Page 3 of 3

Alerts

Posted: Mon Aug 23, 2004 8:39 pm
by Tami
W64.Shruggle.1318
Discovered on: August 20, 2004
Last Updated on: August 24, 2004 09:06:24 AM

W64.Shruggle.1318 is a direct-action file infector, similar to W64.Rugrat.3344, which infects AMD64 Windows Portable Executable (PE) files. It is a fairly simple proof-of-concept virus; however, it is the first known virus to attack 64-bit Windows executables on AMD64 systems.

The virus is written in AMD64 assembly code.

Type: Virus
Infection Length: 1318 bytes

Systems Affected: Windows 64-bit (AMD64)
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 2000, Windows 3.x, Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

Technical Details:

When W64.Shruggle.1318 is executed, it searches 64-bit executable files that are in same folder, and all subfolders, as the one from which the virus was executed. When it finds a 64-bit executable file, the virus appends itself to the file, including .dll files.

Note: The virus does not infect 32-bit Portable Executable files, and it will not run natively on 32-bit Windows platforms. However, it can be run on a 32-bit computer that is using 64-bit simulation software.


Removal Instructions:

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


Update the virus definitions.
Run a full system scan, and delete all of the files that are detected as W64.Shruggle.1318.

Additional information:

The virus uses a small number of Win64 APIs from the following three libraries:

Ntdll.dll
Sfc_os.dll
Kernel32.dll

From Ntdll.dll, the virus uses the following functions:
LdrGetDllHandle()
RtlAddVectoredExceptionHandler()
RtlRemoveVectoredExceptionHandler()

The virus supports vectored exception handling to avoid crashing during infections.

The SfcIsFileProtected() function of Sfc_os.dll is used to avoid infecting executables that are protected by the System File Checker (SFC).

The following sixteen functions are used from Kernel32.dll to implement a standard file infection of a AMD64 Portable Executable image:
CreateFileMappingA()
CreateFileW()
CloseHandle()
FindFirstFileW()
FindNextFileW
FindClose()
GetFullPathNameW()
GetTickCount()
GlobalAlloc()
GlobalFree()
LoadLibraryA()
MapViewOfFile()
SetCurrentDirectoryW()
SetFileAttributesW()
SetFileTime()
UnmapViewOfFile()

The virus carries the following string, which is never displayed, within itself:

Shrug - roy g biv

The file infection routine is standard. The last section of the executable is marked as executable, the virus body is inserted into the last section, and a random number of bytes are appended to the end of the virus body.

The virus author is also the author of a number of other proof-of-concept viruses. These are collected under the name [url="http://securityresponse.symantec.com/avcenter/venc/data/w32.chiton.gen.html"]W32.Chiton.gen[/url].

[url="http://securityresponse.symantec.com/avcenter/venc/data/w64.shruggle.1318.html"]source[/url]

Alerts

Posted: Mon Aug 23, 2004 8:44 pm
by Tami
[b]Trojan.Mitglieder.O
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 04:44:15 PM [/b]

Trojan.Mitglieder.O is a Trojan horse that allows an infected computer to be used as an email relay.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: Linux, Macintosh OS X, Novell Netware, OS/2, UNIX

When Trojan.Mitglieder.O runs, it does the following:


Copies itself as the following files:

%System%\foõ.exe
%System%\norat.exe
%System%\winerdir.exe.

Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds a value:

"ssgrate.exe"="%System%\winerdir.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\WindowsCurrentVersion\Run

so that the worm runs when you restart Windows.


Adds the values:

"port" = "0x000097e3"
"uid" = "[random number]"
"wdrn" = "0x00000001"

to the registry key:

HKEY_CURRENT_USER\Software\DateTime8


Attempts to injects itself as a thread into the Explorer.exe process.


Opens and listens on TCP port 28883.

Note: This functionality is usually employed to send unsolicited commercial email.


Terminates the following processes:

AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET.EXE
CFINET32.EXE
CFINET32.EXE
CLEAN.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMGRDIAN.EXE
CMON016.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
Drvddll.exe
drvsys.exe
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE


Attempts to run a PHP script on one of the following domains, passing details about the infected host to the Web server:

artesproduction.com
avistrade.ru
bernlocher.de
blackwidow.nsk.ru
comdat.de
dabigbadboy.de
die-cliquee.de
egogo.ru
gaz-service.ru
gnet30.gamesnet.de
hannes-wacker.de
investexpo.ru
komtel.spb.ru
mc-figga.de
mir-auto.ru
mir-vesov.ru
monomah-city.ru
multi-gaming.com
partiyazerna.1gb.ru
plastikp.ru
prizmapr.ru
promco.ru
pvcps.ru
rdwufa.ru
roszvetmet.com
schiffsparty.de
service6.valuehost.ru
shop-of-innovations.de
sound-cell.de
st-agnes.de
stroyindustry.ru
tpoint.ru
unbound.de
vladzernoproduct.ru
web298.server7.webplus24.de
www.13tw22rigobert.de
www.admlaw.ru
www.deadlygames.de
www.emil-zittau.de
www.etype.hostingcity.net
www.eurostretch.ru
www.ferienwohnung-in-masuren.de
www.gasterixx.de
www.gay-traffic.de
www.hhc-online.de
www.komandor.ru
www.levada.ru
www.lowenbrau.ru
www.metzgerei-gebhart.de
www.mirage.ru
www.ordendeslichts.de
www.progame.de
www.psnr.ru
www.thomas-we.de

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Mitglieder.N.
Reverse the changes made to the registry.

To reverse the changes made to the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.


Type regedit

Then click OK.


Navigate to the following key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"ssgrate.exe"="%System%\winerdir.exe"


Navigate to the key:

HKEY_CURRENT_USER\Software\DateTime8


In the right pane, delete the values:

"port" = "0x000097e3"
"uid" = "[random number]"
"wdrn" = "0x00000001"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.mitglieder.o.html"]Source[/url]

[b]Trojan.Mitglieder.N
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 04:44:42 PM [/b]

Trojan.Mitglieder.N is a Trojan horse that allows an infected computer to be used as an email relay.

Also Known As: W32/Bagle.ak!proxy [McAfee]

Type: Trojan Horse
Infection Length: 17,920 bytes, 1,536 bytes, 26,112 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

When Trojan.Mitglieder.N runs, it does the following:


Copies itself as the following files:

%System%\fi?.exe
%System%\nopat.exe
%System%\sysdoor.exe.

Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds a value:

"ssgrate.exe"="%System%\sysdoor.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\WindowsCurrentVersion\Run

so that the Trojan runs when you restart Windows.


Adds the values:

"port" = "0x000070d2"
"uid" = "[random number]"
"wdrn" = "0x00000001"

to the registry key:

HKEY_CURRENT_USER\Software\DateTime8


Attempts to injects itself as a thread into the Explorer.exe process.


Opens and listens on TCP port 28882.

Note: This functionality is usually employed to send unsolicited commercial email.


Terminates the following processes:

AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET.EXE
CFINET32.EXE
CFINET32.EXE
CLEAN.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMGRDIAN.EXE
CMON016.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
Drvddll.exe
drvsys.exe
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE


Attempts to run a PHP script on one of the following domains, passing details about the infected host to the Web server:

artesproduction.com
avistrade.ru
bernlocher.de
blackwidow.nsk.ru
comdat.de
dabigbadboy.de
die-cliquee.de
egogo.ru
gaz-service.ru
gnet30.gamesnet.de
hannes-wacker.de
investexpo.ru
komtel.spb.ru
mc-figga.de
mir-auto.ru
mir-vesov.ru
monomah-city.ru
multi-gaming.com
partiyazerna.1gb.ru
plastikp.ru
prizmapr.ru
promco.ru
pvcps.ru
rdwufa.ru
roszvetmet.com
schiffsparty.de
service6.valuehost.ru
shop-of-innovations.de
sound-cell.de
st-agnes.de
stroyindustry.ru
tpoint.ru
unbound.de
vladzernoproduct.ru
web298.server7.webplus24.de
www.13tw22rigobert.de
www.admlaw.ru
www.deadlygames.de
www.emil-zittau.de
www.etype.hostingcity.net
www.eurostretch.ru
www.ferienwohnung-in-masuren.de
www.gasterixx.de
www.gay-traffic.de
www.hhc-online.de
www.komandor.ru
www.levada.ru
www.lowenbrau.ru
www.metzgerei-gebhart.de
www.mirage.ru
www.ordendeslichts.de
www.progame.de
www.psnr.ru
www.thomas-we.de

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Mitglieder.N.
Reverse the changes made to the registry.

To reverse the changes made to the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.


Type regedit

Then click OK.


Navigate to the following key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"ssgrate.exe"="%System%\sysdoor.exe"


Navigate to the key:

HKEY_CURRENT_USER\Software\DateTime8\


In the right pane, delete the values:

"port" = "0x000070d2"
"uid" = "[random number]"
"wdrn" = "0x00000001"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.mitglieder.n.html"]Source[/url]

Alerts

Posted: Wed Aug 25, 2004 4:05 am
by Tami
W32.Sasser.G
Discovered on: August 23, 2004
Last Updated on: August 24, 2004 04:53:59 PM

W32.Sasser.G is a variant of [url="http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.html"]W32.Sasser.Worm[/url] that attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin [url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx"]MS04-011[/url]. The worm spreads by scanning random IP addresses and drops [url="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.ac@mm.html"]W32.Netsky.AC@mm[/url].

Variants: W32.Sasser.Worm
Type: Worm
Infection Length: 58,880 bytes

Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003

Technical Details:

When W32.Sasser.G runs, it does the following:


Attempts to create mutexes named "PinaasoSky" and "Jobaka3", exiting if it fails. This ensures that no more than one instance of the worm can run on a computer at any time.


Copies itself as one of the following files:

%Windir%\avserve3.exe.
%Windir%\wserver.exe

Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.


Drops and executes the following files:

%Windir%\skynet.cpl
%Windir%\comp.cpl

Note: These files are detected as W32.Netsky.AC@mm.


Adds one of the following values:

"avserve3.exe"="%Windir%\avserv3.exe"
"wserver"="%Windir%\wserver.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you start Windows.


Prevents any attempts to shut down or restart the computer.


Starts an FTP server on TCP port 5554. This server is used to spread the worm to other hosts.


Retrieves the IP addresses of the infected computer.


Generates a second IP address, based on one of the IP addresses retrieved from the infected computer.


Connects to the generated IP address on TCP port 445 to determine whether a remote computer is online.


If a connection is made to a remote computer, the worm will send shell code to it, which may cause it to open a remote shell on TCP port 9996.


Uses the shell on the remote computer to reconnect to the infected computer's FTP server and retrieve a copy of the worm. This copy will have a name consisting of four or five numbers, followed by _up.exe. For example, 74354_up.exe.


Creates a file at C:\win2.log that contains the IP address of the computer that the worm most recently attempted to infect, as well as the number of infected computers.

Note: The Lsass.exe process will crash after the worm exploits the Windows LSASS vulnerability. Windows will display the alert and shut down the system in one minute.

Removal Instructions:

Before you begin:
If you are running Windows 2000 or XP, and have not yet done so, you must patch for the vulnerability described in Microsoft Security Bulletin MS04-011. If you do not, it is likely that your computer will continue to be reinfected.

What to do if the computer shuts down before you can patch or get the tool
This threat can cause Windows to keep shutting down and restarting. This can prevent you from installing the Microsoft patch or downloading the tool described below.


--------------------------------------------------------------------------------
Notes:
You may have to try this several times, as you only have about 20 seconds to do steps 3 to 6.
This will not work on Windows 2000.
--------------------------------------------------------------------------------


To prevent the shut down, do the following:

Disconnect the computer from the network/Internet connection. (Disconnect the cable if necessary.)
Restart the computer.
As soon as Windows opens and you see the Windows desktop, click Start > Run.
Type:

cmd

and press Enter.


Type:

shutdown -i

and press Enter.


In the Remote Shutdown Dialog that opens, do the following:

Click Add, type your computer name into the Add Computers dialog box, and then click OK.
In the "Display warning for" field, type 9999.
Type the following text in the Comment box:

Delay Lsass.exe shutdown.


Click OK.


Reconnect the network/Internet connection.
Connect to the Internet, and get the patch. Then continue with the steps described below.

When you have patched your computer and removed the threat, you can re-enable the 20 second default warning if you wish.


The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

End the malicious process (Windows NT/2000/XP).
Disable System Restore (Windows XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Sasser.G.
Reverse the change made to the registry.

For details on each of these steps, read the following instructions.

1. To end the malicious process
On Windows NT/2000/XP computers, you must first end the malicious process. Follow these instructions:
Press Ctrl+Alt+Delete once.
Click Task Manager.
Click the Processes tab.
Double-click the Image Name column header to alphabetically sort the processes.
Scroll through the list and look for the following processes:
napatch.exe
any process with a name consisting of four or five numbers, followed by _up.exe (for example, 74354_up.exe).


If you find any such process, click it, and then click End Process.
Exit the Task Manager.

To Edit The Registry:

Click Start, and then click Run. (The Run dialog box appears.)
Type regedit

Then click OK. (The Registry Editor opens.)


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the values, if present:

"avserve3.exe"="%Windir%\avserve3.exe"
"wserver"="%Windir%\wserver.exe"


Exit the Registry Editor.

[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.g.html"]source[/url]

Alerts

Posted: Wed Aug 25, 2004 6:09 pm
by Tami
Backdoor.Berbew.J
Discovered on: August 24, 2004
Last Updated on: August 25, 2004 03:09:02 PM

Backdoor.Berbew.J is a Trojan horse program that attempts to steal cached passwords from an infected computer. It may also display fake windows to gather confidential information from the user.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

When the Trojan is executed, it performs the following actions:


Creates a mutex named "Engel_12", which ensures that only one instance of the Trojan is running on the infected computer at one time.


Drops the following files:
%System%\[8 random characters].exe
%System%\[8 random characters].dll

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the following files, which are used for saving password information and any downloaded configuration data for the Trojan:

%System%\Engl32.dat
%System%\Rtdx1[random number].htm
%System%\engl32.vxd
%System%\Rtdx1[random number].dat
%System%\ccct32.dat


Creates several .htm files in the %Temp% directory, named [8 random characters].htm. The Trojan may then open these files in Internet Explorer.

Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).


Adds the value:

"WebEvent Logger"="{79ECA078-17FF-726B-E811-213280E5C831}"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

so that the Trojan starts when Windows starts.


Creates the following registry key:

HKEY_CLASSES_ROOT\CLSID\{79ECA078-17FF-726B-E811-213280E5C831}

which causes %System%\[8 random characters].dll to be called as a browser help object by Internet Explorer.


Adds the value:

"MGR" = "D-REPORTS-[8 random letters]"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\IE4

to prevent Internet Explorer from asking users if they are sure that they want to submit unencrypted form data.


Adds the value:

"1601"="0x0"

to the registry keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4

to prevent Internet Explorer from asking users if they are sure that they want to submit unencrypted form data.


Adds the value:

"GlobalUserOffline" = "0x0"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings

to prevent Internet Explorer from asking users if they wish to work offline, when using Internet Explorer and not connected to the Internet.


Adds the value:

"BrowseNewProcess" = "Yes"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings

to enable Windows Explorer to access the Internet.


Adds the value:

"AutoSuggest" = "Yes"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AutoComplete

to disable autocomplete in Internet Explorer.


Adds the value:

"Use FormSuggest" = "Yes"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main

to disable autocomplete in Internet Explorer.


Adds the value:

"FormSuggest Passwords" = "Yes"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main

to disable autocomplete in Internet Explorer.


Adds the value:

"FormSuggest PW Ask" = "Yes"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main

to disable autocomplete in Internet Explorer.


Opens the following:
a rootshell on TCP port 23232.
an FTP server on TCP port 32121.
backdoors on TCP ports 12065 and 28253.


Collects passwords from the infected computer and intercepts data entered into forms in Internet Explorer.
Sends the information gathered to a remote attacker.


Uploads configuration data through the web to a URL in the domain pidorasam.net .

Removal Instructions:

Disable System Restore (Windows Me/XP).

Update the virus definitions.

To restart the computer in Safe mode or VGA mode.

Run a full system scan and delete all the files detected as Backdoor.Berbew.J.

To restore the Internet Security settings:

Start Internet Explorer.
b. Click Tools, click Internet Options, and then click the Security tab.
c. Set the desired level for every zone. (The easiest way to do this is to click Default Level for each one.)

Delete the value that was added to the registry:

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad


In the right pane, delete the value:

"Web Event Logger"="{79ECA078-17FF-726B-E811-213280E5C831}"


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\IE4


In the right pane, delete the value:

"MGR" = "D-REPORTS-[8 random letters]"


Navigate to the key:

HKEY_CLASSES_ROOT\CLSID\{79ECA078-17FF-726B-E811-213280E5C831}

delete the key.


Exit the Registry Editor.

[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.berbew.j.html"]source[/url]

Alerts

Posted: Thu Aug 26, 2004 6:38 am
by Tami
VBS.Voodoo.C
Discovered on: August 24, 2004
Last Updated on: August 26, 2004 10:06:25 AM

VBS.Voodoo.C is a virus written in Visual Basic Script (VBS). It prepends itself to the files that have .asp, .htm, .hta, .htx, .html, and .htt file extensions.

Also Known As: VBS.Voodoo.B [Kaspersky], VBS/Reality [McAfee]
Variants: VBS.Voodoo.A
Type: Virus

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Technical Details:

When VBS.Voodoo.C is executed, it performs the following actions:


Modifies the value:

"1201"=0

in the registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0

so that the security protection that Microsoft Internet Explorer provides is lowered to a level that is less safe.


Infects .asp, .htm, .hta, .htx, .html, and .htt (html template) files that are located in:

The same folder as the virus.
The parent folder of the currently infecting folder, and recursively up to the root folder.
The following locations:
C:\My Documents
C:\Windows\Desktop
C:\Inetpub\wwwroot


May add the value:

"RegisteredOwner"="BLASTER"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RegisteredOwner


May create the following entry in your Internet Explorer Favorites list:

Blaster.URL: http:/ /www.coderz.net


Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as VBS.Voodoo.C.

[url="http://securityresponse.symantec.com/avcenter/venc/data/vbs.voodoo.c.html"]source[/url]

Alerts

Posted: Thu Aug 26, 2004 6:40 am
by Tami
W32.Tiniresu
Discovered on: August 24, 2004
Last Updated on: August 26, 2004 07:28:46 AM

W32.Tiniresu is a virus that infects the Userinit.exe file and downloads and executes a file from a remote location.

Type: Virus
Infection Length: 48,132 Bytes

Systems Affected: Windows 2000, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98

Technical Details:

When W32.Tiniresu is executed, it performs the following actions:


Locates %System%\Userinit.exe, and if the file is less than 25,600 bytes long, infects it by prepending 48,128 bytes and appending four extra bytes at the end of the file.

Note: %System% is a variable that refers to the System folder. By default, this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Opens backdoor ports and sends the infected system's IP address and backdoor port numbers to the following addresses:

brtblrvn.hopto.org
brtblrvn.no-ip.info
dlzdvlnj.hopto.org
dlzdvlnj.no-ip.info
hzlhpzxb.hopto.org
hzlhpzxb.no-ip.info
jtrjztpx.hopto.org
jtrjztpx.no-ip.info
lnxljnht.hopto.org
lnxljnht.no-ip.info
nhdnthzp.hopto.org
nhdnthzp.no-ip.info
pbjpdbrl.hopto.org
pbjpdbrl.no-ip.info
rvprnvjh.hopto.org
rvprnvjh.no-ip.info
tpvtxpbd.hopto.org
tpvtxpbd.no-ip.info
vjbvhjtz.hopto.org
vjbvhjtz.no-ip.info
xdhxrdlv.hopto.org
xdhxrdlv.no-ip.info
zxnzbxdr.hopto.org
zxnzbxdr.no-ip.info

Note: no-ip.info and hopto.org are dynamic DNS sites.


Retrieves and executes a file from a remote location.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as W32.Tiniresu.

[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.tiniresu.html"]source[/url]

Alerts

Posted: Thu Aug 26, 2004 6:44 am
by Tami
W32.Lovgate.AO@mm
Discovered on: August 25, 2004
Last Updated on: August 26, 2004 10:09:36 AM

W32.Lovgate.AO@mm is a mass-mailing worm that propagates through open network shares and prepends itself to .exe files.

The email has a variable subject and attachment name, with a .bat, .cmd, .com, .exe, .pif, .scr, or.zip file extension.

Also Known As: I-Worm.LovGate.ah [Kaspersky]

Type: Worm
Infection Length: varies

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x

Technical Details:

When W32.Lovgate.AO@mm is run, it does the following:


Creates a network share, named JAVA, which is mapped to %Windir%\JAVA.

Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.


Copies itself to all the network shares using one or more of the following names:

Daemon Tools v3.41.exe
EnterNet 500 V1.5 RC1.exe
Flash2X Flash Hunter v1.1.2.pif
FoxMail V5.0.500.0.exe
Microsoft Office.exe
Minilyrics_Std_2.7.233.pif
Serv-U FTP Server 4.1.exe
Support Tools.exe
WINISO 5.3.exe
WinGate V5.0.10 Build.exe
Winamp skin_FinalFantasy.exe
Windows 2000 sp4.ZIP.exe
Windows Media Player.zip.exe
autoexec.bat
eMule-0.42e-VeryCD0407Install.exe
i386.exe


Creates the following files:

%Windir%\Office.exe
%Windir%\Video.EXE
%System%\IEXPLORE.EXE
%System%\Kernel66.dll (A hidden file.)
%System%\TkBellExe.exe
%System%\Update_OB.exe
%System%\hxdef.exe
%System%\iexplorer.exe
%System%\real.exe

Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the following files:

%System%\Lmmib20.dll
%System%\MSSIGN30.DLL
%System%\ODBC16.dll
%System%\msjdbc11.dll

which make up the worm's backdoor component.


Creates the file, upDate.exe, in the root folder of all the drives, except for CD-ROM drives. The file attributes of this file are set to System, Hidden, and Read-only.


Drops a file named %System%\WinPatch.dll.


Creates and starts the following services:
_reg
Windows Management Protocol v.0(experimental)


Overwrites the autorun.inf file on each drive with the following:

[AUTORUN]
Open="C:\upDate.exe" /StartExplorer


Creates an archive containing a copy of the worm with the following format in the root folder of all the drives, unless the drive letter is A or B:

<filename>.RAR

where <filename> may be one of the following:

Bakeup
ghost
email


Adds the values:

"Microsoft Inc." = "iexplorer.exe..."
"Program In Windows" = "%System%\IEXPLORE.EXE"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"WinHelp" = "%System%\TkBellExe.exe..."

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that it executes every time Windows starts.


Adds the values:

"Installed shell32.dll" = "Office.exe..."
"SystemTra" = "C:\WINDOWS\Video.EXE"
"Soft Profile Inc" = "%System%\hxdef.exe..."

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices

so that it executes every time Windows 95/98/Me starts.


Adds the value:

"run" = "real.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows


Adds the value:

"(Default)" = "Update_OB.exe %1..."

to the registry key:

HKEY_CLASSES_ROOT\txtfile\shell\open\command

so that the worm runs each time a .txt file is opened.


Stops the following services:

Rising Realtime Monitor Service
Symantec AntiVirus Client
Symantec AntiVirus Server


Terminates any processes with the following strings in their names:

Duba
Gate
KAV
KV
McAfee
NAV
RavMon.exe
Rfw.exe
SkyNet
Symantec
kill
rising


Injects a process-watching procedure as a thread into either Explorer.exe or Taskmgr.exe. This thread will attempt to launch %System%\Iexplore.exe if it detects that the worm's process has stopped.


The worm will then listen on TCP port 6060. The backdoor procedures steal information of an infected computer and stores it in the file, C:\Netlog.txt. The worm then emails the stolen information to the hacker.


Extracts the location of the KaZaA-shared folder from the registry. Then, it copies itself to the folder as one of the following:

BlackIcePCPSetup_creak
HEROSOFT
Passware5.3
REALONE
W32Dasm
orcard_original_creak
rainbowcrack-1.1-win
setup
word_pass_creak
wrar320sc
<random file name>

with a .bat, .exe, .pif, or .scr file extension.


Scans all the computers attached to the same network segment as the infected computer. The worm will attempt to authenticate to administrative shares on systems that are found, using "Administrator" as a user name, combined with the following passwords:

!@#$
!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
000000
00000000
007
110
111
111111
11111111
121212
123
123123
1234
12345
123456
1234567
12345678
123456789
123abc
123asd
2003
2004
2600
321
54321
654321
666666
888888
88888888
Admin
Administrator
Guest
Internet
Login
Password
aaa
abc
abc123
abcd
abcdef
abcdefg
admin
admin123
administrator
alpha
asdf
asdfgh
computer
database
enable
god
godblessyou
guest
home
login
love
mypass
mypass123
mypc
mypc123
oracle
owner
pass
passwd
password
pw123
pwd
root
secret
server
sex
sql
super
sybase
temp
temp123
test
test123
win
yxcv
zxcv
zzz


If the worm successfully authenticates to a remote system, it will attempt to copy itself as:

\\<remote computer name>\admin$\system32\TelePhone.exe


Starts the file as the service, "NetWork Associates Inc."


Replies to any messages that arrive in the mailbox of certain MAPI-compliant email clients, such as Microsoft Outlook.

For example, if the incoming email has the following properties:

Subject: <subject>
From: <sender>@<domain.com>
Message: <original message body>

the worm will attempt to send the following email:

Subject: Re: <subject>
To: <sender>@<domain.com>

Message:
'<sender>' wrote:
====
> <original message body>
====

<domain.com> account auto-reply:

... ... more details,look to the attachment.

> Get your FREE <domain.com> account now! <

Attachment: (One of the following)
Butterfly Garden.scr
FlashFXP.exe
HyperSnap-DX v5.rar.exe
Industry Giant II.exe
MSN Messenger.exe
MacroMedia.pif
Macromedia Flash.scr
Matrix Reloaded 3D.exe
MyIE.AVI.pif
Photoshop.EXE
Shakira.zip.exe
StarWars2 - CloneAttack.rm.scr
WindowsXP Creak.exe
dreamweaver MX (crack).exe
joke.exe
s3msong.MP3.pif


Retrieves the email addresses on the infected machine and sends an email with the following properties. The From field may be spoofed.

Subject: (One of the following)

Delivery Status Notification (Delay)
Error
Hi
Mail Transaction Failed
Test
<blank>

Message: (One of the following)

Delivery to the following recipient has failed:
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.
Mail failed. For further assistance, Please contact!
THIS IS A WARNING MESSAGE ONLY.
The message contains Uniocode characters and has been sent as a binary attachment.
This is an automatically generated Delivery Status Notification
YOU DO NOT NEED TO RESEND YOUR MESSAGE.
<blank>

Attachment: (One of the following)

Body
Doc
Document
File
Message
Readme
Test
Text
data
<random>

Extension: (One of the following)

.bat
.cmd
.com
.exe
.pif
.scr
.zip


Searches the hard disk for .exe files. When it finds one, it creates a viral file, %System%\temp.uuu, and prepends this file to the .exe file. These files will be detected as W32.Lovgate.AO@mm!inf.

Removal Instructions:

Disable System Restore (Windows Me/XP).

Update the virus definitions.

Reverse the changes made to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the values:

"Microsoft Inc." = "iexplorer.exe..."
"Program In Windows" = "%System%\IEXPLORE.EXE"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"WinHelp" = "%system%\TkBellExe.exe..."


If you are using Windows 95/98/Me, navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices


In the right pane, delete the values:

"SystemTra" = "C:\WINDOWS\Video.EXE"
"Soft Profile Inc" = "%System%\hxdef.exe..."
"Installed shell32.dll" = "Office.exe..."


If you are using Windows NT/2000/XP, navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows


In the right pane, delete the value:

"run" = "real.exe"


Navigate to the key:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services


In the right pane, delete the subkeys:

_reg
Windows Management Protocol v.0(experimental)


Navigate to the key:

HKEY_CLASSES_ROOT\txtfile\shell\open\command


In the right pane, change the value to:

Windows 95/98/Me:
"(Default)"="WINDOWS\NOTEPAD.EXE %1"

Windows NT/2000/XP:
"(Default)"="%SystemRoot%\system32\NOTEPAD.EXE %1"


Exit the Registry Editor.


Restart the computer in Safe mode or VGA mode.

Run a full system scan and delete all the files detected as W32.Lovgate.AO@mm.

Repair those detected as W32.Lovgate.AO@mm!inf.

[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.ao@mm.html"]source[/url]

Alerts

Posted: Fri Aug 27, 2004 9:37 am
by Tami
W32.Scane
Discovered on: August 26, 2004
Last Updated on: August 27, 2004 04:11:26 PM

W32.Scane is a worm that attempts to spread by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability.



Type: Worm
Infection Length: 71,416 bytes



Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT


Technical Details:

When W32.Scane executes, it does the following:

May copy itself as %System%\servicec.exe

Note: %System% is a variable that refers to the System folder. By default this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the values:

"WinLsass"="%System%\servicec.exe" or
"WinLsass"="<path to original threat file>"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the W32.Scane runs when you start Windows.


Creates multiple threads that attempt to connect to a random block of IP addresses by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability on TCP port 445. If successful, the remote system attempts to download a copy of the worm from the host.


Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restarting the computer in Safe mode or VGA mode
Run a full system scan and delete all the files detected as W32.Scane.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete either of the following values:

"WinLsass"="%System%\servicec.exe"
"WinLsass"="<path to original threat file>"


Exit the Registry Editor.

[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.scane.html"]source[/url]

Alerts

Posted: Fri Aug 27, 2004 8:40 pm
by Tami
W32.Spybot.DAZ
Discovered on: August 27, 2004
Last Updated on: August 28, 2004 10:58:19 AM

W32.Spybot.DAZ is a worm that spreads through IRC, network shares, exploits, and computers that are infected with common backdoor Trojan horses.

Type: Worm

Systems Affected: Windows 2000, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details

When W32.Spybot.DAZ is executed, it does the following:


Copies itself as %System%\mvsc.exe

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the value:

"Microsoft Update" = "mvsc.exe"

to the registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

Note: The name of the value may change if an attacker sends a command to change it.


Modifies the value:

"EnableDCOM" = "N"

in the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM


Modifies the value:

"restrictanonymous" = "1"

in the registry key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa


Scans for other computers on the network, attempting to connect to shared resources using a predetermined list of usernames and passwords. If successful, the worm will attempt to copy itself to the remote computer.


Connects to a remote IRC server on TCP port 6667 and listens for commands, including any of following:

Download and execute files.
Scan the network for server with running backdoor trojan horses.
List, stop, and start processes.
Launch Denial of Service (DoS) attacks.
Steal system information and send it to the attacker.
Log keystrokes to a file in the %System% folder.
Open a backdoor port.
Control the file system (Delete, create, and list files).
Perform port redirection.
Flush DNS server.


Creates a log file, named c:\debug.txt, containing information about the IRC servers the worm is connected to.


May spread by exploiting the following vulnerabilities:

The DCOM RPC Vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135.
The Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011).
The vulnerabilities in the Microsoft SQL Server 2000 or MSDE 2000 audit (described in Microsoft Security Bulletin MS02-061) using UDP port 1434.
The WebDav Vulnerability (described in Microsoft Security Bulletin MS03-007) using TCP port 80.
The UPnP NOTIFY Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS01-059).
The Workstation Service Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-049) using TCP port 445. Windows XP users are protected against this vulnerability if the patch in Microsoft Security Bulletin MS03-043 has been applied. Windows 2000 users must apply the patch in Microsoft Security Bulletin MS03-049.


May steal CD keys and passwords for the following games:

Battlefield 1942
Battlefield 1942 (Road To Rome)
Battlefield 1942 (Secret Weapons of WWII)
Battlfield Vietnam
Black and White
Chrome
Command and Conquer: Generals
Command and Conquer: Red Alert
Command and Conquer: Red Alert 2
Command and Conquer: Tiberian Sun
Counter-Strike
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden & Dangerous 2
IGI 2: Covert Strike
Industry Giant 2
James Bond 007: Nightfire
Legends of Might and Magic
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
Need For Speed Hot Pursuit 2
Need For Speed: Underground
Neverwinter Nights
Neverwinter Nights (Hordes of the Underdark)
Neverwinter Nights (Shadows of Undrentide)
NHL 2002
NHL 2003
NOX
Rainbow Six III RavenShield
Shogun: Total War: Warlord Edition
Soldier of Fortune II - Double Helix
Soldiers Of Anarchy
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Spybot.DAZ
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the following keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Microsoft Update" = "mvsc.exe"


Exit the Registry Editor

[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.daz.html"]source[/url]

Alerts

Posted: Wed Sep 01, 2004 9:48 am
by Tami
Downloader.CDT
Discovered on: August 30, 2004
Last Updated on: September 01, 2004 11:08:09 AM

Downloader.CDT is a Trojan horse program that downloads several files from a specific website.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

When the Trojan is executed it performs the following actions:


Creates the following copy of itself:
[Random name].exe


Adds the following values:

"CurrentLevel" = "0"
"Flags" = "0"
"1001" = "0"
"1004" = "0"
"1200" = "0"
"1201" = "0"
"1206" = "0"
"1400" = "0"
"1402" = "0"
"1405" = "0"
"1406" = "0"
"1407" = "0"
"1601" = "0"
"1604" = "0"
"1605" = "0"
"1606" = "0"
"1607" = "0"
"1608" = "0"
"1609" = "0"
"1800" = "0"
"1802" = "0"
"1803" = "0"
"1804" = "0"
"1805" = "0"
"1A00" = "0"
"1A02" = "0"
"1A03" = "0"
"1A04" = "0"
"1A05" = "0"
"1A06" = "0"
"1A10" = "0"
"2001" = "0"
"2004" = "0"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3

to lower the security settings in Microsoft Internet Explorer.


Attempts to open a Web site in the domain counterstrike.server.us, and download a program named Adware.CDT.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Downloader.CDT.
Restoring security settings in Microsoft Internet Explorer.

To restore the security level, complete the following steps:
Start Internet Explorer.
Click Tools, and then click Internet Options.
Select the Security tab.
Reset the security settings to the level you desire.

[url="http://securityresponse.symantec.com/avcenter/venc/data/downloader.cdt.html"]source[/url]

Alerts

Posted: Wed Sep 01, 2004 9:54 am
by Tami
Trojan.Hiva
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 10:54:38 AM

Trojan.Hiva is a Trojan horse program that uses net-send commands to send alert messages, moves the mouse randomly, and closes program windows.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

When the Trojan is executed, it does the following:


Creates the following files:
Windows%\HIV.exe
Windows%\HIVmod1.exe
Windows%\HIVmod2.exe
Windows%\HIVmod3.exe
Windows%\HIVmod4.exe


Adds the following value:

"HIV"="HIV.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that it is executed every time Windows starts.


Uses net-send commands to display the following alert box:

HIV+ infected


Performs some of the following actions:
Moves the mouse randomly
Closes program windows
Attempts to open the CD-ROM drive


Uses net-send commands to send alert messages to random IP addresses.


Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Hiva.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"HIV"="HIV.exe"


Exit the Registry Editor.

[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.hiva.html"]source[/url]

Alerts

Posted: Wed Sep 01, 2004 9:55 am
by Tami
Backdoor.Alets
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 10:52:46 AM

Backdoor.Alets is a backdoor Trojan horse that allows a remote attacker to have unauthorized access to an infected computer, via IRC channels.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

Once the Trojan is executed, it performs the following actions:


Creates the following copy of itself:

%Windir%\services.exe


Adds the following value:

"Microsoft Services"="%Windir%\services.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that it is executed every time Windows starts.


Contacts an IRC server on the domain, ctgbn.stellaremperor.com, through TCP port 32440.


Awaits commands from a remote attacker to perform the following actions:
Kill processes
Download and execute files

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Alets.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Microsoft Services"="%Windir%\services.exe"


Exit the Registry Editor.

[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.alets.html"]source[/url]

Alerts

Posted: Wed Sep 01, 2004 10:01 am
by Tami
Download.Ject.D
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 04:27:11 PM

Download.Ject.D is a variant of [url="http://securityresponse.symantec.com/avcenter/venc/data/download.ject.c.html"]Download.Ject.C[/url] that attempts to download and execute files.

Note: LiveUpdate Virus definitions are scheduled to be released on 8/31/04 to provide protection against this threat. Virus definitions version 60831j (extended version 8/31/2004 rev. 36) and greater are required for detection.

Variants: Download.Ject.C
Type: Trojan Horse
Infection Length: 12,800 Bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Technical Details:

When Download.Ject.D is executed, it performs the following actions:



Creates the following files:

%System%\Doriot.exe (A copy of itself)
%System%\Gdqfw.exe (A downloader module)

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the value:

"wersds" = "%System%\doriot.exe"

to the registry keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs when you start Windows.


Injects Gdqfw.exe into Explorer.exe as a remote thread, which attempts to do the following:

Stops the service, "SharedAccess," and then sets the Startup type of this service to Disabled.

Terminates the following processes:

ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE


Attempts to download a file from one of the following domains. The file is saved as %Windir%\_re_file.exe, and is then executed.

Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.

allianzsp.sk
coolweb.psg.sk
cryofthespirit.com
dollypop.com
execpage.com
helpdemos.com
helpingyouth.org
jamesbronner.com
koti.pl
miracle.v6.cz
mountainwings.com
mountainwings4.com
naturalpros.com
oracal.pl
shock.evernet.com.pl
SportLine.go.ro
stroipolymer.ru
theonlineword.com
virtualchurch.com
visionforsouls.org
wingsoverlife.com
www.1800thewoman.com
www.1944.pl
www.45partsdepot.com
www.7pe.friko.pl
www.air-computers.com.ar
www.ametist.spb.ru
www.apodis.pl
www.arrasy.pl
www.arthurspeaks.com
www.astermed.pl
www.atomique.pl
www.atw.hu
www.avatar.ee
www.avers.com.pl
www.baltexpo.spb.ru
www.bomart.cz
www.bravo.gliwice.pl
www.bronnerbros.com
www.buycare.com
www.cumparacd.go.ro
www.da-rom.co.il
www.domu.net
www.eastandard.co.ke
www.elblu.republika.pl
www.elcorsy.com
www.elite-style.com
www.enduser1.fast.net
www.enitex.by
www.enitex-m.by
www.eris.pl
www.europharm.pl
www.extreme-racing.lg.ua
www.fotel.pl
www.fotolab.sk
www.frater.hu
www.gardameditech.com
www.generex.de
www.goldgates.com
www.goodboy.dem.ru
www.hards.pl
www.healthcometh.com
www.holz-studio.at
www.ibplus.sk
www.icpnet.pl
www.icpnet.pl
www.inlan.sk
www.jamesbronner.com
www.jbplus.cz
www.justmatchit.com
www.kubtelecom.ru
www.kuda.com.ua
www.lacittadifiorenzuola.it
www.lotusdog.net
www.ltvo.spb.ru
www.master.pl
www.members.aon.at
www.moteplassen1.com
www.mountainwings2.com
www.multifoto.sk
www.nadodrze.pl
www.nairobiwebspace.com
www.nameitright.com
www.nardo.bbe.pl
www.netland.gda.pl
www.netta.pl
www.nikola.piwko.pl
www.ntrlab.com
www.nustep.sk
www.octava.pl
www.odevnictvo.sk
www.oftza.friko.pl
www.oktbroiler.ru
www.online40.com
www.online50.com
www.oto.lv
www.pancoopzsv.co.yu
www.pay5495.com
www.pc-hard.com.ua
www.perfect-beauty.at
www.pharmag.pl
www.polsl.katowice.pl
www.prophetcollins.com
www.propi.cz
www.pursuit.rv.ua
www.pyrlandia-boogie.pl
www.quatro.sk
www.r-bazar.ru
www.roszkowski.pl
www.silvic.ro
www.sincron.go.ro
www.skylive.pl
www.smgkrc.pl
www.soulring.com
www.star-max.it
www.sunbud.com.pl
www.swez.net
www.system5electronics.com
www.tcvwebtv.com.ar
www.thewoman.com
www.tivis.cz
www.ukpl.pl
www.vacation-network.net
www.wyspian.iap.pl
www.zasada-rowery.pl

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Download.Ject.D.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"wersds" = "%System%\doriot.exe"


Exit the Registry Editor.

Restart the computer in normal mode.

[url="http://securityresponse.symantec.com/avcenter/venc/data/download.ject.d.html"]source[/url]

Alerts

Posted: Wed Sep 01, 2004 10:04 am
by Tami
W32.Beagle.AQ@mm
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 04:22:27 PM

W32.Beagle.AQ@mm is a variant of W32.Beagle.AO@mm, which is a mass-mailing worm that uses its own SMTP engine to spread. The email attachment is a downloader, similar to Trojan.Mitglieder and Download.Ject.C, that downloads the worm from an external source.

The worm also contains backdoor functionality, opening TCP port 80 and UDP port 80.

Variants: W32.Beagle.AO@mm
Type: Worm
Infection Length: 12,800 bytes, 18,436 bytes, 9,728 Bytes. 4,996 Bytes, 9,728 Bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Techincal Details:

When W32.Beagle.AQ@mm runs, it does the following:


Copies itself as the following files:

%System%\windll.exe. (A copy of the worm)
%System%\windll.exeopen (A copy of the worm)
%System%\windll.exeopenopen (A copy of the worm)

Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the value:

"erthgdr"="%System%\windll.exe"

to the registry key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n



Creates seven mutexes with the following names, which prevent some variants of the W32.Netsky@mm family of worms from running:

MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_




Deletes any values that contain the following strings:

9XHtProtect
Antivirus
EasyAV
FirewallSvr
HtProtect
ICQ Net
ICQNet
Jammer2nd
KasperskyAVEng
MsInfo
My AV
NetDy
Norton Antivirus AV
PandaAVEngine
SkynetsRevenge
Special Firewall Service
SysMonXP
Tiny AV
Zone Labs Client Ex
service

from the registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n


Create copies of itself in any folder that contains the characters "shar". The files will have the following file names:

Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral, (cens) cool, awesome!!.exe
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe


Attempts to download and execute files from the following Web sites as %System%\_re_file.exe:

allianzsp.sk
coolweb.psg.sk
cryofthespirit.com
dollypop.com
execpage.com
helpdemos.com
helpingyouth.org
jamesbronner.com
koti.pl
miracle.v6.cz
mountainwings.com
mountainwings4.com
naturalpros.com
oracal.pl
shock.evernet.com.pl
SportLine.go.ro
stroipolymer.ru
theonlineword.com
virtualchurch.com
visionforsouls.org
wingsoverlife.com
www.1800thewoman.com
www.1944.pl
www.45partsdepot.com
www.7pe.friko.pl
www.air-computers.com.ar
www.ametist.spb.ru
www.apodis.pl
www.arrasy.pl
www.arthurspeaks.com
www.astermed.pl
www.atomique.pl
www.atw.hu
www.avatar.ee
www.avers.com.pl
www.baltexpo.spb.ru
www.bomart.cz
www.bravo.gliwice.pl
www.bronnerbros.com
www.buycare.com
www.cumparacd.go.ro
www.da-rom.co.il
www.domu.net
www.eastandard.co.ke
www.elblu.republika.pl
www.elcorsy.com
www.elite-style.com
www.enduser1.fast.net
www.enitex.by
www.enitex-m.by
www.eris.pl
www.europharm.pl
www.extreme-racing.lg.ua
www.fotel.pl
www.fotolab.sk
www.frater.hu
www.gardameditech.com
www.generex.de
www.goldgates.com
www.goodboy.dem.ru
www.hards.pl
www.healthcometh.com
www.holz-studio.at
www.ibplus.sk
www.icpnet.pl
www.icpnet.pl
www.inlan.sk
www.jamesbronner.com
www.jbplus.cz
www.justmatchit.com
www.kubtelecom.ru
www.kuda.com.ua
www.lacittadifiorenzuola.it
www.lotusdog.net
www.ltvo.spb.ru
www.master.pl
www.members.aon.at
www.moteplassen1.com
www.mountainwings2.com
www.multifoto.sk
www.nadodrze.pl
www.nairobiwebspace.com
www.nameitright.com
www.nardo.bbe.pl
www.netland.gda.pl
www.netta.pl
www.nikola.piwko.pl
www.ntrlab.com
www.nustep.sk
www.octava.pl
www.odevnictvo.sk
www.oftza.friko.pl
www.oktbroiler.ru
www.online40.com
www.online50.com
www.oto.lv
www.pancoopzsv.co.yu
www.pay5495.com
www.pc-hard.com.ua
www.perfect-beauty.at
www.pharmag.pl
www.polsl.katowice.pl
www.prophetcollins.com
www.propi.cz
www.pursuit.rv.ua
www.pyrlandia-boogie.pl
www.quatro.sk
www.r-bazar.ru
www.roszkowski.pl
www.silvic.ro
www.sincron.go.ro
www.skylive.pl
www.smgkrc.pl
www.soulring.com
www.star-max.it
www.sunbud.com.pl
www.swez.net
www.system5electronics.com
www.tcvwebtv.com.ar
www.thewoman.com
www.tivis.cz
www.ukpl.pl
www.vacation-network.net
www.wyspian.iap.pl
www.zasada-rowery.pl

Note: %System% is a variable. The Trojan locates the Windows installation folder and saves the downloaded files to that location. By default, this is C:\Windows\System32 or C:\Winnt\System32.



Terminates the following processes:

ATUPDATER.EXE
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE


Searches for the email addresses in files that have the following extensions:

.adb
.asp
.cfg
.cgi
.dbx
.dhtm
.eml
.htm
.jsp
.mbx
.mdx
.mht
.mmf
.msg
.nch
.ods
.oft
.php
.pl
.sht
.shtm
.stm
.tbb
.txt
.uin
.wab
.wsh
.xls
.xml


Skips email addresses that contain the following strings:

@avp.
@derewrdgrs
@eerswqe
@foo
@iana
@messagelab
@microsoft
abuse
admin
anyone@
bsd
bugs@
cafee
certific
contract@
feste
free-av
f-secur
gold-certs@
google
help@
icrosoft
info@
kasp
linux
listserv
local
news
nobody@
noone@
noreply
ntivi
panda
pgp
postmaster@
rating@
root@
samples
sopho
spam
support
unix
update
winrar
winzip


Uses its own SMTP engine to send email messages to any addresses that are found.

The email may have the attachments "fotos.zip", which is a WinZip file containing "foto.html", and "foto1.exe".

Creates the following files:

%System%\Doriot.exe (A copy of foto1.exe)
%System%\Gdqfw.exe (A downloader module)

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the value:

"wersds" = "%System%\doriot.exe"

to the registry keys:

HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you start Windows.

Opens backdoors on TCP port 80 and UDP port 80, which allow the infected computer to be used as an email relay.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AQ@mm.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n


In the right pane, delete the value:

"erthgdr"="%System%\windll.exe"


Navigate to the key:

HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Run


In the right pance, delete the value

"wersds" = "%System%\doriot.exe"


Navigate to the key:

HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Run


In the right pance, delete the value

"wersds" = "%System%\doriot.exe"


Exit the Registry Editor.

[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.aq@mm.html"]source[/url]

Alerts

Posted: Thu Sep 02, 2004 12:46 am
by Tami
Trojan.Yipid
Discovered on: September 01, 2004
Last Updated on: September 02, 2004 03:02:58 PM

Trojan.Yipid is a trojan that downloads files from the Internet, searches the system for email addresses, and sends a Chinese language email to all the addresses it finds.

Infection Length: 61440 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX

When Trojan.Yipid is executed it performs the following actions:


Copies itself to the %System% as:

Rund132.exe


Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

Attempts to download files from the domain chinaweb.a184.zgsj.com to the following folders:

%system%\MSWinsck.ocx (a legitimate file)
%system%\conmax.exe (collects email addresses)
%system%\msimn.exe (sends out emails)


Adds the value:

"Run"="%System%\Rund1.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows


And adds the value:

"Taskbell.exe" = "%System%\Rund1.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsCurrentVersion\Run

These entries ensure that Trojan.Yipid runs upon Windows startup.


Collects email addresses from files with the following extensions:

.txt
.htm
.html
.asp
.xml
.com


The trojan avoids email addresses that contain any of the following substrings:

guang
searchgov
edu
microsoft
rising
jiangmin
kingsoft
symantec
norton
263
163
nease
126
tom
371
sina
china
sohu
chinaren
21cn


Appends the found email addresses to the file:

%system%\mmtxt.txt


Registers the legitimate file, mswinsck.ocx, and sends email to all the collected addresses. The From address is spoofed and the message contains a text written in Chinese inviting the recipient to visit the domain chinaweb.a184.zgsj.com

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Yipid.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Taskbell.exe" = "%System%\Rund1.exe"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows


In the right pane, delete the value:

"Run"="%System%\Rund1.exe"


Exit the Registry Editor.

[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.yipid.html"]source[/url]

Alerts

Posted: Fri Sep 03, 2004 6:48 am
by Tami
W32.IRCBot.F
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 01:59:58 PM

W32.IRCBot.F is a backdoor Trojan horse that connects to an IRC server and waits for commands from an attacker.

Variants: W32.IRCBot.E
Type: Trojan Horse
Infection Length: 95,744

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, UNIX, Windows 3.x

When W32.IRCBot.F is executed, it attempts to perform the following actions:


Copies itself as %System%\Securitychk.exe.

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the value:

"Microsoft Secure Messenger.NET Service" = "securitychk.exe"

to the registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs when you start Windows.


Deletes the shares from local drives.


Connects to the IRC server tehr8x.spbx.net using TCP port 6667.


Joins a predefined channel, using a random nickname, and waits for commands from the IRC server. These commands can allow the attacker to:
Manage the installation of the Trojan
Control the IRC client on a compromised computer
Update the installed Trojan
Send the Trojan to other IRC channels
Download and execute files
Perform Denial of Service (DoS) attacks against a target, which the hacker defines
Uninstall itself completely by removing the relevant registry entries
Go to Web sites
Copy itself to shared folders on other computers
Steal license keys for games including:
Battlefield 1942
Battlefield 1942: Secret Weapons of WWII
Battlefield 1942: The Road To Rome
Battlefield 1942: Vietnam
Black and White
Command and Conquer: Generals
Command and Conquer: Generals: Zero Hour
Command and Conquer: Red Alert2
Command and Conquer: Tiberian Sun
Counter-Strike
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden and Dangerous 2
IGI2: Covert Strike
Industry Giant 2
James Bond 007: Nightfire
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
NHL 2002
NHL 2003
Need for Speed: Hot Pursuit 2
Need for Speed: Underground
Neverwinter Nights
Ravenshield
Shogun: Total War: Warlord Edition
Soldiers Of Anarchy
Soldier Of Fortune 2
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004
Soldier Of Fortune II - Double Helix


Terminate processes. Refer to the "Additional Information" section for a list of the processes that may be terminated.

Removal Instructions

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.IRCBot.F.
Delete the values that were added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to each of these keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

Note: All the keys will not be found on all the systems.


From each key that is found, in the right pane, delete the value:

"Microsoft Secure Messenger.NET Service" = "securitychk.exe"


Exit the Registry Editor.

Restart the computer in normal mode.

[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.ircbot.f.html"]source[/url]

Alerts

Posted: Fri Sep 03, 2004 6:50 am
by Tami
Backdoor.Balkart
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 11:22:24 AM

Backdoor.Balkart is a backdoor Trojan horse that can act as a HTTP proxy or FTP server.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

When the Trojan is executed, it performs the following tasks:


Copies itself as %Windir%\ÎäÒíÑ.exe.

Notes:
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
The file name is in Arabic. On systems that do not have the Arabic character set installed, it will be displayed as shown above. If the Arabic character set is installed, it may look like this:




Adds the value:

"alkasr" = "%windir%\ÎäÒíÑ.exe"

to the registry entry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the Trojan is executed every time that Windows starts.


Creates a backdoor by opening port 12121/TCP.


Performs a HTTP GET request, providing the attacker with a log of infected machines.


Waits for commands from a remote attacker to do any of the following:
Stop processes
Execute commands
Use the compromised system as an FTP server or SOCKS proxy

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Balkart.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"alkasr" = "%windir%\ÎäÒíÑ.exe"


Exit the Registry Editor.

[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.balkart.html"]source[/url]

Alerts

Posted: Fri Sep 03, 2004 6:52 am
by Tami
Backdoor.Akak
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 11:16:52 AM

Backdoor.Akak is a backdoor server that also creates a SOCKS proxy on the compromised system. Reports indicate that Web sites exploiting the Microsoft Internet Explorer Drag And Drop File Installation Vulnerability may install it.

Also Known As: Backdoor.Win32.BoomRaster.a (KAV)

Type: Trojan Horse
Infection Length: 8704 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

Backdoor.Akak is a backdoor server program that may be installed when you visit a malicious Web site using Internet Explorer. These pages may contain code that exploits the Microsoft Internet Explorer Drag And Drop File Installation Vulnerability.

If Backdoor.Akak runs, it will download the file, Testexe.exe or Rb.exe, to the Windows Startup folder.

Following this, when you start Windows, it does the following:


Executes the downloaded file.


Creates the mutex "J&^srl!hsl^AHSgh" so that only one instance of the backdoor is present in memory.


Registers itself as a service so that it continues to run even if you log off.


Copies itself as %System%\rb.exe.

Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the value:

"RamBooster2"="%System%\rb.exe "

in the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs every time that Windows starts.


Issues the command "net stop SharedAccess" to disable the Windows Internet Connection Firewall (ICF), if it is running on the system. (Windows 2000/XP).


Contacts a master server located at 202.104.242.156 on TCP port 4321 and downloads information, which is stored in the file, %System%\lhosts.txt.


If the backdoor cannot create the lhosts.txt file, it will instead store this information in the file, Kaka2.txt, which it creates in the current working folder.


Creates a SOCKS proxy on TCP port 5555. This allows the compromised computer to be used to proxy protocols such as HTTP.


Listens on TCP port 4321 for commands from the remote attacker. The attacker can do any of the following:
Obtain system information
Download and execute files on the compromised computer
Uninstall the back door
Update the address of the master server

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Akak.
Delete the value that was added to the registry.
Re-enable the SharedAccess service (Windows 2000/XP only).

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"RamBooster2" =" %System%\rb.exe"


Exit the Registry Editor.


5. To re-enable the SharedAccess service (Windows 2000/XP only)
The SharedAccess service is responsible for maintaining Internet Connection Sharing and the Windows Firewall/Internet Connection Firewall applications in Windows. (The presence and names of these applications vary depending on the operating system and service pack you are using.) To protect your computer and maintain network functionality, re-enable this service if you are using any of these programs.


Windows XP Service Pack 2
If you are running Windows XP with Service Pack 2 and are using the Windows Firewall, the operating system will alert you when the SharedAccess service is stopped, by displaying an alert balloon saying that your Firewall status is unknown. Perform the following steps to ensure that the Windows Firewall is re-enabled:

Click Start > Control Panel.


Double-click the Security Center.


Ensure that the Firewall security essential is marked ON.

Note: If the Firewall security essential is marked on, your Windows Firewall is on and you do not need to continue with these steps.

If the Firewall security essential is not marked on, click the "Recommendations" button.


Under "Recommendations," click Enable Now. A window appears telling you that the Windows Firewall was successfully turned on.


Click Close > OK.


Close the Security Center.


Windows 2000 or Windows XP Service Pack 1, or earlier
Complete the following steps to re-enable the SharedAccess service:

Click Start > Run.
Type services.msc

Then click OK.


Do one of the following:

Windows 2000: Under the Name column, locate the "Internet Connection Sharing (ICS)" service and double-click it.
Windows XP: Under the Named column, locate the "Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS)" service and double-click it.


Under "Startup Type:", select "Automatic" from the drop-down menu.


Under "Service Status:", click the Start button.


Once the service has completed starting, click OK.


Close the Services window.

[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.akak.html"]source[/url]

Alerts

Posted: Fri Sep 03, 2004 7:24 am
by Tami
PWSteal.Tarno.I
Discovered on: September 01, 2004
Last Updated on: September 02, 2004 12:58:40 PM

PWSteal.Tarno.I is a Trojan horse that attempts to steal user names and passwords for certain Internet banking sites, by capturing screenshots and logging keystrokes.

Also Known As: Troj/Tofger-BG [Sophos]

Type: Trojan Horse
Infection Length: 179,200 Bytes, 11,004 Bytes, 6,000 Bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x

When PWSteal.Tarno.I is executed, it performs the following actions:


Creates the following files:

%Windir%\Vhchost.exe: Detected as PWSteal.Tarno.I
%Windir%\Scrnr32.dll: Detected as PWSteal.Tarno.I
%System%\Winrr.exe: Non-malicious utility file that PWSteal.Tarno.I uses to create RAR file.

Notes:
%System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).


Adds the value:

"Default System Research" = "%Windir%\vhchost.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs when you start Windows.


Monitors the URL field in Internet Explorer for the following strings:

e-gold
bank
hsbc
halifax
barclays
openplan
lloyds
abbey
cahoot
nationwide
nwolb
natwest
nationet
woolwich


Stores keystrokes and the content of the clipboard (the buffer for copy and paste) in the file, %System%\Usert\<10digits>_<8digits>.txt, where the digits are derived from the system time.


Stores screenshots in the file, %System%\Usert\<10digits>_<8digits>.bmp, where these digits are derived from the system time.


Using %System%\Winrr.exe, which it previously created, the Trojan creates the RAR file, %System%\Usert, which contains the keystrokes and screeenshots.


Attempts to send the RAR file to a remote Web server.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as PWSteal.Tarno.I.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Default System Research" = "%Windir%\vhchost.exe"


Exit the Registry Editor.

[url="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.tarno.i.html"]source[/url]

Alerts

Posted: Sun Sep 05, 2004 1:19 pm
by Tami
W32.Remadmin
Discovered on: September 02, 2004
Last Updated on: September 04, 2004 12:31:07 PM

W32.Remadmin is a worm that attempts to propagate through network shares.

Also Known As: WORM_REMADM.A [Trend]

Type: Worm
Infection Length: 842,304 bytes

Systems Affected: Windows 2000, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: Linux, Macintosh, UNIX

W32.Remadmin is composed of batch files, hacktools, and legitimate administration tools.

When the worm is executed, it does the following:


Extracts the following files:
AdmDll.dll: A .dll component of Remacc.Radmin.
icon.reg *: A registry file.
Kcah.cmd: A batch file that copies utili.dll to <ip address>\ADMIN$\SYSTEM32 and attempts to stop certain processes.
Msdos.exe: An .exe file that is detected as Remacc.Radmin.
Msxml3b.dll *: A clean text file with a list of I.D.'s
Msxml4b.dll *: A clean text file with a list of passwords.
Naer.cmd: A batch file that calls Kcah.cmd with a specified ip address (excluding 192.168.0.x and 127.0.0.x).
Psexec.exe *: A Sysinternals remote execution tool.
Raddrv.dll: A .dll component of Remacc.Radmin.
Regedit4.exe *: A registry editor.
Rs.cmd *: A batch file that calls msdos.exe.
Run.bat: A starting batch file for the Worm.
Secfind.exe: A hacktool used to search for IPC$ shares.
Secscan.exe: A .exe file that is detected as Hacktool.RunService.
Star.cmd: A batch file that calls Kcah.cmd with random ip address.
Unrar.exe : A rar archive containing:
i.cmd *: A starting batch file that stops/removes netsvc.exe and overwrites files but does not seem viral.
instsrv.exe *: A service installer.
Regedit4.exe *: A registry editor.
Rep.exe *: Replace Commander - a non-malicious program used to replace specific strings in a file.
S.bin *: A clean file used to overwrite.
V.bin *: A clean file used to overwrite.
W.exe *: A clean file used to overwrite.

NOTE: Files that marked with an asterisk ( * ) are either commercial utilities or are clean files. As such, Symantec antivirus products do not detect them.


Creates the registry key:

HKEY_LOCAL_MACHINE\System\RAdmin


Executes Run.bat which:
Copies Rar.exe to Utili.dll
Enable these network shares:
IPC$
ADMIN$
C$=C:\
Executes Star.cmd which executes Naer.cmd, Kcah.cmd, and Secfind.exe with a randomly-generated ip number
Executes Secfind.exe with a range of ip address to search for IPC$ shares.
Executes Kcah.cmd and Naer.cmd and copies Utili.dll into <victim's ip address>\ADMIN$\SYSTEM32\Rar.exe and stops certain processes.
Executes Rar.exe.
Executes Unrar.exe to stop Netsvc.exe and overwrite the following files.
Copies v.bin to %SystemRoot%\.{21EC2020-3AEA-1069-A2DD-08002B-30309D}\netsvc.exe
Copies w.exe to %SystemRoot%\.{21EC2020-3AEA-1069-A2DD-08002B-30309D}\netsvc.ini
Copies s.bin to %SystemRoot%\System32\netsvc.exe

Removal Instructions:

Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Remadmin.
Delete the values that were added to the registry.

Click Start > Run.
Type regedit

Then click OK.

Navigate to the following key:

HKEY_LOCAL_MACHINE\System

In the left pane, delete the key:

"RAdmin"

Exit the Registry Editor.

Restart the computer in normal mode.

Additional information:

Some of the processes that the Worm may terminate are:

DefWatch
Symantec AntiVirus Client
NSCTOP
Symantec Core LC
SAVScan
SAVFMSE
ccEvtMgr
navapsvc
ccSetMgr
VisNetic AntiVirus Plug-in
McShield
AlertManger
McAfeeFramework
AVExch32Service
AVUPDService
McTaskManager
Network Associates Log Service
Outbreak Manager
MCVSRte
mcupdmgr.exe
AvgServ
AvgCore
AvgFsh
awhost32
Ahnlab task Scheduler
MonSvcNT
V3MonNT
V3MonSvc
FSDFWD

[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.remadmin.html"]source[/url]

Alerts

Posted: Sun Sep 05, 2004 1:22 pm
by Tami
W32.Bugbear.M@mm
Discovered on: September 03, 2004
Last Updated on: September 04, 2004 12:43:28 PM

W32.Bugbear.M@mm is a mass-mailing worm that sends itself to email addresses it gathers from certain files on the system, using its own SMTP engine.

Variants: W32.Bugbear@mm
Type: Virus, Worm

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX

Technical Details:

When W32.Bugbear.M@mm runs, it does the following:


Creates the following files:

%System%\<random filename>.nls
%System%\<random filename>.dat
%System%\<random filename>.tmp
%System%\<random filename>.dll
%System%\<random filename>.exe


Attempts to add the value:

"<random value>" = "%System%\<random filename>.exe"

in the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the worm starts when Windows starts.


Attempts to append its code to the following files in the %Windir% folder and %ProgramFiles% folder:

scandskw.exe
regedit.exe
mplayer.exe
hh.exe
notepad.exe
winhelp.exe
Internet Explorer\iexplore.exe
adobe\acrobat 7.0\reader\acrord32.exe
WinRAR\WinRAR.exe
Windows Media Player\mplayer2.exe
Real\RealPlayer\realplay.exe
Outlook Express\msimn.exe
Far\Far.exe
CuteFTP\cutftp32.exe
Adobe\Acrobat 6.0\Reader\AcroRd32.exe
Adobe\Acrobat 5.0\Reader\AcroRd32.exe
Adobe\Acrobat 4.0\Reader\AcroRd32.exe
ACDSee32\ACDSee32.exe
MSN Messenger\msnmsgr.exe
WS_FTP\WS_FTP95.exe
QuickTime\QuickTimePlayer.exe
StreamCast\Morpheus\Morpheus.exe
Zone Labs\ZoneAlarm\ZoneAlarm.exe
Trillian\Trillian.exe
Lavasoft\Ad-aware 6\Ad-aware.exe
AIM95\aim.exe
Winamp\winamp.exe
DAP\DAP.exe
ICQ\Icq.exe
kazaa\kazaa.exe
winzip\winzip32.exe

The worm is a polymorphic file infector.

Note:
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
%ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.


Scans all hard disks for files with file paths containing any of the following strings:

BEAR
DONKEY
DOWNLOAD
FTP
HTDOCS
HTTP
MORPHEUS
ICQ
KAZAA
LIME
MULE
INCOMING
SHAR
UPLOAD


If a file within these folders contains files with an .exe extension, the worm will attempt to infect those files.
Otherwise, it will copy itself as <original filename.ext>.exe (where .ext is the original file's extension).


Gathers email address from files whose filename contains any of the following strings:

.dbx
.tbb
.eml
.mbx
.nch
.mmf
Inbox
.ods
.htm
.asp
.txt
.sht


Uses its own SMTP engine to email itself to the email addresses that it collects.

The email has the following characteristics:
Subject: Starts with "Re: "

Attachment:
The worm searches for a specific folder by querying the following registry value:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell\Folders\Personal

Once the worm locates the name of the folder, it looks for a file that does not have a .INI, .ini, .rdp extentions. The worm uses the filename and then changes the file extension to .jpg and uses it as an attachment of the email.

Otherwise, the attachment may be one of the following:
a000032.jpg.scr
song.wav.scr
music.mp3.scr
video.avi.scr
photo.jpg.scr
pic.jpg.scr
message.txt.scr
image.jpg.scr
news.doc.scr
myphoto.jpg.scr
you.jpg.scr
love.jpg.scr
readme.txt.scr


Locates the following information from the infected computer and sends it to the attacker:

Cookies
Clipboard contents
Logged keystrokes
Text from open windows

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan, delete or repair all the files detected as W32.Bugbear.M@mm.
Reverse the changes made to the registry.

Click Start, and then click Run. (The Run dialog box appears.)


Type regedit

Then click OK. (The Registry Editor opens.)


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\


In the right pane, delete the value:

"<random value>" = "%System%\<random filename>.exe"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbear.m@mm.html"]source[/url]

Alerts

Posted: Sun Sep 05, 2004 1:27 pm
by Tami
W32.Mydoom.R@mm
Discovered on: September 03, 2004
Last Updated on: September 04, 2004 02:43:54 PM

W32.Mydoom.R@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses that it finds on an infected computer. The email contains a spoofed From address. The subject and message body vary, and the attachment has a .bat, .cmd, .exe, .pif, .scr, or .zip extension.

This threat is packed using UPX.


Also Known As: W32/Mydoom.t@MM [McAfee], WORM_MYDOOM.T [Trend], MyDoom.T [F-Secure]
Variants: W32.Mydoom.P@mm
Type: Worm
Infection Length: 37,888 bytes, 8,192 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

When W32.Mydoom.R@mm is executed, it does the following:


Copies itself as %System%\tasker.exe.

Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the file %System%\Nemog.dll(8,192 bytes), which is a component of W32.Mydoom.R@mm.


Creates the file, %Temp%\Message, and then opens it with Notepad.


Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).


Creates a mutex, "EnD-Of-SkyNet", which allows only one instance of the worm to run in memory.


Adds the value:

"Task"="%System%\tasker.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the worm starts when Windows starts.


Adds the value:

"(Default)"="%System%\Nemog.dll"

to the registry key:

HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32


Creates the following registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version


May also attempt to open a back door on port 5422 and allow a remote attacker to have unauthorized access to the infected system. This would allow a remote attacker to download and execute remote files.


Copies itself to Kazaa shared folders using one of the following file names:

cleaner
crack
Fixtool
Hotmail hacker
mydoom
netsky
ps2 emulator
SoBig
Upload
Vahos
Viraus
Wenrar
Winzip
xbox emulator
XXX Pictures
XXX Videos
yahoo hacker


Retrieves the email addresses from the files that have the following extensions on drives C through Y:

.adbh
.aspd
.dbxn
.htmb
.phpq
.pl
.shtl
.tbbg
.wab


Retrieves the email addresses from the Windows Address Book files.


Guesses the name of the SMTP server by prepending the following names to the domain names gathered from the local system:

gate.
mail.
mail1.
msx.
mx.
mx1.
ns.
relay.
smtp.


Gathers email addresses form the local system. It also derives email addresses by prepending the following strings to the domain names gathered from the system:

alice
andrew
brenda
brent
brian
claudia
david
debby
george
helen
james
jerry
jimmy
julie
kevin
linda
maria
michael
peter
robert
sandra
smith
steve


Sends itself to the email addresses that it finds.

The email has the following characteristics:

From:
The From address is spoofed.

Subject: The subject may be one of the following:

<Garbage string>
<none>
document
Error
hello
hi
Information
Mail Delivery System
Mail Transaction Failed
message
RE:my .....
RE:test
readme
Server Report
Status
test


Message: The message may be one of the following:

!!!!!!!!!!!, check the attachment!!!.
(Norton Anti Virus : No Virusses Found , Check The Attachment For More Information.
(Norton ANti Virus,Panda,Mcafee No Virusses Found).
Check the attachment for more information!.
check the attachment to get the lastest news.
check.
come back my friend.
error , sorry we can't send the email so check the attachment.
error to send the mail!!!!!.
error, check the attachment for more information.
failed to send the email!, check the attachment for more information.
failed,check the attachment for more information.
hello :)
hello check the attachment thx.
hello.
here is what you need,thx.
loooooool ;)))
Mail transaction failed. Partial message is available.
sorry we can't send the mail try later , check the attachment for more information.
the attachment for more information.
Try Later, Check the Attachment.
you can check the attachment for more information.
your attachment , thx.


Attachment: The attachment name may be one of the following:

body
data
doc
document
file
message
readme
test
text


with one or two of the following extensions:

.bat
.com
.doc
.exe
.htm
.scr
.tmp
.txt


It avoids sending itself to the email addresses that contains any of the following:

-._!@
abuse
accoun
acketst
admin
anyone
arin.
be_loyal:
berkeley
borlan
certific
contact
example
feste
gold-certs
google
ibm.com
icrosof
icrosoft
inpris
isc.o
isi.e
kernel
linux
listserv
mit.e
mozilla
mydomai
nobody
nodomai
noone
nothing
ntivi
panda
postmaster
privacy
rating
rfc-ed
ripe.
ruslis
samples
secur
sendmail
service
somebody
someone
sopho
submit
support
tanford.e
the.bat
usenet
utgers.ed
webmaster

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Mydoom.R@mm.
Reverse the changes made to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Task"="%System%\tasker.exe"


Navigate to the key:

HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32


In the right pane, delete the value:

"(Default)"="%System%\Nemog.dll"


Navigate to and delete the keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Version


Exit the Registry Editor.


Restart the computer in Normal mode.

[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.r@mm.html"]source[/url]

Alerts

Posted: Sat Sep 11, 2004 4:52 pm
by Endo
A virus has been identified by Sophos anti-virus experts which attempts to talk to end users over their speakers. The worm, known as W32/Amus-A, spreads via e-mail using subject lines such as "Listen and Smile". If users launch the attached file the worm will attempt to spread, and also tries to use the Microsoft Speech engine to read out a greeting as follows:

"hamsi. I am seeing you. Haaaaaaaa. You must come to turkiye. I am cleaning your computer. 5. 4. 3. 2. 1. 0. Gule. Gule."

As well as this the worm changes the users Internet Explorer settings so users see a message in Turkish rather than their usual start page. Graham Cluley, senior technology consultant for Sophos, said the following about the worm:

"It's depressing to see virus writers are active in Turkey. It seems whoever created this worm has complaints about the quality of internet service in his country, but this isn't the proper way to register his opinion. Hopefully if any internet users receive an Amus-infected email they will treat it with suspicion and not launch the attachment."

The worm is not particuarly widespread, nor is it particuarly damaging in its present form. However, users are recommend as always to keep their anti-virus definitions up to date to prevent worms like this from propagating, and to be careful when opening attachments, even if they appear to be from a trusted source.

[url="http://itvibe.com/?NewsID=2874"][Source][/url]

Alerts

Posted: Tue Nov 09, 2004 1:26 am
by RuffRyders
[b]New MyDoom draws on IE flaw to spread[/b]
[i]A new version of MyDoom uses an unpatched flaw in Microsoft's Internet Explorer to spread, antivirus companies warned on Monday.[/i]

[size=1]By Robert Lemos[/size]

The recently discovered vulnerability in the browser software allows the offshoot to infect a PC after a user clicks on a link, according to advisories from security software makers Symantec and McAfee. The program sneaks past antivirus applications that detect malicious software by scanning e-mail messages with attached programs.

The companies said they had only detected a few instances of the infector, which is labelled MyDoom.AG by McAfee and MyDoom.AH by Symantec.

"We have only received one submission from the field, but the technical aspects of this are concerning," said Craig Schmugar, senior virus research manager at McAfee. "It has all the components there to become a significant virus."

It's not the first time a code writer has exploited a flaw in a Microsoft product before the software giant has had a chance to plug the hole. An aggressive advertiser attempted to [url="http://news.com.com/Pop-up+toolbar+spreads+via+IE+flaws/2100-1002_3-5229707.html?tag=nl"]surreptitiously install[/url] a pop-up toolbar in victim's Web browsers using two previously unpatched security flaws in Internet Explorer.

Microsoft said that it was investigating the flaw and was aware of a new virus exploiting the issue.

"As a best practice, users should always exercise extreme caution when opening unsolicited attachments from both known and unknown sources," said Microsoft in a statement sent to CNET News.com. "In addition, we continue to encourage customers follow our 'Protect Your PC' guidance of enabling a firewall, getting software updates and installing antivirus software."

The latest MyDoom virus appears as an e-mail in an inbox. The body of the message states: "Look at my homepage with my last webcam photos!" or "FREE ADULT VIDEO! SIGN UP NOW!" Both messages have text that links them to a Web page generated by the virus and hosted on the infected computer that sent the e-mail.

When the victim clicks on the link, a Windows-based PC will call Internet Explorer and load a malicious Web page from the previously infected computer. The page contains the [url="http://news.com.com/Exploit+code+makes+IE+flaw+more+dangerous/2100-1002_3-5439370.html?tag=nl"]IFrame vulnerability recently publicized[/url] on security mailing lists. The virus uses the flaw to execute code on the victim's computer, infecting the system. The virus harvests e-mail addresses on the compromised system, sends out mail to spread the virus further, sets up a Web server and attempts to contact several Internet relay chat (IRC) servers as a way to notify the virus's creator of that a new system has been compromised.

The fact that the virus creates a Web server and uses that server to infect other systems is a significant departure from previous versions of MyDoom, and other viruses in general, Schmugar said.

"There was a decent amount of work that went into this," he said. "There was a good bit of attention (among security researchers) to the demo code (of this flaw). Someone grabbed the demo code and tweaked it quite a bit."

McAfee rates the program a low threat, but Schmugar said he thinks it might spread widely.

[url="http://news.com.com/New+MyDoom+draws+on+IE+flaw+to+spread/2100-7349_3-5443828.html?tag=nefd.top"][Source][/url]

Alerts

Posted: Wed Nov 10, 2004 10:08 am
by Tami
MyDoom worm is back
By JACK KAPICA
Globe and Mail Update



In a development certain to trouble computer security experts, only four days passed between the discovery of a vulnerability in the Internet Explorer browser and the appearance of a worm designed to exploit it.

The virus — in this case, technically a worm — is a variant of the well-known mass-mailing MyDoom infection, with the difference that rather than delivering an attachment, the e-mail just asks recipients to click on a link. The browser is then directed to the infected destination site, where the worm, dubbed Mydoom.ah by McAfee Inc.,

installs itself on the victim's computer.

The worm targets a Microsoft Internet Explorer IFRAME buffer overflow vulnerability, which was discovered and made public by two hackers with aliases "ned" and "SkyLined" on Friday. Only four days later a worm exploiting the weakness was developed and set loose, virus-tracking companies said reported.

The period of time between discovery of a flaw and the appearance of an infection has been shortening recently. Last year, the time difference was, on average, 28 days.

McAfee's Anti-virus and Vulnerability Emergency Response Team (AVERT) raised the risk assessment of MyDoom.ah to medium after receiving close to 100 reports of the virus being stopped or infecting users from the field, from both the virus itself as well as customer submissions. Most of these reports have arrived from the United States.

The new variant is a mass-mailing worm that sends messages with a hyperlink directing people to an infected machine. Following the hyperlink results in an infection occurring on vulnerable Microsoft Internet Explorer Web browsers.

The worm contains its own SMTP engine to construct outgoing messages. It harvests addresses from local files and then uses those addresses in the "From" field to send itself, producing a message with a spoofed return address.

Users should be wary, McAfee warned, and should delete any e-mail with the subject:

"hi!", "hey!", "Confirmation" or just blank. The message body will be one of the following:

"Congratulations! PayPal has successfully charged $175 to your credit card."

"Your order tracking number is A866DEC0, and your item will be shipped within three business days."

"To see details please click this link."

Another variation pretends to be an invitation to a sex site. The text of the message says: "Hi! I am looking for new friends. My name is Jane, I am from Miami, FL. See my homepage with my weblog and last webcam photos! See you!"

McAfee and Symantec, two makers of popular antivirus products, have updated their virus definition files to include MyDoom.ah for subscribers.

Microsoft Corp., which makes the Internet Explorer browser, is expected to issue its monthly batch of security patches later on Tuesday, but it was not immediately clear whether it would include a patch for the new worm.

The company did say that users of Windows XP who had installed Service Pack 2 were at a "reduced risk."

[url="http://www.globetechnology.com/servlet/story/RTGAM.20041109.gtdoomnov9/BNStory/Technology/"]source[/url]

Alerts

Posted: Thu Feb 03, 2005 10:09 am
by Tami
New Bropia worm rated "code orange"



SEOUL, Feb. 3 — Korean security specialists at Globeal Hauri are warning of a new variant of the recently discovered Bropia worm, which is more dangerous than its predecessor.

Symptoms include a file, seemingly sent from a "buddy," which is loaded with the virus and infects the PC as soon as it opened. Remote access hijacks the infected PC. Volume differences and right mouse click might indicate the PC user that something is wrong.

Once Bropia infects a system, it resides in the memory and continues spreading through MSN Messenger. Bropia is a member of the Rbot family of worms affecting the Windows platform, which installs a back door on the system and gives an attacker a way of accessing and controlling the infected system remotely. That would allow unauthorized remote access to the infected computer via specific IRC channels while running in the background as a service process.

Another interesting component is that the new Bropia is loaded with a Bot virus component that opens the 1294 port.

The new Bropia copies itself into the system folders and creates one of the following file names: LOL.scr, Webcam.pif, bedroom-thongs.pif, naked_drunk.pif, LMAO.pif, ROFL.pif, underware.pif, Hot.pif or webcam.pif

The infected system folder can vary, depending on each user's configuration, with the most common being C:\Windows\System (Windows 95/98/Me); C:\Winnt\System32 (Windows NT/2000) and C:\Windows\System32 (Windows XP).

The worm can be temporarily disabled bly blocking the 1294 port with any firewall. This is not a "spreading" port but the PC might receive an attack order from this port.

[url="http://www.globetechnology.com/servlet/story/RTGAM.20050203.gtbropia0203/BNStory/Technology/"]source[/url]

Alerts

Posted: Thu Feb 03, 2005 1:33 pm
by Josh
Is this the same thing that Mess.Be has reported which is spreading through MSN Messenger?

Alerts

Posted: Sat Feb 05, 2005 10:28 pm
by Endo
Trend Micro Inc has released an overview of a worm that is currently doing the rounds infecting users PC's and transferring itself through the MSN Messenger service.

MSN Messenger is under attack of a worm that comes with a seductive name and download link. The user clicks on the link and gets the copy of attached worm for his PC. The worm can spread on the network and shared computers. The worm can disable the Anti-Virus software and then infect the Files in PC, It can also spread easily after it disables anti virus program.

Trend Micro Inc. has also raised the threat level on the W32/Bropia worm. The company said that worm could cause more harm in case it spread more through MSN Messenger buddies and Shared Networks. The virus has antidebugging feature also.

The virus logs keystrokes. It can also retrieve credit card numbers and other sensitive information. The W32/Bropia worm contains a variant of the Rbot backdoor Trojan. The virus could be a higher threat to sensitive information as it can store information. It is also capable of using the infected machine to hijack sensitive data.
[url="http://www.neowin.net/comments.php?id=26963&category=main"][Source][/url]

[b][color="darkred"]-------------------------------------------------------[/b][/color]

As of February 2, 2005, 6:55 PM (Pacific Standard Time/GMT -8:00), TrendLabs has declared a Medium-Risk alert to control the spread of this new WORM_BROPIA variant that is spreading in Korea, China, Taiwan, and the United States.

This memory-resident worm propagates itself via MSN Messenger by sending a copy of itself using different file names to all available or online contacts. Thus, users of the said messaging program should not accept or open these files to avoid infection.

System administrators can also block MSN Messenger transfers to control the spread of this worm.

As a general rule, MSN Messenger users should avoid accepting file transfers coming from an untrusted source.

This worm also drops and executes the file SEXY.JPG in the root folder. This normal .JPG file displays the following [url="http://www.trendmicro.com/vinfo/images/WORM_BROPIA_F.gif"]image.[/url]
It also attempts to drop and execute a bot program, which Trend Micro detects as WORM_AGOBOT.AJC.

Unlike its previous variants, this worm also has an anti-debugging technique. That is, this worm will not run if any of the following debugging applications are currently running on the affected system:
* NT-ice
* Softice
It is also capable of setting the affected system's volume levels to zero, which may be used to prevent users from hearing any sound prompts, especially those that may be coming from antivirus and security applications.
[url="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BROPIA.F"][Source][/url]

[color="red"][url="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FBROPIA%2EF&VSect=Sn"]REMOVAL INSTRUCTIONS[/url][/color]

Alerts

Posted: Wed Feb 23, 2005 6:08 pm
by NightStorm
<table width="100%" align="center"> <tr> <td bgColor="#ffffff" valign="top"> <font face="Trebuchet MS,Bookman Old Style,Arial" color="#000000" size="3"> <div style="MARGIN-LEFT: 15px; MARGIN-RIGHT: 15px; TEXT-ALIGN: justify"> <font face="Arial" color="#2d8f26"><b>Virus:</b></font> &nbsp; SoberK <br> <br> <noindex><font face="Arial" color="#2d8f26"><b>Status:</b></font> &nbsp; <font face="Arial" color="#ff0000"><b><i>Real.</i></b></font> </noindex> <br> <br> <font face="Arial" color="#2d8f26"><b>Example:</b></font> &nbsp; <font face="Trebuchet MS,Bookman Old Style,Arial" color="#2d8f26"><i> [Collected on the Internet, 2005]</i></font> <br> <br>&nbsp;<table width="90%" align="center" bgColor="#000000" border="0"> <tr> <td bgColor="#eaf2e5"><font face="Verdana" size="2"> <div style="MARGIN: 10px 15px; TEXT-ALIGN: justify"> Dear Sir/Madam, <br> <br> we have logged your IP-address on more than 40 illegal Websites. <br> <br> Important: Please answer our questions!<br> The list of questions are attached. <br> <br> Yours faithfully,<br> M. John Stellford <br> <br> ++-++ Federal Bureau of Investigation -FBI-<br> ++-++ 935 Pennsylvania Avenue, NW, Room 2130<br> ++-++ Washington, DC 20535<br> ++-++ (202) 324-3000 </div> </font></td> </tr> </table> <p><br> <font face="Arial" color="#2d8f26"><b>Origins:</b></font> &nbsp; In mid-February 2005, <nobr>e-mails</nobr> accusing recipients of having visited &quot;more than <nobr>40 illegal</nobr> Websites&quot; and purporting to come from the Federal Bureau of Investigation began turning up. Those cowed by the charge into opening the attachment (indictment_cit9792.zip) unwittingly released the W32.Sober.K@mm virus into their computers, a mass-mailing worm that uses its own SMTP engine to send itself to <nobr> e-mail</nobr> addresses gathered from compromised computers. <br> <br> The FBI has nothing to do with these letters — these missives are purely the work of the virus originator, his or her way of ensuring the attachment accompanying the <nobr>e-mail</nobr> gets opened and thus its payload triggered. On <nobr>22 February</nobr> 2005, the FBI issued the following <a onmouseover="window.status='FBI press release about virus';return true" onmouseout="window.status='';return true" href="http://www.fbi.gov/pressrel/pressrel05/022205.htm" target="fbi" style="color: #0000FF; text-decoration: underline"> press release</a> about these letters: <br>&nbsp;<font face="Verdana" size="2"></p> <div style="MARGIN: 15px 30px; TEXT-ALIGN: justify"> FBI ALERTS PUBLIC TO RECENT E-MAIL SCHEME <br> <br> E-mails purporting to come from FBI are phony <br> <br> Washington, D.C. - The FBI today warned the public to avoid falling victim to an on-going mass <nobr>e-mail</nobr> scheme wherein computer users receive unsolicited <nobr>e-mails</nobr> purportedly sent by the FBI. These scam <nobr>e-mails</nobr> tell the recipients that their Internet use has been monitored by the FBI’s Internet Fraud Complaint Center and that they have accessed illegal web sites. The <nobr> e-mails</nobr> then direct recipients to open an attachment and answer questions. The attachments contain a computer virus. <br> <br> These e-mails did not come from the FBI. Recipients of this or similar solicitations should know that the FBI does not engage in the practice of sending unsolicited <nobr>e-mails</nobr> to the public in this manner. <br> <br> Opening e-mail attachments from an unknown sender is a risky and dangerous endeavor as such attachments frequently contain viruses that can infect the recipient’s computer. The FBI strongly encourages computer users not to open such attachments. <br> <br> The FBI takes this matter seriously and is investigating. Users receiving <nobr>e-mails</nobr> of this nature are encouraged to report it to the Internet Crime Complaint Center via <a onmouseover="window.status='Internet Crime Complaint Center';return true" onmouseout="window.status='';return true" href="http://www.ic3.gov" target="ICCC" style="color: #0000FF; text-decoration: underline"> [url="http://www.ic3.gov</a>"]http://www.ic3.gov</a>[/url]. </div> </font> <p>This is not the first time a virus has been spread via an <nobr> e-mail</nobr> purporting to come from the FBI. In January 2004, a <a onmouseover="window.status='Sober.C';return true" onmouseout="window.status='';return true" href="http://www.snopes.com/inboxer/hoaxes/download.asp" target="SoberC" style="color: #0000FF; text-decoration: underline"> SoberC</a> variant was passed along in similar fashion with its payload <nobr>e-mails</nobr> serving notice that &quot;your computer was scanned&quot; and the &quot;contents of your computer were confiscated.&quot; <!--Symantec offers a <A HREF="http://securityresponse.symantec.com/avcenter/venc/data/w32.sober@mm.removal.tool.html" TARGET=remove>removal tool</A> for Sober.C on their web site.--><br> <br> <font face="Arial" color="#2d8f26"><b>Additional information:</b></font> </p> <table cellSpacing="20" width="277"> <tr> <td width="235"> <font face="Trebuchet MS,Bookman Old Style,Arial" color="#ff0000" size="3"> <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.sober.k@mm.html"> W32.Sober.K Virus (<i>Symantec</i>)</a></font><a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.sober.k@mm.html"> </a></td> </tr> <tr> <td width="235"> <font face="Trebuchet MS,Bookman Old Style,Arial" color="#ff0000" size="3"> <a href="http://www.sophos.com/virusinfo/analyses/w32soberk.html"> W32.Sober.K (Sophos) (<i>Sophos</i>)</a></font><a href="http://www.sophos.com/virusinfo/analyses/w32soberk.html"> </a></td> </tr> <tr> <td width="235"> <font face="Trebuchet MS,Bookman Old Style,Arial" color="#ff0000" size="3"> <a href="http://www.f-secure.com/v-descs/sober_k.shtml">W32.Sober.K Virus (<i>F-Secure</i>)</a></font></td> </tr> </table> </div> </font></td> </tr> </table></div>

Alerts

Posted: Tue Mar 08, 2005 9:29 pm
by Tami
Zafi-D a 'High-Alert' Top Threat

esecurityplanet : Online Threats & Alerts: Zafi-D a 'High-Alert' Top Threat

Success Story - F5 Networks Helps Santa Barbara Charter Fly

IT Management Glossary
data mining
ERP
extranet
grid computing
intranet
network appliance
outsourcing
storage
VPN
virus
FREE Tech Newsletters

Zafi-D a 'High-Alert' Top Threat
March 4, 2005
The Zafi-D worm has not only received 'high alert' threat status, it's become the most widespread malware roaming the Internet.

The worm, which spreads via email attachments and peer-to-peer accounts, received 'high alert' threat status from Sophos, Inc., an anti-virus and anti-spam company with U.S. headquarters in Lynnfield, Mass. Sophos analysts report that the worm harvests email addresses off infected computers and emails copies of itself out to them, and it also installs itself on the computer's registry. When it copies itself to the Windows system folder with the filename Norton Update.exe.

Sophos reports that Zafi-D makes up 30.8 percent of all malware traffic in the wild.

''It looks like the Zafi-D worm is going to be hanging around like a bored teenager for some time to come, unless more home users realise how important it is to update their anti-virus software,'' says Carol Theriault, a security consultant at Sophos. ''This Hungarian worm accounts for almost one in three viruses reported.''

Zafi-D is reported to display a fake error message box with the caption ''CRC: 04F6Bh'' and the text ''Error in packed file!''.


[url="http://www.esecurityplanet.com/alerts/article.php/3487646"]source[/url]

Alerts

Posted: Wed Mar 09, 2005 8:08 am
by Tami
Worm.Win32.Sober.L Alert! A new variant of the Sober worm is spreading fast. As it's predecessors, Sober.L spreads as an email attachment in emails which are sent to all email addresses found on the victim's harddisk. Even if the executable file is packed in a .ZIP file, many users open the file and activate the worm this way. For novice users it's hard to see that it is a worm generated email because the email subject is "your password + accountnumber !". The email body text is the following: hi, i've got an admin mail with a Password and Account info! but the mail recipient are you! it's probably an esmtp error, i think. i've copied the full mail text in the Windows text-editor & zipped. ok, cya... The recipient is advised to open the attached file "Acc_text.zip". The worm also spreads in a German version, which is used on all German email addresses. The German subject is "ich habe ihre e-mail bekommen !". The email body text is: Hallo, jemand schickt ihre privaten Mails auf meinem Account. Ich schaetze mal, das es ein Fehler vom Provider ist. Insgesamt waren es jetzt schon 6 Mails! Ich habe alle Mail-Texte im Texteditor kopiert und gezippt. Wenn es doch kein Fehler vom Provider ist, sorge dafuer das diese Dinger nicht mehr auf meinem Account landen, es Nervt naemlich. Gruss If you start the worm, you will see this window: [attachment=625:attachment] [url="http://www.emsisoft.com/en/malware/?Worm.Win32.Sober.L"]Source & More Information[/url]

Alerts

Posted: Wed Jun 15, 2005 2:36 am
by Endo
W32.Kelvir.DA is a worm that spreads a variant of W32.Randex through MSN Messenger.

Type: Worm
Infection Length: 6,442 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

When W32.Kelvir.DA is executed, it performs the following actions:

1. Sends the following message with a link to all the MSN Messenger contacts on the compromised computer:

its you in this cartoon!!
[http://]cartoonics.nl/[REMOVED]/cartoon.php?email=[RANDOM EMAIL ADDRESS]

Note: It has been reported that [RANDOM EMAIL ADDRESS] may be called nav_rro@hotmail.com.

2. Drops a variant of W32.Randex on the compromised computer if a recipient clicks on the link and downloads the file [RANDOM EMAIL ADDRESS].

Another recent worm puts the word "fucker" in the mouths of the infected, sends out the message: "you are on this picture and you never told me" and links to a would-be Pearl Jam fansite. The badly spelled "groupicture.php" in the URL gives it away, really. That, and the fact that I have not heard about Pearl Jam for 7 years, let alone be on a picture with them.

Other variations claim you're a staff member at a company/hotel/restaurant/whatever called Millenium ("i didnt know you worked here????"), you have a profile page at the wrongly spelled vbulettin site or that you are starring in a packet of beach pictures. For one last time (figuratively, I'm afraid): pictures and zipfiles do NOT have a .PIF extension... nothing worthwile does, actually. And secondly, never ever click links that end with your MSN Messenger account address.

[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.kelvir.da.html"][u][More information \ Source][/u][/url]

Alerts

Posted: Fri Jul 08, 2005 10:49 am
by Tami
Top Threat:Mitglieder.DQ
Executive Summary
Name: Mitglieder.DQ (Panda)
Affects: Windows 2003/XP/2000/NT/ME/98/95
Size: 36,864 bytes

What it does: Mitglieder.DQ is a Trojan horse program with no direct mechanism for spreading. It is placed on web sites and other media from which users are tricked into downloading and executing it.

It contains a large number of process names belonging to security software and the software that keeps it up to date and it attempts to stop these processes. It then attempts to download the file OSA3.GIF from a large list of web sites. The .GIF extension is meant to trick users and security software; the file is actually an executable.

The program also copies two files, WINSHOST.EXE and WIWSHOST.EXE, to the Windows System directory. The first is a copy of the Trojan, the second a DLL used by it. It also overwrites the Windows HOSTS file with the following text:

127.0.0.1 localhost

It also creates registry values for itself in the HKEY_LOCAL_MACHINE and HKEY_CURRENT_USER Run keys in order to run itself at boot time. It creates one more value:

HKEY_CURRENT_USER\ Software\ FirstRun
FirstRunRR = 0x00000001

as an infection mark, in order to check if it has already affected the computer.

How to avoid it: Install antivirus software and keep it up to date. Only run executables from highly-trusted sources.

How to remove it: Delete the following registry keys from the system:

* HKEY_LOCAL_MACHINE\ Software\ Microsoft\ Windows\ CurrentVersion\ Run
winshost.exe = %sysdir%\winshost.exe
* HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Run
winshost.exe = %sysdir%\winshost.exe
* HKEY_CURRENT_USER\ Software\ FirstRun
FirstRunRR = 0x00000001

(%sysdir% is the Windows system directory)

Then restart the computer. Afterwards delete %sysdir%\winshost.exe and %sysdir%\wiwshost.exe.

It's best also to scan your system with an up-to-date anti-virus scanner at this point.

[url="http://www.pcmag.com/article2/0,1895,1832264,00.asp"]source: PCMag[/url]