Alerts

Moderators: Moderator, Global Moderator

Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Trojan.Mitglieder.M
Discovered on: July 22, 2004
Last Updated on: July 24, 2004 11:41:36 AM

Trojan.Mitglieder.M is a Trojan horse that attempts to download files from the Internet.

Definitions prior to July 23, 2004 may detect this threat as Trojan.Wingle.

Also Known As: W32/Bagle.aj!proxy [McAfee]

Type: Trojan Horse
Infection Length: 5,924 bytes, 11,776 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates processes associated with security software.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When Trojan.Mitglieder.M runs, it does the following:


Copies itself as %System%\WINdirect.exe.


Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds a value:

"win_upd.exe"="%System%\WINdirect.exe"

to the registry keys:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that it runs when you restart Windows.


Creates a file, %System%\_dll.exe.


Injects %System%\_dll.exe as a thread into a process with a window class name of "Shell_TrayWnd." If successful, this threat will continue to run within the infected process. All the actions described in the next steps will appear to be done by the infected process, and the worm will not show when viewing the process list in the Windows Task Manager.


Terminates the following processes:

ATUPDATER.EXE
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE
sys_xp.exe
sysxp.exe
winxp.exe


Attempts to download files from the following Web sites as %Windir%\~.exe, and then run it:

134.102.228.45
196.12.49.27
213.188.129.72
64.62.172.118
abi-2004.org
advm1.gm.fh-koeln.de
alexey.pioneers.com.ru
alfinternational.ru
aus-Zeit.com
binn.ru
burn2k.ipupdater.com
carabi.ru
catalog.zelnet.ru
cavalierland.5u.com
celine.artics.ru
change.east.ru
colleen.ai.net
controltechniques.ru
dev.tikls.net
diablo.homelinux.com
dodgetheatre.com
dozenten.f1.fhtw-berlin.de
emnesty.w.interia.pl
emnezz.e-mania.pl
euroviolence.com
evadia.ru
fairy.dataforce.net
financial.washingtonpost.com
free.bestialityhost.com
gutemine.wu-wien.ac.at
herzog.cs.uni-magdeburg.de
home.profootball.ru
host.businessweek.com
host.wallstreetcity.com
host23.ipowerweb.com
hsr.zhp.org.pl
infokom.pl
kafka.punkt.pl
kooltokyo.ru
kypexin.ru
lars-s.privat.t-online.de
lottery.h11.ru
matzlinger.com
megion.ru
mmag.ru
molinero-berlin.de
momentum.ru
niebo.net
nominal.kaliningrad.ru
omegat.ru
ourcj.com
packages.debian.or.jp
pb195.slupsk.sdi.tpnet.pl
photo.gornet.ru
pixel.co.il
pocono.ru
polobeer.de
porno-mania.net
protek.ru
przeglad-tygodnik.pl
przeglad-tygodnik.pl
quotes.barchart.com
r2626r.de
rausis.latnet.lv
relay.great.ru
republika.pl
sacred.ru
sbuilder.ru
sec.polbox.pl
shadkhan.ru
silesianet.pl
silesianet.pl
slavarik.ru
sovea.de
spbbook.ru
strony.wp.pl
szm.sk
tarkosale.net
tdi-router.opola.pl
terramail.pl
thorpedo.us
traveldeals.sidestep.com
ultimate-best-hgh.0my.net
vip.pnet.pl
werel1.web-gratis.net
www.5100.ru
www.PlayGround.ru
www.aannemers-nederland.nl
www.abcdesign.ru
www.airnav.com
www.aktor.ru
www.ankil.ru
www.antykoncepcja.net
www.aphel.de
www.artics.ru
www.astoria-stuttgart.de
www.avant.ru
www.baltmatours.com
www.baltnet.ru
www.biratnagarmun.org.np
www.biysk.ru
www.boglen.com
www.bridesinrussia.com
www.busheron.ru
www.ccbootcamp.com
www.chat4adult.com
www.chelny.ru
www.ciachoo.pl
www.dami.com.pl
www.ddosers.net
www.dicto.ru
www.dilver.ru
www.dsmedia.ru
www.dynex.ru
www.elemental.ru
www.elit-line.ru
www.epski.gr
www.forbes.com
www.free-time.ru
www.gamma.vyborg.ru
www.gantke-net.com
www.gin.ru
www.glass-master.ru
www.glavriba.ru
www.gradinter.ru
www.hack-gegen-rechts.com
www.hbz-nrw.de
www.hgr.de
www.hgrstrailer.com
www.ifa-guide.co.uk
www.iluminati.kicks-ass.net
www.infognt.com
www.intellect.lvc
www.interfoodtd.ru
www.interrybflot.ru
www.inversorlatino.com
www.jewishgen.org
www.k2kapital.com
www.kefaloniaresorts.com
www.lamatec.com
www.landofcash.net
www.laserbuild.ru
www.math.kobe-u.ac.jp
www.mcschnaeppchen.com
www.mdmedia.org
www.met.pl
www.metacenter.ru
www.milm.ru
www.myrtoscorp.com
www.nefkom.net
www.neostrada.pl
www.neprifan.ru
www.netradar.com
www.no-abi2003.de
www.oldtownradio.com
www.omnicom.ru
www.oshweb.com
www.pakwerk.ru
www.perfectgirls.net
www.perfectjewel.com
www.peterstar.ru
www.pgipearls.com
www.phg.pl
www.porsa.ru
www.porta.de
www.rafani.cz
www.rastt.ru
www.republika.pl
www.republika.pl
www.rollenspielzirkel.de
www.rubikon.pl
www.rumbgeo.ru
www.rweb.ru
www.scli.ru
www.sdsauto.ru
www.sensi.com
www.silesianet.pl
www.sjgreatdeals.com
www.sposob.ru
www.strefa.pl
www.tanzen-in-sh.de
www.taom-clan.de
www.tayles.com
www.teatr-estrada.ru
www.teleline.ru
www.thepositivesideofsports.com
www.timelessimages.com
www.tuhart.net
www.vconsole.net
www.vendex.ru
www.virtmemb.com
www.vivamedia.ru
www.vrack.net
www.wapf.com
www.webpark.pl
www.webronet.com
www.webzdarma.cz
www.yarcity.ru
www.youbuynow.com
www.zeiss.ru
www.zelnet.ru
www.zhp.gdynia.pl
wynnsjammer.proboards18.com
yaguark.h10.ru


Note: %Windir% is a variable. The Trojan locates the Windows installation folder and saves the downloaded files to that location. By default, this is C:\Windows or C:\Winnt.

Removal Instructions

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Mitglieder.M.
Reverse the changes made to the registry.

To reverse the changes made to the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to each of the following keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"win_upd.exe"="%System%\WINdirect.exe"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.mitglieder.m.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W97M.Seliuq.D
Discovered on: July 23, 2004
Last Updated on: July 24, 2004 02:23:52 PM

W97M.Seliuq.D is a virus that infects Microsoft Word documents and templates. It also makes some menu changes so that macros cannot be edited.

Also Known As: W97M/Assilem.g.gen[McAfee], W97M_SELIUQ.C[Trend], WM97/Seliuq-A[Sophos], Macro.Word97.Seliuq.c[Kaspersky]

Type: Macro
Infection Length: 1 module

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Disables the Word macro virus protection.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When a document infected with W97M.Seliuq.D is opened, it deletes existing macros.

When the infected document is closed, it does the following:


Disables the Word Tools->Macro menu and hides the Visual Basic icon.


Infects the Normal.dot template and other active documents.


Broadcasts one of the following predefined messages to domain computers with a 10% probability if the date is between the 9th and 15th:

If the computer's country setting is Argentina, Chile, LatinAmerica, Mexico, Peru, Spain, or Venezuela:
Me c*go en tu m*dre
Eres una P*ta
P*rra arr*bal*ra
J*dete c*m*pinga
So c*lo r*to
Est* es para que *prendas. Ch*lo de V*eja
So M*ric?
Que p*erco eres, c*rdo, m*rrano!!!
Que m*mal*na eres
Eres un p*j*so


If the computer's country setting is any of the following:
/censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> you
/censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' />
M*therF*cker
/censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> you as*h*le
A*sh*le
B*stard
D*c Head
You are a P*G!!!
You L*mer
M*ron

Removal Instructions

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as W97M.Seliuq.D.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w97m.seliuq.d.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Mydoom.M@mm
Discovered on: July 26, 2004
Last Updated on: July 26, 2004 04:10:53 PM

W32.Mydoom.M@mmis a mass-mailing worm that opens a backdoor and uses its own SMTP engine to spread through email.

The worm is packed using UPX.

Type: Worm

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Yes
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: Varies
Name of attachment: Varies
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When W32.Mydoom.M@mm is executed, it performs the following actions:


Copies itself as:

%Windir%\java.exe
%Windir%\services.exe

Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.


Adds the values:

"Services" = "%Windir%\services.exe"
"JavaVM" = "%Windir%\java.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

so that it will load when Windows starts.


May create the following files for logging purposes:

%Temp%\zincite.log
%Temp%\[randomly named file].log


Attempts to copy itself to all folders whose names contain the following strings:

USERPROFILE
yahoo.com


Gathers email addresses from files with the following extensions:

.doc
.txt
.htm
.html


When the worm finds an open Outlook window, it will attempt to send itself to email addresses it found.

The email has the following characteristics:

From:
The From address will be spoofed.

Subject: (One of the following)

say helo to my litl friend
click me baby, one more time
hello
error
status
test
report
delivery failed
Message could not be delivered
Mail System Error - Returned Mail
Delivery reports about your e-mail
Returned mail: see transcript for details
Returned mail: Data format error

Body:
The message body will be as follows, where one of each phrase/word in brackets will appear:

Dear user {[To address of mail]|of [domain of To address]},{ {{M|m}ail {system|server} administrator|administration} of [domain of To address] would like to {inform you{ that{:|,}|}|let you know {that|the following}{.|:|,}}|||||}
{We have {detected|found|received reports} that y|Y}our {e{-|}mail |}account {has been|was} used to send a {large|huge} amount of {{unsolicited{ commercial|}|junk} e{-|}mail|spam}{ messages|} during {this|the {last|recent}} week.
{We suspect that|Probably,|Most likely|Obviously,} your computer {had been|was} {compromised|infected{ by a recent v{iru}s|}} and now {run|contain}s a {trojan{ed|}|hidden} proxy server.
{Please|We recommend {that you|you to}} follow {our |the |}instruction{s|} {in the {attachment|attached {text |}file} |}in order to keep your computer safe.
{{Virtually|Sincerely} yours|Best {wishe|regard}s|Have a nice day},
{[domain of To address] {user |technical |}support team.|The [domain of To address] {support |}team.}

{The|This|Your} message was{ undeliverable| not delivered} due to the following reason{(s)|}:
Your message {was not|could not be} delivered because the destination {computer|server} was
{not |un}reachable within the allowed queue period. The amount of time
a message is queued before it is returned depends on local configura-
tion parameters.
Most likely there is a network problem that prevented delivery, but
it is also possible that the computer is turned off, or does not
have a mail system running right now.

Your message {was not|could not be} delivered within [random number] days:
{{{Mail s|S}erver}|Host} [host used to send mail] is not responding.
The following recipients {did|could} not receive this message:
<[To address of mail]>
Please reply to postmaster@{[domain of From address]|[domain of To address]}
if you feel this message to be in error.
The original message was received at [current time]{
| }from {[domain of From address] [[host used to send mail]]|{[host used to send mail]|[[host used to send mail]]}}
----- The following addresses had permanent fatal errors -----
{<[To address of mail]>|[To address of mail]}
{----- Transcript of {the ||}session follows -----
... while talking to {host |{mail |}server ||||}{[domain of To address].|[host used to send mail]}:
{>>> MAIL F{rom|ROM}:[From address of mail]
<<< 50$d {[From address of mail]... |}{Refused|{Access d|D}enied|{User|Domain|Address} {unknown|blacklisted}}|554 <[To address of mail]>... {Mail quota exceeded|Message is too large}
554 <[To address of mail]>... Service unavailable|550 5.1.2 <[To address of mail]>... Host unknown (Name server: host not found)|554 {5.0.0 |}Service unavailable; [[host used to send mail]] blocked using {relays.osirusoft.com|bl.spamcop.net}{, reason: Blocked|}
Session aborted{, reason: lost connection|}|>>> RCPT To:<[To address of mail]>
<<< 550 {MAILBOX NOT FOUND|5.1.1 <[To address of mail]>... {User unknown|Invalid recipient|Not known here}}|>>> DATA
{<<< 400-aturner; %MAIL-E-OPENOUT, error opening !AS as output
|}{<<< 400-aturner; -RMS-E-CRE, ACP file create failed
|}{<<< 400-aturner; -SYSTEM-F-EXDISKQUOTA, disk quota exceeded
|}<<< 400}|}
The original message was included as attachment

{{The|Your} m|M}essage could not be delivered

Attachment: (One of the following)
readme
instruction
transcript
mail
letter
file
text
attachment
document
message

with one of the following extensions:
cmd
bat
com
exe
pif
scr

The worm will not send itself to addresses containing the following strings:
mailer-d
spam
abuse
master
sample
accou
privacycertific
bugs
listserv
submit
ntivi
support
admin
page
the.bat
gold-certs
feste
not
help
foo
soft
site
rating
you
your
someone
anyone
nothing
nobody
noone
info
winrar
winzip
rarsoft
sf.net
sourceforge
ripe.
arin.
google
gnu.
gmail
seclist
secur
bar.
foo.com
trend
update
uslis
domain
example
sophos
yahoo
spersk
panda
hotmail
msn.
msdn.
microsoft
sarc.
syma
avp

Removal Instructions

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Mydoom.M@mm.
Reverse the changes made to the registry.

To reverse the changes made to the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.


Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Services" = "%Windir%\services.exe"
"JavaVM" = "%Windir%\java.exe"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.m@mm.html\"]Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Backdoor.Zincite.A
Discovered on: July 26, 2004
Last Updated on: July 26, 2004 04:45:56 PM

Backdoor.Zincite.A is a backdoor server program that allows unauthorized remote access to a compromised computer. It runs on TCP port 1034.

This Trojan is dropped by W32.Mydoom.M@mm.

Type: Trojan Horse
Infection Length: 8,192 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Allows unauthorized remote access.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: 1034/tcp
Shared drives: n/a
Target of infection: n/a


When Backdoor.Zincite.A is executed it performs the following actions:


Copies itself as:

%Windir%\services.exe

Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.


Adds the value:

"Services" = "%Windir%\services.exe"

to the registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


Attempts to make contact with other infected systems by probing random IP addresses on port 1034.


Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Zincite.A.
Delete the value that was added to the registry.

To delete the value from the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Services"="%Windir%\services.exe"


Exit the Registry Editor.


[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.zincite.a.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

PWSteal.Ldpinch.B
Discovered on: July 23, 2004
Last Updated on: July 27, 2004 02:54:50 PM

PWSteal.Ldpinch.B is a password-stealing Trojan horse that attempts to steal information from an infected computer and send it to the author of the Trojan.

Also Known As: Multidropper-KN[Mcafee], Backdoor-CEX[Mcafee], Ldpinch.W[Panda]
Variants: PWSteal.Ldpinch
Type: Trojan Horse
Infection Length: 11,601 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: steals various information
Compromises security settings: n/a
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When the Trojan is executed, it does the following:


Copies itself as %Windir%\csrss.exe.


Note: %Windir% is a variable. The Trojan locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.


Creates the file, %Windir%\dll.dll, which is not malicious and is not detected.


Adds the value:

"Systask" = "{randomly generated CLSID value}"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

and:

"(Default)" = "dll.dll"

to the registry key:

HKEY_CURRENT_ROOT\CLSID\{CLSID value referred to above}\InProcServer32

so that the Trojan runs when you start Windows.


Adds the following registry keys:

HKEY_CURRENT_USER\Software\Mirabilis
HKEY_CURRENT_USER\Software\RIT
HKEY_CURRENT_USER\Software\Far
HKEY_CURRENT_USER\Software\Ghisler
HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\&RQ
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trillian
HKEY_LOCAL_MACHINE\Software\Mirabilis
HKEY_LOCAL_MACHINE\Software\Miranda


Queries the following registry keys, and subkeys of those keys:

HKEY_CURRENT_USER\Software\Mirabilis
HKEY_CURRENT_USER\Software\RIT
HKEY_CURRENT_USER\Identities
HKEY_CURRENT_USER\Software\Far
HKEY_CURRENT_USER\Software\Ghisler
HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\&RQ
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trillian


Stores the user's mail server information in a base64-encoded string in the following registry key:

HKEY_CURRENT_USER\Software\Intel\Data


Information from the keys mentioned in steps 4 and 5 will be stored and sent by email to the remote attacker.

The email will have the following characteristics:

From: excel@gardener.com
To: tanja19@nnf.xpsweb.com
Subject: Passes from Pinch Pro

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files that are detected as PWSteal.Ldpinch.B.
Delete the values that were added to the registry.

To delete the values that was added to the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document "How to make a backup of the Windows registry" for instructions.

Click Start > Run.
Type regedit, and then click OK.
Navigate to the keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad


In the right pane, delete the value:

"Systask" = "{randomly generated CLSID value}"


Navigate to the key:

HKEY_CURRENT_ROOT\CLSID\{CLSID value referred to above}\InProcServer32


In the right pane, delete the value:

"(Default)" = "dll.dll"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.ldpinch.b.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Zindos.A
Discovered on: July 27, 2004
Last Updated on: July 27, 2004 02:51:32 PM

W32.Zindos.A is a worm that performs a Denial of Service (DoS) attack against the domain, microsoft.com. The worm spreads through the backdoor opened on TCP port 1034, by Backdoor.Zincite.A.

Note: Backdoor.Zincite.A is a backdoor Trojan horse that is dropped by W32.Mydoom.M@mm.

Type: Worm
Infection Length: 5760 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Performs a DoS against microsoft.com which may take up large amounts of network bandwidth.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 1034
Shared drives: n/a
Target of infection: Computers infected with Backdoor.Zincite.A.


When W32.Zindos.A is executed, it performs the following actions:


Probes random IP addresses on port 1034 searching for infections of Backdoor.Zincite.A.


When an open port is found, the worm will send itself to the infected computer.


Saves itself in the %Temp% folder as a randomly named .exe file, then executes.


Adds the value:

"Tray"="<file name of worm>.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm is executed at startup.


Performs a DoS attack against the domain, microsoft.com.

Note: The DoS attack is not date-triggered and will being within a few minutes of execution.

Removal Instructions

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Zindos.A.
Delete the value that was added to the registry.

To delete the value from the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Tray"="<file name of worm>.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.zindos.a.html\"]Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Mits.A@mm
Discovered on: July 24, 2004
Last Updated on: July 28, 2004 04:14:36 PM

W32.Mits.A@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses that it finds on an infected host.

The worm alters many system settings, including registry editing to make it difficult to remove.


Also Known As: Trojan.Win32.Smith

Type: Worm
Infection Length: 504,832 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Mass-mails itself to the email addresses found on the host.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Worm activity significantly degrades system performance.
Causes system instability: Continuous display setting changes may cause the system to be unusable.
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: n/a
Name of attachment: Varies
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When W32.Mits.A@mm is executed, it performs the following actions:


Copies itself as one of the following:

C:\WINDOWS\system32\WinServer.exe
C:\WINDOWS\system32\Setup.exe
C:\WINDOWS\system32\WinBios.exe
C:\WINDOWS\system32\NetBios.exe
C:\WINDOWS\system32\NetServer.exe
C:\WINDOWS\system32\WinNote.exe
C:\WINDOWS\system32\WinProfile.exe
C:\WINDOWS\system32\WinLoadfile.exe
C:\WINDOWS\system32\WinAuto.exe
C:\WINDOWS\system\WinConfig.exe


Continuously changes the display settings to different graphics modes, causing the screen to blink, flash, and switch on and off.


Deletes the default values from the following registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command


Adds the value

"(<double-byte characters>)" = "txtfile"

to the registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg


Adds the value

"(<double-byte characters>)" = "C:\WINDOWS\system32\<worm file name>"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command


Adds the value

"<worm file name>" = "C:\WINDOWS\system32\<worm file name>"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Adds the following registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SOFTWARE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WinLogon


Sets the following values:

"NoChangeStartMenu" = "1"
"NoDrives" = "8"
"NoFind" = "1"
"NoFolderOptions" = "1"
"NoLogOff" = "1"
"NoRealMode" = "1"
"NoRecentDocsMenu" = "1"
"NoRun" = "1"
"NoSetFolders" = "1"
"NoSetTaskBar" = "1"
"NoStartMenu" = "1"

in the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

making it difficult to remove the worm from the infected computer.


Sets the value:

"DisableRegistryTools" = "1"

in the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System


Sets the values:

"Show_StatusBar" = "no"
"Show_URLToolBar" = "no"

in the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main


Sets the value:

"AutoEndTasks" = "no"

in the registry key:

HKEY_CURRENT_USER\Control Panel\Desktop


Scans the local hard disk to collect the email addresses to which it will send copies of itself.

The email message has the following characteristics:

From:
Either spoofed or the following email address:

windowsnet@263.com.cn

If the sender's email address is spoofed, it will be composed using the random combination of strings from the following lists:
a
ai
ao
ba
bai
bang
bao
bi
bin
bing
bo
bon
bu
bun
ca
cai
can
ce
chuan
co
cu
cun
da
dan
dang
dao
de
di
din
ding
du
du
dun
e
en
eng
er
fa
fan
fen
feng
fong
fu
ga
gang
ge
gen
geng
go
gong
gu
gui
ha
hai
hao
he
hen
hong
hou
hua
huan
huang
huo
jian
jin
ka
kan
ke
kong
ku
la
lai
lang
lao
le
len
leng
Li
li
liang
liao
lie
ling
Liu
liu
ma
mai
mao
mei
mi
min
ming
mo
mong
mu
na
nan
nang
nao
ne
no
nong
nun
o
ong
pa
pao
pen
peng
pi
ping
pu
qi
qiao
qing
qiong
qiu
quan
re
ren
reng
rong
rou
sa
san
sang
sao
she
shi
shu
su
ta
tie
tong
wa
wang
we
wen
weng
Wu
wun
xi
xia
xiang
xing
ya
yan
yang
yin
ying
yong
you
yuan
zhang
Zhao
zhi
zhong
zhou
zi


windows
windowsxp
windows98
windows95
windowsnet
smilesnow
smiler
snow
flower
wood
westwind
computer
lover
Linux
linuxsir
unix
wind


@163.com
@126.com
@263.net
@yahoo.com.cn
@sohu.com
@china.com
@hotmail.com
@msn.com
@sina.com.cn
@263.com.cn


Message:
The text of the message is in Chinese, which may look similar to the text displayed below:

[img]http://www.killanet.net/uploads/w32.mits.a.gif[/img]

Attachment:
The file name of the attachment is randomly selected from the following list:

WinBios.exe
NetBios.exe
NetServer.exe
WinNote.exe
WinProfile.exe
WinLoadfile.exe
WinAuto.exe


The worm will skip the email addresses that contain the following strings:

@yahoo.com.cn
@china.com
@hotmail.com
@sina.com.cn
@263.com.cn
webmaster@panda.com

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Download a tool that will restore the use of the Registry Editor.

To download the tool
Download the file, [url=\"http://securityresponse.symantec.com/avcenter/UnHookExec.inf\"]UnHookExec.inf[/url], and save it to your Windows desktop. Do not run it at this time, download it only.

If you cannot connect to the Internet from an infected computer:
Download to an uninfected computer, and then save it to a floppy disk.
Take the floppy disk and insert it into the floppy disk drive of the infected computer.

Restart the computer in Safe mode (Windows 95/98/Me), or Safe mode with Command Prompt (Windows 2000/XP).

Run the tool.

Reverse the changes made to the registry.

To reverse the changes made to the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.

Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"[WORM FILENAME]" = "C:\WINDOWS\system32\[WORM FILENAME]"


Navigate to and delete the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SOFTWARE


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command


In the right pane, delete the value:

"([DOUBLE-BYTE CHARACTERS])" = "C:\WINDOWS\system32\[WORM FILENAME]"


Navigate to and delete the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WinLogon


Navigate to each of these the keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg


From each one, in the right pane, delete the value:

"([DOUBLE-BYTE CHARACTERS])" = "txtfile"


Navigate to the key:

HKEY_Current_USER\Software\Microsoft\Internet Explorer\Main


In the right pane, delete the values:

"Show_StatusBar" = "no"
"Show_URLToolBar" = "no"


Navigate to the key:

HKEY_Current_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer


In the right pane, delete the values:

"NoChangeStartMenu" = dword:00000001
"NoDrives" = dword:00000008
"NoFind" = dword:00000001
"NoFolderOptions" = dword:00000001
"NoLogOff" = dword:00000001
"NoRealMode" = dword:00000001
"NoRecentDocsMenu" = dword:00000001
"NoRun" = dword:00000001
"NoSetFolders" = dword:00000001
"NoSetTaskBar" = dword:00000001
"NoStartMenu" = dword:00000001


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf


In the right pane, double-click (Default)

and change the Value data to:

inffile


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg


In the right pane, double-click (Default)

and change the Value data to:

regfile


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command


In the right pane, double-click (Default)

and change the Value data to:

%System%\NOTEDPAD.EXE %1


Navigate to the key:

HKEY_LOCAL_MACHINE\Control Panel\Desktop


In the right pane, double-click AutoEndTasks and change the Value data to: 0


Exit the Registry Editor.


Run a full system scan and delete all the files detected as W32.Mits.A@mm.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mits.a@mm.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Korgo.Z
Discovered on: July 27, 2004
Last Updated on: July 28, 2004 01:45:27 PM

W32.Korgo.Z is a worm that attempts to propagate by exploiting the Microsoft Windows PCT Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011) on TCP port 113. Previous Korgo variants used a different vulnerability, the LSASS Buffer Overrun Vulnerability.


Also Known As: WORM_KORGO.AC[Trend], Worm.Win32.Padobot.gen[Kaspersky], Win32.Korgo.AC[CA]
Variants: W32.Korgo.Y
Type: Worm
Infection Length: 9,359 bytes



Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Network propagation routines may degrade overall network performance.
Causes system instability: n/a
Releases confidential info: Backdoor functionality allows unauthorized access.
Compromises security settings: Backdoor functionality may compromise security settings.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 445 and a random port.
Shared drives: n/a
Target of infection: Unpatched computers vulnerable to the Microsoft LSASS Windows exploit.


When W32.Korgo.Z is executed, it does the following:


Deletes the file, ftpupd.exe, from the folder in which the worm was executed.


Creates the mutex "uterm19.2" to ensure that only one instance of the worm is executed on the computer:


Creates the following mutexes:

u10
u10x
u11
u11x
u12
u12x
u13
u13i
u13x
u14
u14x
u15
u15x
u16
u16x
u17
u17x
u18
u18x
u19
u8
u9


Deletes the values:

avserve.exe
avserve2.exeUpdate Service
Bot Loader
Disk Defragmenter
MS Config v13
System Restore Service
SysTray
Windows Security Manager
Windows Update
Windows Update Service
WinUpdate

from the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Copies itself as %System%\<random filename>.exe.

Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the values:

"Client"="1"
"ID"="<random value>"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless


Adds the value:

"Cryptographic Service"="%System%\<random filename>.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Attempts to inject a function into Explorer.exe as a thread.

If successful, this threat will continue to run in the Explorer.exe process. All of the worm's subsequent actions will appear to be done by Explorer.exe, and the worm will not show when viewing the process list in the Windows Task Manager.

If unsuccessful, the worm will continue to run as its own process.


Opens a random TCP port, which the worm uses to send itself.


Attempts to connect and update itself from one of the following IRC servers:

0AB1cvv.ru
adult-empire.com
asechka.ru
citi-bank.ru
color-bank.ru
crutop.nu
fethard.biz
filesearch.ru
kavkaz.tv
kidos-bank.ru
konfiskat.org
master-x.com
mazafaka.ru
parex-bank.ru
roboxchange.com
www.redline.ru
xware.cjb.net

The worm joins a channel and waits for commands, including a command to download and execute a file from a Web server.


Attempts to exploit the Microsoft Windows PCT Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011), against random IP addresses. If the worm successfully finds a vulnerable computer, the computer will attempt to reconnect to the infected computer to download the worm.

Before you begin
If you are running Windows 2000 or XP, and have not yet done so, you must patch for the vulnerability. Microsoft Security Bulletin [url=\"http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx\"]MS04-011[/url] describes this process. If you do not, it is likely that your computer will continue to be re-infected.

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Korgo.Z.
Reverse the changes made to the registry.

To reverse the changes made to the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.

Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Microsoft Update Service"="%System%\<random filename>.exe"


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless


In the right pane, delete the values, if they exist:

"Client"="1"
"ID" = "<random value>"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.korgoz.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
drew
Newbie
Newbie
Posts: 22
Joined: Sat Jul 17, 2004 6:55 am

Alerts

Post by drew »

*updates all virus definations*
*downloads fix* (cuz i know a few friends will have it)
there. now im safe! /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
Image
drew
Newbie
Newbie
Posts: 22
Joined: Sat Jul 17, 2004 6:55 am

Alerts

Post by drew »

humm i was wondering why people make viruses. like whats the point. do people get there jollies by ******* up other peoples computers? if i knew who was making these, and was able to see them in person, i would definatly punch them in the nose because this is bullcrap, i dont understand why people insist on always crashing and killing other computers, being able to hvae Internet is a PRIVLEDGE. so why screw it up!
Image
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Lovgate.AK@mm
Discovered on: July 28, 2004
Last Updated on: July 29, 2004 10:57:05 AM

W32.Lovgate.AK@mm is a variant of W32.Lovgate.W@mm that:

Attempts to reply to all the email messages in the Microsoft Outlook inbox.
Scans files that have the .txt, .pl, .wab, .adb, .tbb, .dbx, .asp, .php, .sht, and .htm extensions for email addresses.
Uses its own SMTP engine to send itself to the addresses that it finds.
Attempts to copy itself to Kazaa-shared folders and all the computers on a local network.

The From line of the email is spoofed and the Subject and the Message vary. The attachment name also varies, with a .bat, .cmd, .exe, .pif, or .scr file extension. The worm may also send a .zip file containing the attachment.

This threat is written in the C++ programming language and is compressed with JDPack, ASPack, and UPX.

Infection Length: 113,664 bytes

Systems Affected: Windows 2000, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 95, Windows 98, Windows Me

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to all the contacts of the Windows Address Book and the Outlook Address Book, and to the email addresses that it finds in files that have the .txt, .pl, .wab, .adb, .tbb, .dbx, .asp, .php, .sht, and .htm. extensions.
Deletes files: n/a
Modifies files: renames .exe files to .zmx
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates processes belonging to various antivirus programs.
Distribution

Subject of email: n/a
Name of attachment: Varies, with .bat, .cmd, .exe, .pif, .scr, or .zip as the extension
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP 6000
Shared drives: Copies itself to network shared folders.
Target of infection: Copies itself to the KaZaA shared folder


When W32.Lovgate.AK@mm runs, it does the following:


Copies itself as the following:

%Windir%\SysTra.exe
%System%\ravmond.exe
%System%\iexplore.exe
%System%\WinHelp.exe
%System%\kernel66.dll (With attributes set to Read Only, Hidden, and System.)

Notes:
%Windir% is a variable: The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
%System% is a variable: The worm locates the System folder and copies itself to that location. By default, this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the following files:

%System%\ODBC16.dll
%System%\msjdbc11.dll
%System%\MSSIGN30.DLL
%System%\LMMIB20.DLL

Note: These files are all the same; they are backdoor components of the worm and each 53,760 bytes in size.


Adds the values:

"Program in Windows"="%system%\iexplore.exe"

"Protected Storage"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"

"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"

"WinHelp"="%system%\WinHelp.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you start Windows.


Adds the value:

"SystemTra"="%Windir%\SysTra.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices

so that the worm runs as a service when you start Windows 95/98/Me.


Adds the value:

"run"="RAVMOND.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows

so that the worm runs when you start Windows NT/2000/XP.


May create the subkey:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ZMXLIB1


Inserts the following line in the [Windows] section of Win.ini file:

run=ravmond.exe


Injects a process-watching routine as a thread into either Explorer.exe or Taskmgr.exe. This remote thread will launch %System%\Iexplore.exe if the worm process is stopped.


Creates a file named AUTORUN.INF in the root folder of all the drives, except the CD-ROM drives, and copies itself as COMMAND.EXE and setup.RAR into that folder.


Terminates all the processes that contain any of the following strings:

KV
KAV
Duba
NAV
kill
RavMon.exe
Rfw.exe
Gate
McAfee
Symantec
SkyNet
rising


Creates a zip file named <filename>.<ext> in the root folder of all the drives, unless the drive letter is A or B.

<filename> will be one of the following:

WORK
setup
Important
bak
letter
pass

and <ext> is one of the following:

RAR
ZIP

This zip file contains a copy of the worm with the file name <filename>.<ext>.

<filename> is one of the following:

WORK
setup
Important
book
email
PassWord

and <ext> is one of the following:

.exe
.com
.pif
.scr


Creates the service, "Windows Management Protocol v.0 (experimental)", which is mapped to "Rundll32.exe msjdbc11.dll ondll_server".


Creates the service, "_reg," which is mapped to "Rundll32.exe msjdbc11.dll ondll_server."


Scans all the drives from C to Z. If the drive type is removable, mapped, or fixed, the worm will do the following on all the drives found:

Attempt to rename the extension on all .exe files to .zmx.
Set the attributes to Hidden and System on these files.
Copy itself as the original file name.


For example, if the worm finds OriginalFile.exe, it will be renamed to OriginalFile.zmx. The worm will then copy itself as OriginalFile.exe.


Runs a Backdoor routine on port 6000. The routine steals information of the infected computer and stores it in the file, C:\Netlog.txt. The worm then sends the stolen information to an email address.


Creates a network share, "Media", which is mapped to "%Windir%\Media".


Copies itself to all network-shared folders and subfolders as any of the following:

Thank you.doc.exe
3D Flash Animator.rar.bat
SWF Browser2.93.txt.exe
Download.exe
Panda Crack.zip.exe
WinRAR V3.2.0 Beta 2.exe
Swish2.00.pif
AAdobe Photoshop7.0 creak.pif
You_Life.JPG.pif
CloneCD crack.exe
WinZip v9.0 Beta Build 5480 crack.exe
Real-DRAW PRO v3.10.exe
Star Wars Downloader.exe
HyperSnap-DX v5.20.01.exe
Adobe Photoshop6.0.zip.exe
HyperSnap-DX v4.51.01.exe


Scans all the computers on the local network and attempts to log on as an Administrator using the following passwords:

Guest
Administrator
zxcv
yxcv
xxx
win
test123
test
temp123
temp
sybase
super
sex
secret
pwd
pw123
Password
owner
oracle
mypc123
mypc
mypass123
mypass
love
login
Login
Internet
home
godblessyou
god
enable
database
computer
alpha
admin123
Admin
abcd
aaa
88888888
2600
2003
2002
123asd
123abc
123456789
1234567
123123
121212
11111111
110
007
00000000
000000
pass
54321
12345
password
passwd
server
sql
!@#$%^&*
!@#$%^&
!@#$%^
!@#$%
asdfgh
asdf
!@#$
1234
111
root
abc123
12345678
abcdefg
abcdef
abc
888888
666666
111111
admin
administrator
guest
654321
123456
321
123

Note: The worm will also attempt to log on as "Administrator" if a password is not set for the account on a remote computer.


If the worm successfully logs on to the remote computer, it will attempt to copy itself as:

\\<remote computer name>\admin$\system32\NetManager.exe

and to start the file as the service, "Windows Management NetWork Service Extensions," which is mapped to "NetManager.exe -exe_start."


Locates the Kazaa file-sharing folder though a registry key and copies itself to that folder as one of the following:

wrar320sc
REALONE
BlackIcePCPSetup_creak
Passware5.3
word_pass_creak
HEROSOFT
orcard_original_creak
rainbowcrack-1.1-win
W32Dasm
setup
<random file name>

with a .bat, .exe, .pif, or .scr file extension.


Retrieves the email addresses from the files with .txt, .pl, .wab, .adb, .tbb, .dbx, .asp, .php, .sht, and .htm file extensions in the following folders:

%Windir%\Local Settings
\Documents and Settings\<current user>\local settings
Temporary Internet Files folder


Retrieves the email addresses from the Windows Address Book files.


Uses its own SMTP engine to send itself to the email addresses that it finds.

The email has the following characteristics:

Subject: (One of the following)
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error

Message: (One of the following)
pass
Mail failed. For further assistance, please contact!
The message contains Unicode characters and has been sent as a binary attachment.
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.

Attachment: (One of the following)
document
readme
doc
text
file
data
test
message
body

with one of the following file extensions:

.bat
.cmd
.exe
.pif
.scr


Replies to all the incoming messages when they arrive in the mailbox of certain MAPI-compliant email clients, including Microsoft Outlook.

If the original email is:

Subject: <subject>
From: <sender>@<domain.com>
Message: <original message body>

the worm will attempt to send the following email:

Subject: Re: <subject>
To: <sender>@<domain.com>

Message:
'<sender>' wrote:
====
> <original message body>
====

<domain.com> account auto-reply:

If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about,don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;
... ... more look to the attachment.


> Get your FREE <domain.com> account now! <

Attachment: (One of the following)
the hardcore game-.pif
Sex in Office.rm.scr
Deutsch BloodPatch!.exe
s3msong.MP3.pif
Me_nude.AVI.pif
How to Crack all gamez.exe
Macromedia Flash.scr
SETUP.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
DSL Modem Uncapper.rar.exe
joke.pif
Britney spears nude.exe.txt.exe
I am For u.doc.exe

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Delete the values from the registry.

To delete the value from the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the values:

"Program in Windows"="%system%\iexplore.exe"

"Protected Storage"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"

"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"

"WinHelp"="%system%\WinHelp.exe"


Follow the steps for your operating system:

Windows 95/98/Me. Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices

In the right pane, delete the value:

"Systemtra"="%Windir%\Systra.exe"


Windows NT/2000/XP. Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows

In the right pane, delete the value:

"run"="RAVMOND.exe"


Exit the Registry Editor

Edit the Win.ini file (Windows 95/98/Me).

To delete the value from the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the values:

"Program in Windows"="%system%\iexplore.exe"

"Protected Storage"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"

"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"

"WinHelp"="%system%\WinHelp.exe"


Follow the steps for your operating system:

Windows 95/98/Me. Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices

In the right pane, delete the value:

"Systemtra"="%Windir%\Systra.exe"


Windows NT/2000/XP. Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows

In the right pane, delete the value:

"run"="RAVMOND.exe"


Exit the Registry Editor

Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lovgate.AK@mm.

Change the .zmx files back to .exe files.

To change the .zmx files to .exe files
Because W32.HLLW.Lovgate.AK@mm changes .exe file extensions to .zmx, you must either restore the .exe file extension or re-install the programs. (In many cases, it may be easier to re-install the software.)

Follow the instructions for your operating system:

Windows 98/Me/2000

On the Windows desktop, click the Start button > Find or Search > Files or Folders.
In the Search Results window, set "Look in" to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Check Include subfolders.
In the "Named" or "Search for..." box, type, or copy and paste, the following:

*.zmx


Click Find Now or Search Now.


Windows XP

On the Windows desktop, click the Start button > Search.
Click All files and folders.
In the "All or part of the file name" box, type, or copy and paste, the following:

*.zmx


Verify that "Look in" is set to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Click More advanced options.
Select Search system folders.
Select Search subfolders.
Select Search hidden files and folders.
Click Search.


For every file that is found, right-click it > Rename. Change the .zmx extension to .exe.


Repeat step 6 for every removable, mapped, or fixed drive type with a drive letter greater than E.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.ak@mm.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Backdoor.Berbew.I
Discovered on: July 28, 2004
Last Updated on: July 29, 2004 11:00:01 AM


Backdoor.Berbew.I attempts to steal cached passwords.

Also Known As: TrojanSpy.Win32.Qukart.gen[Kaspersky], W32/Berbew.G[Fprot]
Variants: Backdoor.Berbew.G
Type: Trojan Horse
Infection Length: 46,080 bytes, 6,657 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Attempts to steal cached passwords. Sends collected information to a predetermined URL.
Compromises security settings: n/a
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When Backdoor.Berbew.I is executed, it performs the following actions:


Creates a mutex, "QueenKarton_13", which ensures that only one instance of the Trojan runs at once.


Creates the files:
%System%\<8 random characters>.exe
%System%\<8 random characters>.dll

Note: %System% is a variable. The Trojan locates the System folder and creates the file in that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates several <8 random characters>.htm files in the %Temp% folder.


Opens the <8 random characters>.htm files in Internet Explorer. Some of the files may access a predetermined URL at the domain, tat-neftbank.ru.


Adds the values:

"(Default)" = "<8 random characters>.dll"
"ThreadingModel" = "Apartment"

to the registry key:

HKEY_CLASSES_ROOT\CLSID\{79FEACFF-FFCE-815E-A900-316290B5B738}\InProcServer32


Adds the value:

"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad


Adds the value:

"QueenKarton" = "D"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft


Modifies the value:

"1601" = "0"

in the registry keys:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4


Modifies the value:

"GlobalUserOffline" = "0"

in the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings


Adds the value:

"BrowseNewProcess" = "yes"

to the registry key:

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess


Collects passwords from the infected computer and intercepts data entered into the forms in Internet Explorer.


May create the following files in the %System% folder to save this password information and any downloaded configuration data:

dnkkq.dll
kkq32.vxd
kkq32.dll
Rtdx1<number>.dat


The stolen information is passed to the attacker by sending HTTP query strings. Configuration data may also be uploaded through the Web to a predetermined URL. at the domain, tat-neftbank.ru.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Berbew.I.
Delete the values that was added to the registry.

To delete the values from the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.


Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_CLASSES_ROOT\CLSID\{79FEACFF-FFCE-815E-A900-316290B5B738}\InProcServer32


In the left pane, delete the subkeys:

"(Default)" = "%System%/<8 random characters>.dll"
"ThreadingModel" = "Apartment"


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad


In the right pane, delete the value:

"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft


In the right pane, delete the value:

"QueenKarton" = "D"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.berbew.i.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Mota.B@mm
Discovered on: July 27, 2004
Last Updated on: July 29, 2004 11:00:49 AM

W32.Mota.B@mm is a worm that propagates by sending itself to the email addresses gathered from the system.

Also Known As: W32/Mabutu.a@MM[McAfee]

Type: Worm
Infection Length: 32,768 bytes, 48,640 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Mails itself to the addresses gathered from an infected system.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may degrade system and network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: Varies
Name of attachment: Varies
Size of attachment: 32,768 bytes
Time stamp of attachment: n/a
Ports: Attempts to connect to IRC servers using port 6667.
Shared drives: n/a
Target of infection: n/a


When W32.Mota.B@mm runs, it does the following:


Copies itself as %Windir%\<random value>.exe (27,136 bytes).


Creates the following files:
%Windir%\<random value>.dll (39,936 bytes)
%WinDir%\CFG.DAT

Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and creates the files in that location.


Adds the value:

"winupdt"="RUNDLL32.EXE %Windir%\[random value].dll,_mainRD"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsfot\Windows\CurrentVersion\Run

so that the worm runs when you restart Windows.


Connects to one of following IRC servers using port 6667:

chat1.voila.fr
austin.tx.us.undernet.org
mesa.az.us.undernet.org
surrey.uk.eu.undernet.org
stockholm.se.eu.undernet.org
moscow.ru.eu.undernet.org
haarlem.nl.eu.undernet.org
amsterdam.nl.eu.undernet.org
amsterdam2.nl.eu.undernet.org
quebec.qu.ca.undernet.orggraz2.at.eu.undernet.org
toronto.on.ca.undernet.org
montreal.qu.ca.undernet.org
vancouver.bc.ca.undernet.org
graz.at.eu.undernet.org
london.uk.eu.undernet.org
brussels.be.eu.undernet.org
diemen.nl.eu.undernet.org
oslo.no.eu.undernet.org
flanders.be.eu.undernet.org
lulea.se.eu.undernet.org
los-angeles.ca.us.undernet.org
phoenix.az.us.undernet.org
washington.dc.us.undernet.org
atlanta.ga.us.undernet.org
manhattan.ks.us.undernet.org
baltimore.md.us.undernet.org
lasvegas.nv.us.undernet.org
newyork.ny.us.undernet.org
dallas.tx.us.undernet.org
saltlake.ut.us.undernet.org
arlington.va.us.undernet.org
auckland.nz.undernet.org
ann-arbor.mi.us.undernet.org
newbrunswick.nj.us.undernet.org
plano.tx.us.undernet.org
mclean.va.us.undernet.org
caen.fr.eu.undernet.org


Gathers the email addresses from the Windows Address Book and from the files that have file names containing any of the following strings:
HTM
HTML
WAB
TXT


Uses its own SMTP engine to send itself to the email addresses that it finds.

The email has the following characteristics:

From: The sender of the email may be spoofed.

Subject: The subject line may be one of the following:

Hi
Hello
Important
I'm in love
Sex
Wet girls
I'm nude
Fetishes
gutted
Ok /censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' />

Attachment: The attachment may have one of the following extensions:

britney.jpg
jenifer.jpg
photo.jpg
creme_de_gruyere.jpg
details
document
message
followed with .scr or .txt.

The attachment may have multiple spaces.

For example, the attachment can be:

creme_de_gruyere.jpg(multiple spaces).SCR

The worm may also send a .zip file as the attachment.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode.
Run a full system scan and delete all the files detected as W32.Mota.B@mm.
Delete the value that was added to the registry.

To delete the value from the registry

WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"RUNDLL32.EXE %Windir%\[random value].dll,_mainRD"


Exit the Registry Editor.

Restart the computer in normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mota.b@mm.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Backdoor.Moonlit
Discovered on: July 27, 2004
Last Updated on: July 29, 2004 10:56:02 AM

Backdoor.Moonlit is a Trojan horse program that can download and execute files, and may act as a proxy server.

Type: Trojan Horse
Infection Length: varies

Damage

Payload Trigger: n/a
Payload: Opens a backdoor.
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: varies.
Shared drives: n/a
Target of infection: n/a


Backdoor.Moonlit consists of a .exe file (the dropper) and a .dll file (the backdoor).

EXE component


Creates the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\MsMoney2003


Stops any processes that contain the following strings, and deletes the associated files:
_up
skynet
hkey.exe
msiwin84.exe
wmiprvsw.exe
avserve.exe
avserve2.exe
msblast.exe
wupdater.
sysupd.
belt.
wkufind.exe
ssgrate.exe
mra.exe
msbb.exe


Creates the following files:
%Temp%\tmp<random numbers>.dll (The backdoor .dll)
%System%\<random letters>.dll (The backdoor .dll with random data appended)


Loads the file, %System%\<random letters>.dll.


DLL component

Creates a new registry key:

HKEY_CLASSES_ROOT\CLSID\{<new CLSID>}


Adds the value:

(Default) = %System%\<random letters>.dll

to the registry key:

HKEY_CLASSES_ROOT\CLSID\{<new CLSID>}

to associate the backdoor DLL with the new clsid.


Adds the value:

<random letters> = {<new CLSID>}

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

so the DLL is loaded when you start Windows.

Note: <random letters> matches the name of the DLL.


Continuously resets these values.


Listens on a random TCP port. Depending on the input, the Trojan may download and execute a file, or act as a proxy server.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Moonlit.
Reverse the changes made to the registry.

To reverse the changes made to the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.


Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad


In the right pane, look for the value:

"<random letters>"="{<random clsid>}"

where <random letters> matches one of the files from step 4. Note the <random clsid>, and then delete the entry.


Navigate to each of the following keys, and delete them:

HKEY_CLASSES_ROOT\CLSID\{<random clsid>}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\MsMoney2003


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.moonlit.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W97M.Moridin
Discovered on: July 28, 2004
Last Updated on: July 29, 2004 12:11:45 PM

W97M.Moridin is a macro virus that infects Microsoft Word documents. It also disables macro virus protection, attempts to create an outgoing Pegasus Mail message, and attempts to run .exe components.

Also Known As: Moridin.b [Kaspersky], W97M/Moridin.gen [McAfee]

Type: Macro
Infection Length: 8,993

Systems Affected: Macintosh, Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Novell Netware, OS/2, UNIX, Windows 3.x

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Disables MS Word macro virus protection.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When W97M.Moridinruns, it performs the following actions:


Infects the Normal.dot file. Once this is done, the virus will be triggered when a Microsoft Word document is opened.


Disables the Microsoft Word macro virus protection.


As a stealth technique, W97M.Moridin hides its code by hooking the ToolsMacro and ViewVBCode automacros. If you attempt to view the macros, the virus deletes its own code.


Creates the file, Impmori.drv, in the %System% or %Windir% folder. This file contains a copy of the virus code. The virus reads from this file when infecting other documents.


Creates a draft message in the Pegasus Mail program.
There is a 12.5% chance that this message will contain the text.:

Check this out!

There is a 87.5% chance that this message will contain the text:

BAAAAAAAM! You just got hit by an attachment, this is the attachment war! Hit someone, NOW!


Attempts to run the following files, which are likely to be malicious:
%Windir%\W32mori.exe
%Windir%\Advapi33.exe

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as W97M.Moridin.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w97m.moridin.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”