Alerts

Moderators: Moderator, Global Moderator

Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Amus.A@mm
Discovered on: August 06, 2004
Last Updated on: August 07, 2004 12:44:25 PM

W32.Amus.A@mm is a mass-mailing worm that sends email with the subject "Listen and Smile" and the attachment "Masum.exe."

Also Known As: WORM_AMUS.A (Trend), Amus.A (Panda), Amus.A (F-Secure)

Type: Worm
Infection Length: 51,782 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows CE

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Yes
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: Listen and Smile
Name of attachment: Masum.exe
Size of attachment: 51,782 bytes
Time stamp of attachment: varies
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When W32.Amus.A@mm runs, it does the following:


Adds the value:

"Microzoft_Ofiz"="%Windir%\KdzEregli.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you start Windows.


Adds the value:

"Who"="OnEmLi_DeGiL"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Masum


Copies itself to the %Windir% folder as:
Pire.exe
Pide.exe
My_Pictures.exe
Meydanbasi.exe
Messenger.exe
KdzEregli.exe
Cekirge.exe
Anti_Virus.exe
Ankara.exe
Adapazari.exe

Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.


Copies itself as C:\Masum.exe.


Uses Microsoft Outlook to send itself to all the contacts in the Microsoft Outlook Address Book.

The email has the following characteristics:

Subject: Listen and Smile

Message Body: Hey. I beg your pardon. You must listen.

Attachment: Masum.exe

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Amus.A@mm.
Delete the value that was added to the registry.

To delete the value from the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Microzoft_Ofiz"="%Windir%\KdzEregli.exe"


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\


In the right pane, delete the subkey:

Masum


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.amus.a@mm.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Josh
Hero Member
Hero Member
Posts: 4627
Joined: Fri Jun 04, 2004 2:54 pm

Alerts

Post by Josh »

"Listen and Smile" eh? /blum.gif\' class=\'bbc_emoticon\' alt=\':P\' /> I got that one today! /biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' /> Glad I didn't open it =x /shocking.gif\' class=\'bbc_emoticon\' alt=\'(ack)\' />

~Josh /sp_ike.gif\' class=\'bbc_emoticon\' alt=\'(spike)\' />
[align=center]

Image

“If you stop learning, you stop living.” ~Tami Quiring

“It's the rare man who understands the value of a single perfect rose.”

[/align]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Beagle.AO@mm
Discovered on: August 09, 2004
Last Updated on: August 09, 2004 03:27:33 PM

W32.Beagle.AO@mm is a mass mailing worm that uses its own SMTP engine to spread. The email attachment is a Mitglieder-like downloader that brings the worm from external sources.

The worm also has a backdoor functionality, opening UDP and TCP port 80.

Note: Virus definitions version 60809aj (extended version 8/9/2004 rev. 36) and greater are required to detect this threat. The respective LiveUpdate definitions which contain protection are version 60809ak (8/9/2004 rev. 37).


Also Known As: W32/Bagle.aq@MM [McAfee], WORM_BAGLE.AC [Trend], Win32.Bagle.AG [Computer Associates]

Type: Worm

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: n/a
Name of attachment: Varies with .zip file extension
Size of attachment: Varies
Time stamp of attachment: n/a
Ports: 80/tcp and 80/udp
Shared drives: n/a
Target of infection: n/a


When W32.Beagle.AO@mm runs, it does the following:


Copies itself as %System%\WINdirect.exe.


Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds a value:

"win_upd.exe"="%System%\WINdirect.exe"

to the registry keys:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that it runs when you restart Windows.


Creates a file, %System%\_dll.exe.


Injects %System%\_dll.exe as a thread into a process with a window class name of "Shell_TrayWnd." If successful, this threat will continue to run within the infected process. All the actions described in the next steps will appear to be done by the infected process, and the Trojan will not show when viewing the process list in the Windows Task Manager.


Terminates the following processes:

ATUPDATER.EXE
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE
sys_xp.exe
sysxp.exe
winxp.exe


Attempts to download files from the following Web sites as %Windir%\~.exe, and then run it:

134.102.228.45
196.12.49.27
213.188.129.72
64.62.172.118
abi-2004.org
advm1.gm.fh-koeln.de
alexey.pioneers.com.ru
alfinternational.ru
aus-Zeit.com
binn.ru
burn2k.ipupdater.com
carabi.ru
catalog.zelnet.ru
cavalierland.5u.com
celine.artics.ru
change.east.ru
colleen.ai.net
controltechniques.ru
dev.tikls.net
diablo.homelinux.com
dodgetheatre.com
dozenten.f1.fhtw-berlin.de
emnesty.w.interia.pl
emnezz.e-mania.pl
euroviolence.com
evadia.ru
fairy.dataforce.net
financial.washingtonpost.com
free.bestialityhost.com
gutemine.wu-wien.ac.at
herzog.cs.uni-magdeburg.de
home.profootball.ru
host.businessweek.com
host.wallstreetcity.com
host23.ipowerweb.com
hsr.zhp.org.pl
infokom.pl
kafka.punkt.pl
kooltokyo.ru
kypexin.ru
lars-s.privat.t-online.de
lottery.h11.ru
matzlinger.com
megion.ru
mmag.ru
molinero-berlin.de
momentum.ru
niebo.net
nominal.kaliningrad.ru
omegat.ru
ourcj.com
packages.debian.or.jp
pb195.slupsk.sdi.tpnet.pl
photo.gornet.ru
pixel.co.il
pocono.ru
polobeer.de
porno-mania.net
protek.ru
przeglad-tygodnik.pl
przeglad-tygodnik.pl
quotes.barchart.com
r2626r.de
rausis.latnet.lv
relay.great.ru
republika.pl
sacred.ru
sbuilder.ru
sec.polbox.pl
shadkhan.ru
silesianet.pl
silesianet.pl
slavarik.ru
sovea.de
spbbook.ru
strony.wp.pl
szm.sk
tarkosale.net
tdi-router.opola.pl
terramail.pl
thorpedo.us
traveldeals.sidestep.com
ultimate-best-hgh.0my.net
vip.pnet.pl
werel1.web-gratis.net
www.5100.ru
www.PlayGround.ru
www.aannemers-nederland.nl
www.abcdesign.ru
www.airnav.com
www.aktor.ru
www.ankil.ru
www.antykoncepcja.net
www.aphel.de
www.artics.ru
www.astoria-stuttgart.de
www.avant.ru
www.baltmatours.com
www.baltnet.ru
www.biratnagarmun.org.np
www.biysk.ru
www.boglen.com
www.bridesinrussia.com
www.busheron.ru
www.ccbootcamp.com
www.chat4adult.com
www.chelny.ru
www.ciachoo.pl
www.dami.com.pl
www.ddosers.net
www.dicto.ru
www.dilver.ru
www.dsmedia.ru
www.dynex.ru
www.elemental.ru
www.elit-line.ru
www.epski.gr
www.forbes.com
www.free-time.ru
www.gamma.vyborg.ru
www.gantke-net.com
www.gin.ru
www.glass-master.ru
www.glavriba.ru
www.gradinter.ru
www.hack-gegen-rechts.com
www.hbz-nrw.de
www.hgr.de
www.hgrstrailer.com
www.ifa-guide.co.uk
www.iluminati.kicks-ass.net
www.infognt.com
www.intellect.lvc
www.interfoodtd.ru
www.interrybflot.ru
www.inversorlatino.com
www.jewishgen.org
www.k2kapital.com
www.kefaloniaresorts.com
www.lamatec.com
www.landofcash.net
www.laserbuild.ru
www.math.kobe-u.ac.jp
www.mcschnaeppchen.com
www.mdmedia.org
www.met.pl
www.metacenter.ru
www.milm.ru
www.myrtoscorp.com
www.nefkom.net
www.neostrada.pl
www.neprifan.ru
www.netradar.com
www.no-abi2003.de
www.oldtownradio.com
www.omnicom.ru
www.oshweb.com
www.pakwerk.ru
www.perfectgirls.net
www.perfectjewel.com
www.peterstar.ru
www.pgipearls.com
www.phg.pl
www.porsa.ru
www.porta.de
www.rafani.cz
www.rastt.ru
www.republika.pl
www.republika.pl
www.rollenspielzirkel.de
www.rubikon.pl
www.rumbgeo.ru
www.rweb.ru
www.scli.ru
www.sdsauto.ru
www.sensi.com
www.silesianet.pl
www.sjgreatdeals.com
www.sposob.ru
www.strefa.pl
www.tanzen-in-sh.de
www.taom-clan.de
www.tayles.com
www.teatr-estrada.ru
www.teleline.ru
www.thepositivesideofsports.com
www.timelessimages.com
www.tuhart.net
www.vconsole.net
www.vendex.ru
www.virtmemb.com
www.vivamedia.ru
www.vrack.net
www.wapf.com
www.webpark.pl
www.webronet.com
www.webzdarma.cz
www.yarcity.ru
www.youbuynow.com
www.zeiss.ru
www.zelnet.ru
www.zhp.gdynia.pl
wynnsjammer.proboards18.com
yaguark.h10.ru


Note: %Windir% is a variable. The Trojan locates the Windows installation folder and saves the downloaded files to that location. By default, this is C:\Windows or C:\Winnt.


When the file which is downloaded is executed it performs the following actions:

Creates seven mutexes with the following names, which prevent some variants of W32.Netsky@mm from running:

MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_


Creates the following files:

%System%\windll.exe.
%System%\windll.exeopen, which is a copy of the worm with randomly appended data.
%System%\windll.exeopenopen, which is a copy of the worm with randomly appended data.
%System%\re_file.exe

Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds a value:

"erthgdr"="%System%\windll.exe"

to the registry key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Deletes any values that contain the following strings:
"9XHtProtect"
"Antivirus"
"EasyAV"
"FirewallSvr"
"HtProtect"
"ICQ Net"
"ICQNet"
"Jammer2nd"
"KasperskyAVEng"
"MsInfo"
"My AV"
"NetDy"
"Norton Antivirus AV"
"PandaAVEngine"
"SkynetsRevenge"
"Special Firewall Service"
"SysMonXP"
"Tiny AV"
"Zone Labs Client Ex"
"service"

from the registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Attempts to create copies of itself in any folder that contains the characters "shar". The files will have the following file names:

Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral, /censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> cool, awesome!!.exe
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe


Searches for the email addresses in files that have the following extensions:
.adb
.asp
.cfg
.cgi
.dbx
.dhtm
.eml
.htm
.jsp
.mbx
.mdx
.mht
.mmf
.msg
.nch
.ods
.oft
.php
.pl
.sht
.shtm
.stm
.tbb
.txt
.uin
.wab
.wsh
.xls
.xml


Uses its own SMTP engine to send email messages to any addresses that it found.

The email may have the following characteristics:

From: <spoofed>

Subject: <empty>

Body: New price

Attachment: (One of the following)
08_price.zip
new__price.zip
new_price.zip
newprice.zip
price.zip
price2.zip
price_08.zip
price_new.zip

Note: The zip file contains an executable with the same name as the zip, and a Price.html. This is the executable which is responsible for downloading the mailer component. There is a mechanism in the code to password protect the zip file, but this does not work.


The worm will not send itself to addresses containing the following strings:
@avp.
@foo
@iana
@messagelab
@microsoft
abuse
admin
anyone@
bsd
bugs@
cafee
certific
contract@
feste
free-av
f-secur
gold-certs@
google
help@
icrosoft
info@
kasp
linux
listserv
local
news
nobody@
noone@
noreply
ntivi
panda
pgp
postmaster@
rating@
root@
samples
sopho
spam
support
unix
update
winrar
winzip


Opens a backdoor on TCP and UDP port 80, which allows the infected computer to be used as an email relay.


Creates the following registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ru1n

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AO@mm.
Delete the value that was added to the registry.

To delete the value from the registry

WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the values:

"win_upd2.exe" = "%System%\WINdirect.exe"
"erthgdr" = "%System%\windll.exe"


Navigate to the key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion


In the left pane, delete the subkey Ru1n


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ao@mm.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Trojan.StartPage.G
Discovered on: August 09, 2004
Last Updated on: August 09, 2004 04:55:10 PM

Trojan.StartPage.G is a Trojan horse that downloads and runs an executable and attempts to change the Internet Explorer home page.

Type: Trojan Horse
Infection Length: 19,500 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When Trojan.StartPage.G is executed, it performs the following actions:


Downloads and executes an .exe file.


Creates the following copies of itself:

%Windir%\system\taskmgr.exe
%Windir%\N0TEPAD.EXE
%Windir%\system\N0TEPAD.EXE
%Windir%\system32\N0TEPAD.EXE
%Windir%\system\windll.dll (A text file.)


Adds the value:

"taskmgr"="%Windows%\system\taskmgr.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs when Windows starts.


Modifies the value to:

"MainStart Page"="about:blank"

in the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer


Adds the value:

"(Default)"="N0TEPAD.EXE %1"

to the registry key:

HKEY_CLASSES_ROOT\txtfile\shell\open\command

so that when an user opens a text file, the Trojan will start.


Adds the value :

"AskUser"="0"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms


Adds the value :

"UseFormSuggest"="no"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main


Opens a Web page at the domain, www.ye.ah.to.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.StartPage.G.
Delete the value that was added to the registry.

To delete the value from the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"taskmgr"="%Windows%\system\taskmgr.exe"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms


In the right pane, delete the value:

"AskUser"="0"


Naviage to the key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main


In the right pane, delete the value:

"UseFormSuggest"="no"


Navigate to the key:

HKEY_CLASSES_ROOT\txtfile\shell\open\command


In the right page, modify the value:


Windows 95/98/Me:
"(Default)"="WINDOWS\NOTEPAD.EXE %1"


Windows NT/2000/XP:
"(Default)"="%SystemRoot%\system32\NOTEPAD.EXE %1"


Exit the Registry Editor.


[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.g.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Trojan.StartPage.F
Discovered on: August 08, 2004
Last Updated on: August 09, 2004 04:55:15 PM

Trojan.StartPage.F is a program that changes the home page of Internet Explorer and installs a Browser Helper Object.

Also Known As: TROJ_STRTPAGE.CQ [Trend Micro], Troj/CWS-C [Sophos], StartPage-CQ.gen [McAfee], TrojanDownloader.Win32.Small.lc [Kaspersky]
Variants: Trojan.StartPage
Type: Trojan Horse
Infection Length: 52,736 bytes, 54,784 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When Trojan.StartPage.F is executed, it performs the following actions:


Changes the home page of Internet Explorer to "homepage.com".


Redirects all URLs through "ehttp.cc"


May display a dialog box:

Serious Security Vulnerability Has Been Found

If the user clicks on the button, the program attempts to open a Web page on the domain, www.security-look.cc.


May launch pop-up windows containing pornographic material.


Deletes the registry key:

HKEY_LOCAL_MACHINE\Software\Classes\PROTOCOLS\Handler\ms-its


Creates the file, %Windir%/dpe.dll. This is a Browser Helper Object.

Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.


Adds the value:

"AddClass" = "<Installation_Path>"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs when you start Windows.


Adds the value:

"Host" = ""

to the registry keys:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Adds the values:

"Default_Search_URL" = "http://%68%6F%6D%..."
"Search Bar" = "http:/ /%68%6F%6D%..."
"Search Page" = "http:/ /%68%6F%6D%..."
"Start Page" = "http:/ /%68%6F%6D%..."

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main


Adds the value:

"(Default)" = "http:/ /%65%68%74%74%70%2E%63%63/?"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix


Adds the value:

"www" = "http:/ /%65%68%74%74%70%2E%63%63/?"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes


Adds the value:

"{834261E1-DD97-4177-853B-C907E5D5BD6E}" = ""

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects


Adds the following registry keys:

HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek
HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek.1
HKEY_CLASSES_ROOT\CLSID\{834261E1-DD97-4177-853B-C907E5D5BD6E}
HKEY_CLASSES_ROOT\TypeLib\{BD0022A3-A43F-4F44-B64F-53EA7575F097}
HKEY_CLASSES_ROOT\Interface\{B1E68D42-02C4-465B-8368-5ED9B732E22D}
HKEY_CLASSES_ROOT\Interface\{0B6EF17E-18E5-4449-86EA-64C82D596EAE}

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Close all open Internet Explorer windows
Run a full system scan and delete all the files detected as Trojan.StartPage.F.
Delete the value that was added to the registry.
Reset the Internet Explorer home page.
Reset the Internet Explorer search page.

To delete the value from the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the values:

"AddClass" = "<Installation_Path>"
"Host" = ""


Navigate to the key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Host" = ""


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects


In the left pane, delete the value:

{834261E1-DD97-4177-853B-C907E5D5BD6E}


Delete the following keys:

HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek
HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek.1
HKEY_CLASSES_ROOT\CLSID\{834261E1-DD97-4177-853B-C907E5D5BD6E}
HKEY_CLASSES_ROOT\TypeLib\{BD0022A3-A43F-4F44-B64F-53EA7575F097}
HKEY_CLASSES_ROOT\Interface\{B1E68D42-02C4-465B-8368-5ED9B732E22D}
HKEY_CLASSES_ROOT\Interface\{0B6EF17E-18E5-4449-86EA-64C82D596EAE}


Exit the Registry Editor.

To reset the Internet Explorer home page
Start Microsoft Internet Explorer.
Connect to the Internet, and then go to the page that you want to set as your home page.
Click Tools > Internet Options.
In the Home page section of the General tab, click Use Current > OK.

For additional information, or if this procedure does not work, read the Microsoft® Knowledge Base article, "Home Page Setting Changes Unexpectedly, or You Cannot Change Your Home Page Setting, Article ID 320159."

7. To reset the Internet Explorer Search page
Follow the instructions for your version of Windows.

Windows 98/Me/2000
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.

Windows XP
Because Windows XP is set by default to use animated characters in the search, how you do this can vary. Read all the instructions before you start.
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
Do one of the following:
If the pane that opens looks similar to this picture:

[img]http://www.killanet.net/uploads/trojan.startpage.f1.gif[/img]

click the word Customize. Then skip to step h.


If the pane that opens has the words "Search Companion" at the top, and the center looks similar to this picture:

[img]http://www.killanet.net/uploads/trojan.startpage.f2.gif[/img]

click the Change preferences link as shown above. Proceed with step d.


Click the Change Internet search behavior link.
Under "Internet Search Behavior," click With Classic Internet Search.
Click OK. Then close Internet Explorer. (Close the program for the change to take effect.)
Start Internet Explorer. When the search pane opens, it should now look similar to this:

[img]http://www.killanet.net/uploads/trojan.startpage.f3.gif[/img]

Click the word Customize, and then proceed with the next step.


In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.
Do one of the following:
If you were using (or want to continue using) the "Classic Internet Search" panel, stop here (or proceed with the next section).
If you want to go back to the "Search Companion" search (it usually has an animated character at the button), proceed with step n.


Click the word Customize again.
In the "Customize Search Settings" window, click Use Search Companion > OK.
Close Internet Explorer. The next time you open it, it will again use the Search Companion.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.f.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Mydoom.P@mm
Discovered on: August 09, 2004
Last Updated on: August 10, 2004 02:34:00 PM

W32.Mydoom.P@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses that it finds on an infected computer. The email contains a spoofed From address. The subject and message body vary, and the attachment has a .bat, .cmd, .exe, .pif, .scr, or .zip extension.

This threat is packed using UPX.


Also Known As: WORM_MYDOOM.R [Trend Micro], W32/Mydoom.r@MM [McAfee], W32/MyDoom-R [Sophos]

Type: Worm
Infection Length: 17,408 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Uses its own SMTP engine to send itself to the email addresses found in the files with certain extensions.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: Varies
Name of attachment: Varies with .bat, .cmd, .exe, .pif, .scr, or .zip file extension.
Size of attachment: 17,408 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When W32.Mydoom.P@mm is executed, it does the following:


Copies itself as %System%\Taskmon.exe.

Notes:
Taskmon.exe is a legitimate file in the Windows 95/98/Me operating systems, but is in the %Windir% folder, not the %System% folder. (By default, this is C:\Windows or C:\Winnt.) Do not delete the legitimate file in the %Windir% folder.
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the file, %Temp%\Message, and then opens it with Notepad.


Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).


Creates a mutex, "SwebSipcSmtxS1", which allows only one instance of the worm to run in memory.


Creates the following registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version


Downloads a file from a predefined Web page as Zsdssfds.exe, and then runs the file.


Retrieves the email addresses from the files that have the following extensions on drives C through Y:

.pl
.abdh
.tbbg
.dbxn
.aspd
.phpq
.shtl
.htmb
.txt
.wab


Retrieves the email addresses from the Windows Address Book files.


Uses its own SMTP engine to send iteslf to the email addresses that it finds.

The email has the following characteristics:

From:
The From address is spoofed.

Subject: The subject may be one of the following:

test
hi
hello
Mail Delieery System
Mail transaction Failed
Server Report
Status
Error

Message: The message may be one of the following:

test
Mail transaction failed. Partial message is available.
The message contains Unicode characters and has been sent as a binary attachment.
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.

Attachment: The attachment name may be one of the following:

document
readme
doc
body
text
file
data
test
messge
body

with one of the following extensions:

.bat
.cmd
.exe
.pif
.scr
.zip


It avoids sending itself to the email addresses that contains any of the following:

mozilla
utgers.ed
tanford.e
pgp
acketst
secur
isc.o
isi.e
ripe.
arin.
sendmail
rfc-ed
ietf
iana
usenet
fido
linux
kernel
google
ibm.com
fsf.
gnu
mit.e
bsd
math
unix
berkeley
foo.
.mil
gov.
.gov
ruslis
nodomai
mydomai
example
inpris
borlan
sopho
panda
hotmail
msn.
icrosof
syma
avp


Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Mydoom.P@mm.
Reverse the changes made to the registry.

To reverse the changes made to the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.


Click Start > Run.
Type regedit

Then click OK.


Navigate to and delete thekeys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.p@mm.html\"]Symantec Security[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Backdoor.Beasty.I
Discovered on: August 10, 2004
Last Updated on: August 11, 2004 11:07:05 AM

Backdoor.Beasty.I is a backdoor Trojan horse that allows an attacker complete access to an infected computer. The Trojan listens on TCP port 9999 and notifies the attacker through ICQ.



Type: Trojan Horse
Infection Length: 30,935 bytes



Systems Affected: Windows 2000, Windows 95, Windows 98, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, OS/2, UNIX

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Opens a backdoor, allowing unauthorized remote access.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP 9999
Shared drives: n/a
Target of infection: n/a


When Backdoor.Beasty.I runs, it performs the following actions:


Displays the following message:

[img]http://www.killanet.net/uploads/beastyI.gif[/img]

Copies the following files to the %System% folder:

mspuep.com
mslg.blf

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Copies the file, e-gold.exe, to the %Windir% folder:

Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.


Copies itself as %Windir%\msagent\msdrce.com.

Note: Under some operating systems, such as Windows 2000, the file may be copied to the %System% folder instead.


May add the value:

"COM Service"="%Windir%\msagent\msdrce.com"

to the registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run


Creates the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CE4021-DE03-E3CC-EA32-40BB12E6015D}


Uses ICQ to notify the author that the Trojan is running.


Opens TCP port 9999 and waits for a commands from the attacker.

The attacker may perform any of the following actions on the compromised system:

Upload, download, and delete files
Manipulate file attributes (Hidden, System, Read-only)
Launch applications
Modify the registry
Kill processes
Perform screen captures
Perform various nuisance actions such as opening and closing the CD-ROM drive

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Beasty.I.
Delete the value that was added to the registry.

To delete the value from the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the following key and delete it:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CE4021-DE03-E3CC-EA32-40BB12E6015D}


Navigate to the following keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
KEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run


In the right pane, delete the value, if present:

"COM Service"="%Windir%\msagent\msdrce.com"


Exit the Registry Editor

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.beasty.i.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Trojan.Boxed.E
Discovered on: August 11, 2004
Last Updated on: August 12, 2004 10:00:44 AM

Trojan.Boxed.E is a Trojan horse that performs a Denial of Service (DoS) attack on certain Web sites. DoS attacks are used to deny legitimate users access to a Web site.



Type: Trojan Horse
Infection Length: 27,206 bytes



Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: Replaces the existing hosts file.
Degrades performance: The Trojan's network activity can degrade system performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates services associated with antivirus programs.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When Trojan.Boxed.E is executed, it performs the following actions:


Deletes the following services that are associated with antivirus software or variants of Trojan.Boxed.

kavsvc
SAVScan
Symantec Core LC
navapsvc
wuauserv
nwclntc
nwclntd
nwclnte
nwclntf


Creates the following registry keys installing itself as a service:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nwclntg

This Trojan uses "nwclntg" as its service name and "Network Client" as its service display name.

Note: This service will automatically run at startup.


Copies itself as %Windir%\system\winlogon.exe.

Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.


Performs DoS attacks on the following Web sites:

logout.xpseek.com
secmemb.xpseek.com
mb.maybugs.com
members.maybugs.com
login.maybugs.com
secure.maybugs.com
mb.hvr-systems.cc
members.hvr-systems.cc
login.hvr-systems.cc
secure.hvr-systems.cc
mb.xpseek.com
members.xpseek.com
login.xpseek.com
secure.xpseek.com
mb.maybirds.org
members.maybirds.org
login.maybirds.org
secure.maybirds.org


Replaces the existing %System%\drivers\etc\hosts file with one that contains the following text, so that any attempts to connect to these Web sites fail:

127.0.0.1 localhost
127.0.0.1 ids.kaspersky-labs.com
127.0.0.1 downloads2.kaspersky-labs.com
127.0.0.1 downloads1.kaspersky-labs.com
127.0.0.1 downloads3.kaspersky-labs.com
127.0.0.1 downloads4.kaspersky-labs.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 update.symantec.com
127.0.0.1 download.mcafee.com
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com
127.0.0.1 www.grisoft.com


Note: %System% is a variable. The Trojan locates the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

Removal Instructions:

Disable System Restore (Windows Me/XP).

Restart the computer in Safe mode or VGA mode.

Delete the registry key (Windows NT/2000/XP).
To delete the key from the registry (Windows NT/2000/XP)

WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Delete the key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nwclntg


Exit the Registry Editor.

Restore the Hosts file.
To restore the Hosts file

Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.


Follow the instructions for your operating system:
Windows 95/98/Me/NT/2000
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
In the "Named" or "Search for..." box, type:

hosts


Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file, except for the following line:

127.0.0.1 localhost


Close Notepad and save your changes when prompted.


Windows XP
Click Start > Search.
Click All files and folders.
In the "All or part of the file name" box, type:

hosts


Verify that "Look in" is set to "Local Hard Drives" or to (C:).
Click More advanced options.
Check Search system folders.
Check Search subfolders.
Click Search.
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file except for the following line:

127.0.0.1 localhost


Close Notepad and save your changes when prompted.

Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Boxed.E.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.boxed.e.html\"]Symantec Source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

W32.Mydoom.Q@mm
Discovered on: August 16, 2004
Last Updated on: August 16, 2004 11:49:46 AM

W32.Mydoom.Q@mm is a mass-mailing worm that downloads an executable file and uses its own SMTP engine to send itself to the email addresses that it finds on the infected computer.
The downloaded file is detected as Backdoor.Nemog.

The email has the following characteristics:

From: <spoofed>

Subject: Photos

Attachment: photos_arc.exe

Notes:

Rapid Release definitions sequence number 34589 or later detect this threat.
Virus definitions version number 60816c (extended version 08/16/2004 rev. 3) or later detect this threat.

Also Known As: W32/Mydoom.s@MM [McAfee], W32/MyDoom-S [Sophos], Win32.Mydoom.S [Computer Associates], WORM_RATOS.A [Trend Micro]

Type: Worm
Infection Length: 27,136 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom@mm.removal.tool.html\"]Removal Tool[/url]

Damage:
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to the email addresses that it finds on the infected computer.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Downloads and executes a Backdoor.Trojan.
Distribution

Subject of email: Photos
Name of attachment: photos_arc.exe
Size of attachment: 27136 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a

Technical Details:

When W32.MyDoom.Q@mm runs it performs the following actions:


Creates a file %Temp%\Message and opens it in Notepad. This file contains garbage data.


Copies itself as the files:

%System%\winpsd.exe
%Windows%\rasor38a.dll

Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP)or C:\Winnt (Windows NT/2000).


Creates a mutex named "43jfds93872", so that only one copy of the worm will run on the infected computer.


Downloads a file from one of the following domains:

www.richcolour.com
zenandjuice.com

Note: The downloaded file is detected as Backdoor.Nemog and is saved as winvpn32.exe, and then executed.


Checks system time. If the time is after 21:11:11 on August 20th, 2004, the worm will exit.


Adds the value:
"winpsd"="%System%winpsd.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm starts when Windows starts.


Adds the value:

"InstaledFlashhMx"="1"

to the registry key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer

as an infection marker, indicating that it has successfully downloaded and executed Backdoor.Nemog.


Creates the following key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32

The worm retrieves email addresses from files that have the following extensions.

.htm
.sht
.php
.asp
.dbx
.tbb
.adb
.wab
.pl


Retrieves email addresses from the Outlook address book.


The worm uses its own SMTP engine to send itself to the email addresses that it finds.

The email has the following characteristics:
From:
The From address is spoofed. It may use an email address of a user on the infected computer, or start with one of the following names:

john
alex
michael
james
mike
kevin
david
george
sam
andrew
jose
leo
maria
jim
brian
serg
mary
ray
tom
peter
robert
bob
jane
joe
dan
dave
matt
steve
smith
stan
bill
bob
jack
fred
ted
adam
brent
alice
anna
brenda
claudia
debby
helen
jerry
jimmy
julie
linda
sandra

the domain will be one of the following:

t-online.de
mail.com
yahoo.com
hotmail.com
The domain of the email address read from:

HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager


Subject: Photos

Message: LOL!/bigwink.gif\' class=\'bbc_emoticon\' alt=\';)\' />)))

Attachment: photos_arc.exe

The worm will not send itself to email addresses that contain the following strings:

avpsyma
icrosof
msn.
hotmail
panda
sopho
borlan
inpris
example
mydomai
nodomai
ruslis
.gov
gov.
.mil
foo.
berkeley
unix
math
bsd
mit.e
gnu
fsf.
ibm.com
google
kernel
linux
fido
usenet
iana
ietf
rfc-ed
sendmail
arin.
ripe.
isi.e
isc.o
secur
acketst
pgp
tanford.e
utgers.ed
mozilla
be_loyal:
root
info
samples
postmaster
webmaster
noone
nobody
nothing
anyone
someone
your
you
bugs
rating
site
contact
soft
somebody
privacy
service
help
not
submit
feste
gold-certs
the.bat
page
admin
icrosoft
support
ntivi
unix
bsd
linux
listserv
certific
google
accoun
abuse
upport
www
spm
spam
www
secur
abuse

Symantec Gateway Security 2.0 - 5400 Series and Symantec Gateway Security 1.0 – 5300 Series

Antivirus component: An update for the Symantec Gateway Security AntiVirus engine to protect against the W32.MyDoom.Q@mm worm is now available. Symantec Gateway Security 5000 Series users are advised to run LiveUpdate.
IDS/IPS component: An update for the Symantec Gateway Security 5000 Series IDS/IPS engine is not expected.
Full application inspection firewall component: By default, when an SMTP rule is configured through the Policy Wizard, the SMTPd proxy on the security gateway will block infected systems from directly sending email to the Internet.

Symantec Enterprise Firewall 8.0
By default, when an SMTP rule is configured through the Policy Wizard, the SMTPd proxy on the security gateway will block infected systems from directly sending email to the Internet.

For Windows based firewalls, unique initial and ongoing system hardening protects the firewall operating system itself, which includes disabling the dx32hhec service created by the worm.

Symantec Enterprise Firewall 7.0.x and Symantec VelociRaptor 1.5
By default, when an SMTP rule is configured through the Policy Wizard, the SMTPd proxy on the security gateway will block infected systems from directly sending email to the Internet.

Symantec Clientless VPN Gateway 4400 Series
Symantec Clientless VPN Gateway v5.0 is not affected by this threat. To reduce risk of further propagation you should also include a rule that only allows mail access from authenticated remote users to your internal mail server.

Symantec Gateway Security 300 Series
Symantec Gateway Security 300 series is not affected by this threat. To reduce risk of further propagation you should also include a rule that only allows mail access from authenticated remote users to your internal mail server.

Symantec Firewall/VPN 100/200 Series
Symantec Gateway Security 100/200 series is not affected by this threat. To reduce risk of further propagation you should also include a rule that only allows mail access from authenticated remote users to your internal mail server.

Removal Instructions:

Removal using the Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of W32.Mydoom.Q@mm. This is the preferred method in most cases.

Manual Removal
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.MydoomQ@mm.
Reverse the changes made to the registry.

To reverse the changes made to the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.


Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"winpsd"="%System%winpsd.exe"


Navigate to the key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer


In the right pane, delete the value:

"InstaledFlashhMx"="1"

Delete the following key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.q@mm.html\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Backdoor.Nemog
Discovered on: August 16, 2004
Last Updated on: August 16, 2004 04:55:49 PM

Backdoor.Nemog is a Backdoor Trojan horse that allows an infected computer to be used as an email relay and HTTP proxy.
This backdoor is dropped by [url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.q@mm.html\"]W32.Mydoom.Q@mm[/url].

Type: Trojan Horse
Infection Length: 139,776, 4,096

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX


Technical Details:

When Backdoor.Nemog is executed, it performs the following actions:


Creates the following files:

%System%\dx32hhlp.exe
%System%\dx32hhec.sys

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the following service so that it executes every time Windows starts:

dx32hhec


Hides its service and files by hooking the following APIs:

ZwQuerySystemInformation
ZwQueryDirectoryFile

and returning empty results when searching for the following string:

dx32hh

Adds the values:

"mutexadmin"="1"
"mutexname"="<random letters>"
"vers"="0x0001003d"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer

which the backdoor uses as an infection marker.


Gets the location of the Startup folder by querying the value of:

"Common Startup"

in the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

and then copies itself to that location as dx32hhlp.exe.


Attempts to contact eMule servers at the following IP addresses and port numbers:
62.241.53.2:4242
211.233.41.235:4661
81.23.250.167:4242
193.19.227.24:4661
66.98.192.99:3306
207.44.222.47:4661
213.158.119.104:4661
207.44.206.27:4661
62.241.53.4:4242
216.127.94.107:4661
67.15.18.45:3306
62.241.53.15:4242
64.246.54.12:3306
62.241.53.16:4242
211.214.161.107:4661
67.15.18.57:3306
66.98.144.100:4242
69.50.187.210:4661
66.111.43.80:4242
212.199.125.36:8080
66.90.68.2:6565
62.241.53.17:4242
69.50.228.50:4646
81.23.250.169:4242
69.57.132.8:4661
64.246.18.98:4661
218.78.211.62:4661
207.44.142.33:4242
64.246.16.11:4661
205.209.176.220:4661
80.64.179.46:4242
65.75.161.70:4661


Allows remote users to relay email through a randomly chosen TCP port.


Runs as an HTTP proxy on another randomly chosen TCP port.


Additional functionality allows the backdoor to:

Uninstall itself
Update itself
Download a file


Appends the following entries to the %System%\DRIVERS\ETC\HOSTS file , preventing access to certain security related Web sites:

127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com

Removal Instructions:

Removal using the Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of W32.Mydoom.M@mm. This is the preferred method in most cases.

Manual Removal
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Nemog.
Delete the value from the registry key.

To delete the value from the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer


In the right pane, delete the value:

"mutexadmin"="1"
"mutexname"="<random letters>"
"vers"="0x0001003d"


Exit the Registry Editor.

Delete the lines added to the Hosts file.

To delete the added lines from the Windows Hosts file

Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.


Follow the instructions for your operating system:
Windows 95/98/Me/NT/2000
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
In the "Named" or "Search for..." box, type:

hosts


Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file, except for the following line:

127.0.0.1 localhost


Close Notepad and save your changes when prompted.

Windows XP
Click Start > Search.
Click All files and folders.
In the "All or part of the file name" box, type:

hosts


Verify that "Look in" is set to "Local Hard Drives" or to (C:).
Click More advanced options.
Check Search system folders.
Check Search subfolders.
Click Search.
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the Always use this program to open this program check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file except for the following line:

127.0.0.1 localhost


Close Notepad and save your changes when prompted.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.nemog.html\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Downloader.Harnig
Discovered on: August 13, 2004
Last Updated on: August 16, 2004 09:55:35 AM

Downloader.Harnig is a program that downloads Trojans, adware, and dialers, and terminates services associated with antivirus software.



Type: Trojan Horse
Infection Length: 5,120 bytes



Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: Linux, Macintosh, Microsoft IIS, OS/2, UNIX, Windows 3.x

Technical Information:

When Downloader.Harnig runs, it performs the following actions:


Creates the following files:

%System%\secure32.txt
%Windir%\system.exe
%Windir%\system32\system32.dll
%Windir%\desktop.exe
%Windir%\toolbar.exe
%Windir%\mstasks1.exe (Detected as Backdoor.Jeem)
%Windir%\mstasks2.exe
%Windir%\test
%Windir%\seksdialer.exe
%Windir%\system32\wintime.exe
%Windir%\system32\dkdial.exe
%Windir%\system32\dial32.exe
%Windir%\Web\i_xx.gif(Where xx is a number between 01 and 20.)
%Windir%\Web\desktop.html

Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).


Adds the value:

"Wintime"="Wintime.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the downloader executes every time Windows starts.


Adds the value:

"ShellServiceObjectDelayLoadSystem"="{0A323FA1-38DE-44EC-B2FA-4002183C143E}"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion


Adds the value:

"(Default)"="%system%\system32.dll"

to the registry key:

HKEY_CLASSES_ROOT\CLSID\{0A323FA1-38DE-44EC-B2FA-4002183C143E}\InProcServer32


Adds the values:

"MinLevel"="Code Download"
"Safety Warning Level"="SucceedSilent"
"Security_RunActiveXControls"="0x01000000"
"Security_RunScripts"="0x01000000"
"Trust Warning Level"="No Security"

to the registry keys:

HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings


Adds an entry "New Dialup Connection" to the RAS phonebook and makes the entry the default. It then attempts to use the modem to dial a predetermined, high-cost phone number and establish a RAS connection.


Terminates the following processes:
MCUPDATE.EXE
CFIAUDIT.EXE
AVXQUAR.EXE
AUTOUPDATE.EXE
AUTOTRACE.EXE
AUTODOWN.EXE
AUPDATE.EXE
NUPGRADE.EXE
UPDATE.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
DRWEBUPW.EXE
LUALL.EXE
AVPUPD.EXE
AVWUPD32.EXE
ATUPDATER.EXE

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode
Run a full system scan and delete all the files detected as Downloader.Harnig.
Delete the values that were added to the registry.

Deleting the value from the registry

CAUTION: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, , "How to make a backup of the Windows registry," for instructions.

Click Start, and then click Run. (The Run dialog box appears.)


Type regedit

Then click OK. (The Registry Editor opens.)


Navigate to the following key and delete it:

HKEY_CLASSES_ROOT\CLSID\{0A323FA1-38DE-44EC-B2FA-4002183C143E}


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Wintime"="Wintime.exe"

Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion


In the right pane, delete the value:

"ShellServiceObjectDelayLoadSystem"="{0A323FA1-38DE-44EC-B2FA-4002183C143E}"


Exit the Registry Editor.


Restore the security level of Microsoft Internet Explorer
Restoring the security level of Microsoft Internet Explorer
To restore the security level, complete the following steps:
Start Internet Explorer.
Click Tools, and then click Internet Options.
Select the Security tab.
Change the security settings to the level you desire.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/downloader.harnig.html\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Trojan.Cargao.B
Discovered on: August 13, 2004
Last Updated on: August 13, 2004 03:51:37 PM

Trojan.Cargao.B is a Trojan horse program that sends an email to all the addresses that it finds in the Microsoft Outlook address book. It also downloads and runs executable files from the Internet.

Type: Trojan Horse
Infection Length: 126,464 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Information:

A binder program may attach Trojan.Cargao.B to a legitimate file. The binder program allows the malicious file to be executed when the legitimate file is run, without the user's knowledge. The binder program drops both files into the %Temp% folder and then executes them.

Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).

When Trojan.Cargao.B is executed, it performs the following actions:


Creates the following file:

C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS\appconn32.exe

Note: This file is usually 126,464 bytes in size, but due to a bug in the code, the file may expand to fill the hard disk.


Attempts to download the following files from the domain, virtualcards.serveftp.com, and then save them to the C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS\ folder:

lsacvn.exe
lsacvn.dll
appconn32.exe
cartao4596724064AC298.exe


Sends an email to the contacts that it finds in the Outlook address book.

Subject: (May contain the following text)

[sender name] te enviou um cart?o

where [sender name] is the sender's name in the email address. For example, "name" in name@example.com.

Body:
Contains HTML and includes links to many predetermined Web sites.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Cargao.B.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.cargao.b.html\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

VBS.Mywav@mm
Discovered on: August 12, 2004
Last Updated on: August 16, 2004 04:05:22 PM

VBS.Mywav@mm is a mass-mailing worm that also infects .html files.

Type: Worm
Infection Length: 20,695 bytes, 20,691 bytes

Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x

Technical Information:

When VBS.Mywav@mm is executed, it performs the following actions:


Displays a message containing the following text:

This page contained a graphic which require the ActiveX controls, Please reload or refresh the page and accept the ActiveX


Creates the following copies of itself:

c:\Greeting.htm (With file attributes set to Hidden.)
%Windir%\Myvwa.htm
%System%\AyaCute.htm
%Temp%\Normal.html

Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP)or C:\Winnt (Windows NT/2000).
%Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).


Searches on all removable, fixed, and network drives for email addresses in files with the following extensions:
htm
.html
.hta
.hte
.htx


Sends an HTML-formatted email, containing VBScript, to the addresses found and all contacts in the Microsoft Outlook address book.

This file will create %System%\Lasiaf.html, if ActiveX is enabled on the computer, which contains a copy of the worm.

The email has the following characteristics:

Subject: (One of the following)
Here is your Greeting card from me
<--Lasiaf-Fait Accompli-Myvwa-->
Greeting Card From Me.. ;p
Important! Please reply my Greeting card.
Friendster.. i'm a new comer..
FWD:Would you be my wife?
RE:Your password in this Greeting card
Hye look at this News...
Product Key!
FWD:Selamat menyambut hari kemerdekaan
Re:Good Luck in your exam
Somebody realy need you...
What ? new virus
Tekanan Emosi... Adik beradik gaduh²

Body:
U r so cute... i like ur childish personality... Aya... ;p by -Lasiaf in confuse-

Greets to: Fait Accompli[myvwa],Nije,Dehe,Bae'i,Asmahani,Atira,Azha,Ema,Erma,Erna and U


Prepends itself to files with .htm or .html extensions on all removable, fixed, and network drives.

Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as VBS.Mywav@mm.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/vbs.mywav@mm.html\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

Trojan.Nullpos
Discovered on: August 12, 2004
Last Updated on: August 13, 2004 03:54:33 PM

Trojan.Nullpos is a Trojan horse program that modifies the screen saver settings to display a message written in Japanese. It also moves all the desktop icons to the "My Document" folder. The Trojan spreads using the Winny file-sharing network.

Infection Length: 315,392 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows CE

Technical Information:

When Trojan.Nullpos is executed, it performs the following actions:


Displays the message:

[img]http://www.killanet.net/uploads/nullpos1.gif[/img]

Copies the file, %System%TASKMGR.EXE, to the %Windows% folder.


Modifies the file, %System%\TASKMGR.EXE.

Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Moves all the shortcut icons on the desktop to the My Documents\<Japanese character string> folder.


Copies itself as %Windows%\bugfix\<Username>.wab.


Copies itself as %Windows%\bugfix\<Japanese character string>.zip.


Creates the file, %Windows%ss.reg.


Adds the values:

"ScreenSaveActive"="1"
"ScreenSaveTimeOut=60"
"SCRNSAVE.EXE"="%system%\ssmarque.scr"

to the registry key:

HKEY_CURRENT_USER\Control Panel\Desktop


Sets the values:

BackgroundColor=0 0
Speed=3
Text=<Japanese character string>
TextColor=255 0 0
Size=48

in the registry key:

HKEY_CURRENT_USER\Control Panel\Screen Saver.Marquee

This enables the following screen saver:

[img]http://www.killanet.net/uploads/trojan.nullpos2.gif[/img]

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as Trojan.Nullpos.

Reset the screen saver.
To reset the screen saver
Right-click on Windows desktop > Properties.
Click the Screen Saver tab and select the desired screen saver.
Click Apply > OK.

Copy the file %Windows%\TASKMGR.EXE to the %System% folder.
To copy the file %Windows%\TASKMGR.EXE to the %System% folder
Using Windows Explorer, locate the file Taskmgr.exe in the %Windir% folder and copy it to the %System% folder.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.nullpos.html\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Alerts

Post by Tami »

PWSteal.Bancos.J
Discovered on: August 17, 2004
Last Updated on: August 18, 2004 11:22:52 AM

PWSteal.Bancos.J is a Trojan horse that mimics the online interfaces of certain Brazilian banks to try to steal account information.

Type: Trojan Horse
Infection Length: 482,816

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x

Technical Details:

When PWSteal.Bancos.J is executed, it performs the following actions:


Copies itself as %System%\Taskimgr.exe.

Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the value:

"CentralProcessor"="%system%\taskimgr.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs when you start Windows.


Terminates some antivirus products.

Monitors the active Internet Explorer windows, waiting for you to open a Web page that matches the characteristics of certain banking sites. When such a site is opened, the Trojan displays one of several logon screens, depending on the site that you visit.

If the URL includes http:/ /www.bancoreal.com.br, the logon screen may look like this:

[img]http://www.killanet.net/uploads/pwsteal.bancos.gif[/img]

If the URL includes http:/ /www.banespa.com.br/portal/bnp/script/templates/GCMRequest.do?page=583, the logon screen may look like this:

[img]http://www.killanet.net/uploads/pwsteal.bancos2.gif[/img]

Any entered information is emailed to the attacker.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as PWSteal.Bancos.J.
Reverse the changes made to the registry

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"CentralProcessor"="%system%\taskimgr.exe"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.j.html\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”