Page 8 of 9

Alerts

Posted: Thu Aug 26, 2004 1:40 pm
by Tami
W32.Tiniresu
Discovered on: August 24, 2004
Last Updated on: August 26, 2004 07:28:46 AM

W32.Tiniresu is a virus that infects the Userinit.exe file and downloads and executes a file from a remote location.

Type: Virus
Infection Length: 48,132 Bytes

Systems Affected: Windows 2000, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98

Technical Details:

When W32.Tiniresu is executed, it performs the following actions:


Locates %System%\Userinit.exe, and if the file is less than 25,600 bytes long, infects it by prepending 48,128 bytes and appending four extra bytes at the end of the file.

Note: %System% is a variable that refers to the System folder. By default, this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Opens backdoor ports and sends the infected system's IP address and backdoor port numbers to the following addresses:

brtblrvn.hopto.org
brtblrvn.no-ip.info
dlzdvlnj.hopto.org
dlzdvlnj.no-ip.info
hzlhpzxb.hopto.org
hzlhpzxb.no-ip.info
jtrjztpx.hopto.org
jtrjztpx.no-ip.info
lnxljnht.hopto.org
lnxljnht.no-ip.info
nhdnthzp.hopto.org
nhdnthzp.no-ip.info
pbjpdbrl.hopto.org
pbjpdbrl.no-ip.info
rvprnvjh.hopto.org
rvprnvjh.no-ip.info
tpvtxpbd.hopto.org
tpvtxpbd.no-ip.info
vjbvhjtz.hopto.org
vjbvhjtz.no-ip.info
xdhxrdlv.hopto.org
xdhxrdlv.no-ip.info
zxnzbxdr.hopto.org
zxnzbxdr.no-ip.info

Note: no-ip.info and hopto.org are dynamic DNS sites.


Retrieves and executes a file from a remote location.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as W32.Tiniresu.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.tiniresu.html\"]source[/url]

Alerts

Posted: Thu Aug 26, 2004 1:44 pm
by Tami
W32.Lovgate.AO@mm
Discovered on: August 25, 2004
Last Updated on: August 26, 2004 10:09:36 AM

W32.Lovgate.AO@mm is a mass-mailing worm that propagates through open network shares and prepends itself to .exe files.

The email has a variable subject and attachment name, with a .bat, .cmd, .com, .exe, .pif, .scr, or.zip file extension.

Also Known As: I-Worm.LovGate.ah [Kaspersky]

Type: Worm
Infection Length: varies

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x

Technical Details:

When W32.Lovgate.AO@mm is run, it does the following:


Creates a network share, named JAVA, which is mapped to %Windir%\JAVA.

Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.


Copies itself to all the network shares using one or more of the following names:

Daemon Tools v3.41.exe
EnterNet 500 V1.5 RC1.exe
Flash2X Flash Hunter v1.1.2.pif
FoxMail V5.0.500.0.exe
Microsoft Office.exe
Minilyrics_Std_2.7.233.pif
Serv-U FTP Server 4.1.exe
Support Tools.exe
WINISO 5.3.exe
WinGate V5.0.10 Build.exe
Winamp skin_FinalFantasy.exe
Windows 2000 sp4.ZIP.exe
Windows Media Player.zip.exe
autoexec.bat
eMule-0.42e-VeryCD0407Install.exe
i386.exe


Creates the following files:

%Windir%\Office.exe
%Windir%\Video.EXE
%System%\IEXPLORE.EXE
%System%\Kernel66.dll (A hidden file.)
%System%\TkBellExe.exe
%System%\Update_OB.exe
%System%\hxdef.exe
%System%\iexplorer.exe
%System%\real.exe

Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the following files:

%System%\Lmmib20.dll
%System%\MSSIGN30.DLL
%System%\ODBC16.dll
%System%\msjdbc11.dll

which make up the worm's backdoor component.


Creates the file, upDate.exe, in the root folder of all the drives, except for CD-ROM drives. The file attributes of this file are set to System, Hidden, and Read-only.


Drops a file named %System%\WinPatch.dll.


Creates and starts the following services:
_reg
Windows Management Protocol v.0(experimental)


Overwrites the autorun.inf file on each drive with the following:

[AUTORUN]
Open="C:\upDate.exe" /StartExplorer


Creates an archive containing a copy of the worm with the following format in the root folder of all the drives, unless the drive letter is A or B:

<filename>.RAR

where <filename> may be one of the following:

Bakeup
ghost
email


Adds the values:

"Microsoft Inc." = "iexplorer.exe..."
"Program In Windows" = "%System%\IEXPLORE.EXE"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"WinHelp" = "%System%\TkBellExe.exe..."

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that it executes every time Windows starts.


Adds the values:

"Installed shell32.dll" = "Office.exe..."
"SystemTra" = "C:\WINDOWS\Video.EXE"
"Soft Profile Inc" = "%System%\hxdef.exe..."

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices

so that it executes every time Windows 95/98/Me starts.


Adds the value:

"run" = "real.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows


Adds the value:

"(Default)" = "Update_OB.exe %1..."

to the registry key:

HKEY_CLASSES_ROOT\txtfile\shell\open\command

so that the worm runs each time a .txt file is opened.


Stops the following services:

Rising Realtime Monitor Service
Symantec AntiVirus Client
Symantec AntiVirus Server


Terminates any processes with the following strings in their names:

Duba
Gate
KAV
KV
McAfee
NAV
RavMon.exe
Rfw.exe
SkyNet
Symantec
kill
rising


Injects a process-watching procedure as a thread into either Explorer.exe or Taskmgr.exe. This thread will attempt to launch %System%\Iexplore.exe if it detects that the worm's process has stopped.


The worm will then listen on TCP port 6060. The backdoor procedures steal information of an infected computer and stores it in the file, C:\Netlog.txt. The worm then emails the stolen information to the hacker.


Extracts the location of the KaZaA-shared folder from the registry. Then, it copies itself to the folder as one of the following:

BlackIcePCPSetup_creak
HEROSOFT
Passware5.3
REALONE
W32Dasm
orcard_original_creak
rainbowcrack-1.1-win
setup
word_pass_creak
wrar320sc
<random file name>

with a .bat, .exe, .pif, or .scr file extension.


Scans all the computers attached to the same network segment as the infected computer. The worm will attempt to authenticate to administrative shares on systems that are found, using "Administrator" as a user name, combined with the following passwords:

!@#$
!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
000000
00000000
007
110
111
111111
11111111
121212
123
123123
1234
12345
123456
1234567
12345678
123456789
123abc
123asd
2003
2004
2600
321
54321
654321
666666
888888
88888888
Admin
Administrator
Guest
Internet
Login
Password
aaa
abc
abc123
abcd
abcdef
abcdefg
admin
admin123
administrator
alpha
asdf
asdfgh
computer
database
enable
god
godblessyou
guest
home
login
love
mypass
mypass123
mypc
mypc123
oracle
owner
pass
passwd
password
pw123
pwd
root
secret
server
sex
sql
super
sybase
temp
temp123
test
test123
win
yxcv
zxcv
zzz


If the worm successfully authenticates to a remote system, it will attempt to copy itself as:

\\<remote computer name>\admin$\system32\TelePhone.exe


Starts the file as the service, "NetWork Associates Inc."


Replies to any messages that arrive in the mailbox of certain MAPI-compliant email clients, such as Microsoft Outlook.

For example, if the incoming email has the following properties:

Subject: <subject>
From: <sender>@<domain.com>
Message: <original message body>

the worm will attempt to send the following email:

Subject: Re: <subject>
To: <sender>@<domain.com>

Message:
'<sender>' wrote:
====
> <original message body>
====

<domain.com> account auto-reply:

... ... more details,look to the attachment.

> Get your FREE <domain.com> account now! <

Attachment: (One of the following)
Butterfly Garden.scr
FlashFXP.exe
HyperSnap-DX v5.rar.exe
Industry Giant II.exe
MSN Messenger.exe
MacroMedia.pif
Macromedia Flash.scr
Matrix Reloaded 3D.exe
MyIE.AVI.pif
Photoshop.EXE
Shakira.zip.exe
StarWars2 - CloneAttack.rm.scr
WindowsXP Creak.exe
dreamweaver MX (crack).exe
joke.exe
s3msong.MP3.pif


Retrieves the email addresses on the infected machine and sends an email with the following properties. The From field may be spoofed.

Subject: (One of the following)

Delivery Status Notification (Delay)
Error
Hi
Mail Transaction Failed
Test
<blank>

Message: (One of the following)

Delivery to the following recipient has failed:
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.
Mail failed. For further assistance, Please contact!
THIS IS A WARNING MESSAGE ONLY.
The message contains Uniocode characters and has been sent as a binary attachment.
This is an automatically generated Delivery Status Notification
YOU DO NOT NEED TO RESEND YOUR MESSAGE.
<blank>

Attachment: (One of the following)

Body
Doc
Document
File
Message
Readme
Test
Text
data
<random>

Extension: (One of the following)

.bat
.cmd
.com
.exe
.pif
.scr
.zip


Searches the hard disk for .exe files. When it finds one, it creates a viral file, %System%\temp.uuu, and prepends this file to the .exe file. These files will be detected as W32.Lovgate.AO@mm!inf.

Removal Instructions:

Disable System Restore (Windows Me/XP).

Update the virus definitions.

Reverse the changes made to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the values:

"Microsoft Inc." = "iexplorer.exe..."
"Program In Windows" = "%System%\IEXPLORE.EXE"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"WinHelp" = "%system%\TkBellExe.exe..."


If you are using Windows 95/98/Me, navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices


In the right pane, delete the values:

"SystemTra" = "C:\WINDOWS\Video.EXE"
"Soft Profile Inc" = "%System%\hxdef.exe..."
"Installed shell32.dll" = "Office.exe..."


If you are using Windows NT/2000/XP, navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows


In the right pane, delete the value:

"run" = "real.exe"


Navigate to the key:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services


In the right pane, delete the subkeys:

_reg
Windows Management Protocol v.0(experimental)


Navigate to the key:

HKEY_CLASSES_ROOT\txtfile\shell\open\command


In the right pane, change the value to:

Windows 95/98/Me:
"(Default)"="WINDOWS\NOTEPAD.EXE %1"

Windows NT/2000/XP:
"(Default)"="%SystemRoot%\system32\NOTEPAD.EXE %1"


Exit the Registry Editor.


Restart the computer in Safe mode or VGA mode.

Run a full system scan and delete all the files detected as W32.Lovgate.AO@mm.

Repair those detected as W32.Lovgate.AO@mm!inf.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.ao@mm.html\"]source[/url]

Alerts

Posted: Fri Aug 27, 2004 4:37 pm
by Tami
W32.Scane
Discovered on: August 26, 2004
Last Updated on: August 27, 2004 04:11:26 PM

W32.Scane is a worm that attempts to spread by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability.



Type: Worm
Infection Length: 71,416 bytes



Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT


Technical Details:

When W32.Scane executes, it does the following:

May copy itself as %System%\servicec.exe

Note: %System% is a variable that refers to the System folder. By default this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the values:

"WinLsass"="%System%\servicec.exe" or
"WinLsass"="<path to original threat file>"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the W32.Scane runs when you start Windows.


Creates multiple threads that attempt to connect to a random block of IP addresses by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability on TCP port 445. If successful, the remote system attempts to download a copy of the worm from the host.


Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restarting the computer in Safe mode or VGA mode
Run a full system scan and delete all the files detected as W32.Scane.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete either of the following values:

"WinLsass"="%System%\servicec.exe"
"WinLsass"="<path to original threat file>"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.scane.html\"]source[/url]

Alerts

Posted: Sat Aug 28, 2004 3:40 am
by Tami
W32.Spybot.DAZ
Discovered on: August 27, 2004
Last Updated on: August 28, 2004 10:58:19 AM

W32.Spybot.DAZ is a worm that spreads through IRC, network shares, exploits, and computers that are infected with common backdoor Trojan horses.

Type: Worm

Systems Affected: Windows 2000, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details

When W32.Spybot.DAZ is executed, it does the following:


Copies itself as %System%\mvsc.exe

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the value:

"Microsoft Update" = "mvsc.exe"

to the registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

Note: The name of the value may change if an attacker sends a command to change it.


Modifies the value:

"EnableDCOM" = "N"

in the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM


Modifies the value:

"restrictanonymous" = "1"

in the registry key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa


Scans for other computers on the network, attempting to connect to shared resources using a predetermined list of usernames and passwords. If successful, the worm will attempt to copy itself to the remote computer.


Connects to a remote IRC server on TCP port 6667 and listens for commands, including any of following:

Download and execute files.
Scan the network for server with running backdoor trojan horses.
List, stop, and start processes.
Launch Denial of Service (DoS) attacks.
Steal system information and send it to the attacker.
Log keystrokes to a file in the %System% folder.
Open a backdoor port.
Control the file system (Delete, create, and list files).
Perform port redirection.
Flush DNS server.


Creates a log file, named c:\debug.txt, containing information about the IRC servers the worm is connected to.


May spread by exploiting the following vulnerabilities:

The DCOM RPC Vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135.
The Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011).
The vulnerabilities in the Microsoft SQL Server 2000 or MSDE 2000 audit (described in Microsoft Security Bulletin MS02-061) using UDP port 1434.
The WebDav Vulnerability (described in Microsoft Security Bulletin MS03-007) using TCP port 80.
The UPnP NOTIFY Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS01-059).
The Workstation Service Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-049) using TCP port 445. Windows XP users are protected against this vulnerability if the patch in Microsoft Security Bulletin MS03-043 has been applied. Windows 2000 users must apply the patch in Microsoft Security Bulletin MS03-049.


May steal CD keys and passwords for the following games:

Battlefield 1942
Battlefield 1942 (Road To Rome)
Battlefield 1942 (Secret Weapons of WWII)
Battlfield Vietnam
Black and White
Chrome
Command and Conquer: Generals
Command and Conquer: Red Alert
Command and Conquer: Red Alert 2
Command and Conquer: Tiberian Sun
Counter-Strike
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden & Dangerous 2
IGI 2: Covert Strike
Industry Giant 2
James Bond 007: Nightfire
Legends of Might and Magic
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
Need For Speed Hot Pursuit 2
Need For Speed: Underground
Neverwinter Nights
Neverwinter Nights (Hordes of the Underdark)
Neverwinter Nights (Shadows of Undrentide)
NHL 2002
NHL 2003
NOX
Rainbow Six III RavenShield
Shogun: Total War: Warlord Edition
Soldier of Fortune II - Double Helix
Soldiers Of Anarchy
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Spybot.DAZ
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the following keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Microsoft Update" = "mvsc.exe"


Exit the Registry Editor

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.daz.html\"]source[/url]

Alerts

Posted: Wed Sep 01, 2004 4:48 pm
by Tami
Downloader.CDT
Discovered on: August 30, 2004
Last Updated on: September 01, 2004 11:08:09 AM

Downloader.CDT is a Trojan horse program that downloads several files from a specific website.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

When the Trojan is executed it performs the following actions:


Creates the following copy of itself:
[Random name].exe


Adds the following values:

"CurrentLevel" = "0"
"Flags" = "0"
"1001" = "0"
"1004" = "0"
"1200" = "0"
"1201" = "0"
"1206" = "0"
"1400" = "0"
"1402" = "0"
"1405" = "0"
"1406" = "0"
"1407" = "0"
"1601" = "0"
"1604" = "0"
"1605" = "0"
"1606" = "0"
"1607" = "0"
"1608" = "0"
"1609" = "0"
"1800" = "0"
"1802" = "0"
"1803" = "0"
"1804" = "0"
"1805" = "0"
"1A00" = "0"
"1A02" = "0"
"1A03" = "0"
"1A04" = "0"
"1A05" = "0"
"1A06" = "0"
"1A10" = "0"
"2001" = "0"
"2004" = "0"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3

to lower the security settings in Microsoft Internet Explorer.


Attempts to open a Web site in the domain counterstrike.server.us, and download a program named Adware.CDT.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Downloader.CDT.
Restoring security settings in Microsoft Internet Explorer.

To restore the security level, complete the following steps:
Start Internet Explorer.
Click Tools, and then click Internet Options.
Select the Security tab.
Reset the security settings to the level you desire.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/downloader.cdt.html\"]source[/url]

Alerts

Posted: Wed Sep 01, 2004 4:54 pm
by Tami
Trojan.Hiva
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 10:54:38 AM

Trojan.Hiva is a Trojan horse program that uses net-send commands to send alert messages, moves the mouse randomly, and closes program windows.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

When the Trojan is executed, it does the following:


Creates the following files:
Windows%\HIV.exe
Windows%\HIVmod1.exe
Windows%\HIVmod2.exe
Windows%\HIVmod3.exe
Windows%\HIVmod4.exe


Adds the following value:

"HIV"="HIV.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that it is executed every time Windows starts.


Uses net-send commands to display the following alert box:

HIV+ infected


Performs some of the following actions:
Moves the mouse randomly
Closes program windows
Attempts to open the CD-ROM drive


Uses net-send commands to send alert messages to random IP addresses.


Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Hiva.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"HIV"="HIV.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.hiva.html\"]source[/url]

Alerts

Posted: Wed Sep 01, 2004 4:55 pm
by Tami
Backdoor.Alets
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 10:52:46 AM

Backdoor.Alets is a backdoor Trojan horse that allows a remote attacker to have unauthorized access to an infected computer, via IRC channels.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

Once the Trojan is executed, it performs the following actions:


Creates the following copy of itself:

%Windir%\services.exe


Adds the following value:

"Microsoft Services"="%Windir%\services.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that it is executed every time Windows starts.


Contacts an IRC server on the domain, ctgbn.stellaremperor.com, through TCP port 32440.


Awaits commands from a remote attacker to perform the following actions:
Kill processes
Download and execute files

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Alets.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Microsoft Services"="%Windir%\services.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.alets.html\"]source[/url]

Alerts

Posted: Wed Sep 01, 2004 5:01 pm
by Tami
Download.Ject.D
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 04:27:11 PM

Download.Ject.D is a variant of [url=\"http://securityresponse.symantec.com/avcenter/venc/data/download.ject.c.html\"]Download.Ject.C[/url] that attempts to download and execute files.

Note: LiveUpdate Virus definitions are scheduled to be released on 8/31/04 to provide protection against this threat. Virus definitions version 60831j (extended version 8/31/2004 rev. 36) and greater are required for detection.

Variants: Download.Ject.C
Type: Trojan Horse
Infection Length: 12,800 Bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Technical Details:

When Download.Ject.D is executed, it performs the following actions:



Creates the following files:

%System%\Doriot.exe (A copy of itself)
%System%\Gdqfw.exe (A downloader module)

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the value:

"wersds" = "%System%\doriot.exe"

to the registry keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs when you start Windows.


Injects Gdqfw.exe into Explorer.exe as a remote thread, which attempts to do the following:

Stops the service, "SharedAccess," and then sets the Startup type of this service to Disabled.

Terminates the following processes:

ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE


Attempts to download a file from one of the following domains. The file is saved as %Windir%\_re_file.exe, and is then executed.

Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.

allianzsp.sk
coolweb.psg.sk
cryofthespirit.com
dollypop.com
execpage.com
helpdemos.com
helpingyouth.org
jamesbronner.com
koti.pl
miracle.v6.cz
mountainwings.com
mountainwings4.com
naturalpros.com
oracal.pl
shock.evernet.com.pl
SportLine.go.ro
stroipolymer.ru
theonlineword.com
virtualchurch.com
visionforsouls.org
wingsoverlife.com
www.1800thewoman.com
www.1944.pl
www.45partsdepot.com
www.7pe.friko.pl
www.air-computers.com.ar
www.ametist.spb.ru
www.apodis.pl
www.arrasy.pl
www.arthurspeaks.com
www.astermed.pl
www.atomique.pl
www.atw.hu
www.avatar.ee
www.avers.com.pl
www.baltexpo.spb.ru
www.bomart.cz
www.bravo.gliwice.pl
www.bronnerbros.com
www.buycare.com
www.cumparacd.go.ro
www.da-rom.co.il
www.domu.net
www.eastandard.co.ke
www.elblu.republika.pl
www.elcorsy.com
www.elite-style.com
www.enduser1.fast.net
www.enitex.by
www.enitex-m.by
www.eris.pl
www.europharm.pl
www.extreme-racing.lg.ua
www.fotel.pl
www.fotolab.sk
www.frater.hu
www.gardameditech.com
www.generex.de
www.goldgates.com
www.goodboy.dem.ru
www.hards.pl
www.healthcometh.com
www.holz-studio.at
www.ibplus.sk
www.icpnet.pl
www.icpnet.pl
www.inlan.sk
www.jamesbronner.com
www.jbplus.cz
www.justmatchit.com
www.kubtelecom.ru
www.kuda.com.ua
www.lacittadifiorenzuola.it
www.lotusdog.net
www.ltvo.spb.ru
www.master.pl
www.members.aon.at
www.moteplassen1.com
www.mountainwings2.com
www.multifoto.sk
www.nadodrze.pl
www.nairobiwebspace.com
www.nameitright.com
www.nardo.bbe.pl
www.netland.gda.pl
www.netta.pl
www.nikola.piwko.pl
www.ntrlab.com
www.nustep.sk
www.octava.pl
www.odevnictvo.sk
www.oftza.friko.pl
www.oktbroiler.ru
www.online40.com
www.online50.com
www.oto.lv
www.pancoopzsv.co.yu
www.pay5495.com
www.pc-hard.com.ua
www.perfect-beauty.at
www.pharmag.pl
www.polsl.katowice.pl
www.prophetcollins.com
www.propi.cz
www.pursuit.rv.ua
www.pyrlandia-boogie.pl
www.quatro.sk
www.r-bazar.ru
www.roszkowski.pl
www.silvic.ro
www.sincron.go.ro
www.skylive.pl
www.smgkrc.pl
www.soulring.com
www.star-max.it
www.sunbud.com.pl
www.swez.net
www.system5electronics.com
www.tcvwebtv.com.ar
www.thewoman.com
www.tivis.cz
www.ukpl.pl
www.vacation-network.net
www.wyspian.iap.pl
www.zasada-rowery.pl

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Download.Ject.D.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"wersds" = "%System%\doriot.exe"


Exit the Registry Editor.

Restart the computer in normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/download.ject.d.html\"]source[/url]

Alerts

Posted: Wed Sep 01, 2004 5:04 pm
by Tami
W32.Beagle.AQ@mm
Discovered on: August 31, 2004
Last Updated on: September 01, 2004 04:22:27 PM

W32.Beagle.AQ@mm is a variant of W32.Beagle.AO@mm, which is a mass-mailing worm that uses its own SMTP engine to spread. The email attachment is a downloader, similar to Trojan.Mitglieder and Download.Ject.C, that downloads the worm from an external source.

The worm also contains backdoor functionality, opening TCP port 80 and UDP port 80.

Variants: W32.Beagle.AO@mm
Type: Worm
Infection Length: 12,800 bytes, 18,436 bytes, 9,728 Bytes. 4,996 Bytes, 9,728 Bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Techincal Details:

When W32.Beagle.AQ@mm runs, it does the following:


Copies itself as the following files:

%System%\windll.exe. (A copy of the worm)
%System%\windll.exeopen (A copy of the worm)
%System%\windll.exeopenopen (A copy of the worm)

Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the value:

"erthgdr"="%System%\windll.exe"

to the registry key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n



Creates seven mutexes with the following names, which prevent some variants of the W32.Netsky@mm family of worms from running:

MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_




Deletes any values that contain the following strings:

9XHtProtect
Antivirus
EasyAV
FirewallSvr
HtProtect
ICQ Net
ICQNet
Jammer2nd
KasperskyAVEng
MsInfo
My AV
NetDy
Norton Antivirus AV
PandaAVEngine
SkynetsRevenge
Special Firewall Service
SysMonXP
Tiny AV
Zone Labs Client Ex
service

from the registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n


Create copies of itself in any folder that contains the characters "shar". The files will have the following file names:

Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral, /censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> cool, awesome!!.exe
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe


Attempts to download and execute files from the following Web sites as %System%\_re_file.exe:

allianzsp.sk
coolweb.psg.sk
cryofthespirit.com
dollypop.com
execpage.com
helpdemos.com
helpingyouth.org
jamesbronner.com
koti.pl
miracle.v6.cz
mountainwings.com
mountainwings4.com
naturalpros.com
oracal.pl
shock.evernet.com.pl
SportLine.go.ro
stroipolymer.ru
theonlineword.com
virtualchurch.com
visionforsouls.org
wingsoverlife.com
www.1800thewoman.com
www.1944.pl
www.45partsdepot.com
www.7pe.friko.pl
www.air-computers.com.ar
www.ametist.spb.ru
www.apodis.pl
www.arrasy.pl
www.arthurspeaks.com
www.astermed.pl
www.atomique.pl
www.atw.hu
www.avatar.ee
www.avers.com.pl
www.baltexpo.spb.ru
www.bomart.cz
www.bravo.gliwice.pl
www.bronnerbros.com
www.buycare.com
www.cumparacd.go.ro
www.da-rom.co.il
www.domu.net
www.eastandard.co.ke
www.elblu.republika.pl
www.elcorsy.com
www.elite-style.com
www.enduser1.fast.net
www.enitex.by
www.enitex-m.by
www.eris.pl
www.europharm.pl
www.extreme-racing.lg.ua
www.fotel.pl
www.fotolab.sk
www.frater.hu
www.gardameditech.com
www.generex.de
www.goldgates.com
www.goodboy.dem.ru
www.hards.pl
www.healthcometh.com
www.holz-studio.at
www.ibplus.sk
www.icpnet.pl
www.icpnet.pl
www.inlan.sk
www.jamesbronner.com
www.jbplus.cz
www.justmatchit.com
www.kubtelecom.ru
www.kuda.com.ua
www.lacittadifiorenzuola.it
www.lotusdog.net
www.ltvo.spb.ru
www.master.pl
www.members.aon.at
www.moteplassen1.com
www.mountainwings2.com
www.multifoto.sk
www.nadodrze.pl
www.nairobiwebspace.com
www.nameitright.com
www.nardo.bbe.pl
www.netland.gda.pl
www.netta.pl
www.nikola.piwko.pl
www.ntrlab.com
www.nustep.sk
www.octava.pl
www.odevnictvo.sk
www.oftza.friko.pl
www.oktbroiler.ru
www.online40.com
www.online50.com
www.oto.lv
www.pancoopzsv.co.yu
www.pay5495.com
www.pc-hard.com.ua
www.perfect-beauty.at
www.pharmag.pl
www.polsl.katowice.pl
www.prophetcollins.com
www.propi.cz
www.pursuit.rv.ua
www.pyrlandia-boogie.pl
www.quatro.sk
www.r-bazar.ru
www.roszkowski.pl
www.silvic.ro
www.sincron.go.ro
www.skylive.pl
www.smgkrc.pl
www.soulring.com
www.star-max.it
www.sunbud.com.pl
www.swez.net
www.system5electronics.com
www.tcvwebtv.com.ar
www.thewoman.com
www.tivis.cz
www.ukpl.pl
www.vacation-network.net
www.wyspian.iap.pl
www.zasada-rowery.pl

Note: %System% is a variable. The Trojan locates the Windows installation folder and saves the downloaded files to that location. By default, this is C:\Windows\System32 or C:\Winnt\System32.



Terminates the following processes:

ATUPDATER.EXE
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE


Searches for the email addresses in files that have the following extensions:

.adb
.asp
.cfg
.cgi
.dbx
.dhtm
.eml
.htm
.jsp
.mbx
.mdx
.mht
.mmf
.msg
.nch
.ods
.oft
.php
.pl
.sht
.shtm
.stm
.tbb
.txt
.uin
.wab
.wsh
.xls
.xml


Skips email addresses that contain the following strings:

@avp.
@derewrdgrs
@eerswqe
@foo
@iana
@messagelab
@microsoft
abuse
admin
anyone@
bsd
bugs@
cafee
certific
contract@
feste
free-av
f-secur
gold-certs@
google
help@
icrosoft
info@
kasp
linux
listserv
local
news
nobody@
noone@
noreply
ntivi
panda
pgp
postmaster@
rating@
root@
samples
sopho
spam
support
unix
update
winrar
winzip


Uses its own SMTP engine to send email messages to any addresses that are found.

The email may have the attachments "fotos.zip", which is a WinZip file containing "foto.html", and "foto1.exe".

Creates the following files:

%System%\Doriot.exe (A copy of foto1.exe)
%System%\Gdqfw.exe (A downloader module)

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the value:

"wersds" = "%System%\doriot.exe"

to the registry keys:

HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you start Windows.

Opens backdoors on TCP port 80 and UDP port 80, which allow the infected computer to be used as an email relay.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AQ@mm.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n


In the right pane, delete the value:

"erthgdr"="%System%\windll.exe"


Navigate to the key:

HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Run


In the right pance, delete the value

"wersds" = "%System%\doriot.exe"


Navigate to the key:

HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Run


In the right pance, delete the value

"wersds" = "%System%\doriot.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.aq@mm.html\"]source[/url]

Alerts

Posted: Thu Sep 02, 2004 7:46 am
by Tami
Trojan.Yipid
Discovered on: September 01, 2004
Last Updated on: September 02, 2004 03:02:58 PM

Trojan.Yipid is a trojan that downloads files from the Internet, searches the system for email addresses, and sends a Chinese language email to all the addresses it finds.

Infection Length: 61440 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX

When Trojan.Yipid is executed it performs the following actions:


Copies itself to the %System% as:

Rund132.exe


Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

Attempts to download files from the domain chinaweb.a184.zgsj.com to the following folders:

%system%\MSWinsck.ocx (a legitimate file)
%system%\conmax.exe (collects email addresses)
%system%\msimn.exe (sends out emails)


Adds the value:

"Run"="%System%\Rund1.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows


And adds the value:

"Taskbell.exe" = "%System%\Rund1.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsCurrentVersion\Run

These entries ensure that Trojan.Yipid runs upon Windows startup.


Collects email addresses from files with the following extensions:

.txt
.htm
.html
.asp
.xml
.com


The trojan avoids email addresses that contain any of the following substrings:

guang
searchgov
edu
microsoft
rising
jiangmin
kingsoft
symantec
norton
263
163
nease
126
tom
371
sina
china
sohu
chinaren
21cn


Appends the found email addresses to the file:

%system%\mmtxt.txt


Registers the legitimate file, mswinsck.ocx, and sends email to all the collected addresses. The From address is spoofed and the message contains a text written in Chinese inviting the recipient to visit the domain chinaweb.a184.zgsj.com

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Yipid.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Taskbell.exe" = "%System%\Rund1.exe"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows


In the right pane, delete the value:

"Run"="%System%\Rund1.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.yipid.html\"]source[/url]

Alerts

Posted: Fri Sep 03, 2004 1:48 pm
by Tami
W32.IRCBot.F
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 01:59:58 PM

W32.IRCBot.F is a backdoor Trojan horse that connects to an IRC server and waits for commands from an attacker.

Variants: W32.IRCBot.E
Type: Trojan Horse
Infection Length: 95,744

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, UNIX, Windows 3.x

When W32.IRCBot.F is executed, it attempts to perform the following actions:


Copies itself as %System%\Securitychk.exe.

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the value:

"Microsoft Secure Messenger.NET Service" = "securitychk.exe"

to the registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs when you start Windows.


Deletes the shares from local drives.


Connects to the IRC server tehr8x.spbx.net using TCP port 6667.


Joins a predefined channel, using a random nickname, and waits for commands from the IRC server. These commands can allow the attacker to:
Manage the installation of the Trojan
Control the IRC client on a compromised computer
Update the installed Trojan
Send the Trojan to other IRC channels
Download and execute files
Perform Denial of Service (DoS) attacks against a target, which the hacker defines
Uninstall itself completely by removing the relevant registry entries
Go to Web sites
Copy itself to shared folders on other computers
Steal license keys for games including:
Battlefield 1942
Battlefield 1942: Secret Weapons of WWII
Battlefield 1942: The Road To Rome
Battlefield 1942: Vietnam
Black and White
Command and Conquer: Generals
Command and Conquer: Generals: Zero Hour
Command and Conquer: Red Alert2
Command and Conquer: Tiberian Sun
Counter-Strike
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden and Dangerous 2
IGI2: Covert Strike
Industry Giant 2
James Bond 007: Nightfire
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
NHL 2002
NHL 2003
Need for Speed: Hot Pursuit 2
Need for Speed: Underground
Neverwinter Nights
Ravenshield
Shogun: Total War: Warlord Edition
Soldiers Of Anarchy
Soldier Of Fortune 2
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004
Soldier Of Fortune II - Double Helix


Terminate processes. Refer to the "Additional Information" section for a list of the processes that may be terminated.

Removal Instructions

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.IRCBot.F.
Delete the values that were added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to each of these keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

Note: All the keys will not be found on all the systems.


From each key that is found, in the right pane, delete the value:

"Microsoft Secure Messenger.NET Service" = "securitychk.exe"


Exit the Registry Editor.

Restart the computer in normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.ircbot.f.html\"]source[/url]

Alerts

Posted: Fri Sep 03, 2004 1:50 pm
by Tami
Backdoor.Balkart
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 11:22:24 AM

Backdoor.Balkart is a backdoor Trojan horse that can act as a HTTP proxy or FTP server.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

When the Trojan is executed, it performs the following tasks:


Copies itself as %Windir%\ÎäÒíÑ.exe.

Notes:
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
The file name is in Arabic. On systems that do not have the Arabic character set installed, it will be displayed as shown above. If the Arabic character set is installed, it may look like this:




Adds the value:

"alkasr" = "%windir%\ÎäÒíÑ.exe"

to the registry entry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the Trojan is executed every time that Windows starts.


Creates a backdoor by opening port 12121/TCP.


Performs a HTTP GET request, providing the attacker with a log of infected machines.


Waits for commands from a remote attacker to do any of the following:
Stop processes
Execute commands
Use the compromised system as an FTP server or SOCKS proxy

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Balkart.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"alkasr" = "%windir%\ÎäÒíÑ.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.balkart.html\"]source[/url]

Alerts

Posted: Fri Sep 03, 2004 1:52 pm
by Tami
Backdoor.Akak
Discovered on: September 02, 2004
Last Updated on: September 03, 2004 11:16:52 AM

Backdoor.Akak is a backdoor server that also creates a SOCKS proxy on the compromised system. Reports indicate that Web sites exploiting the Microsoft Internet Explorer Drag And Drop File Installation Vulnerability may install it.

Also Known As: Backdoor.Win32.BoomRaster.a (KAV)

Type: Trojan Horse
Infection Length: 8704 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

Backdoor.Akak is a backdoor server program that may be installed when you visit a malicious Web site using Internet Explorer. These pages may contain code that exploits the Microsoft Internet Explorer Drag And Drop File Installation Vulnerability.

If Backdoor.Akak runs, it will download the file, Testexe.exe or Rb.exe, to the Windows Startup folder.

Following this, when you start Windows, it does the following:


Executes the downloaded file.


Creates the mutex "J&^srl!hsl^AHSgh" so that only one instance of the backdoor is present in memory.


Registers itself as a service so that it continues to run even if you log off.


Copies itself as %System%\rb.exe.

Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the value:

"RamBooster2"="%System%\rb.exe "

in the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs every time that Windows starts.


Issues the command "net stop SharedAccess" to disable the Windows Internet Connection Firewall (ICF), if it is running on the system. (Windows 2000/XP).


Contacts a master server located at 202.104.242.156 on TCP port 4321 and downloads information, which is stored in the file, %System%\lhosts.txt.


If the backdoor cannot create the lhosts.txt file, it will instead store this information in the file, Kaka2.txt, which it creates in the current working folder.


Creates a SOCKS proxy on TCP port 5555. This allows the compromised computer to be used to proxy protocols such as HTTP.


Listens on TCP port 4321 for commands from the remote attacker. The attacker can do any of the following:
Obtain system information
Download and execute files on the compromised computer
Uninstall the back door
Update the address of the master server

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Akak.
Delete the value that was added to the registry.
Re-enable the SharedAccess service (Windows 2000/XP only).

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"RamBooster2" =" %System%\rb.exe"


Exit the Registry Editor.


5. To re-enable the SharedAccess service (Windows 2000/XP only)
The SharedAccess service is responsible for maintaining Internet Connection Sharing and the Windows Firewall/Internet Connection Firewall applications in Windows. (The presence and names of these applications vary depending on the operating system and service pack you are using.) To protect your computer and maintain network functionality, re-enable this service if you are using any of these programs.


Windows XP Service Pack 2
If you are running Windows XP with Service Pack 2 and are using the Windows Firewall, the operating system will alert you when the SharedAccess service is stopped, by displaying an alert balloon saying that your Firewall status is unknown. Perform the following steps to ensure that the Windows Firewall is re-enabled:

Click Start > Control Panel.


Double-click the Security Center.


Ensure that the Firewall security essential is marked ON.

Note: If the Firewall security essential is marked on, your Windows Firewall is on and you do not need to continue with these steps.

If the Firewall security essential is not marked on, click the "Recommendations" button.


Under "Recommendations," click Enable Now. A window appears telling you that the Windows Firewall was successfully turned on.


Click Close > OK.


Close the Security Center.


Windows 2000 or Windows XP Service Pack 1, or earlier
Complete the following steps to re-enable the SharedAccess service:

Click Start > Run.
Type services.msc

Then click OK.


Do one of the following:

Windows 2000: Under the Name column, locate the "Internet Connection Sharing (ICS)" service and double-click it.
Windows XP: Under the Named column, locate the "Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS)" service and double-click it.


Under "Startup Type:", select "Automatic" from the drop-down menu.


Under "Service Status:", click the Start button.


Once the service has completed starting, click OK.


Close the Services window.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.akak.html\"]source[/url]

Alerts

Posted: Fri Sep 03, 2004 2:24 pm
by Tami
PWSteal.Tarno.I
Discovered on: September 01, 2004
Last Updated on: September 02, 2004 12:58:40 PM

PWSteal.Tarno.I is a Trojan horse that attempts to steal user names and passwords for certain Internet banking sites, by capturing screenshots and logging keystrokes.

Also Known As: Troj/Tofger-BG [Sophos]

Type: Trojan Horse
Infection Length: 179,200 Bytes, 11,004 Bytes, 6,000 Bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x

When PWSteal.Tarno.I is executed, it performs the following actions:


Creates the following files:

%Windir%\Vhchost.exe: Detected as PWSteal.Tarno.I
%Windir%\Scrnr32.dll: Detected as PWSteal.Tarno.I
%System%\Winrr.exe: Non-malicious utility file that PWSteal.Tarno.I uses to create RAR file.

Notes:
%System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).


Adds the value:

"Default System Research" = "%Windir%\vhchost.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs when you start Windows.


Monitors the URL field in Internet Explorer for the following strings:

e-gold
bank
hsbc
halifax
barclays
openplan
lloyds
abbey
cahoot
nationwide
nwolb
natwest
nationet
woolwich


Stores keystrokes and the content of the clipboard (the buffer for copy and paste) in the file, %System%\Usert\<10digits>_<8digits>.txt, where the digits are derived from the system time.


Stores screenshots in the file, %System%\Usert\<10digits>_<8digits>.bmp, where these digits are derived from the system time.


Using %System%\Winrr.exe, which it previously created, the Trojan creates the RAR file, %System%\Usert, which contains the keystrokes and screeenshots.


Attempts to send the RAR file to a remote Web server.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as PWSteal.Tarno.I.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Default System Research" = "%Windir%\vhchost.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.tarno.i.html\"]source[/url]

Alerts

Posted: Sun Sep 05, 2004 8:19 pm
by Tami
W32.Remadmin
Discovered on: September 02, 2004
Last Updated on: September 04, 2004 12:31:07 PM

W32.Remadmin is a worm that attempts to propagate through network shares.

Also Known As: WORM_REMADM.A [Trend]

Type: Worm
Infection Length: 842,304 bytes

Systems Affected: Windows 2000, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: Linux, Macintosh, UNIX

W32.Remadmin is composed of batch files, hacktools, and legitimate administration tools.

When the worm is executed, it does the following:


Extracts the following files:
AdmDll.dll: A .dll component of Remacc.Radmin.
icon.reg *: A registry file.
Kcah.cmd: A batch file that copies utili.dll to <ip address>\ADMIN$\SYSTEM32 and attempts to stop certain processes.
Msdos.exe: An .exe file that is detected as Remacc.Radmin.
Msxml3b.dll *: A clean text file with a list of I.D.'s
Msxml4b.dll *: A clean text file with a list of passwords.
Naer.cmd: A batch file that calls Kcah.cmd with a specified ip address (excluding 192.168.0.x and 127.0.0.x).
Psexec.exe *: A Sysinternals remote execution tool.
Raddrv.dll: A .dll component of Remacc.Radmin.
Regedit4.exe *: A registry editor.
Rs.cmd *: A batch file that calls msdos.exe.
Run.bat: A starting batch file for the Worm.
Secfind.exe: A hacktool used to search for IPC$ shares.
Secscan.exe: A .exe file that is detected as Hacktool.RunService.
Star.cmd: A batch file that calls Kcah.cmd with random ip address.
Unrar.exe : A rar archive containing:
i.cmd *: A starting batch file that stops/removes netsvc.exe and overwrites files but does not seem viral.
instsrv.exe *: A service installer.
Regedit4.exe *: A registry editor.
Rep.exe *: Replace Commander - a non-malicious program used to replace specific strings in a file.
S.bin *: A clean file used to overwrite.
V.bin *: A clean file used to overwrite.
W.exe *: A clean file used to overwrite.

NOTE: Files that marked with an asterisk ( * ) are either commercial utilities or are clean files. As such, Symantec antivirus products do not detect them.


Creates the registry key:

HKEY_LOCAL_MACHINE\System\RAdmin


Executes Run.bat which:
Copies Rar.exe to Utili.dll
Enable these network shares:
IPC$
ADMIN$
C$=C:\
Executes Star.cmd which executes Naer.cmd, Kcah.cmd, and Secfind.exe with a randomly-generated ip number
Executes Secfind.exe with a range of ip address to search for IPC$ shares.
Executes Kcah.cmd and Naer.cmd and copies Utili.dll into <victim's ip address>\ADMIN$\SYSTEM32\Rar.exe and stops certain processes.
Executes Rar.exe.
Executes Unrar.exe to stop Netsvc.exe and overwrite the following files.
Copies v.bin to %SystemRoot%\.{21EC2020-3AEA-1069-A2DD-08002B-30309D}\netsvc.exe
Copies w.exe to %SystemRoot%\.{21EC2020-3AEA-1069-A2DD-08002B-30309D}\netsvc.ini
Copies s.bin to %SystemRoot%\System32\netsvc.exe

Removal Instructions:

Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Remadmin.
Delete the values that were added to the registry.

Click Start > Run.
Type regedit

Then click OK.

Navigate to the following key:

HKEY_LOCAL_MACHINE\System

In the left pane, delete the key:

"RAdmin"

Exit the Registry Editor.

Restart the computer in normal mode.

Additional information:

Some of the processes that the Worm may terminate are:

DefWatch
Symantec AntiVirus Client
NSCTOP
Symantec Core LC
SAVScan
SAVFMSE
ccEvtMgr
navapsvc
ccSetMgr
VisNetic AntiVirus Plug-in
McShield
AlertManger
McAfeeFramework
AVExch32Service
AVUPDService
McTaskManager
Network Associates Log Service
Outbreak Manager
MCVSRte
mcupdmgr.exe
AvgServ
AvgCore
AvgFsh
awhost32
Ahnlab task Scheduler
MonSvcNT
V3MonNT
V3MonSvc
FSDFWD

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.remadmin.html\"]source[/url]