan horses.
Type: Worm
Systems Affected: Windows 2000, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details
When W32.Spybot.DAZ is executed, it does the following:
Copies itself as %System%\mvsc.exe
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"Microsoft Update" = "mvsc.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Note: The name of the value may change if an attacker sends a command to change it.
Modifies the value:
"EnableDCOM" = "N"
in the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM
Modifies the value:
"restrictanonymous" = "1"
in the registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
Scans for other computers on the network, attempting to connect to shared resources using a predetermined list of usernames and passwords. If successful, the worm will attempt to copy itself to the remote computer.
Connects to a remote IRC server on TCP port 6667 and listens for commands, including any of following:
Download and execute files.
Scan the network for server with running backdoor trojan horses.
List, stop, and start processes.
Launch Denial of Service (DoS) attacks.
Steal system information and send it to the attacker.
Log keystrokes to a file in the %System% folder.
Open a backdoor port.
Control the file system (Delete, create, and list files).
Perform port redirection.
Flush DNS server.
Creates a log file, named c:\debug.txt, containing information about the IRC servers the worm is connected to.
May spread by exploiting the following vulnerabilities:
The DCOM RPC Vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135.
The Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011).
The vulnerabilities in the Microsoft SQL Server 2000 or MSDE 2000 audit (described in Microsoft Security Bulletin MS02-061) using UDP port 1434.
The WebDav Vulnerability (described in Microsoft Security Bulletin MS03-007) using TCP port 80.
The UPnP NOTIFY Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS01-059).
The Workstation Service Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-049) using TCP port 445. Windows XP users are protected against this vulnerability if the patch in Microsoft Security Bulletin MS03-043 has been applied. Windows 2000 users must apply the patch in Microsoft Security Bulletin MS03-049.
May steal CD keys and passwords for the following games:
Battlefield 1942
Battlefield 1942 (Road To Rome)
Battlefield 1942 (Secret Weapons of WWII)
Battlfield Vietnam
Black and White
Chrome
Command and Conquer: Generals
Command and Conquer: Red Alert
Command and Conquer: Red Alert 2
Command and Conquer: Tiberian Sun
Counter-Strike
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden & Dangerous 2
IGI 2: Covert Strike
Industry Giant 2
James Bond 007: Nightfire
Legends of Might and Magic
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
Need For Speed Hot Pursuit 2
Need For Speed: Underground
Neverwinter Nights
Neverwinter Nights (Hordes of the Underdark)
Neverwinter Nights (Shadows of Undrentide)
NHL 2002
NHL 2003
NOX
Rainbow Six III RavenShield
Shogun: Total War: Warlord Edition
Soldier of Fortune II - Double Helix
Soldiers Of Anarchy
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Spybot.DAZ
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the following keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Microsoft Update" = "mvsc.exe"
Exit the Registry Editor
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.daz.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Downloader.CDT
Discovered on: August 30, 2004
Last Updated on: September 01, 2004 11:08:09 AM
Downloader.CDT is a Trojan horse program that downloads several files from a specific website.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When the Trojan is executed it performs the following actions:
Creates the following copy of itself:
[Random name].exe
Adds the following values:
"CurrentLevel" = "0"
"Flags" = "0"
"1001" = "0"
"1004" = "0"
"1200" = "0"
"1201" = "0"
"1206" = "0"
"1400" = "0"
"1402" = "0"
"1405" = "0"
"1406" = "0"
"1407" = "0"
"1601" = "0"
"1604" = "0"
"1605" = "0"
"1606" = "0"
"1607" = "0"
"1608" = "0"
"1609" = "0"
"1800" = "0"
"1802" = "0"
"1803" = "0"
"1804" = "0"
"1805" = "0"
"1A00" = "0"
"1A02" = "0"
"1A03" = "0"
"1A04" = "0"
"1A05" = "0"
"1A06" = "0"
"1A10" = "0"
"2001" = "0"
"2004" = "0"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
to lower the security settings in Microsoft Internet Explorer.
Attempts to open a Web site in the domain counterstrike.server.us, and download a program named Adware.CDT.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Downloader.CDT.
Restoring security settings in Microsoft Internet Explorer.
To restore the security level, complete the following steps:
Start Internet Explorer.
Click Tools, and then click Internet Options.
Select the Security tab.
Reset the security settings to the level you desire.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/downloader.cdt.html\"]source[/url]
Discovered on: August 30, 2004
Last Updated on: September 01, 2004 11:08:09 AM
Downloader.CDT is a Trojan horse program that downloads several files from a specific website.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When the Trojan is executed it performs the following actions:
Creates the following copy of itself:
[Random name].exe
Adds the following values:
"CurrentLevel" = "0"
"Flags" = "0"
"1001" = "0"
"1004" = "0"
"1200" = "0"
"1201" = "0"
"1206" = "0"
"1400" = "0"
"1402" = "0"
"1405" = "0"
"1406" = "0"
"1407" = "0"
"1601" = "0"
"1604" = "0"
"1605" = "0"
"1606" = "0"
"1607" = "0"
"1608" = "0"
"1609" = "0"
"1800" = "0"
"1802" = "0"
"1803" = "0"
"1804" = "0"
"1805" = "0"
"1A00" = "0"
"1A02" = "0"
"1A03" = "0"
"1A04" = "0"
"1A05" = "0"
"1A06" = "0"
"1A10" = "0"
"2001" = "0"
"2004" = "0"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
to lower the security settings in Microsoft Internet Explorer.
Attempts to open a Web site in the domain counterstrike.server.us, and download a program named Adware.CDT.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Downloader.CDT.
Restoring security settings in Microsoft Internet Explorer.
To restore the security level, complete the following steps:
Start Internet Explorer.
Click Tools, and then click Internet Options.
Select the Security tab.
Reset the security settings to the level you desire.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/downloader.cdt.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.Hiva
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 10:54:38 AM
Trojan.Hiva is a Trojan horse program that uses net-send commands to send alert messages, moves the mouse randomly, and closes program windows.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When the Trojan is executed, it does the following:
Creates the following files:
Windows%\HIV.exe
Windows%\HIVmod1.exe
Windows%\HIVmod2.exe
Windows%\HIVmod3.exe
Windows%\HIVmod4.exe
Adds the following value:
"HIV"="HIV.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that it is executed every time Windows starts.
Uses net-send commands to display the following alert box:
HIV+ infected
Performs some of the following actions:
Moves the mouse randomly
Closes program windows
Attempts to open the CD-ROM drive
Uses net-send commands to send alert messages to random IP addresses.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Hiva.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"HIV"="HIV.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.hiva.html\"]source[/url]
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 10:54:38 AM
Trojan.Hiva is a Trojan horse program that uses net-send commands to send alert messages, moves the mouse randomly, and closes program windows.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When the Trojan is executed, it does the following:
Creates the following files:
Windows%\HIV.exe
Windows%\HIVmod1.exe
Windows%\HIVmod2.exe
Windows%\HIVmod3.exe
Windows%\HIVmod4.exe
Adds the following value:
"HIV"="HIV.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that it is executed every time Windows starts.
Uses net-send commands to display the following alert box:
HIV+ infected
Performs some of the following actions:
Moves the mouse randomly
Closes program windows
Attempts to open the CD-ROM drive
Uses net-send commands to send alert messages to random IP addresses.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Hiva.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"HIV"="HIV.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.hiva.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Backdoor.Alets
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 10:52:46 AM
Backdoor.Alets is a backdoor Trojan horse that allows a remote attacker to have unauthorized access to an infected computer, via IRC channels.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
Once the Trojan is executed, it performs the following actions:
Creates the following copy of itself:
%Windir%\services.exe
Adds the following value:
"Microsoft Services"="%Windir%\services.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that it is executed every time Windows starts.
Contacts an IRC server on the domain, ctgbn.stellaremperor.com, through TCP port 32440.
Awaits commands from a remote attacker to perform the following actions:
Kill processes
Download and execute files
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Alets.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Microsoft Services"="%Windir%\services.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.alets.html\"]source[/url]
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 10:52:46 AM
Backdoor.Alets is a backdoor Trojan horse that allows a remote attacker to have unauthorized access to an infected computer, via IRC channels.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
Once the Trojan is executed, it performs the following actions:
Creates the following copy of itself:
%Windir%\services.exe
Adds the following value:
"Microsoft Services"="%Windir%\services.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that it is executed every time Windows starts.
Contacts an IRC server on the domain, ctgbn.stellaremperor.com, through TCP port 32440.
Awaits commands from a remote attacker to perform the following actions:
Kill processes
Download and execute files
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Alets.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Microsoft Services"="%Windir%\services.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.alets.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Download.Ject.D
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 04:27:11 PM
Download.Ject.D is a variant of [url=\"http://securityresponse.symantec.com/avcenter/venc/data/download.ject.c.html\"]Download.Ject.C[/url] that attempts to download and execute files.
Note: LiveUpdate Virus definitions are scheduled to be released on 8/31/04 to provide protection against this threat. Virus definitions version 60831j (extended version 8/31/2004 rev. 36) and greater are required for detection.
Variants: Download.Ject.C
Type: Trojan Horse
Infection Length: 12,800 Bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Technical Details:
When Download.Ject.D is executed, it performs the following actions:
Creates the following files:
%System%\Doriot.exe (A copy of itself)
%System%\Gdqfw.exe (A downloader module)
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"wersds" = "%System%\doriot.exe"
to the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
Injects Gdqfw.exe into Explorer.exe as a remote thread, which attempts to do the following:
Stops the service, "SharedAccess," and then sets the Startup type of this service to Disabled.
Terminates the following processes:
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE
Attempts to download a file from one of the following domains. The file is saved as %Windir%\_re_file.exe, and is then executed.
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
allianzsp.sk
coolweb.psg.sk
cryofthespirit.com
dollypop.com
execpage.com
helpdemos.com
helpingyouth.org
jamesbronner.com
koti.pl
miracle.v6.cz
mountainwings.com
mountainwings4.com
naturalpros.com
oracal.pl
shock.evernet.com.pl
SportLine.go.ro
stroipolymer.ru
theonlineword.com
virtualchurch.com
visionforsouls.org
wingsoverlife.com
www.1800thewoman.com
www.1944.pl
www.45partsdepot.com
www.7pe.friko.pl
www.air-computers.com.ar
www.ametist.spb.ru
www.apodis.pl
www.arrasy.pl
www.arthurspeaks.com
www.astermed.pl
www.atomique.pl
www.atw.hu
www.avatar.ee
www.avers.com.pl
www.baltexpo.spb.ru
www.bomart.cz
www.bravo.gliwice.pl
www.bronnerbros.com
www.buycare.com
www.cumparacd.go.ro
www.da-rom.co.il
www.domu.net
www.eastandard.co.ke
www.elblu.republika.pl
www.elcorsy.com
www.elite-style.com
www.enduser1.fast.net
www.enitex.by
www.enitex-m.by
www.eris.pl
www.europharm.pl
www.extreme-racing.lg.ua
www.fotel.pl
www.fotolab.sk
www.frater.hu
www.gardameditech.com
www.generex.de
www.goldgates.com
www.goodboy.dem.ru
www.hards.pl
www.healthcometh.com
www.holz-studio.at
www.ibplus.sk
www.icpnet.pl
www.icpnet.pl
www.inlan.sk
www.jamesbronner.com
www.jbplus.cz
www.justmatchit.com
www.kubtelecom.ru
www.kuda.com.ua
www.lacittadifiorenzuola.it
www.lotusdog.net
www.ltvo.spb.ru
www.master.pl
www.members.aon.at
www.moteplassen1.com
www.mountainwings2.com
www.multifoto.sk
www.nadodrze.pl
www.nairobiwebspace.com
www.nameitright.com
www.nardo.bbe.pl
www.netland.gda.pl
www.netta.pl
www.nikola.piwko.pl
www.ntrlab.com
www.nustep.sk
www.octava.pl
www.odevnictvo.sk
www.oftza.friko.pl
www.oktbroiler.ru
www.online40.com
www.online50.com
www.oto.lv
www.pancoopzsv.co.yu
www.pay5495.com
www.pc-hard.com.ua
www.perfect-beauty.at
www.pharmag.pl
www.polsl.katowice.pl
www.prophetcollins.com
www.propi.cz
www.pursuit.rv.ua
www.pyrlandia-boogie.pl
www.quatro.sk
www.r-bazar.ru
www.roszkowski.pl
www.silvic.ro
www.sincron.go.ro
www.skylive.pl
www.smgkrc.pl
www.soulring.com
www.star-max.it
www.sunbud.com.pl
www.swez.net
www.system5electronics.com
www.tcvwebtv.com.ar
www.thewoman.com
www.tivis.cz
www.ukpl.pl
www.vacation-network.net
www.wyspian.iap.pl
www.zasada-rowery.pl
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Download.Ject.D.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"wersds" = "%System%\doriot.exe"
Exit the Registry Editor.
Restart the computer in normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/download.ject.d.html\"]source[/url]
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 04:27:11 PM
Download.Ject.D is a variant of [url=\"http://securityresponse.symantec.com/avcenter/venc/data/download.ject.c.html\"]Download.Ject.C[/url] that attempts to download and execute files.
Note: LiveUpdate Virus definitions are scheduled to be released on 8/31/04 to provide protection against this threat. Virus definitions version 60831j (extended version 8/31/2004 rev. 36) and greater are required for detection.
Variants: Download.Ject.C
Type: Trojan Horse
Infection Length: 12,800 Bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Technical Details:
When Download.Ject.D is executed, it performs the following actions:
Creates the following files:
%System%\Doriot.exe (A copy of itself)
%System%\Gdqfw.exe (A downloader module)
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"wersds" = "%System%\doriot.exe"
to the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
Injects Gdqfw.exe into Explorer.exe as a remote thread, which attempts to do the following:
Stops the service, "SharedAccess," and then sets the Startup type of this service to Disabled.
Terminates the following processes:
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE
Attempts to download a file from one of the following domains. The file is saved as %Windir%\_re_file.exe, and is then executed.
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
allianzsp.sk
coolweb.psg.sk
cryofthespirit.com
dollypop.com
execpage.com
helpdemos.com
helpingyouth.org
jamesbronner.com
koti.pl
miracle.v6.cz
mountainwings.com
mountainwings4.com
naturalpros.com
oracal.pl
shock.evernet.com.pl
SportLine.go.ro
stroipolymer.ru
theonlineword.com
virtualchurch.com
visionforsouls.org
wingsoverlife.com
www.1800thewoman.com
www.1944.pl
www.45partsdepot.com
www.7pe.friko.pl
www.air-computers.com.ar
www.ametist.spb.ru
www.apodis.pl
www.arrasy.pl
www.arthurspeaks.com
www.astermed.pl
www.atomique.pl
www.atw.hu
www.avatar.ee
www.avers.com.pl
www.baltexpo.spb.ru
www.bomart.cz
www.bravo.gliwice.pl
www.bronnerbros.com
www.buycare.com
www.cumparacd.go.ro
www.da-rom.co.il
www.domu.net
www.eastandard.co.ke
www.elblu.republika.pl
www.elcorsy.com
www.elite-style.com
www.enduser1.fast.net
www.enitex.by
www.enitex-m.by
www.eris.pl
www.europharm.pl
www.extreme-racing.lg.ua
www.fotel.pl
www.fotolab.sk
www.frater.hu
www.gardameditech.com
www.generex.de
www.goldgates.com
www.goodboy.dem.ru
www.hards.pl
www.healthcometh.com
www.holz-studio.at
www.ibplus.sk
www.icpnet.pl
www.icpnet.pl
www.inlan.sk
www.jamesbronner.com
www.jbplus.cz
www.justmatchit.com
www.kubtelecom.ru
www.kuda.com.ua
www.lacittadifiorenzuola.it
www.lotusdog.net
www.ltvo.spb.ru
www.master.pl
www.members.aon.at
www.moteplassen1.com
www.mountainwings2.com
www.multifoto.sk
www.nadodrze.pl
www.nairobiwebspace.com
www.nameitright.com
www.nardo.bbe.pl
www.netland.gda.pl
www.netta.pl
www.nikola.piwko.pl
www.ntrlab.com
www.nustep.sk
www.octava.pl
www.odevnictvo.sk
www.oftza.friko.pl
www.oktbroiler.ru
www.online40.com
www.online50.com
www.oto.lv
www.pancoopzsv.co.yu
www.pay5495.com
www.pc-hard.com.ua
www.perfect-beauty.at
www.pharmag.pl
www.polsl.katowice.pl
www.prophetcollins.com
www.propi.cz
www.pursuit.rv.ua
www.pyrlandia-boogie.pl
www.quatro.sk
www.r-bazar.ru
www.roszkowski.pl
www.silvic.ro
www.sincron.go.ro
www.skylive.pl
www.smgkrc.pl
www.soulring.com
www.star-max.it
www.sunbud.com.pl
www.swez.net
www.system5electronics.com
www.tcvwebtv.com.ar
www.thewoman.com
www.tivis.cz
www.ukpl.pl
www.vacation-network.net
www.wyspian.iap.pl
www.zasada-rowery.pl
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Download.Ject.D.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"wersds" = "%System%\doriot.exe"
Exit the Registry Editor.
Restart the computer in normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/download.ject.d.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Beagle.AQ@mm
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 04:22:27 PM
W32.Beagle.AQ@mm is a variant of W32.Beagle.AO@mm, which is a mass-mailing worm that uses its own SMTP engine to spread. The email attachment is a downloader, similar to Trojan.Mitglieder and Download.Ject.C, that downloads the worm from an external source.
The worm also contains backdoor functionality, opening TCP port 80 and UDP port 80.
Variants: W32.Beagle.AO@mm
Type: Worm
Infection Length: 12,800 bytes, 18,436 bytes, 9,728 Bytes. 4,996 Bytes, 9,728 Bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Techincal Details:
When W32.Beagle.AQ@mm runs, it does the following:
Copies itself as the following files:
%System%\windll.exe. (A copy of the worm)
%System%\windll.exeopen (A copy of the worm)
%System%\windll.exeopenopen (A copy of the worm)
Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"erthgdr"="%System%\windll.exe"
to the registry key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n
Creates seven mutexes with the following names, which prevent some variants of the W32.Netsky@mm family of worms from running:
MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_
Deletes any values that contain the following strings:
9XHtProtect
Antivirus
EasyAV
FirewallSvr
HtProtect
ICQ Net
ICQNet
Jammer2nd
KasperskyAVEng
MsInfo
My AV
NetDy
Norton Antivirus AV
PandaAVEngine
SkynetsRevenge
Special Firewall Service
SysMonXP
Tiny AV
Zone Labs Client Ex
service
from the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n
Create copies of itself in any folder that contains the characters "shar". The files will have the following file names:
Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral,
/censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> cool, awesome!!.exe
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe
Attempts to download and execute files from the following Web sites as %System%\_re_file.exe:
allianzsp.sk
coolweb.psg.sk
cryofthespirit.com
dollypop.com
execpage.com
helpdemos.com
helpingyouth.org
jamesbronner.com
koti.pl
miracle.v6.cz
mountainwings.com
mountainwings4.com
naturalpros.com
oracal.pl
shock.evernet.com.pl
SportLine.go.ro
stroipolymer.ru
theonlineword.com
virtualchurch.com
visionforsouls.org
wingsoverlife.com
www.1800thewoman.com
www.1944.pl
www.45partsdepot.com
www.7pe.friko.pl
www.air-computers.com.ar
www.ametist.spb.ru
www.apodis.pl
www.arrasy.pl
www.arthurspeaks.com
www.astermed.pl
www.atomique.pl
www.atw.hu
www.avatar.ee
www.avers.com.pl
www.baltexpo.spb.ru
www.bomart.cz
www.bravo.gliwice.pl
www.bronnerbros.com
www.buycare.com
www.cumparacd.go.ro
www.da-rom.co.il
www.domu.net
www.eastandard.co.ke
www.elblu.republika.pl
www.elcorsy.com
www.elite-style.com
www.enduser1.fast.net
www.enitex.by
www.enitex-m.by
www.eris.pl
www.europharm.pl
www.extreme-racing.lg.ua
www.fotel.pl
www.fotolab.sk
www.frater.hu
www.gardameditech.com
www.generex.de
www.goldgates.com
www.goodboy.dem.ru
www.hards.pl
www.healthcometh.com
www.holz-studio.at
www.ibplus.sk
www.icpnet.pl
www.icpnet.pl
www.inlan.sk
www.jamesbronner.com
www.jbplus.cz
www.justmatchit.com
www.kubtelecom.ru
www.kuda.com.ua
www.lacittadifiorenzuola.it
www.lotusdog.net
www.ltvo.spb.ru
www.master.pl
www.members.aon.at
www.moteplassen1.com
www.mountainwings2.com
www.multifoto.sk
www.nadodrze.pl
www.nairobiwebspace.com
www.nameitright.com
www.nardo.bbe.pl
www.netland.gda.pl
www.netta.pl
www.nikola.piwko.pl
www.ntrlab.com
www.nustep.sk
www.octava.pl
www.odevnictvo.sk
www.oftza.friko.pl
www.oktbroiler.ru
www.online40.com
www.online50.com
www.oto.lv
www.pancoopzsv.co.yu
www.pay5495.com
www.pc-hard.com.ua
www.perfect-beauty.at
www.pharmag.pl
www.polsl.katowice.pl
www.prophetcollins.com
www.propi.cz
www.pursuit.rv.ua
www.pyrlandia-boogie.pl
www.quatro.sk
www.r-bazar.ru
www.roszkowski.pl
www.silvic.ro
www.sincron.go.ro
www.skylive.pl
www.smgkrc.pl
www.soulring.com
www.star-max.it
www.sunbud.com.pl
www.swez.net
www.system5electronics.com
www.tcvwebtv.com.ar
www.thewoman.com
www.tivis.cz
www.ukpl.pl
www.vacation-network.net
www.wyspian.iap.pl
www.zasada-rowery.pl
Note: %System% is a variable. The Trojan locates the Windows installation folder and saves the downloaded files to that location. By default, this is C:\Windows\System32 or C:\Winnt\System32.
Terminates the following processes:
ATUPDATER.EXE
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE
Searches for the email addresses in files that have the following extensions:
.adb
.asp
.cfg
.cgi
.dbx
.dhtm
.eml
.htm
.jsp
.mbx
.mdx
.mht
.mmf
.msg
.nch
.ods
.oft
.php
.pl
.sht
.shtm
.stm
.tbb
.txt
.uin
.wab
.wsh
.xls
.xml
Skips email addresses that contain the following strings:
@avp.
@derewrdgrs
@eerswqe
@foo
@iana
@messagelab
@microsoft
abuse
admin
anyone@
bsd
bugs@
cafee
certific
contract@
feste
free-av
f-secur
gold-certs@
google
help@
icrosoft
info@
kasp
linux
listserv
local
news
nobody@
noone@
noreply
ntivi
panda
pgp
postmaster@
rating@
root@
samples
sopho
spam
support
unix
update
winrar
winzip
Uses its own SMTP engine to send email messages to any addresses that are found.
The email may have the attachments "fotos.zip", which is a WinZip file containing "foto.html", and "foto1.exe".
Creates the following files:
%System%\Doriot.exe (A copy of foto1.exe)
%System%\Gdqfw.exe (A downloader module)
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"wersds" = "%System%\doriot.exe"
to the registry keys:
HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Opens backdoors on TCP port 80 and UDP port 80, which allow the infected computer to be used as an email relay.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AQ@mm.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n
In the right pane, delete the value:
"erthgdr"="%System%\windll.exe"
Navigate to the key:
HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Run
In the right pance, delete the value
"wersds" = "%System%\doriot.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Run
In the right pance, delete the value
"wersds" = "%System%\doriot.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.aq@mm.html\"]source[/url]
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 04:22:27 PM
W32.Beagle.AQ@mm is a variant of W32.Beagle.AO@mm, which is a mass-mailing worm that uses its own SMTP engine to spread. The email attachment is a downloader, similar to Trojan.Mitglieder and Download.Ject.C, that downloads the worm from an external source.
The worm also contains backdoor functionality, opening TCP port 80 and UDP port 80.
Variants: W32.Beagle.AO@mm
Type: Worm
Infection Length: 12,800 bytes, 18,436 bytes, 9,728 Bytes. 4,996 Bytes, 9,728 Bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Techincal Details:
When W32.Beagle.AQ@mm runs, it does the following:
Copies itself as the following files:
%System%\windll.exe. (A copy of the worm)
%System%\windll.exeopen (A copy of the worm)
%System%\windll.exeopenopen (A copy of the worm)
Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"erthgdr"="%System%\windll.exe"
to the registry key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n
Creates seven mutexes with the following names, which prevent some variants of the W32.Netsky@mm family of worms from running:
MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_
Deletes any values that contain the following strings:
9XHtProtect
Antivirus
EasyAV
FirewallSvr
HtProtect
ICQ Net
ICQNet
Jammer2nd
KasperskyAVEng
MsInfo
My AV
NetDy
Norton Antivirus AV
PandaAVEngine
SkynetsRevenge
Special Firewall Service
SysMonXP
Tiny AV
Zone Labs Client Ex
service
from the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n
Create copies of itself in any folder that contains the characters "shar". The files will have the following file names:
Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral,
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe
Attempts to download and execute files from the following Web sites as %System%\_re_file.exe:
allianzsp.sk
coolweb.psg.sk
cryofthespirit.com
dollypop.com
execpage.com
helpdemos.com
helpingyouth.org
jamesbronner.com
koti.pl
miracle.v6.cz
mountainwings.com
mountainwings4.com
naturalpros.com
oracal.pl
shock.evernet.com.pl
SportLine.go.ro
stroipolymer.ru
theonlineword.com
virtualchurch.com
visionforsouls.org
wingsoverlife.com
www.1800thewoman.com
www.1944.pl
www.45partsdepot.com
www.7pe.friko.pl
www.air-computers.com.ar
www.ametist.spb.ru
www.apodis.pl
www.arrasy.pl
www.arthurspeaks.com
www.astermed.pl
www.atomique.pl
www.atw.hu
www.avatar.ee
www.avers.com.pl
www.baltexpo.spb.ru
www.bomart.cz
www.bravo.gliwice.pl
www.bronnerbros.com
www.buycare.com
www.cumparacd.go.ro
www.da-rom.co.il
www.domu.net
www.eastandard.co.ke
www.elblu.republika.pl
www.elcorsy.com
www.elite-style.com
www.enduser1.fast.net
www.enitex.by
www.enitex-m.by
www.eris.pl
www.europharm.pl
www.extreme-racing.lg.ua
www.fotel.pl
www.fotolab.sk
www.frater.hu
www.gardameditech.com
www.generex.de
www.goldgates.com
www.goodboy.dem.ru
www.hards.pl
www.healthcometh.com
www.holz-studio.at
www.ibplus.sk
www.icpnet.pl
www.icpnet.pl
www.inlan.sk
www.jamesbronner.com
www.jbplus.cz
www.justmatchit.com
www.kubtelecom.ru
www.kuda.com.ua
www.lacittadifiorenzuola.it
www.lotusdog.net
www.ltvo.spb.ru
www.master.pl
www.members.aon.at
www.moteplassen1.com
www.mountainwings2.com
www.multifoto.sk
www.nadodrze.pl
www.nairobiwebspace.com
www.nameitright.com
www.nardo.bbe.pl
www.netland.gda.pl
www.netta.pl
www.nikola.piwko.pl
www.ntrlab.com
www.nustep.sk
www.octava.pl
www.odevnictvo.sk
www.oftza.friko.pl
www.oktbroiler.ru
www.online40.com
www.online50.com
www.oto.lv
www.pancoopzsv.co.yu
www.pay5495.com
www.pc-hard.com.ua
www.perfect-beauty.at
www.pharmag.pl
www.polsl.katowice.pl
www.prophetcollins.com
www.propi.cz
www.pursuit.rv.ua
www.pyrlandia-boogie.pl
www.quatro.sk
www.r-bazar.ru
www.roszkowski.pl
www.silvic.ro
www.sincron.go.ro
www.skylive.pl
www.smgkrc.pl
www.soulring.com
www.star-max.it
www.sunbud.com.pl
www.swez.net
www.system5electronics.com
www.tcvwebtv.com.ar
www.thewoman.com
www.tivis.cz
www.ukpl.pl
www.vacation-network.net
www.wyspian.iap.pl
www.zasada-rowery.pl
Note: %System% is a variable. The Trojan locates the Windows installation folder and saves the downloaded files to that location. By default, this is C:\Windows\System32 or C:\Winnt\System32.
Terminates the following processes:
ATUPDATER.EXE
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE
Searches for the email addresses in files that have the following extensions:
.adb
.asp
.cfg
.cgi
.dbx
.dhtm
.eml
.htm
.jsp
.mbx
.mdx
.mht
.mmf
.msg
.nch
.ods
.oft
.php
.pl
.sht
.shtm
.stm
.tbb
.txt
.uin
.wab
.wsh
.xls
.xml
Skips email addresses that contain the following strings:
@avp.
@derewrdgrs
@eerswqe
@foo
@iana
@messagelab
@microsoft
abuse
admin
anyone@
bsd
bugs@
cafee
certific
contract@
feste
free-av
f-secur
gold-certs@
help@
icrosoft
info@
kasp
linux
listserv
local
news
nobody@
noone@
noreply
ntivi
panda
pgp
postmaster@
rating@
root@
samples
sopho
spam
support
unix
update
winrar
winzip
Uses its own SMTP engine to send email messages to any addresses that are found.
The email may have the attachments "fotos.zip", which is a WinZip file containing "foto.html", and "foto1.exe".
Creates the following files:
%System%\Doriot.exe (A copy of foto1.exe)
%System%\Gdqfw.exe (A downloader module)
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"wersds" = "%System%\doriot.exe"
to the registry keys:
HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Opens backdoors on TCP port 80 and UDP port 80, which allow the infected computer to be used as an email relay.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AQ@mm.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n
In the right pane, delete the value:
"erthgdr"="%System%\windll.exe"
Navigate to the key:
HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Run
In the right pance, delete the value
"wersds" = "%System%\doriot.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Run
In the right pance, delete the value
"wersds" = "%System%\doriot.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.aq@mm.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.Yipid
Discovered on: September 01, 2004
Last Updated on: September 02, 2004 03:02:58 PM
Trojan.Yipid is a trojan that downloads files from the Internet, searches the system for email addresses, and sends a Chinese language email to all the addresses it finds.
Infection Length: 61440 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX
When Trojan.Yipid is executed it performs the following actions:
Copies itself to the %System% as:
Rund132.exe
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Attempts to download files from the domain chinaweb.a184.zgsj.com to the following folders:
%system%\MSWinsck.ocx (a legitimate file)
%system%\conmax.exe (collects email addresses)
%system%\msimn.exe (sends out emails)
Adds the value:
"Run"="%System%\Rund1.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows
And adds the value:
"Taskbell.exe" = "%System%\Rund1.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsCurrentVersion\Run
These entries ensure that Trojan.Yipid runs upon Windows startup.
Collects email addresses from files with the following extensions:
.txt
.htm
.html
.asp
.xml
.com
The trojan avoids email addresses that contain any of the following substrings:
guang
searchgov
edu
microsoft
rising
jiangmin
kingsoft
symantec
norton
263
163
nease
126
tom
371
sina
china
sohu
chinaren
21cn
Appends the found email addresses to the file:
%system%\mmtxt.txt
Registers the legitimate file, mswinsck.ocx, and sends email to all the collected addresses. The From address is spoofed and the message contains a text written in Chinese inviting the recipient to visit the domain chinaweb.a184.zgsj.com
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Yipid.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Taskbell.exe" = "%System%\Rund1.exe"
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows
In the right pane, delete the value:
"Run"="%System%\Rund1.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.yipid.html\"]source[/url]
Discovered on: September 01, 2004
Last Updated on: September 02, 2004 03:02:58 PM
Trojan.Yipid is a trojan that downloads files from the Internet, searches the system for email addresses, and sends a Chinese language email to all the addresses it finds.
Infection Length: 61440 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX
When Trojan.Yipid is executed it performs the following actions:
Copies itself to the %System% as:
Rund132.exe
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Attempts to download files from the domain chinaweb.a184.zgsj.com to the following folders:
%system%\MSWinsck.ocx (a legitimate file)
%system%\conmax.exe (collects email addresses)
%system%\msimn.exe (sends out emails)
Adds the value:
"Run"="%System%\Rund1.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows
And adds the value:
"Taskbell.exe" = "%System%\Rund1.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsCurrentVersion\Run
These entries ensure that Trojan.Yipid runs upon Windows startup.
Collects email addresses from files with the following extensions:
.txt
.htm
.html
.asp
.xml
.com
The trojan avoids email addresses that contain any of the following substrings:
guang
searchgov
edu
microsoft
rising
jiangmin
kingsoft
symantec
norton
263
163
nease
126
tom
371
sina
china
sohu
chinaren
21cn
Appends the found email addresses to the file:
%system%\mmtxt.txt
Registers the legitimate file, mswinsck.ocx, and sends email to all the collected addresses. The From address is spoofed and the message contains a text written in Chinese inviting the recipient to visit the domain chinaweb.a184.zgsj.com
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Yipid.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Taskbell.exe" = "%System%\Rund1.exe"
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows
In the right pane, delete the value:
"Run"="%System%\Rund1.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.yipid.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.IRCBot.F
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 01:59:58 PM
W32.IRCBot.F is a backdoor Trojan horse that connects to an IRC server and waits for commands from an attacker.
Variants: W32.IRCBot.E
Type: Trojan Horse
Infection Length: 95,744
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, UNIX, Windows 3.x
When W32.IRCBot.F is executed, it attempts to perform the following actions:
Copies itself as %System%\Securitychk.exe.
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"Microsoft Secure Messenger.NET Service" = "securitychk.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
Deletes the shares from local drives.
Connects to the IRC server tehr8x.spbx.net using TCP port 6667.
Joins a predefined channel, using a random nickname, and waits for commands from the IRC server. These commands can allow the attacker to:
Manage the installation of the Trojan
Control the IRC client on a compromised computer
Update the installed Trojan
Send the Trojan to other IRC channels
Download and execute files
Perform Denial of Service (DoS) attacks against a target, which the hacker defines
Uninstall itself completely by removing the relevant registry entries
Go to Web sites
Copy itself to shared folders on other computers
Steal license keys for games including:
Battlefield 1942
Battlefield 1942: Secret Weapons of WWII
Battlefield 1942: The Road To Rome
Battlefield 1942: Vietnam
Black and White
Command and Conquer: Generals
Command and Conquer: Generals: Zero Hour
Command and Conquer: Red Alert2
Command and Conquer: Tiberian Sun
Counter-Strike
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden and Dangerous 2
IGI2: Covert Strike
Industry Giant 2
James Bond 007: Nightfire
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
NHL 2002
NHL 2003
Need for Speed: Hot Pursuit 2
Need for Speed: Underground
Neverwinter Nights
Ravenshield
Shogun: Total War: Warlord Edition
Soldiers Of Anarchy
Soldier Of Fortune 2
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004
Soldier Of Fortune II - Double Helix
Terminate processes. Refer to the "Additional Information" section for a list of the processes that may be terminated.
Removal Instructions
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.IRCBot.F.
Delete the values that were added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to each of these keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Note: All the keys will not be found on all the systems.
From each key that is found, in the right pane, delete the value:
"Microsoft Secure Messenger.NET Service" = "securitychk.exe"
Exit the Registry Editor.
Restart the computer in normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.ircbot.f.html\"]source[/url]
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 01:59:58 PM
W32.IRCBot.F is a backdoor Trojan horse that connects to an IRC server and waits for commands from an attacker.
Variants: W32.IRCBot.E
Type: Trojan Horse
Infection Length: 95,744
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, UNIX, Windows 3.x
When W32.IRCBot.F is executed, it attempts to perform the following actions:
Copies itself as %System%\Securitychk.exe.
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"Microsoft Secure Messenger.NET Service" = "securitychk.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
Deletes the shares from local drives.
Connects to the IRC server tehr8x.spbx.net using TCP port 6667.
Joins a predefined channel, using a random nickname, and waits for commands from the IRC server. These commands can allow the attacker to:
Manage the installation of the Trojan
Control the IRC client on a compromised computer
Update the installed Trojan
Send the Trojan to other IRC channels
Download and execute files
Perform Denial of Service (DoS) attacks against a target, which the hacker defines
Uninstall itself completely by removing the relevant registry entries
Go to Web sites
Copy itself to shared folders on other computers
Steal license keys for games including:
Battlefield 1942
Battlefield 1942: Secret Weapons of WWII
Battlefield 1942: The Road To Rome
Battlefield 1942: Vietnam
Black and White
Command and Conquer: Generals
Command and Conquer: Generals: Zero Hour
Command and Conquer: Red Alert2
Command and Conquer: Tiberian Sun
Counter-Strike
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden and Dangerous 2
IGI2: Covert Strike
Industry Giant 2
James Bond 007: Nightfire
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
NHL 2002
NHL 2003
Need for Speed: Hot Pursuit 2
Need for Speed: Underground
Neverwinter Nights
Ravenshield
Shogun: Total War: Warlord Edition
Soldiers Of Anarchy
Soldier Of Fortune 2
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004
Soldier Of Fortune II - Double Helix
Terminate processes. Refer to the "Additional Information" section for a list of the processes that may be terminated.
Removal Instructions
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.IRCBot.F.
Delete the values that were added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to each of these keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Note: All the keys will not be found on all the systems.
From each key that is found, in the right pane, delete the value:
"Microsoft Secure Messenger.NET Service" = "securitychk.exe"
Exit the Registry Editor.
Restart the computer in normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.ircbot.f.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Backdoor.Balkart
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 11:22:24 AM
Backdoor.Balkart is a backdoor Trojan horse that can act as a HTTP proxy or FTP server.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
When the Trojan is executed, it performs the following tasks:
Copies itself as %Windir%\ÎäÒíÑ.exe.
Notes:
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
The file name is in Arabic. On systems that do not have the Arabic character set installed, it will be displayed as shown above. If the Arabic character set is installed, it may look like this:
Adds the value:
"alkasr" = "%windir%\ÎäÒíÑ.exe"
to the registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the Trojan is executed every time that Windows starts.
Creates a backdoor by opening port 12121/TCP.
Performs a HTTP GET request, providing the attacker with a log of infected machines.
Waits for commands from a remote attacker to do any of the following:
Stop processes
Execute commands
Use the compromised system as an FTP server or SOCKS proxy
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Balkart.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"alkasr" = "%windir%\ÎäÒíÑ.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.balkart.html\"]source[/url]
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 11:22:24 AM
Backdoor.Balkart is a backdoor Trojan horse that can act as a HTTP proxy or FTP server.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
When the Trojan is executed, it performs the following tasks:
Copies itself as %Windir%\ÎäÒíÑ.exe.
Notes:
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
The file name is in Arabic. On systems that do not have the Arabic character set installed, it will be displayed as shown above. If the Arabic character set is installed, it may look like this:
Adds the value:
"alkasr" = "%windir%\ÎäÒíÑ.exe"
to the registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the Trojan is executed every time that Windows starts.
Creates a backdoor by opening port 12121/TCP.
Performs a HTTP GET request, providing the attacker with a log of infected machines.
Waits for commands from a remote attacker to do any of the following:
Stop processes
Execute commands
Use the compromised system as an FTP server or SOCKS proxy
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Balkart.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"alkasr" = "%windir%\ÎäÒíÑ.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.balkart.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Backdoor.Akak
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 11:16:52 AM
Backdoor.Akak is a backdoor server that also creates a SOCKS proxy on the compromised system. Reports indicate that Web sites exploiting the Microsoft Internet Explorer Drag And Drop File Installation Vulnerability may install it.
Also Known As: Backdoor.Win32.BoomRaster.a (KAV)
Type: Trojan Horse
Infection Length: 8704 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Backdoor.Akak is a backdoor server program that may be installed when you visit a malicious Web site using Internet Explorer. These pages may contain code that exploits the Microsoft Internet Explorer Drag And Drop File Installation Vulnerability.
If Backdoor.Akak runs, it will download the file, Testexe.exe or Rb.exe, to the Windows Startup folder.
Following this, when you start Windows, it does the following:
Executes the downloaded file.
Creates the mutex "J&^srl!hsl^AHSgh" so that only one instance of the backdoor is present in memory.
Registers itself as a service so that it continues to run even if you log off.
Copies itself as %System%\rb.exe.
Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the value:
"RamBooster2"="%System%\rb.exe "
in the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs every time that Windows starts.
Issues the command "net stop SharedAccess" to disable the Windows Internet Connection Firewall (ICF), if it is running on the system. (Windows 2000/XP).
Contacts a master server located at 202.104.242.156 on TCP port 4321 and downloads information, which is stored in the file, %System%\lhosts.txt.
If the backdoor cannot create the lhosts.txt file, it will instead store this information in the file, Kaka2.txt, which it creates in the current working folder.
Creates a SOCKS proxy on TCP port 5555. This allows the compromised computer to be used to proxy protocols such as HTTP.
Listens on TCP port 4321 for commands from the remote attacker. The attacker can do any of the following:
Obtain system information
Download and execute files on the compromised computer
Uninstall the back door
Update the address of the master server
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Akak.
Delete the value that was added to the registry.
Re-enable the SharedAccess service (Windows 2000/XP only).
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"RamBooster2" =" %System%\rb.exe"
Exit the Registry Editor.
5. To re-enable the SharedAccess service (Windows 2000/XP only)
The SharedAccess service is responsible for maintaining Internet Connection Sharing and the Windows Firewall/Internet Connection Firewall applications in Windows. (The presence and names of these applications vary depending on the operating system and service pack you are using.) To protect your computer and maintain network functionality, re-enable this service if you are using any of these programs.
Windows XP Service Pack 2
If you are running Windows XP with Service Pack 2 and are using the Windows Firewall, the operating system will alert you when the SharedAccess service is stopped, by displaying an alert balloon saying that your Firewall status is unknown. Perform the following steps to ensure that the Windows Firewall is re-enabled:
Click Start > Control Panel.
Double-click the Security Center.
Ensure that the Firewall security essential is marked ON.
Note: If the Firewall security essential is marked on, your Windows Firewall is on and you do not need to continue with these steps.
If the Firewall security essential is not marked on, click the "Recommendations" button.
Under "Recommendations," click Enable Now. A window appears telling you that the Windows Firewall was successfully turned on.
Click Close > OK.
Close the Security Center.
Windows 2000 or Windows XP Service Pack 1, or earlier
Complete the following steps to re-enable the SharedAccess service:
Click Start > Run.
Type services.msc
Then click OK.
Do one of the following:
Windows 2000: Under the Name column, locate the "Internet Connection Sharing (ICS)" service and double-click it.
Windows XP: Under the Named column, locate the "Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS)" service and double-click it.
Under "Startup Type:", select "Automatic" from the drop-down menu.
Under "Service Status:", click the Start button.
Once the service has completed starting, click OK.
Close the Services window.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.akak.html\"]source[/url]
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 11:16:52 AM
Backdoor.Akak is a backdoor server that also creates a SOCKS proxy on the compromised system. Reports indicate that Web sites exploiting the Microsoft Internet Explorer Drag And Drop File Installation Vulnerability may install it.
Also Known As: Backdoor.Win32.BoomRaster.a (KAV)
Type: Trojan Horse
Infection Length: 8704 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Backdoor.Akak is a backdoor server program that may be installed when you visit a malicious Web site using Internet Explorer. These pages may contain code that exploits the Microsoft Internet Explorer Drag And Drop File Installation Vulnerability.
If Backdoor.Akak runs, it will download the file, Testexe.exe or Rb.exe, to the Windows Startup folder.
Following this, when you start Windows, it does the following:
Executes the downloaded file.
Creates the mutex "J&^srl!hsl^AHSgh" so that only one instance of the backdoor is present in memory.
Registers itself as a service so that it continues to run even if you log off.
Copies itself as %System%\rb.exe.
Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the value:
"RamBooster2"="%System%\rb.exe "
in the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs every time that Windows starts.
Issues the command "net stop SharedAccess" to disable the Windows Internet Connection Firewall (ICF), if it is running on the system. (Windows 2000/XP).
Contacts a master server located at 202.104.242.156 on TCP port 4321 and downloads information, which is stored in the file, %System%\lhosts.txt.
If the backdoor cannot create the lhosts.txt file, it will instead store this information in the file, Kaka2.txt, which it creates in the current working folder.
Creates a SOCKS proxy on TCP port 5555. This allows the compromised computer to be used to proxy protocols such as HTTP.
Listens on TCP port 4321 for commands from the remote attacker. The attacker can do any of the following:
Obtain system information
Download and execute files on the compromised computer
Uninstall the back door
Update the address of the master server
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Akak.
Delete the value that was added to the registry.
Re-enable the SharedAccess service (Windows 2000/XP only).
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"RamBooster2" =" %System%\rb.exe"
Exit the Registry Editor.
5. To re-enable the SharedAccess service (Windows 2000/XP only)
The SharedAccess service is responsible for maintaining Internet Connection Sharing and the Windows Firewall/Internet Connection Firewall applications in Windows. (The presence and names of these applications vary depending on the operating system and service pack you are using.) To protect your computer and maintain network functionality, re-enable this service if you are using any of these programs.
Windows XP Service Pack 2
If you are running Windows XP with Service Pack 2 and are using the Windows Firewall, the operating system will alert you when the SharedAccess service is stopped, by displaying an alert balloon saying that your Firewall status is unknown. Perform the following steps to ensure that the Windows Firewall is re-enabled:
Click Start > Control Panel.
Double-click the Security Center.
Ensure that the Firewall security essential is marked ON.
Note: If the Firewall security essential is marked on, your Windows Firewall is on and you do not need to continue with these steps.
If the Firewall security essential is not marked on, click the "Recommendations" button.
Under "Recommendations," click Enable Now. A window appears telling you that the Windows Firewall was successfully turned on.
Click Close > OK.
Close the Security Center.
Windows 2000 or Windows XP Service Pack 1, or earlier
Complete the following steps to re-enable the SharedAccess service:
Click Start > Run.
Type services.msc
Then click OK.
Do one of the following:
Windows 2000: Under the Name column, locate the "Internet Connection Sharing (ICS)" service and double-click it.
Windows XP: Under the Named column, locate the "Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS)" service and double-click it.
Under "Startup Type:", select "Automatic" from the drop-down menu.
Under "Service Status:", click the Start button.
Once the service has completed starting, click OK.
Close the Services window.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.akak.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
PWSteal.Tarno.I
Discovered on: September 01, 2004
Last Updated on: September 02, 2004 12:58:40 PM
PWSteal.Tarno.I is a Trojan horse that attempts to steal user names and passwords for certain Internet banking sites, by capturing screenshots and logging keystrokes.
Also Known As: Troj/Tofger-BG [Sophos]
Type: Trojan Horse
Infection Length: 179,200 Bytes, 11,004 Bytes, 6,000 Bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x
When PWSteal.Tarno.I is executed, it performs the following actions:
Creates the following files:
%Windir%\Vhchost.exe: Detected as PWSteal.Tarno.I
%Windir%\Scrnr32.dll: Detected as PWSteal.Tarno.I
%System%\Winrr.exe: Non-malicious utility file that PWSteal.Tarno.I uses to create RAR file.
Notes:
%System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).
Adds the value:
"Default System Research" = "%Windir%\vhchost.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
Monitors the URL field in Internet Explorer for the following strings:
e-gold
bank
hsbc
halifax
barclays
openplan
lloyds
abbey
cahoot
nationwide
nwolb
natwest
nationet
woolwich
Stores keystrokes and the content of the clipboard (the buffer for copy and paste) in the file, %System%\Usert\<10digits>_<8digits>.txt, where the digits are derived from the system time.
Stores screenshots in the file, %System%\Usert\<10digits>_<8digits>.bmp, where these digits are derived from the system time.
Using %System%\Winrr.exe, which it previously created, the Trojan creates the RAR file, %System%\Usert, which contains the keystrokes and screeenshots.
Attempts to send the RAR file to a remote Web server.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as PWSteal.Tarno.I.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Default System Research" = "%Windir%\vhchost.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.tarno.i.html\"]source[/url]
Discovered on: September 01, 2004
Last Updated on: September 02, 2004 12:58:40 PM
PWSteal.Tarno.I is a Trojan horse that attempts to steal user names and passwords for certain Internet banking sites, by capturing screenshots and logging keystrokes.
Also Known As: Troj/Tofger-BG [Sophos]
Type: Trojan Horse
Infection Length: 179,200 Bytes, 11,004 Bytes, 6,000 Bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x
When PWSteal.Tarno.I is executed, it performs the following actions:
Creates the following files:
%Windir%\Vhchost.exe: Detected as PWSteal.Tarno.I
%Windir%\Scrnr32.dll: Detected as PWSteal.Tarno.I
%System%\Winrr.exe: Non-malicious utility file that PWSteal.Tarno.I uses to create RAR file.
Notes:
%System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).
Adds the value:
"Default System Research" = "%Windir%\vhchost.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
Monitors the URL field in Internet Explorer for the following strings:
e-gold
bank
hsbc
halifax
barclays
openplan
lloyds
abbey
cahoot
nationwide
nwolb
natwest
nationet
woolwich
Stores keystrokes and the content of the clipboard (the buffer for copy and paste) in the file, %System%\Usert\<10digits>_<8digits>.txt, where the digits are derived from the system time.
Stores screenshots in the file, %System%\Usert\<10digits>_<8digits>.bmp, where these digits are derived from the system time.
Using %System%\Winrr.exe, which it previously created, the Trojan creates the RAR file, %System%\Usert, which contains the keystrokes and screeenshots.
Attempts to send the RAR file to a remote Web server.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as PWSteal.Tarno.I.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Default System Research" = "%Windir%\vhchost.exe"
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.tarno.i.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Remadmin
Discovered on: September 02, 2004
Last Updated on: September 04, 2004 12:31:07 PM
W32.Remadmin is a worm that attempts to propagate through network shares.
Also Known As: WORM_REMADM.A [Trend]
Type: Worm
Infection Length: 842,304 bytes
Systems Affected: Windows 2000, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: Linux, Macintosh, UNIX
W32.Remadmin is composed of batch files, hacktools, and legitimate administration tools.
When the worm is executed, it does the following:
Extracts the following files:
AdmDll.dll: A .dll component of Remacc.Radmin.
icon.reg *: A registry file.
Kcah.cmd: A batch file that copies utili.dll to <ip address>\ADMIN$\SYSTEM32 and attempts to stop certain processes.
Msdos.exe: An .exe file that is detected as Remacc.Radmin.
Msxml3b.dll *: A clean text file with a list of I.D.'s
Msxml4b.dll *: A clean text file with a list of passwords.
Naer.cmd: A batch file that calls Kcah.cmd with a specified ip address (excluding 192.168.0.x and 127.0.0.x).
Psexec.exe *: A Sysinternals remote execution tool.
Raddrv.dll: A .dll component of Remacc.Radmin.
Regedit4.exe *: A registry editor.
Rs.cmd *: A batch file that calls msdos.exe.
Run.bat: A starting batch file for the Worm.
Secfind.exe: A hacktool used to search for IPC$ shares.
Secscan.exe: A .exe file that is detected as Hacktool.RunService.
Star.cmd: A batch file that calls Kcah.cmd with random ip address.
Unrar.exe : A rar archive containing:
i.cmd *: A starting batch file that stops/removes netsvc.exe and overwrites files but does not seem viral.
instsrv.exe *: A service installer.
Regedit4.exe *: A registry editor.
Rep.exe *: Replace Commander - a non-malicious program used to replace specific strings in a file.
S.bin *: A clean file used to overwrite.
V.bin *: A clean file used to overwrite.
W.exe *: A clean file used to overwrite.
NOTE: Files that marked with an asterisk ( * ) are either commercial utilities or are clean files. As such, Symantec antivirus products do not detect them.
Creates the registry key:
HKEY_LOCAL_MACHINE\System\RAdmin
Executes Run.bat which:
Copies Rar.exe to Utili.dll
Enable these network shares:
IPC$
ADMIN$
C$=C:\
Executes Star.cmd which executes Naer.cmd, Kcah.cmd, and Secfind.exe with a randomly-generated ip number
Executes Secfind.exe with a range of ip address to search for IPC$ shares.
Executes Kcah.cmd and Naer.cmd and copies Utili.dll into <victim's ip address>\ADMIN$\SYSTEM32\Rar.exe and stops certain processes.
Executes Rar.exe.
Executes Unrar.exe to stop Netsvc.exe and overwrite the following files.
Copies v.bin to %SystemRoot%\.{21EC2020-3AEA-1069-A2DD-08002B-30309D}\netsvc.exe
Copies w.exe to %SystemRoot%\.{21EC2020-3AEA-1069-A2DD-08002B-30309D}\netsvc.ini
Copies s.bin to %SystemRoot%\System32\netsvc.exe
Removal Instructions:
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Remadmin.
Delete the values that were added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the following key:
HKEY_LOCAL_MACHINE\System
In the left pane, delete the key:
"RAdmin"
Exit the Registry Editor.
Restart the computer in normal mode.
Additional information:
Some of the processes that the Worm may terminate are:
DefWatch
Symantec AntiVirus Client
NSCTOP
Symantec Core LC
SAVScan
SAVFMSE
ccEvtMgr
navapsvc
ccSetMgr
VisNetic AntiVirus Plug-in
McShield
AlertManger
McAfeeFramework
AVExch32Service
AVUPDService
McTaskManager
Network Associates Log Service
Outbreak Manager
MCVSRte
mcupdmgr.exe
AvgServ
AvgCore
AvgFsh
awhost32
Ahnlab task Scheduler
MonSvcNT
V3MonNT
V3MonSvc
FSDFWD
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.remadmin.html\"]source[/url]
Discovered on: September 02, 2004
Last Updated on: September 04, 2004 12:31:07 PM
W32.Remadmin is a worm that attempts to propagate through network shares.
Also Known As: WORM_REMADM.A [Trend]
Type: Worm
Infection Length: 842,304 bytes
Systems Affected: Windows 2000, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: Linux, Macintosh, UNIX
W32.Remadmin is composed of batch files, hacktools, and legitimate administration tools.
When the worm is executed, it does the following:
Extracts the following files:
AdmDll.dll: A .dll component of Remacc.Radmin.
icon.reg *: A registry file.
Kcah.cmd: A batch file that copies utili.dll to <ip address>\ADMIN$\SYSTEM32 and attempts to stop certain processes.
Msdos.exe: An .exe file that is detected as Remacc.Radmin.
Msxml3b.dll *: A clean text file with a list of I.D.'s
Msxml4b.dll *: A clean text file with a list of passwords.
Naer.cmd: A batch file that calls Kcah.cmd with a specified ip address (excluding 192.168.0.x and 127.0.0.x).
Psexec.exe *: A Sysinternals remote execution tool.
Raddrv.dll: A .dll component of Remacc.Radmin.
Regedit4.exe *: A registry editor.
Rs.cmd *: A batch file that calls msdos.exe.
Run.bat: A starting batch file for the Worm.
Secfind.exe: A hacktool used to search for IPC$ shares.
Secscan.exe: A .exe file that is detected as Hacktool.RunService.
Star.cmd: A batch file that calls Kcah.cmd with random ip address.
Unrar.exe : A rar archive containing:
i.cmd *: A starting batch file that stops/removes netsvc.exe and overwrites files but does not seem viral.
instsrv.exe *: A service installer.
Regedit4.exe *: A registry editor.
Rep.exe *: Replace Commander - a non-malicious program used to replace specific strings in a file.
S.bin *: A clean file used to overwrite.
V.bin *: A clean file used to overwrite.
W.exe *: A clean file used to overwrite.
NOTE: Files that marked with an asterisk ( * ) are either commercial utilities or are clean files. As such, Symantec antivirus products do not detect them.
Creates the registry key:
HKEY_LOCAL_MACHINE\System\RAdmin
Executes Run.bat which:
Copies Rar.exe to Utili.dll
Enable these network shares:
IPC$
ADMIN$
C$=C:\
Executes Star.cmd which executes Naer.cmd, Kcah.cmd, and Secfind.exe with a randomly-generated ip number
Executes Secfind.exe with a range of ip address to search for IPC$ shares.
Executes Kcah.cmd and Naer.cmd and copies Utili.dll into <victim's ip address>\ADMIN$\SYSTEM32\Rar.exe and stops certain processes.
Executes Rar.exe.
Executes Unrar.exe to stop Netsvc.exe and overwrite the following files.
Copies v.bin to %SystemRoot%\.{21EC2020-3AEA-1069-A2DD-08002B-30309D}\netsvc.exe
Copies w.exe to %SystemRoot%\.{21EC2020-3AEA-1069-A2DD-08002B-30309D}\netsvc.ini
Copies s.bin to %SystemRoot%\System32\netsvc.exe
Removal Instructions:
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Remadmin.
Delete the values that were added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the following key:
HKEY_LOCAL_MACHINE\System
In the left pane, delete the key:
"RAdmin"
Exit the Registry Editor.
Restart the computer in normal mode.
Additional information:
Some of the processes that the Worm may terminate are:
DefWatch
Symantec AntiVirus Client
NSCTOP
Symantec Core LC
SAVScan
SAVFMSE
ccEvtMgr
navapsvc
ccSetMgr
VisNetic AntiVirus Plug-in
McShield
AlertManger
McAfeeFramework
AVExch32Service
AVUPDService
McTaskManager
Network Associates Log Service
Outbreak Manager
MCVSRte
mcupdmgr.exe
AvgServ
AvgCore
AvgFsh
awhost32
Ahnlab task Scheduler
MonSvcNT
V3MonNT
V3MonSvc
FSDFWD
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.remadmin.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Bugbear.M@mm
Discovered on: September 03, 2004
Last Updated on: September 04, 2004 12:43:28 PM
W32.Bugbear.M@mm is a mass-mailing worm that sends itself to email addresses it gathers from certain files on the system, using its own SMTP engine.
Variants: W32.Bugbear@mm
Type: Virus, Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX
Technical Details:
When W32.Bugbear.M@mm runs, it does the following:
Creates the following files:
%System%\<random filename>.nls
%System%\<random filename>.dat
%System%\<random filename>.tmp
%System%\<random filename>.dll
%System%\<random filename>.exe
Attempts to add the value:
"<random value>" = "%System%\<random filename>.exe"
in the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Attempts to append its code to the following files in the %Windir% folder and %ProgramFiles% folder:
scandskw.exe
regedit.exe
mplayer.exe
hh.exe
notepad.exe
winhelp.exe
Internet Explorer\iexplore.exe
adobe\acrobat 7.0\reader\acrord32.exe
WinRAR\WinRAR.exe
Windows Media Player\mplayer2.exe
Real\RealPlayer\realplay.exe
Outlook Express\msimn.exe
Far\Far.exe
CuteFTP\cutftp32.exe
Adobe\Acrobat 6.0\Reader\AcroRd32.exe
Adobe\Acrobat 5.0\Reader\AcroRd32.exe
Adobe\Acrobat 4.0\Reader\AcroRd32.exe
ACDSee32\ACDSee32.exe
MSN Messenger\msnmsgr.exe
WS_FTP\WS_FTP95.exe
QuickTime\QuickTimePlayer.exe
StreamCast\Morpheus\Morpheus.exe
Zone Labs\ZoneAlarm\ZoneAlarm.exe
Trillian\Trillian.exe
Lavasoft\Ad-aware 6\Ad-aware.exe
AIM95\aim.exe
Winamp\winamp.exe
DAP\DAP.exe
ICQ\Icq.exe
kazaa\kazaa.exe
winzip\winzip32.exe
The worm is a polymorphic file infector.
Note:
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
%ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.
Scans all hard disks for files with file paths containing any of the following strings:
BEAR
DONKEY
DOWNLOAD
FTP
HTDOCS
HTTP
MORPHEUS
ICQ
KAZAA
LIME
MULE
INCOMING
SHAR
UPLOAD
If a file within these folders contains files with an .exe extension, the worm will attempt to infect those files.
Otherwise, it will copy itself as <original filename.ext>.exe (where .ext is the original file's extension).
Gathers email address from files whose filename contains any of the following strings:
.dbx
.tbb
.eml
.mbx
.nch
.mmf
Inbox
.ods
.htm
.asp
.txt
.sht
Uses its own SMTP engine to email itself to the email addresses that it collects.
The email has the following characteristics:
Subject: Starts with "Re: "
Attachment:
The worm searches for a specific folder by querying the following registry value:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell\Folders\Personal
Once the worm locates the name of the folder, it looks for a file that does not have a .INI, .ini, .rdp extentions. The worm uses the filename and then changes the file extension to .jpg and uses it as an attachment of the email.
Otherwise, the attachment may be one of the following:
a000032.jpg.scr
song.wav.scr
music.mp3.scr
video.avi.scr
photo.jpg.scr
pic.jpg.scr
message.txt.scr
image.jpg.scr
news.doc.scr
myphoto.jpg.scr
you.jpg.scr
love.jpg.scr
readme.txt.scr
Locates the following information from the infected computer and sends it to the attacker:
Cookies
Clipboard contents
Logged keystrokes
Text from open windows
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan, delete or repair all the files detected as W32.Bugbear.M@mm.
Reverse the changes made to the registry.
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
In the right pane, delete the value:
"<random value>" = "%System%\<random filename>.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbear.m@mm.html\"]source[/url]
Discovered on: September 03, 2004
Last Updated on: September 04, 2004 12:43:28 PM
W32.Bugbear.M@mm is a mass-mailing worm that sends itself to email addresses it gathers from certain files on the system, using its own SMTP engine.
Variants: W32.Bugbear@mm
Type: Virus, Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX
Technical Details:
When W32.Bugbear.M@mm runs, it does the following:
Creates the following files:
%System%\<random filename>.nls
%System%\<random filename>.dat
%System%\<random filename>.tmp
%System%\<random filename>.dll
%System%\<random filename>.exe
Attempts to add the value:
"<random value>" = "%System%\<random filename>.exe"
in the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Attempts to append its code to the following files in the %Windir% folder and %ProgramFiles% folder:
scandskw.exe
regedit.exe
mplayer.exe
hh.exe
notepad.exe
winhelp.exe
Internet Explorer\iexplore.exe
adobe\acrobat 7.0\reader\acrord32.exe
WinRAR\WinRAR.exe
Windows Media Player\mplayer2.exe
Real\RealPlayer\realplay.exe
Outlook Express\msimn.exe
Far\Far.exe
CuteFTP\cutftp32.exe
Adobe\Acrobat 6.0\Reader\AcroRd32.exe
Adobe\Acrobat 5.0\Reader\AcroRd32.exe
Adobe\Acrobat 4.0\Reader\AcroRd32.exe
ACDSee32\ACDSee32.exe
MSN Messenger\msnmsgr.exe
WS_FTP\WS_FTP95.exe
QuickTime\QuickTimePlayer.exe
StreamCast\Morpheus\Morpheus.exe
Zone Labs\ZoneAlarm\ZoneAlarm.exe
Trillian\Trillian.exe
Lavasoft\Ad-aware 6\Ad-aware.exe
AIM95\aim.exe
Winamp\winamp.exe
DAP\DAP.exe
ICQ\Icq.exe
kazaa\kazaa.exe
winzip\winzip32.exe
The worm is a polymorphic file infector.
Note:
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
%ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.
Scans all hard disks for files with file paths containing any of the following strings:
BEAR
DONKEY
DOWNLOAD
FTP
HTDOCS
HTTP
MORPHEUS
ICQ
KAZAA
LIME
MULE
INCOMING
SHAR
UPLOAD
If a file within these folders contains files with an .exe extension, the worm will attempt to infect those files.
Otherwise, it will copy itself as <original filename.ext>.exe (where .ext is the original file's extension).
Gathers email address from files whose filename contains any of the following strings:
.dbx
.tbb
.eml
.mbx
.nch
.mmf
Inbox
.ods
.htm
.asp
.txt
.sht
Uses its own SMTP engine to email itself to the email addresses that it collects.
The email has the following characteristics:
Subject: Starts with "Re: "
Attachment:
The worm searches for a specific folder by querying the following registry value:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell\Folders\Personal
Once the worm locates the name of the folder, it looks for a file that does not have a .INI, .ini, .rdp extentions. The worm uses the filename and then changes the file extension to .jpg and uses it as an attachment of the email.
Otherwise, the attachment may be one of the following:
a000032.jpg.scr
song.wav.scr
music.mp3.scr
video.avi.scr
photo.jpg.scr
pic.jpg.scr
message.txt.scr
image.jpg.scr
news.doc.scr
myphoto.jpg.scr
you.jpg.scr
love.jpg.scr
readme.txt.scr
Locates the following information from the infected computer and sends it to the attacker:
Cookies
Clipboard contents
Logged keystrokes
Text from open windows
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan, delete or repair all the files detected as W32.Bugbear.M@mm.
Reverse the changes made to the registry.
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
In the right pane, delete the value:
"<random value>" = "%System%\<random filename>.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbear.m@mm.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Mydoom.R@mm
Discovered on: September 03, 2004
Last Updated on: September 04, 2004 02:43:54 PM
W32.Mydoom.R@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses that it finds on an infected computer. The email contains a spoofed From address. The subject and message body vary, and the attachment has a .bat, .cmd, .exe, .pif, .scr, or .zip extension.
This threat is packed using UPX.
Also Known As: W32/Mydoom.t@MM [McAfee], WORM_MYDOOM.T [Trend], MyDoom.T [F-Secure]
Variants: W32.Mydoom.P@mm
Type: Worm
Infection Length: 37,888 bytes, 8,192 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When W32.Mydoom.R@mm is executed, it does the following:
Copies itself as %System%\tasker.exe.
Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the file %System%\Nemog.dll(8,192 bytes), which is a component of W32.Mydoom.R@mm.
Creates the file, %Temp%\Message, and then opens it with Notepad.
Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
Creates a mutex, "EnD-Of-SkyNet", which allows only one instance of the worm to run in memory.
Adds the value:
"Task"="%System%\tasker.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Adds the value:
"(Default)"="%System%\Nemog.dll"
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32
Creates the following registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version
May also attempt to open a back door on port 5422 and allow a remote attacker to have unauthorized access to the infected system. This would allow a remote attacker to download and execute remote files.
Copies itself to Kazaa shared folders using one of the following file names:
cleaner
crack
Fixtool
Hotmail hacker
mydoom
netsky
ps2 emulator
SoBig
Upload
Vahos
Viraus
Wenrar
Winzip
xbox emulator
XXX Pictures
XXX Videos
yahoo hacker
Retrieves the email addresses from the files that have the following extensions on drives C through Y:
.adbh
.aspd
.dbxn
.htmb
.phpq
.pl
.shtl
.tbbg
.wab
Retrieves the email addresses from the Windows Address Book files.
Guesses the name of the SMTP server by prepending the following names to the domain names gathered from the local system:
gate.
mail.
mail1.
msx.
mx.
mx1.
ns.
relay.
smtp.
Gathers email addresses form the local system. It also derives email addresses by prepending the following strings to the domain names gathered from the system:
alice
andrew
brenda
brent
brian
claudia
david
debby
george
helen
james
jerry
jimmy
julie
kevin
linda
maria
michael
peter
robert
sandra
smith
steve
Sends itself to the email addresses that it finds.
The email has the following characteristics:
From:
The From address is spoofed.
Subject: The subject may be one of the following:
<Garbage string>
<none>
document
Error
hello
hi
Information
Mail Delivery System
Mail Transaction Failed
message
RE:my .....
RE:test
readme
Server Report
Status
test
Message: The message may be one of the following:
!!!!!!!!!!!, check the attachment!!!.
(Norton Anti Virus : No Virusses Found , Check The Attachment For More Information.
(Norton ANti Virus,Panda,Mcafee No Virusses Found).
Check the attachment for more information!.
check the attachment to get the lastest news.
check.
come back my friend.
error , sorry we can't send the email so check the attachment.
error to send the mail!!!!!.
error, check the attachment for more information.
failed to send the email!, check the attachment for more information.
failed,check the attachment for more information.
hello
/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
hello check the attachment thx.
hello.
here is what you need,thx.
loooooool
/bigwink.gif\' class=\'bbc_emoticon\' alt=\';)\' />))
Mail transaction failed. Partial message is available.
sorry we can't send the mail try later , check the attachment for more information.
the attachment for more information.
Try Later, Check the Attachment.
you can check the attachment for more information.
your attachment , thx.
Attachment: The attachment name may be one of the following:
body
data
doc
document
file
message
readme
test
text
with one or two of the following extensions:
.bat
.com
.doc
.exe
.htm
.scr
.tmp
.txt
It avoids sending itself to the email addresses that contains any of the following:
-._!@
abuse
accoun
acketst
admin
anyone
arin.
be_loyal:
berkeley
borlan
certific
contact
example
feste
gold-certs
google
ibm.com
icrosof
icrosoft
inpris
isc.o
isi.e
kernel
linux
listserv
mit.e
mozilla
mydomai
nobody
nodomai
noone
nothing
ntivi
panda
postmaster
privacy
rating
rfc-ed
ripe.
ruslis
samples
secur
sendmail
service
somebody
someone
sopho
submit
support
tanford.e
the.bat
usenet
utgers.ed
webmaster
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Mydoom.R@mm.
Reverse the changes made to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Task"="%System%\tasker.exe"
Navigate to the key:
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32
In the right pane, delete the value:
"(Default)"="%System%\Nemog.dll"
Navigate to and delete the keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.r@mm.html\"]source[/url]
Discovered on: September 03, 2004
Last Updated on: September 04, 2004 02:43:54 PM
W32.Mydoom.R@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses that it finds on an infected computer. The email contains a spoofed From address. The subject and message body vary, and the attachment has a .bat, .cmd, .exe, .pif, .scr, or .zip extension.
This threat is packed using UPX.
Also Known As: W32/Mydoom.t@MM [McAfee], WORM_MYDOOM.T [Trend], MyDoom.T [F-Secure]
Variants: W32.Mydoom.P@mm
Type: Worm
Infection Length: 37,888 bytes, 8,192 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When W32.Mydoom.R@mm is executed, it does the following:
Copies itself as %System%\tasker.exe.
Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the file %System%\Nemog.dll(8,192 bytes), which is a component of W32.Mydoom.R@mm.
Creates the file, %Temp%\Message, and then opens it with Notepad.
Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
Creates a mutex, "EnD-Of-SkyNet", which allows only one instance of the worm to run in memory.
Adds the value:
"Task"="%System%\tasker.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Adds the value:
"(Default)"="%System%\Nemog.dll"
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32
Creates the following registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version
May also attempt to open a back door on port 5422 and allow a remote attacker to have unauthorized access to the infected system. This would allow a remote attacker to download and execute remote files.
Copies itself to Kazaa shared folders using one of the following file names:
cleaner
crack
Fixtool
Hotmail hacker
mydoom
netsky
ps2 emulator
SoBig
Upload
Vahos
Viraus
Wenrar
Winzip
xbox emulator
XXX Pictures
XXX Videos
yahoo hacker
Retrieves the email addresses from the files that have the following extensions on drives C through Y:
.adbh
.aspd
.dbxn
.htmb
.phpq
.pl
.shtl
.tbbg
.wab
Retrieves the email addresses from the Windows Address Book files.
Guesses the name of the SMTP server by prepending the following names to the domain names gathered from the local system:
gate.
mail.
mail1.
msx.
mx.
mx1.
ns.
relay.
smtp.
Gathers email addresses form the local system. It also derives email addresses by prepending the following strings to the domain names gathered from the system:
alice
andrew
brenda
brent
brian
claudia
david
debby
george
helen
james
jerry
jimmy
julie
kevin
linda
maria
michael
peter
robert
sandra
smith
steve
Sends itself to the email addresses that it finds.
The email has the following characteristics:
From:
The From address is spoofed.
Subject: The subject may be one of the following:
<Garbage string>
<none>
document
Error
hello
hi
Information
Mail Delivery System
Mail Transaction Failed
message
RE:my .....
RE:test
readme
Server Report
Status
test
Message: The message may be one of the following:
!!!!!!!!!!!, check the attachment!!!.
(Norton Anti Virus : No Virusses Found , Check The Attachment For More Information.
(Norton ANti Virus,Panda,Mcafee No Virusses Found).
Check the attachment for more information!.
check the attachment to get the lastest news.
check.
come back my friend.
error , sorry we can't send the email so check the attachment.
error to send the mail!!!!!.
error, check the attachment for more information.
failed to send the email!, check the attachment for more information.
failed,check the attachment for more information.
hello
hello check the attachment thx.
hello.
here is what you need,thx.
loooooool
Mail transaction failed. Partial message is available.
sorry we can't send the mail try later , check the attachment for more information.
the attachment for more information.
Try Later, Check the Attachment.
you can check the attachment for more information.
your attachment , thx.
Attachment: The attachment name may be one of the following:
body
data
doc
document
file
message
readme
test
text
with one or two of the following extensions:
.bat
.com
.doc
.exe
.htm
.scr
.tmp
.txt
It avoids sending itself to the email addresses that contains any of the following:
-._!@
abuse
accoun
acketst
admin
anyone
arin.
be_loyal:
berkeley
borlan
certific
contact
example
feste
gold-certs
ibm.com
icrosof
icrosoft
inpris
isc.o
isi.e
kernel
linux
listserv
mit.e
mozilla
mydomai
nobody
nodomai
noone
nothing
ntivi
panda
postmaster
privacy
rating
rfc-ed
ripe.
ruslis
samples
secur
sendmail
service
somebody
someone
sopho
submit
support
tanford.e
the.bat
usenet
utgers.ed
webmaster
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Mydoom.R@mm.
Reverse the changes made to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Task"="%System%\tasker.exe"
Navigate to the key:
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32
In the right pane, delete the value:
"(Default)"="%System%\Nemog.dll"
Navigate to and delete the keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.r@mm.html\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
A virus has been identified by Sophos anti-virus experts which attempts to talk to end users over their speakers. The worm, known as W32/Amus-A, spreads via e-mail using subject lines such as "Listen and Smile". If users launch the attached file the worm will attempt to spread, and also tries to use the Microsoft Speech engine to read out a greeting as follows:
"hamsi. I am seeing you. Haaaaaaaa. You must come to turkiye. I am cleaning your computer. 5. 4. 3. 2. 1. 0. Gule. Gule."
As well as this the worm changes the users Internet Explorer settings so users see a message in Turkish rather than their usual start page. Graham Cluley, senior technology consultant for Sophos, said the following about the worm:
"It's depressing to see virus writers are active in Turkey. It seems whoever created this worm has complaints about the quality of internet service in his country, but this isn't the proper way to register his opinion. Hopefully if any internet users receive an Amus-infected email they will treat it with suspicion and not launch the attachment."
The worm is not particuarly widespread, nor is it particuarly damaging in its present form. However, users are recommend as always to keep their anti-virus definitions up to date to prevent worms like this from propagating, and to be careful when opening attachments, even if they appear to be from a trusted source.
[url=\"http://itvibe.com/?NewsID=2874\"][Source][/url]
"hamsi. I am seeing you. Haaaaaaaa. You must come to turkiye. I am cleaning your computer. 5. 4. 3. 2. 1. 0. Gule. Gule."
As well as this the worm changes the users Internet Explorer settings so users see a message in Turkish rather than their usual start page. Graham Cluley, senior technology consultant for Sophos, said the following about the worm:
"It's depressing to see virus writers are active in Turkey. It seems whoever created this worm has complaints about the quality of internet service in his country, but this isn't the proper way to register his opinion. Hopefully if any internet users receive an Amus-infected email they will treat it with suspicion and not launch the attachment."
The worm is not particuarly widespread, nor is it particuarly damaging in its present form. However, users are recommend as always to keep their anti-virus definitions up to date to prevent worms like this from propagating, and to be careful when opening attachments, even if they appear to be from a trusted source.
[url=\"http://itvibe.com/?NewsID=2874\"][Source][/url]
-
RuffRyders
- Hero Member

- Posts: 1138
- Joined: Mon Jun 14, 2004 12:47 am
Alerts
[b]New MyDoom draws on IE flaw to spread[/b]
[i]A new version of MyDoom uses an unpatched flaw in Microsoft's Internet Explorer to spread, antivirus companies warned on Monday.[/i]
[size=1]By Robert Lemos[/size]
The recently discovered vulnerability in the browser software allows the offshoot to infect a PC after a user clicks on a link, according to advisories from security software makers Symantec and McAfee. The program sneaks past antivirus applications that detect malicious software by scanning e-mail messages with attached programs.
The companies said they had only detected a few instances of the infector, which is labelled MyDoom.AG by McAfee and MyDoom.AH by Symantec.
"We have only received one submission from the field, but the technical aspects of this are concerning," said Craig Schmugar, senior virus research manager at McAfee. "It has all the components there to become a significant virus."
It's not the first time a code writer has exploited a flaw in a Microsoft product before the software giant has had a chance to plug the hole. An aggressive advertiser attempted to [url=\"http://news.com.com/Pop-up+toolbar+spreads+via+IE+flaws/2100-1002_3-5229707.html?tag=nl\"]surreptitiously install[/url] a pop-up toolbar in victim's Web browsers using two previously unpatched security flaws in Internet Explorer.
Microsoft said that it was investigating the flaw and was aware of a new virus exploiting the issue.
"As a best practice, users should always exercise extreme caution when opening unsolicited attachments from both known and unknown sources," said Microsoft in a statement sent to CNET News.com. "In addition, we continue to encourage customers follow our 'Protect Your PC' guidance of enabling a firewall, getting software updates and installing antivirus software."
The latest MyDoom virus appears as an e-mail in an inbox. The body of the message states: "Look at my homepage with my last webcam photos!" or "FREE ADULT VIDEO! SIGN UP NOW!" Both messages have text that links them to a Web page generated by the virus and hosted on the infected computer that sent the e-mail.
When the victim clicks on the link, a Windows-based PC will call Internet Explorer and load a malicious Web page from the previously infected computer. The page contains the [url=\"http://news.com.com/Exploit+code+makes+IE+flaw+more+dangerous/2100-1002_3-5439370.html?tag=nl\"]IFrame vulnerability recently publicized[/url] on security mailing lists. The virus uses the flaw to execute code on the victim's computer, infecting the system. The virus harvests e-mail addresses on the compromised system, sends out mail to spread the virus further, sets up a Web server and attempts to contact several Internet relay chat (IRC) servers as a way to notify the virus's creator of that a new system has been compromised.
The fact that the virus creates a Web server and uses that server to infect other systems is a significant departure from previous versions of MyDoom, and other viruses in general, Schmugar said.
"There was a decent amount of work that went into this," he said. "There was a good bit of attention (among security researchers) to the demo code (of this flaw). Someone grabbed the demo code and tweaked it quite a bit."
McAfee rates the program a low threat, but Schmugar said he thinks it might spread widely.
[url=\"http://news.com.com/New+MyDoom+draws+on+IE+flaw+to+spread/2100-7349_3-5443828.html?tag=nefd.top\"][Source][/url]
[i]A new version of MyDoom uses an unpatched flaw in Microsoft's Internet Explorer to spread, antivirus companies warned on Monday.[/i]
[size=1]By Robert Lemos[/size]
The recently discovered vulnerability in the browser software allows the offshoot to infect a PC after a user clicks on a link, according to advisories from security software makers Symantec and McAfee. The program sneaks past antivirus applications that detect malicious software by scanning e-mail messages with attached programs.
The companies said they had only detected a few instances of the infector, which is labelled MyDoom.AG by McAfee and MyDoom.AH by Symantec.
"We have only received one submission from the field, but the technical aspects of this are concerning," said Craig Schmugar, senior virus research manager at McAfee. "It has all the components there to become a significant virus."
It's not the first time a code writer has exploited a flaw in a Microsoft product before the software giant has had a chance to plug the hole. An aggressive advertiser attempted to [url=\"http://news.com.com/Pop-up+toolbar+spreads+via+IE+flaws/2100-1002_3-5229707.html?tag=nl\"]surreptitiously install[/url] a pop-up toolbar in victim's Web browsers using two previously unpatched security flaws in Internet Explorer.
Microsoft said that it was investigating the flaw and was aware of a new virus exploiting the issue.
"As a best practice, users should always exercise extreme caution when opening unsolicited attachments from both known and unknown sources," said Microsoft in a statement sent to CNET News.com. "In addition, we continue to encourage customers follow our 'Protect Your PC' guidance of enabling a firewall, getting software updates and installing antivirus software."
The latest MyDoom virus appears as an e-mail in an inbox. The body of the message states: "Look at my homepage with my last webcam photos!" or "FREE ADULT VIDEO! SIGN UP NOW!" Both messages have text that links them to a Web page generated by the virus and hosted on the infected computer that sent the e-mail.
When the victim clicks on the link, a Windows-based PC will call Internet Explorer and load a malicious Web page from the previously infected computer. The page contains the [url=\"http://news.com.com/Exploit+code+makes+IE+flaw+more+dangerous/2100-1002_3-5439370.html?tag=nl\"]IFrame vulnerability recently publicized[/url] on security mailing lists. The virus uses the flaw to execute code on the victim's computer, infecting the system. The virus harvests e-mail addresses on the compromised system, sends out mail to spread the virus further, sets up a Web server and attempts to contact several Internet relay chat (IRC) servers as a way to notify the virus's creator of that a new system has been compromised.
The fact that the virus creates a Web server and uses that server to infect other systems is a significant departure from previous versions of MyDoom, and other viruses in general, Schmugar said.
"There was a decent amount of work that went into this," he said. "There was a good bit of attention (among security researchers) to the demo code (of this flaw). Someone grabbed the demo code and tweaked it quite a bit."
McAfee rates the program a low threat, but Schmugar said he thinks it might spread widely.
[url=\"http://news.com.com/New+MyDoom+draws+on+IE+flaw+to+spread/2100-7349_3-5443828.html?tag=nefd.top\"][Source][/url]
The bruises fade but memories are made.
Alerts
MyDoom worm is back
By JACK KAPICA
Globe and Mail Update
In a development certain to trouble computer security experts, only four days passed between the discovery of a vulnerability in the Internet Explorer browser and the appearance of a worm designed to exploit it.
The virus — in this case, technically a worm — is a variant of the well-known mass-mailing MyDoom infection, with the difference that rather than delivering an attachment, the e-mail just asks recipients to click on a link. The browser is then directed to the infected destination site, where the worm, dubbed Mydoom.ah by McAfee Inc.,
installs itself on the victim's computer.
The worm targets a Microsoft Internet Explorer IFRAME buffer overflow vulnerability, which was discovered and made public by two hackers with aliases "ned" and "SkyLined" on Friday. Only four days later a worm exploiting the weakness was developed and set loose, virus-tracking companies said reported.
The period of time between discovery of a flaw and the appearance of an infection has been shortening recently. Last year, the time difference was, on average, 28 days.
McAfee's Anti-virus and Vulnerability Emergency Response Team (AVERT) raised the risk assessment of MyDoom.ah to medium after receiving close to 100 reports of the virus being stopped or infecting users from the field, from both the virus itself as well as customer submissions. Most of these reports have arrived from the United States.
The new variant is a mass-mailing worm that sends messages with a hyperlink directing people to an infected machine. Following the hyperlink results in an infection occurring on vulnerable Microsoft Internet Explorer Web browsers.
The worm contains its own SMTP engine to construct outgoing messages. It harvests addresses from local files and then uses those addresses in the "From" field to send itself, producing a message with a spoofed return address.
Users should be wary, McAfee warned, and should delete any e-mail with the subject:
"hi!", "hey!", "Confirmation" or just blank. The message body will be one of the following:
"Congratulations! PayPal has successfully charged $175 to your credit card."
"Your order tracking number is A866DEC0, and your item will be shipped within three business days."
"To see details please click this link."
Another variation pretends to be an invitation to a sex site. The text of the message says: "Hi! I am looking for new friends. My name is Jane, I am from Miami, FL. See my homepage with my weblog and last webcam photos! See you!"
McAfee and Symantec, two makers of popular antivirus products, have updated their virus definition files to include MyDoom.ah for subscribers.
Microsoft Corp., which makes the Internet Explorer browser, is expected to issue its monthly batch of security patches later on Tuesday, but it was not immediately clear whether it would include a patch for the new worm.
The company did say that users of Windows XP who had installed Service Pack 2 were at a "reduced risk."
[url=\"http://www.globetechnology.com/servlet/story/RTGAM.20041109.gtdoomnov9/BNStory/Technology/\"]source[/url]
By JACK KAPICA
Globe and Mail Update
In a development certain to trouble computer security experts, only four days passed between the discovery of a vulnerability in the Internet Explorer browser and the appearance of a worm designed to exploit it.
The virus — in this case, technically a worm — is a variant of the well-known mass-mailing MyDoom infection, with the difference that rather than delivering an attachment, the e-mail just asks recipients to click on a link. The browser is then directed to the infected destination site, where the worm, dubbed Mydoom.ah by McAfee Inc.,
installs itself on the victim's computer.
The worm targets a Microsoft Internet Explorer IFRAME buffer overflow vulnerability, which was discovered and made public by two hackers with aliases "ned" and "SkyLined" on Friday. Only four days later a worm exploiting the weakness was developed and set loose, virus-tracking companies said reported.
The period of time between discovery of a flaw and the appearance of an infection has been shortening recently. Last year, the time difference was, on average, 28 days.
McAfee's Anti-virus and Vulnerability Emergency Response Team (AVERT) raised the risk assessment of MyDoom.ah to medium after receiving close to 100 reports of the virus being stopped or infecting users from the field, from both the virus itself as well as customer submissions. Most of these reports have arrived from the United States.
The new variant is a mass-mailing worm that sends messages with a hyperlink directing people to an infected machine. Following the hyperlink results in an infection occurring on vulnerable Microsoft Internet Explorer Web browsers.
The worm contains its own SMTP engine to construct outgoing messages. It harvests addresses from local files and then uses those addresses in the "From" field to send itself, producing a message with a spoofed return address.
Users should be wary, McAfee warned, and should delete any e-mail with the subject:
"hi!", "hey!", "Confirmation" or just blank. The message body will be one of the following:
"Congratulations! PayPal has successfully charged $175 to your credit card."
"Your order tracking number is A866DEC0, and your item will be shipped within three business days."
"To see details please click this link."
Another variation pretends to be an invitation to a sex site. The text of the message says: "Hi! I am looking for new friends. My name is Jane, I am from Miami, FL. See my homepage with my weblog and last webcam photos! See you!"
McAfee and Symantec, two makers of popular antivirus products, have updated their virus definition files to include MyDoom.ah for subscribers.
Microsoft Corp., which makes the Internet Explorer browser, is expected to issue its monthly batch of security patches later on Tuesday, but it was not immediately clear whether it would include a patch for the new worm.
The company did say that users of Windows XP who had installed Service Pack 2 were at a "reduced risk."
[url=\"http://www.globetechnology.com/servlet/story/RTGAM.20041109.gtdoomnov9/BNStory/Technology/\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
New Bropia worm rated "code orange"
SEOUL, Feb. 3 — Korean security specialists at Globeal Hauri are warning of a new variant of the recently discovered Bropia worm, which is more dangerous than its predecessor.
Symptoms include a file, seemingly sent from a "buddy," which is loaded with the virus and infects the PC as soon as it opened. Remote access hijacks the infected PC. Volume differences and right mouse click might indicate the PC user that something is wrong.
Once Bropia infects a system, it resides in the memory and continues spreading through MSN Messenger. Bropia is a member of the Rbot family of worms affecting the Windows platform, which installs a back door on the system and gives an attacker a way of accessing and controlling the infected system remotely. That would allow unauthorized remote access to the infected computer via specific IRC channels while running in the background as a service process.
Another interesting component is that the new Bropia is loaded with a Bot virus component that opens the 1294 port.
The new Bropia copies itself into the system folders and creates one of the following file names: LOL.scr, Webcam.pif, bedroom-thongs.pif, naked_drunk.pif, LMAO.pif, ROFL.pif, underware.pif, Hot.pif or webcam.pif
The infected system folder can vary, depending on each user's configuration, with the most common being C:\Windows\System (Windows 95/98/Me); C:\Winnt\System32 (Windows NT/2000) and C:\Windows\System32 (Windows XP).
The worm can be temporarily disabled bly blocking the 1294 port with any firewall. This is not a "spreading" port but the PC might receive an attack order from this port.
[url=\"http://www.globetechnology.com/servlet/story/RTGAM.20050203.gtbropia0203/BNStory/Technology/\"]source[/url]
SEOUL, Feb. 3 — Korean security specialists at Globeal Hauri are warning of a new variant of the recently discovered Bropia worm, which is more dangerous than its predecessor.
Symptoms include a file, seemingly sent from a "buddy," which is loaded with the virus and infects the PC as soon as it opened. Remote access hijacks the infected PC. Volume differences and right mouse click might indicate the PC user that something is wrong.
Once Bropia infects a system, it resides in the memory and continues spreading through MSN Messenger. Bropia is a member of the Rbot family of worms affecting the Windows platform, which installs a back door on the system and gives an attacker a way of accessing and controlling the infected system remotely. That would allow unauthorized remote access to the infected computer via specific IRC channels while running in the background as a service process.
Another interesting component is that the new Bropia is loaded with a Bot virus component that opens the 1294 port.
The new Bropia copies itself into the system folders and creates one of the following file names: LOL.scr, Webcam.pif, bedroom-thongs.pif, naked_drunk.pif, LMAO.pif, ROFL.pif, underware.pif, Hot.pif or webcam.pif
The infected system folder can vary, depending on each user's configuration, with the most common being C:\Windows\System (Windows 95/98/Me); C:\Winnt\System32 (Windows NT/2000) and C:\Windows\System32 (Windows XP).
The worm can be temporarily disabled bly blocking the 1294 port with any firewall. This is not a "spreading" port but the PC might receive an attack order from this port.
[url=\"http://www.globetechnology.com/servlet/story/RTGAM.20050203.gtbropia0203/BNStory/Technology/\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Is this the same thing that Mess.Be has reported which is spreading through MSN Messenger?
[align=center]

“If you stop learning, you stop living.” ~Tami Quiring
“It's the rare man who understands the value of a single perfect rose.”
[/align]

“If you stop learning, you stop living.” ~Tami Quiring
“It's the rare man who understands the value of a single perfect rose.”
[/align]
Alerts
Trend Micro Inc has released an overview of a worm that is currently doing the rounds infecting users PC's and transferring itself through the MSN Messenger service.
MSN Messenger is under attack of a worm that comes with a seductive name and download link. The user clicks on the link and gets the copy of attached worm for his PC. The worm can spread on the network and shared computers. The worm can disable the Anti-Virus software and then infect the Files in PC, It can also spread easily after it disables anti virus program.
Trend Micro Inc. has also raised the threat level on the W32/Bropia worm. The company said that worm could cause more harm in case it spread more through MSN Messenger buddies and Shared Networks. The virus has antidebugging feature also.
The virus logs keystrokes. It can also retrieve credit card numbers and other sensitive information. The W32/Bropia worm contains a variant of the Rbot backdoor Trojan. The virus could be a higher threat to sensitive information as it can store information. It is also capable of using the infected machine to hijack sensitive data.
[url=\"http://www.neowin.net/comments.php?id=26963&category=main\"][Source][/url]
[b][color=\"darkred\"]-------------------------------------------------------[/b][/color]
As of February 2, 2005, 6:55 PM (Pacific Standard Time/GMT -8:00), TrendLabs has declared a Medium-Risk alert to control the spread of this new WORM_BROPIA variant that is spreading in Korea, China, Taiwan, and the United States.
This memory-resident worm propagates itself via MSN Messenger by sending a copy of itself using different file names to all available or online contacts. Thus, users of the said messaging program should not accept or open these files to avoid infection.
System administrators can also block MSN Messenger transfers to control the spread of this worm.
As a general rule, MSN Messenger users should avoid accepting file transfers coming from an untrusted source.
This worm also drops and executes the file SEXY.JPG in the root folder. This normal .JPG file displays the following [url=\"http://www.trendmicro.com/vinfo/images/WORM_BROPIA_F.gif\"]image.[/url]
It also attempts to drop and execute a bot program, which Trend Micro detects as WORM_AGOBOT.AJC.
Unlike its previous variants, this worm also has an anti-debugging technique. That is, this worm will not run if any of the following debugging applications are currently running on the affected system:
* NT-ice
* Softice
It is also capable of setting the affected system's volume levels to zero, which may be used to prevent users from hearing any sound prompts, especially those that may be coming from antivirus and security applications.
[url=\"http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BROPIA.F\"][Source][/url]
[color=\"red\"][url=\"http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FBROPIA%2EF&VSect=Sn\"]REMOVAL INSTRUCTIONS[/url][/color]
MSN Messenger is under attack of a worm that comes with a seductive name and download link. The user clicks on the link and gets the copy of attached worm for his PC. The worm can spread on the network and shared computers. The worm can disable the Anti-Virus software and then infect the Files in PC, It can also spread easily after it disables anti virus program.
Trend Micro Inc. has also raised the threat level on the W32/Bropia worm. The company said that worm could cause more harm in case it spread more through MSN Messenger buddies and Shared Networks. The virus has antidebugging feature also.
The virus logs keystrokes. It can also retrieve credit card numbers and other sensitive information. The W32/Bropia worm contains a variant of the Rbot backdoor Trojan. The virus could be a higher threat to sensitive information as it can store information. It is also capable of using the infected machine to hijack sensitive data.
[url=\"http://www.neowin.net/comments.php?id=26963&category=main\"][Source][/url]
[b][color=\"darkred\"]-------------------------------------------------------[/b][/color]
As of February 2, 2005, 6:55 PM (Pacific Standard Time/GMT -8:00), TrendLabs has declared a Medium-Risk alert to control the spread of this new WORM_BROPIA variant that is spreading in Korea, China, Taiwan, and the United States.
This memory-resident worm propagates itself via MSN Messenger by sending a copy of itself using different file names to all available or online contacts. Thus, users of the said messaging program should not accept or open these files to avoid infection.
System administrators can also block MSN Messenger transfers to control the spread of this worm.
As a general rule, MSN Messenger users should avoid accepting file transfers coming from an untrusted source.
This worm also drops and executes the file SEXY.JPG in the root folder. This normal .JPG file displays the following [url=\"http://www.trendmicro.com/vinfo/images/WORM_BROPIA_F.gif\"]image.[/url]
It also attempts to drop and execute a bot program, which Trend Micro detects as WORM_AGOBOT.AJC.
Unlike its previous variants, this worm also has an anti-debugging technique. That is, this worm will not run if any of the following debugging applications are currently running on the affected system:
* NT-ice
* Softice
It is also capable of setting the affected system's volume levels to zero, which may be used to prevent users from hearing any sound prompts, especially those that may be coming from antivirus and security applications.
[url=\"http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BROPIA.F\"][Source][/url]
[color=\"red\"][url=\"http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FBROPIA%2EF&VSect=Sn\"]REMOVAL INSTRUCTIONS[/url][/color]
-
NightStorm
- Administrator

- Posts: 779
- Joined: Mon May 17, 2004 9:05 am
Alerts
<table width="100%" align="center"> <tr> <td bgColor="#ffffff" valign="top"> <font face="Trebuchet MS,Bookman Old Style,Arial" color="#000000" size="3"> <div style="MARGIN-LEFT: 15px; MARGIN-RIGHT: 15px; TEXT-ALIGN: justify"> <font face="Arial" color="#2d8f26"><b>Virus:</b></font> SoberK <br> <br> <noindex><font face="Arial" color="#2d8f26"><b>Status:</b></font> <font face="Arial" color="#ff0000"><b><i>Real.</i></b></font> </noindex> <br> <br> <font face="Arial" color="#2d8f26"><b>Example:</b></font> <font face="Trebuchet MS,Bookman Old Style,Arial" color="#2d8f26"><i> [Collected on the Internet, 2005]</i></font> <br> <br> <table width="90%" align="center" bgColor="#000000" border="0"> <tr> <td bgColor="#eaf2e5"><font face="Verdana" size="2"> <div style="MARGIN: 10px 15px; TEXT-ALIGN: justify"> Dear Sir/Madam, <br> <br> we have logged your IP-address on more than 40 illegal Websites. <br> <br> Important: Please answer our questions!<br> The list of questions are attached. <br> <br> Yours faithfully,<br> M. John Stellford <br> <br> ++-++ Federal Bureau of Investigation -FBI-<br> ++-++ 935 Pennsylvania Avenue, NW, Room 2130<br> ++-++ Washington, DC 20535<br> ++-++ (202) 324-3000 </div> </font></td> </tr> </table> <p><br> <font face="Arial" color="#2d8f26"><b>Origins:</b></font> In mid-February 2005, <nobr>e-mails</nobr> accusing recipients of having visited "more than <nobr>40 illegal</nobr> Websites" and purporting to come from the Federal Bureau of Investigation began turning up. Those cowed by the charge into opening the attachment (indictment_cit9792.zip) unwittingly released the W32.Sober.K@mm virus into their computers, a mass-mailing worm that uses its own SMTP engine to send itself to <nobr> e-mail</nobr> addresses gathered from compromised computers. <br> <br> The FBI has nothing to do with these letters — these missives are purely the work of the virus originator, his or her way of ensuring the attachment accompanying the <nobr>e-mail</nobr> gets opened and thus its payload triggered. On <nobr>22 February</nobr> 2005, the FBI issued the following <a onmouseover="window.status='FBI press release about virus';return true" onmouseout="window.status='';return true" href="http://www.fbi.gov/pressrel/pressrel05/022205.htm" target="fbi" style="color: #0000FF; text-decoration: underline"> press release</a> about these letters: <br> <font face="Verdana" size="2"></p> <div style="MARGIN: 15px 30px; TEXT-ALIGN: justify"> FBI ALERTS PUBLIC TO RECENT E-MAIL SCHEME <br> <br> E-mails purporting to come from FBI are phony <br> <br> Washington, D.C. - The FBI today warned the public to avoid falling victim to an on-going mass <nobr>e-mail</nobr> scheme wherein computer users receive unsolicited <nobr>e-mails</nobr> purportedly sent by the FBI. These scam <nobr>e-mails</nobr> tell the recipients that their Internet use has been monitored by the FBI’s Internet Fraud Complaint Center and that they have accessed illegal web sites. The <nobr> e-mails</nobr> then direct recipients to open an attachment and answer questions. The attachments contain a computer virus. <br> <br> These e-mails did not come from the FBI. Recipients of this or similar solicitations should know that the FBI does not engage in the practice of sending unsolicited <nobr>e-mails</nobr> to the public in this manner. <br> <br> Opening e-mail attachments from an unknown sender is a risky and dangerous endeavor as such attachments frequently contain viruses that can infect the recipient’s computer. The FBI strongly encourages computer users not to open such attachments. <br> <br> The FBI takes this matter seriously and is investigating. Users receiving <nobr>e-mails</nobr> of this nature are encouraged to report it to the Internet Crime Complaint Center via <a onmouseover="window.status='Internet Crime Complaint Center';return true" onmouseout="window.status='';return true" href="http://www.ic3.gov" target="ICCC" style="color: #0000FF; text-decoration: underline"> [url=\"http://www.ic3.gov</a>\"]http://www.ic3.gov</a>[/url]. </div> </font> <p>This is not the first time a virus has been spread via an <nobr> e-mail</nobr> purporting to come from the FBI. In January 2004, a <a onmouseover="window.status='Sober.C';return true" onmouseout="window.status='';return true" href="http://www.snopes.com/inboxer/hoaxes/download.asp" target="SoberC" style="color: #0000FF; text-decoration: underline"> SoberC</a> variant was passed along in similar fashion with its payload <nobr>e-mails</nobr> serving notice that "your computer was scanned" and the "contents of your computer were confiscated." <!--Symantec offers a <A HREF="http://securityresponse.symantec.com/avcenter/venc/data/w32.sober@mm.removal.tool.html" TARGET=remove>removal tool</A> for Sober.C on their web site.--><br> <br> <font face="Arial" color="#2d8f26"><b>Additional information:</b></font> </p> <table cellSpacing="20" width="277"> <tr> <td width="235"> <font face="Trebuchet MS,Bookman Old Style,Arial" color="#ff0000" size="3"> <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.sober.k@mm.html"> W32.Sober.K Virus (<i>Symantec</i>)</a></font><a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.sober.k@mm.html"> </a></td> </tr> <tr> <td width="235"> <font face="Trebuchet MS,Bookman Old Style,Arial" color="#ff0000" size="3"> <a href="http://www.sophos.com/virusinfo/analyses/w32soberk.html"> W32.Sober.K (Sophos) (<i>Sophos</i>)</a></font><a href="http://www.sophos.com/virusinfo/analyses/w32soberk.html"> </a></td> </tr> <tr> <td width="235"> <font face="Trebuchet MS,Bookman Old Style,Arial" color="#ff0000" size="3"> <a href="http://www.f-secure.com/v-descs/sober_k.shtml">W32.Sober.K Virus (<i>F-Secure</i>)</a></font></td> </tr> </table> </div> </font></td> </tr> </table></div>
Alerts
Zafi-D a 'High-Alert' Top Threat
esecurityplanet : Online Threats & Alerts: Zafi-D a 'High-Alert' Top Threat
Success Story - F5 Networks Helps Santa Barbara Charter Fly
IT Management Glossary
data mining
ERP
extranet
grid computing
intranet
network appliance
outsourcing
storage
VPN
virus
FREE Tech Newsletters
Zafi-D a 'High-Alert' Top Threat
March 4, 2005
The Zafi-D worm has not only received 'high alert' threat status, it's become the most widespread malware roaming the Internet.
The worm, which spreads via email attachments and peer-to-peer accounts, received 'high alert' threat status from Sophos, Inc., an anti-virus and anti-spam company with U.S. headquarters in Lynnfield, Mass. Sophos analysts report that the worm harvests email addresses off infected computers and emails copies of itself out to them, and it also installs itself on the computer's registry. When it copies itself to the Windows system folder with the filename Norton Update.exe.
Sophos reports that Zafi-D makes up 30.8 percent of all malware traffic in the wild.
''It looks like the Zafi-D worm is going to be hanging around like a bored teenager for some time to come, unless more home users realise how important it is to update their anti-virus software,'' says Carol Theriault, a security consultant at Sophos. ''This Hungarian worm accounts for almost one in three viruses reported.''
Zafi-D is reported to display a fake error message box with the caption ''CRC: 04F6Bh'' and the text ''Error in packed file!''.
[url=\"http://www.esecurityplanet.com/alerts/article.php/3487646\"]source[/url]
esecurityplanet : Online Threats & Alerts: Zafi-D a 'High-Alert' Top Threat
Success Story - F5 Networks Helps Santa Barbara Charter Fly
IT Management Glossary
data mining
ERP
extranet
grid computing
intranet
network appliance
outsourcing
storage
VPN
virus
FREE Tech Newsletters
Zafi-D a 'High-Alert' Top Threat
March 4, 2005
The Zafi-D worm has not only received 'high alert' threat status, it's become the most widespread malware roaming the Internet.
The worm, which spreads via email attachments and peer-to-peer accounts, received 'high alert' threat status from Sophos, Inc., an anti-virus and anti-spam company with U.S. headquarters in Lynnfield, Mass. Sophos analysts report that the worm harvests email addresses off infected computers and emails copies of itself out to them, and it also installs itself on the computer's registry. When it copies itself to the Windows system folder with the filename Norton Update.exe.
Sophos reports that Zafi-D makes up 30.8 percent of all malware traffic in the wild.
''It looks like the Zafi-D worm is going to be hanging around like a bored teenager for some time to come, unless more home users realise how important it is to update their anti-virus software,'' says Carol Theriault, a security consultant at Sophos. ''This Hungarian worm accounts for almost one in three viruses reported.''
Zafi-D is reported to display a fake error message box with the caption ''CRC: 04F6Bh'' and the text ''Error in packed file!''.
[url=\"http://www.esecurityplanet.com/alerts/article.php/3487646\"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Worm.Win32.Sober.L Alert!
A new variant of the Sober worm is spreading fast. As it's predecessors, Sober.L spreads as an email attachment in emails which are sent to all email addresses found on the victim's harddisk. Even if the executable file is packed in a .ZIP file, many users open the file and activate the worm this way. For novice users it's hard to see that it is a worm generated email because the email subject is "your password + accountnumber !". The email body text is the following:
hi,
i've got an admin mail with a Password and Account info!
but the mail recipient are you! it's probably an esmtp error, i think.
i've copied the full mail text in the Windows text-editor & zipped.
ok, cya...
The recipient is advised to open the attached file "Acc_text.zip". The worm also spreads in a German version, which is used on all German email addresses. The German subject is "ich habe ihre e-mail bekommen !". The email body text is:
Hallo,
jemand schickt ihre privaten Mails auf meinem Account.
Ich schaetze mal, das es ein Fehler vom Provider ist.
Insgesamt waren es jetzt schon 6 Mails!
Ich habe alle Mail-Texte im Texteditor kopiert und gezippt.
Wenn es doch kein Fehler vom Provider ist, sorge dafuer das diese Dinger nicht mehr auf meinem Account landen, es Nervt naemlich.
Gruss
If you start the worm, you will see this window:
[attachment=625:attachment]
[url=\"http://www.emsisoft.com/en/malware/?Worm.Win32.Sober.L\"]Source & More Information[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Kelvir.DA is a worm that spreads a variant of W32.Randex through MSN Messenger.
Type: Worm
Infection Length: 6,442 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
When W32.Kelvir.DA is executed, it performs the following actions:
1. Sends the following message with a link to all the MSN Messenger contacts on the compromised computer:
its you in this cartoon!!
[http://]cartoonics.nl/[REMOVED]/cartoon.php?email=[RANDOM EMAIL ADDRESS]
Note: It has been reported that [RANDOM EMAIL ADDRESS] may be called nav_rro@hotmail.com.
2. Drops a variant of W32.Randex on the compromised computer if a recipient clicks on the link and downloads the file [RANDOM EMAIL ADDRESS].
Another recent worm puts the word "fucker" in the mouths of the infected, sends out the message: "you are on this picture and you never told me" and links to a would-be Pearl Jam fansite. The badly spelled "groupicture.php" in the URL gives it away, really. That, and the fact that I have not heard about Pearl Jam for 7 years, let alone be on a picture with them.
Other variations claim you're a staff member at a company/hotel/restaurant/whatever called Millenium ("i didnt know you worked here????"), you have a profile page at the wrongly spelled vbulettin site or that you are starring in a packet of beach pictures. For one last time (figuratively, I'm afraid): pictures and zipfiles do NOT have a .PIF extension... nothing worthwile does, actually. And secondly, never ever click links that end with your MSN Messenger account address.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.kelvir.da.html\"][u][More information \ Source][/u][/url]
Type: Worm
Infection Length: 6,442 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
When W32.Kelvir.DA is executed, it performs the following actions:
1. Sends the following message with a link to all the MSN Messenger contacts on the compromised computer:
its you in this cartoon!!
[http://]cartoonics.nl/[REMOVED]/cartoon.php?email=[RANDOM EMAIL ADDRESS]
Note: It has been reported that [RANDOM EMAIL ADDRESS] may be called nav_rro@hotmail.com.
2. Drops a variant of W32.Randex on the compromised computer if a recipient clicks on the link and downloads the file [RANDOM EMAIL ADDRESS].
Another recent worm puts the word "fucker" in the mouths of the infected, sends out the message: "you are on this picture and you never told me" and links to a would-be Pearl Jam fansite. The badly spelled "groupicture.php" in the URL gives it away, really. That, and the fact that I have not heard about Pearl Jam for 7 years, let alone be on a picture with them.
Other variations claim you're a staff member at a company/hotel/restaurant/whatever called Millenium ("i didnt know you worked here????"), you have a profile page at the wrongly spelled vbulettin site or that you are starring in a packet of beach pictures. For one last time (figuratively, I'm afraid): pictures and zipfiles do NOT have a .PIF extension... nothing worthwile does, actually. And secondly, never ever click links that end with your MSN Messenger account address.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.kelvir.da.html\"][u][More information \ Source][/u][/url]
Alerts
Top Threat:Mitglieder.DQ
Executive Summary
Name: Mitglieder.DQ (Panda)
Affects: Windows 2003/XP/2000/NT/ME/98/95
Size: 36,864 bytes
What it does: Mitglieder.DQ is a Trojan horse program with no direct mechanism for spreading. It is placed on web sites and other media from which users are tricked into downloading and executing it.
It contains a large number of process names belonging to security software and the software that keeps it up to date and it attempts to stop these processes. It then attempts to download the file OSA3.GIF from a large list of web sites. The .GIF extension is meant to trick users and security software; the file is actually an executable.
The program also copies two files, WINSHOST.EXE and WIWSHOST.EXE, to the Windows System directory. The first is a copy of the Trojan, the second a DLL used by it. It also overwrites the Windows HOSTS file with the following text:
127.0.0.1 localhost
It also creates registry values for itself in the HKEY_LOCAL_MACHINE and HKEY_CURRENT_USER Run keys in order to run itself at boot time. It creates one more value:
HKEY_CURRENT_USER\ Software\ FirstRun
FirstRunRR = 0x00000001
as an infection mark, in order to check if it has already affected the computer.
How to avoid it: Install antivirus software and keep it up to date. Only run executables from highly-trusted sources.
How to remove it: Delete the following registry keys from the system:
* HKEY_LOCAL_MACHINE\ Software\ Microsoft\ Windows\ CurrentVersion\ Run
winshost.exe = %sysdir%\winshost.exe
* HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Run
winshost.exe = %sysdir%\winshost.exe
* HKEY_CURRENT_USER\ Software\ FirstRun
FirstRunRR = 0x00000001
(%sysdir% is the Windows system directory)
Then restart the computer. Afterwards delete %sysdir%\winshost.exe and %sysdir%\wiwshost.exe.
It's best also to scan your system with an up-to-date anti-virus scanner at this point.
[url=\"http://www.pcmag.com/article2/0,1895,1832264,00.asp\"]source: PCMag[/url]
Executive Summary
Name: Mitglieder.DQ (Panda)
Affects: Windows 2003/XP/2000/NT/ME/98/95
Size: 36,864 bytes
What it does: Mitglieder.DQ is a Trojan horse program with no direct mechanism for spreading. It is placed on web sites and other media from which users are tricked into downloading and executing it.
It contains a large number of process names belonging to security software and the software that keeps it up to date and it attempts to stop these processes. It then attempts to download the file OSA3.GIF from a large list of web sites. The .GIF extension is meant to trick users and security software; the file is actually an executable.
The program also copies two files, WINSHOST.EXE and WIWSHOST.EXE, to the Windows System directory. The first is a copy of the Trojan, the second a DLL used by it. It also overwrites the Windows HOSTS file with the following text:
127.0.0.1 localhost
It also creates registry values for itself in the HKEY_LOCAL_MACHINE and HKEY_CURRENT_USER Run keys in order to run itself at boot time. It creates one more value:
HKEY_CURRENT_USER\ Software\ FirstRun
FirstRunRR = 0x00000001
as an infection mark, in order to check if it has already affected the computer.
How to avoid it: Install antivirus software and keep it up to date. Only run executables from highly-trusted sources.
How to remove it: Delete the following registry keys from the system:
* HKEY_LOCAL_MACHINE\ Software\ Microsoft\ Windows\ CurrentVersion\ Run
winshost.exe = %sysdir%\winshost.exe
* HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Run
winshost.exe = %sysdir%\winshost.exe
* HKEY_CURRENT_USER\ Software\ FirstRun
FirstRunRR = 0x00000001
(%sysdir% is the Windows system directory)
Then restart the computer. Afterwards delete %sysdir%\winshost.exe and %sysdir%\wiwshost.exe.
It's best also to scan your system with an up-to-date anti-virus scanner at this point.
[url=\"http://www.pcmag.com/article2/0,1895,1832264,00.asp\"]source: PCMag[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]

