Alerts
Moderators: Moderator, Global Moderator
Alerts
W32.Zindos.A
Discovered on: July 27, 2004
Last Updated on: July 27, 2004 02:51:32 PM
W32.Zindos.A is a worm that performs a Denial of Service (DoS) attack against the domain, microsoft.com. The worm spreads through the backdoor opened on TCP port 1034, by Backdoor.Zincite.A.
Note: Backdoor.Zincite.A is a backdoor Trojan horse that is dropped by W32.Mydoom.M@mm.
Type: Worm
Infection Length: 5760 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Performs a DoS against microsoft.com which may take up large amounts of network bandwidth.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 1034
Shared drives: n/a
Target of infection: Computers infected with Backdoor.Zincite.A.
When W32.Zindos.A is executed, it performs the following actions:
Probes random IP addresses on port 1034 searching for infections of Backdoor.Zincite.A.
When an open port is found, the worm will send itself to the infected computer.
Saves itself in the %Temp% folder as a randomly named .exe file, then executes.
Adds the value:
"Tray"="<file name of worm>.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm is executed at startup.
Performs a DoS attack against the domain, microsoft.com.
Note: The DoS attack is not date-triggered and will being within a few minutes of execution.
Removal Instructions
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Zindos.A.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Tray"="<file name of worm>.exe"
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.zindos.a.html"]Source[/url]
Discovered on: July 27, 2004
Last Updated on: July 27, 2004 02:51:32 PM
W32.Zindos.A is a worm that performs a Denial of Service (DoS) attack against the domain, microsoft.com. The worm spreads through the backdoor opened on TCP port 1034, by Backdoor.Zincite.A.
Note: Backdoor.Zincite.A is a backdoor Trojan horse that is dropped by W32.Mydoom.M@mm.
Type: Worm
Infection Length: 5760 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Performs a DoS against microsoft.com which may take up large amounts of network bandwidth.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 1034
Shared drives: n/a
Target of infection: Computers infected with Backdoor.Zincite.A.
When W32.Zindos.A is executed, it performs the following actions:
Probes random IP addresses on port 1034 searching for infections of Backdoor.Zincite.A.
When an open port is found, the worm will send itself to the infected computer.
Saves itself in the %Temp% folder as a randomly named .exe file, then executes.
Adds the value:
"Tray"="<file name of worm>.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm is executed at startup.
Performs a DoS attack against the domain, microsoft.com.
Note: The DoS attack is not date-triggered and will being within a few minutes of execution.
Removal Instructions
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Zindos.A.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Tray"="<file name of worm>.exe"
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.zindos.a.html"]Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Mits.A@mm
Discovered on: July 24, 2004
Last Updated on: July 28, 2004 04:14:36 PM
W32.Mits.A@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses that it finds on an infected host.
The worm alters many system settings, including registry editing to make it difficult to remove.
Also Known As: Trojan.Win32.Smith
Type: Worm
Infection Length: 504,832 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Mass-mails itself to the email addresses found on the host.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Worm activity significantly degrades system performance.
Causes system instability: Continuous display setting changes may cause the system to be unusable.
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: Varies
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Mits.A@mm is executed, it performs the following actions:
Copies itself as one of the following:
C:\WINDOWS\system32\WinServer.exe
C:\WINDOWS\system32\Setup.exe
C:\WINDOWS\system32\WinBios.exe
C:\WINDOWS\system32\NetBios.exe
C:\WINDOWS\system32\NetServer.exe
C:\WINDOWS\system32\WinNote.exe
C:\WINDOWS\system32\WinProfile.exe
C:\WINDOWS\system32\WinLoadfile.exe
C:\WINDOWS\system32\WinAuto.exe
C:\WINDOWS\system\WinConfig.exe
Continuously changes the display settings to different graphics modes, causing the screen to blink, flash, and switch on and off.
Deletes the default values from the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command
Adds the value
"(<double-byte characters>)" = "txtfile"
to the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg
Adds the value
"(<double-byte characters>)" = "C:\WINDOWS\system32\<worm file name>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command
Adds the value
"<worm file name>" = "C:\WINDOWS\system32\<worm file name>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Adds the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SOFTWARE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WinLogon
Sets the following values:
"NoChangeStartMenu" = "1"
"NoDrives" = "8"
"NoFind" = "1"
"NoFolderOptions" = "1"
"NoLogOff" = "1"
"NoRealMode" = "1"
"NoRecentDocsMenu" = "1"
"NoRun" = "1"
"NoSetFolders" = "1"
"NoSetTaskBar" = "1"
"NoStartMenu" = "1"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
making it difficult to remove the worm from the infected computer.
Sets the value:
"DisableRegistryTools" = "1"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
Sets the values:
"Show_StatusBar" = "no"
"Show_URLToolBar" = "no"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Sets the value:
"AutoEndTasks" = "no"
in the registry key:
HKEY_CURRENT_USER\Control Panel\Desktop
Scans the local hard disk to collect the email addresses to which it will send copies of itself.
The email message has the following characteristics:
From:
Either spoofed or the following email address:
windowsnet@263.com.cn
If the sender's email address is spoofed, it will be composed using the random combination of strings from the following lists:
a
ai
ao
ba
bai
bang
bao
bi
bin
bing
bo
bon
bu
bun
ca
cai
can
ce
chuan
co
cu
cun
da
dan
dang
dao
de
di
din
ding
du
du
dun
e
en
eng
er
fa
fan
fen
feng
fong
fu
ga
gang
ge
gen
geng
go
gong
gu
gui
ha
hai
hao
he
hen
hong
hou
hua
huan
huang
huo
jian
jin
ka
kan
ke
kong
ku
la
lai
lang
lao
le
len
leng
Li
li
liang
liao
lie
ling
Liu
liu
ma
mai
mao
mei
mi
min
ming
mo
mong
mu
na
nan
nang
nao
ne
no
nong
nun
o
ong
pa
pao
pen
peng
pi
ping
pu
qi
qiao
qing
qiong
qiu
quan
re
ren
reng
rong
rou
sa
san
sang
sao
she
shi
shu
su
ta
tie
tong
wa
wang
we
wen
weng
Wu
wun
xi
xia
xiang
xing
ya
yan
yang
yin
ying
yong
you
yuan
zhang
Zhao
zhi
zhong
zhou
zi
windows
windowsxp
windows98
windows95
windowsnet
smilesnow
smiler
snow
flower
wood
westwind
computer
lover
Linux
linuxsir
unix
wind
@163.com
@126.com
@263.net
@yahoo.com.cn
@sohu.com
@china.com
@hotmail.com
@msn.com
@sina.com.cn
@263.com.cn
Message:
The text of the message is in Chinese, which may look similar to the text displayed below:
[img]http://www.killanet.net/uploads/w32.mits.a.gif[/img]
Attachment:
The file name of the attachment is randomly selected from the following list:
WinBios.exe
NetBios.exe
NetServer.exe
WinNote.exe
WinProfile.exe
WinLoadfile.exe
WinAuto.exe
The worm will skip the email addresses that contain the following strings:
@yahoo.com.cn
@china.com
@hotmail.com
@sina.com.cn
@263.com.cn
webmaster@panda.com
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Download a tool that will restore the use of the Registry Editor.
To download the tool
Download the file, [url="http://securityresponse.symantec.com/avcenter/UnHookExec.inf"]UnHookExec.inf[/url], and save it to your Windows desktop. Do not run it at this time, download it only.
If you cannot connect to the Internet from an infected computer:
Download to an uninfected computer, and then save it to a floppy disk.
Take the floppy disk and insert it into the floppy disk drive of the infected computer.
Restart the computer in Safe mode (Windows 95/98/Me), or Safe mode with Command Prompt (Windows 2000/XP).
Run the tool.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"[WORM FILENAME]" = "C:\WINDOWS\system32\[WORM FILENAME]"
Navigate to and delete the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SOFTWARE
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command
In the right pane, delete the value:
"([DOUBLE-BYTE CHARACTERS])" = "C:\WINDOWS\system32\[WORM FILENAME]"
Navigate to and delete the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WinLogon
Navigate to each of these the keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg
From each one, in the right pane, delete the value:
"([DOUBLE-BYTE CHARACTERS])" = "txtfile"
Navigate to the key:
HKEY_Current_USER\Software\Microsoft\Internet Explorer\Main
In the right pane, delete the values:
"Show_StatusBar" = "no"
"Show_URLToolBar" = "no"
Navigate to the key:
HKEY_Current_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
In the right pane, delete the values:
"NoChangeStartMenu" = dword:00000001
"NoDrives" = dword:00000008
"NoFind" = dword:00000001
"NoFolderOptions" = dword:00000001
"NoLogOff" = dword:00000001
"NoRealMode" = dword:00000001
"NoRecentDocsMenu" = dword:00000001
"NoRun" = dword:00000001
"NoSetFolders" = dword:00000001
"NoSetTaskBar" = dword:00000001
"NoStartMenu" = dword:00000001
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf
In the right pane, double-click (Default)
and change the Value data to:
inffile
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg
In the right pane, double-click (Default)
and change the Value data to:
regfile
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command
In the right pane, double-click (Default)
and change the Value data to:
%System%\NOTEDPAD.EXE %1
Navigate to the key:
HKEY_LOCAL_MACHINE\Control Panel\Desktop
In the right pane, double-click AutoEndTasks and change the Value data to: 0
Exit the Registry Editor.
Run a full system scan and delete all the files detected as W32.Mits.A@mm.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mits.a@mm.html"]Symantec Source[/url]
Discovered on: July 24, 2004
Last Updated on: July 28, 2004 04:14:36 PM
W32.Mits.A@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses that it finds on an infected host.
The worm alters many system settings, including registry editing to make it difficult to remove.
Also Known As: Trojan.Win32.Smith
Type: Worm
Infection Length: 504,832 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Mass-mails itself to the email addresses found on the host.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Worm activity significantly degrades system performance.
Causes system instability: Continuous display setting changes may cause the system to be unusable.
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: Varies
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Mits.A@mm is executed, it performs the following actions:
Copies itself as one of the following:
C:\WINDOWS\system32\WinServer.exe
C:\WINDOWS\system32\Setup.exe
C:\WINDOWS\system32\WinBios.exe
C:\WINDOWS\system32\NetBios.exe
C:\WINDOWS\system32\NetServer.exe
C:\WINDOWS\system32\WinNote.exe
C:\WINDOWS\system32\WinProfile.exe
C:\WINDOWS\system32\WinLoadfile.exe
C:\WINDOWS\system32\WinAuto.exe
C:\WINDOWS\system\WinConfig.exe
Continuously changes the display settings to different graphics modes, causing the screen to blink, flash, and switch on and off.
Deletes the default values from the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command
Adds the value
"(<double-byte characters>)" = "txtfile"
to the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg
Adds the value
"(<double-byte characters>)" = "C:\WINDOWS\system32\<worm file name>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command
Adds the value
"<worm file name>" = "C:\WINDOWS\system32\<worm file name>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Adds the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SOFTWARE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WinLogon
Sets the following values:
"NoChangeStartMenu" = "1"
"NoDrives" = "8"
"NoFind" = "1"
"NoFolderOptions" = "1"
"NoLogOff" = "1"
"NoRealMode" = "1"
"NoRecentDocsMenu" = "1"
"NoRun" = "1"
"NoSetFolders" = "1"
"NoSetTaskBar" = "1"
"NoStartMenu" = "1"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
making it difficult to remove the worm from the infected computer.
Sets the value:
"DisableRegistryTools" = "1"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
Sets the values:
"Show_StatusBar" = "no"
"Show_URLToolBar" = "no"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Sets the value:
"AutoEndTasks" = "no"
in the registry key:
HKEY_CURRENT_USER\Control Panel\Desktop
Scans the local hard disk to collect the email addresses to which it will send copies of itself.
The email message has the following characteristics:
From:
Either spoofed or the following email address:
windowsnet@263.com.cn
If the sender's email address is spoofed, it will be composed using the random combination of strings from the following lists:
a
ai
ao
ba
bai
bang
bao
bi
bin
bing
bo
bon
bu
bun
ca
cai
can
ce
chuan
co
cu
cun
da
dan
dang
dao
de
di
din
ding
du
du
dun
e
en
eng
er
fa
fan
fen
feng
fong
fu
ga
gang
ge
gen
geng
go
gong
gu
gui
ha
hai
hao
he
hen
hong
hou
hua
huan
huang
huo
jian
jin
ka
kan
ke
kong
ku
la
lai
lang
lao
le
len
leng
Li
li
liang
liao
lie
ling
Liu
liu
ma
mai
mao
mei
mi
min
ming
mo
mong
mu
na
nan
nang
nao
ne
no
nong
nun
o
ong
pa
pao
pen
peng
pi
ping
pu
qi
qiao
qing
qiong
qiu
quan
re
ren
reng
rong
rou
sa
san
sang
sao
she
shi
shu
su
ta
tie
tong
wa
wang
we
wen
weng
Wu
wun
xi
xia
xiang
ya
yan
yang
yin
ying
yong
you
yuan
zhang
Zhao
zhi
zhong
zhou
zi
windows
windowsxp
windows98
windows95
windowsnet
smilesnow
smiler
snow
flower
wood
westwind
computer
lover
Linux
linuxsir
unix
wind
@163.com
@126.com
@263.net
@yahoo.com.cn
@sohu.com
@china.com
@hotmail.com
@msn.com
@sina.com.cn
@263.com.cn
Message:
The text of the message is in Chinese, which may look similar to the text displayed below:
[img]http://www.killanet.net/uploads/w32.mits.a.gif[/img]
Attachment:
The file name of the attachment is randomly selected from the following list:
WinBios.exe
NetBios.exe
NetServer.exe
WinNote.exe
WinProfile.exe
WinLoadfile.exe
WinAuto.exe
The worm will skip the email addresses that contain the following strings:
@yahoo.com.cn
@china.com
@hotmail.com
@sina.com.cn
@263.com.cn
webmaster@panda.com
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Download a tool that will restore the use of the Registry Editor.
To download the tool
Download the file, [url="http://securityresponse.symantec.com/avcenter/UnHookExec.inf"]UnHookExec.inf[/url], and save it to your Windows desktop. Do not run it at this time, download it only.
If you cannot connect to the Internet from an infected computer:
Download to an uninfected computer, and then save it to a floppy disk.
Take the floppy disk and insert it into the floppy disk drive of the infected computer.
Restart the computer in Safe mode (Windows 95/98/Me), or Safe mode with Command Prompt (Windows 2000/XP).
Run the tool.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"[WORM FILENAME]" = "C:\WINDOWS\system32\[WORM FILENAME]"
Navigate to and delete the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SOFTWARE
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command
In the right pane, delete the value:
"([DOUBLE-BYTE CHARACTERS])" = "C:\WINDOWS\system32\[WORM FILENAME]"
Navigate to and delete the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WinLogon
Navigate to each of these the keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg
From each one, in the right pane, delete the value:
"([DOUBLE-BYTE CHARACTERS])" = "txtfile"
Navigate to the key:
HKEY_Current_USER\Software\Microsoft\Internet Explorer\Main
In the right pane, delete the values:
"Show_StatusBar" = "no"
"Show_URLToolBar" = "no"
Navigate to the key:
HKEY_Current_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
In the right pane, delete the values:
"NoChangeStartMenu" = dword:00000001
"NoDrives" = dword:00000008
"NoFind" = dword:00000001
"NoFolderOptions" = dword:00000001
"NoLogOff" = dword:00000001
"NoRealMode" = dword:00000001
"NoRecentDocsMenu" = dword:00000001
"NoRun" = dword:00000001
"NoSetFolders" = dword:00000001
"NoSetTaskBar" = dword:00000001
"NoStartMenu" = dword:00000001
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf
In the right pane, double-click (Default)
and change the Value data to:
inffile
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg
In the right pane, double-click (Default)
and change the Value data to:
regfile
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\open\command
In the right pane, double-click (Default)
and change the Value data to:
%System%\NOTEDPAD.EXE %1
Navigate to the key:
HKEY_LOCAL_MACHINE\Control Panel\Desktop
In the right pane, double-click AutoEndTasks and change the Value data to: 0
Exit the Registry Editor.
Run a full system scan and delete all the files detected as W32.Mits.A@mm.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mits.a@mm.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Korgo.Z
Discovered on: July 27, 2004
Last Updated on: July 28, 2004 01:45:27 PM
W32.Korgo.Z is a worm that attempts to propagate by exploiting the Microsoft Windows PCT Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011) on TCP port 113. Previous Korgo variants used a different vulnerability, the LSASS Buffer Overrun Vulnerability.
Also Known As: WORM_KORGO.AC[Trend], Worm.Win32.Padobot.gen[Kaspersky], Win32.Korgo.AC[CA]
Variants: W32.Korgo.Y
Type: Worm
Infection Length: 9,359 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Network propagation routines may degrade overall network performance.
Causes system instability: n/a
Releases confidential info: Backdoor functionality allows unauthorized access.
Compromises security settings: Backdoor functionality may compromise security settings.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 445 and a random port.
Shared drives: n/a
Target of infection: Unpatched computers vulnerable to the Microsoft LSASS Windows exploit.
When W32.Korgo.Z is executed, it does the following:
Deletes the file, ftpupd.exe, from the folder in which the worm was executed.
Creates the mutex "uterm19.2" to ensure that only one instance of the worm is executed on the computer:
Creates the following mutexes:
u10
u10x
u11
u11x
u12
u12x
u13
u13i
u13x
u14
u14x
u15
u15x
u16
u16x
u17
u17x
u18
u18x
u19
u8
u9
Deletes the values:
avserve.exe
avserve2.exeUpdate Service
Bot Loader
Disk Defragmenter
MS Config v13
System Restore Service
SysTray
Windows Security Manager
Windows Update
Windows Update Service
WinUpdate
from the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Copies itself as %System%\<random filename>.exe.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the values:
"Client"="1"
"ID"="<random value>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
Adds the value:
"Cryptographic Service"="%System%\<random filename>.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Attempts to inject a function into Explorer.exe as a thread.
If successful, this threat will continue to run in the Explorer.exe process. All of the worm's subsequent actions will appear to be done by Explorer.exe, and the worm will not show when viewing the process list in the Windows Task Manager.
If unsuccessful, the worm will continue to run as its own process.
Opens a random TCP port, which the worm uses to send itself.
Attempts to connect and update itself from one of the following IRC servers:
0AB1cvv.ru
adult-empire.com
asechka.ru
citi-bank.ru
color-bank.ru
crutop.nu
fethard.biz
filesearch.ru
kavkaz.tv
kidos-bank.ru
konfiskat.org
master-x.com
mazafaka.ru
parex-bank.ru
roboxchange.com
www.redline.ru
xware.cjb.net
The worm joins a channel and waits for commands, including a command to download and execute a file from a Web server.
Attempts to exploit the Microsoft Windows PCT Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011), against random IP addresses. If the worm successfully finds a vulnerable computer, the computer will attempt to reconnect to the infected computer to download the worm.
Before you begin
If you are running Windows 2000 or XP, and have not yet done so, you must patch for the vulnerability. Microsoft Security Bulletin [url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx"]MS04-011[/url] describes this process. If you do not, it is likely that your computer will continue to be re-infected.
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Korgo.Z.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Microsoft Update Service"="%System%\<random filename>.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
In the right pane, delete the values, if they exist:
"Client"="1"
"ID" = "<random value>"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.korgoz.html"]Symantec Source[/url]
Discovered on: July 27, 2004
Last Updated on: July 28, 2004 01:45:27 PM
W32.Korgo.Z is a worm that attempts to propagate by exploiting the Microsoft Windows PCT Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011) on TCP port 113. Previous Korgo variants used a different vulnerability, the LSASS Buffer Overrun Vulnerability.
Also Known As: WORM_KORGO.AC[Trend], Worm.Win32.Padobot.gen[Kaspersky], Win32.Korgo.AC[CA]
Variants: W32.Korgo.Y
Type: Worm
Infection Length: 9,359 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Network propagation routines may degrade overall network performance.
Causes system instability: n/a
Releases confidential info: Backdoor functionality allows unauthorized access.
Compromises security settings: Backdoor functionality may compromise security settings.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 445 and a random port.
Shared drives: n/a
Target of infection: Unpatched computers vulnerable to the Microsoft LSASS Windows exploit.
When W32.Korgo.Z is executed, it does the following:
Deletes the file, ftpupd.exe, from the folder in which the worm was executed.
Creates the mutex "uterm19.2" to ensure that only one instance of the worm is executed on the computer:
Creates the following mutexes:
u10
u10x
u11
u11x
u12
u12x
u13
u13i
u13x
u14
u14x
u15
u15x
u16
u16x
u17
u17x
u18
u18x
u19
u8
u9
Deletes the values:
avserve.exe
avserve2.exeUpdate Service
Bot Loader
Disk Defragmenter
MS Config v13
System Restore Service
SysTray
Windows Security Manager
Windows Update
Windows Update Service
WinUpdate
from the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Copies itself as %System%\<random filename>.exe.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the values:
"Client"="1"
"ID"="<random value>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
Adds the value:
"Cryptographic Service"="%System%\<random filename>.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Attempts to inject a function into Explorer.exe as a thread.
If successful, this threat will continue to run in the Explorer.exe process. All of the worm's subsequent actions will appear to be done by Explorer.exe, and the worm will not show when viewing the process list in the Windows Task Manager.
If unsuccessful, the worm will continue to run as its own process.
Opens a random TCP port, which the worm uses to send itself.
Attempts to connect and update itself from one of the following IRC servers:
0AB1cvv.ru
adult-empire.com
asechka.ru
citi-bank.ru
color-bank.ru
crutop.nu
fethard.biz
filesearch.ru
kavkaz.tv
kidos-bank.ru
konfiskat.org
master-x.com
mazafaka.ru
parex-bank.ru
roboxchange.com
www.redline.ru
xware.cjb.net
The worm joins a channel and waits for commands, including a command to download and execute a file from a Web server.
Attempts to exploit the Microsoft Windows PCT Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011), against random IP addresses. If the worm successfully finds a vulnerable computer, the computer will attempt to reconnect to the infected computer to download the worm.
Before you begin
If you are running Windows 2000 or XP, and have not yet done so, you must patch for the vulnerability. Microsoft Security Bulletin [url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx"]MS04-011[/url] describes this process. If you do not, it is likely that your computer will continue to be re-infected.
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Korgo.Z.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Microsoft Update Service"="%System%\<random filename>.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
In the right pane, delete the values, if they exist:
"Client"="1"
"ID" = "<random value>"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.korgoz.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
humm i was wondering why people make viruses. like whats the point. do people get there jollies by ******* up other peoples computers? if i knew who was making these, and was able to see them in person, i would definatly punch them in the nose because this is bullcrap, i dont understand why people insist on always crashing and killing other computers, being able to hvae Internet is a PRIVLEDGE. so why screw it up!

Alerts
W32.Lovgate.AK@mm
Discovered on: July 28, 2004
Last Updated on: July 29, 2004 10:57:05 AM
W32.Lovgate.AK@mm is a variant of W32.Lovgate.W@mm that:
Attempts to reply to all the email messages in the Microsoft Outlook inbox.
Scans files that have the .txt, .pl, .wab, .adb, .tbb, .dbx, .asp, .php, .sht, and .htm extensions for email addresses.
Uses its own SMTP engine to send itself to the addresses that it finds.
Attempts to copy itself to Kazaa-shared folders and all the computers on a local network.
The From line of the email is spoofed and the Subject and the Message vary. The attachment name also varies, with a .bat, .cmd, .exe, .pif, or .scr file extension. The worm may also send a .zip file containing the attachment.
This threat is written in the C++ programming language and is compressed with JDPack, ASPack, and UPX.
Infection Length: 113,664 bytes
Systems Affected: Windows 2000, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 95, Windows 98, Windows Me
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to all the contacts of the Windows Address Book and the Outlook Address Book, and to the email addresses that it finds in files that have the .txt, .pl, .wab, .adb, .tbb, .dbx, .asp, .php, .sht, and .htm. extensions.
Deletes files: n/a
Modifies files: renames .exe files to .zmx
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates processes belonging to various antivirus programs.
Distribution
Subject of email: n/a
Name of attachment: Varies, with .bat, .cmd, .exe, .pif, .scr, or .zip as the extension
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP 6000
Shared drives: Copies itself to network shared folders.
Target of infection: Copies itself to the KaZaA shared folder
When W32.Lovgate.AK@mm runs, it does the following:
Copies itself as the following:
%Windir%\SysTra.exe
%System%\ravmond.exe
%System%\iexplore.exe
%System%\WinHelp.exe
%System%\kernel66.dll (With attributes set to Read Only, Hidden, and System.)
Notes:
%Windir% is a variable: The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
%System% is a variable: The worm locates the System folder and copies itself to that location. By default, this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following files:
%System%\ODBC16.dll
%System%\msjdbc11.dll
%System%\MSSIGN30.DLL
%System%\LMMIB20.DLL
Note: These files are all the same; they are backdoor components of the worm and each 53,760 bytes in size.
Adds the values:
"Program in Windows"="%system%\iexplore.exe"
"Protected Storage"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"WinHelp"="%system%\WinHelp.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Adds the value:
"SystemTra"="%Windir%\SysTra.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices
so that the worm runs as a service when you start Windows 95/98/Me.
Adds the value:
"run"="RAVMOND.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
so that the worm runs when you start Windows NT/2000/XP.
May create the subkey:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ZMXLIB1
Inserts the following line in the [Windows] section of Win.ini file:
run=ravmond.exe
Injects a process-watching routine as a thread into either Explorer.exe or Taskmgr.exe. This remote thread will launch %System%\Iexplore.exe if the worm process is stopped.
Creates a file named AUTORUN.INF in the root folder of all the drives, except the CD-ROM drives, and copies itself as COMMAND.EXE and setup.RAR into that folder.
Terminates all the processes that contain any of the following strings:
KV
KAV
Duba
NAV
kill
RavMon.exe
Rfw.exe
Gate
McAfee
Symantec
SkyNet
rising
Creates a zip file named <filename>.<ext> in the root folder of all the drives, unless the drive letter is A or B.
<filename> will be one of the following:
WORK
setup
Important
bak
letter
pass
and <ext> is one of the following:
RAR
ZIP
This zip file contains a copy of the worm with the file name <filename>.<ext>.
<filename> is one of the following:
WORK
setup
Important
book
email
PassWord
and <ext> is one of the following:
.exe
.com
.pif
.scr
Creates the service, "Windows Management Protocol v.0 (experimental)", which is mapped to "Rundll32.exe msjdbc11.dll ondll_server".
Creates the service, "_reg," which is mapped to "Rundll32.exe msjdbc11.dll ondll_server."
Scans all the drives from C to Z. If the drive type is removable, mapped, or fixed, the worm will do the following on all the drives found:
Attempt to rename the extension on all .exe files to .zmx.
Set the attributes to Hidden and System on these files.
Copy itself as the original file name.
For example, if the worm finds OriginalFile.exe, it will be renamed to OriginalFile.zmx. The worm will then copy itself as OriginalFile.exe.
Runs a Backdoor routine on port 6000. The routine steals information of the infected computer and stores it in the file, C:\Netlog.txt. The worm then sends the stolen information to an email address.
Creates a network share, "Media", which is mapped to "%Windir%\Media".
Copies itself to all network-shared folders and subfolders as any of the following:
Thank you.doc.exe
3D Flash Animator.rar.bat
SWF Browser2.93.txt.exe
Download.exe
Panda Crack.zip.exe
WinRAR V3.2.0 Beta 2.exe
Swish2.00.pif
AAdobe Photoshop7.0 creak.pif
You_Life.JPG.pif
CloneCD crack.exe
WinZip v9.0 Beta Build 5480 crack.exe
Real-DRAW PRO v3.10.exe
Star Wars Downloader.exe
HyperSnap-DX v5.20.01.exe
Adobe Photoshop6.0.zip.exe
HyperSnap-DX v4.51.01.exe
Scans all the computers on the local network and attempts to log on as an Administrator using the following passwords:
Guest
Administrator
zxcv
yxcv
xxx
win
test123
test
temp123
temp
sybase
super
sex
secret
pwd
pw123
Password
owner
oracle
mypc123
mypc
mypass123
mypass
love
login
Login
Internet
home
godblessyou
god
enable
database
computer
alpha
admin123
Admin
abcd
aaa
88888888
2600
2003
2002
123asd
123abc
123456789
1234567
123123
121212
11111111
110
007
00000000
000000
pass
54321
12345
password
passwd
server
sql
!@#$%^&*
!@#$%^&
!@#$%^
!@#$%
asdfgh
asdf
!@#$
1234
111
root
abc123
12345678
abcdefg
abcdef
abc
888888
666666
111111
admin
administrator
guest
654321
123456
321
123
Note: The worm will also attempt to log on as "Administrator" if a password is not set for the account on a remote computer.
If the worm successfully logs on to the remote computer, it will attempt to copy itself as:
\\<remote computer name>\admin$\system32\NetManager.exe
and to start the file as the service, "Windows Management NetWork Service Extensions," which is mapped to "NetManager.exe -exe_start."
Locates the Kazaa file-sharing folder though a registry key and copies itself to that folder as one of the following:
wrar320sc
REALONE
BlackIcePCPSetup_creak
Passware5.3
word_pass_creak
HEROSOFT
orcard_original_creak
rainbowcrack-1.1-win
W32Dasm
setup
<random file name>
with a .bat, .exe, .pif, or .scr file extension.
Retrieves the email addresses from the files with .txt, .pl, .wab, .adb, .tbb, .dbx, .asp, .php, .sht, and .htm file extensions in the following folders:
%Windir%\Local Settings
\Documents and Settings\<current user>\local settings
Temporary Internet Files folder
Retrieves the email addresses from the Windows Address Book files.
Uses its own SMTP engine to send itself to the email addresses that it finds.
The email has the following characteristics:
Subject: (One of the following)
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error
Message: (One of the following)
pass
Mail failed. For further assistance, please contact!
The message contains Unicode characters and has been sent as a binary attachment.
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.
Attachment: (One of the following)
document
readme
doc
text
file
data
test
message
body
with one of the following file extensions:
.bat
.cmd
.exe
.pif
.scr
Replies to all the incoming messages when they arrive in the mailbox of certain MAPI-compliant email clients, including Microsoft Outlook.
If the original email is:
Subject: <subject>
From: <sender>@<domain.com>
Message: <original message body>
the worm will attempt to send the following email:
Subject: Re: <subject>
To: <sender>@<domain.com>
Message:
'<sender>' wrote:
====
> <original message body>
====
<domain.com> account auto-reply:
If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about,don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;
... ... more look to the attachment.
> Get your FREE <domain.com> account now! <
Attachment: (One of the following)
the hardcore game-.pif
Sex in Office.rm.scr
Deutsch BloodPatch!.exe
s3msong.MP3.pif
Me_nude.AVI.pif
How to Crack all gamez.exe
Macromedia Flash.scr
SETUP.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
DSL Modem Uncapper.rar.exe
joke.pif
Britney spears nude.exe.txt.exe
I am For u.doc.exe
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Delete the values from the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values:
"Program in Windows"="%system%\iexplore.exe"
"Protected Storage"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"WinHelp"="%system%\WinHelp.exe"
Follow the steps for your operating system:
Windows 95/98/Me. Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices
In the right pane, delete the value:
"Systemtra"="%Windir%\Systra.exe"
Windows NT/2000/XP. Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
In the right pane, delete the value:
"run"="RAVMOND.exe"
Exit the Registry Editor
Edit the Win.ini file (Windows 95/98/Me).
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values:
"Program in Windows"="%system%\iexplore.exe"
"Protected Storage"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"WinHelp"="%system%\WinHelp.exe"
Follow the steps for your operating system:
Windows 95/98/Me. Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices
In the right pane, delete the value:
"Systemtra"="%Windir%\Systra.exe"
Windows NT/2000/XP. Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
In the right pane, delete the value:
"run"="RAVMOND.exe"
Exit the Registry Editor
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lovgate.AK@mm.
Change the .zmx files back to .exe files.
To change the .zmx files to .exe files
Because W32.HLLW.Lovgate.AK@mm changes .exe file extensions to .zmx, you must either restore the .exe file extension or re-install the programs. (In many cases, it may be easier to re-install the software.)
Follow the instructions for your operating system:
Windows 98/Me/2000
On the Windows desktop, click the Start button > Find or Search > Files or Folders.
In the Search Results window, set "Look in" to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Check Include subfolders.
In the "Named" or "Search for..." box, type, or copy and paste, the following:
*.zmx
Click Find Now or Search Now.
Windows XP
On the Windows desktop, click the Start button > Search.
Click All files and folders.
In the "All or part of the file name" box, type, or copy and paste, the following:
*.zmx
Verify that "Look in" is set to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Click More advanced options.
Select Search system folders.
Select Search subfolders.
Select Search hidden files and folders.
Click Search.
For every file that is found, right-click it > Rename. Change the .zmx extension to .exe.
Repeat step 6 for every removable, mapped, or fixed drive type with a drive letter greater than E.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.ak@mm.html"]Symantec Source[/url]
Discovered on: July 28, 2004
Last Updated on: July 29, 2004 10:57:05 AM
W32.Lovgate.AK@mm is a variant of W32.Lovgate.W@mm that:
Attempts to reply to all the email messages in the Microsoft Outlook inbox.
Scans files that have the .txt, .pl, .wab, .adb, .tbb, .dbx, .asp, .php, .sht, and .htm extensions for email addresses.
Uses its own SMTP engine to send itself to the addresses that it finds.
Attempts to copy itself to Kazaa-shared folders and all the computers on a local network.
The From line of the email is spoofed and the Subject and the Message vary. The attachment name also varies, with a .bat, .cmd, .exe, .pif, or .scr file extension. The worm may also send a .zip file containing the attachment.
This threat is written in the C++ programming language and is compressed with JDPack, ASPack, and UPX.
Infection Length: 113,664 bytes
Systems Affected: Windows 2000, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 95, Windows 98, Windows Me
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to all the contacts of the Windows Address Book and the Outlook Address Book, and to the email addresses that it finds in files that have the .txt, .pl, .wab, .adb, .tbb, .dbx, .asp, .php, .sht, and .htm. extensions.
Deletes files: n/a
Modifies files: renames .exe files to .zmx
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates processes belonging to various antivirus programs.
Distribution
Subject of email: n/a
Name of attachment: Varies, with .bat, .cmd, .exe, .pif, .scr, or .zip as the extension
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP 6000
Shared drives: Copies itself to network shared folders.
Target of infection: Copies itself to the KaZaA shared folder
When W32.Lovgate.AK@mm runs, it does the following:
Copies itself as the following:
%Windir%\SysTra.exe
%System%\ravmond.exe
%System%\iexplore.exe
%System%\WinHelp.exe
%System%\kernel66.dll (With attributes set to Read Only, Hidden, and System.)
Notes:
%Windir% is a variable: The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
%System% is a variable: The worm locates the System folder and copies itself to that location. By default, this is C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following files:
%System%\ODBC16.dll
%System%\msjdbc11.dll
%System%\MSSIGN30.DLL
%System%\LMMIB20.DLL
Note: These files are all the same; they are backdoor components of the worm and each 53,760 bytes in size.
Adds the values:
"Program in Windows"="%system%\iexplore.exe"
"Protected Storage"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"WinHelp"="%system%\WinHelp.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Adds the value:
"SystemTra"="%Windir%\SysTra.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices
so that the worm runs as a service when you start Windows 95/98/Me.
Adds the value:
"run"="RAVMOND.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
so that the worm runs when you start Windows NT/2000/XP.
May create the subkey:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ZMXLIB1
Inserts the following line in the [Windows] section of Win.ini file:
run=ravmond.exe
Injects a process-watching routine as a thread into either Explorer.exe or Taskmgr.exe. This remote thread will launch %System%\Iexplore.exe if the worm process is stopped.
Creates a file named AUTORUN.INF in the root folder of all the drives, except the CD-ROM drives, and copies itself as COMMAND.EXE and setup.RAR into that folder.
Terminates all the processes that contain any of the following strings:
KV
KAV
Duba
NAV
kill
RavMon.exe
Rfw.exe
Gate
McAfee
Symantec
SkyNet
rising
Creates a zip file named <filename>.<ext> in the root folder of all the drives, unless the drive letter is A or B.
<filename> will be one of the following:
WORK
setup
Important
bak
letter
pass
and <ext> is one of the following:
RAR
ZIP
This zip file contains a copy of the worm with the file name <filename>.<ext>.
<filename> is one of the following:
WORK
setup
Important
book
PassWord
and <ext> is one of the following:
.exe
.com
.pif
.scr
Creates the service, "Windows Management Protocol v.0 (experimental)", which is mapped to "Rundll32.exe msjdbc11.dll ondll_server".
Creates the service, "_reg," which is mapped to "Rundll32.exe msjdbc11.dll ondll_server."
Scans all the drives from C to Z. If the drive type is removable, mapped, or fixed, the worm will do the following on all the drives found:
Attempt to rename the extension on all .exe files to .zmx.
Set the attributes to Hidden and System on these files.
Copy itself as the original file name.
For example, if the worm finds OriginalFile.exe, it will be renamed to OriginalFile.zmx. The worm will then copy itself as OriginalFile.exe.
Runs a Backdoor routine on port 6000. The routine steals information of the infected computer and stores it in the file, C:\Netlog.txt. The worm then sends the stolen information to an email address.
Creates a network share, "Media", which is mapped to "%Windir%\Media".
Copies itself to all network-shared folders and subfolders as any of the following:
Thank you.doc.exe
3D Flash Animator.rar.bat
SWF Browser2.93.txt.exe
Download.exe
Panda Crack.zip.exe
WinRAR V3.2.0 Beta 2.exe
Swish2.00.pif
AAdobe Photoshop7.0 creak.pif
You_Life.JPG.pif
CloneCD crack.exe
WinZip v9.0 Beta Build 5480 crack.exe
Real-DRAW PRO v3.10.exe
Star Wars Downloader.exe
HyperSnap-DX v5.20.01.exe
Adobe Photoshop6.0.zip.exe
HyperSnap-DX v4.51.01.exe
Scans all the computers on the local network and attempts to log on as an Administrator using the following passwords:
Guest
Administrator
zxcv
yxcv
xxx
win
test123
test
temp123
temp
sybase
super
sex
secret
pwd
pw123
Password
owner
oracle
mypc123
mypc
mypass123
mypass
love
login
Login
Internet
home
godblessyou
god
enable
database
computer
alpha
admin123
Admin
abcd
aaa
88888888
2600
2003
2002
123asd
123abc
123456789
1234567
123123
121212
11111111
110
007
00000000
000000
pass
54321
12345
password
passwd
server
sql
!@#$%^&*
!@#$%^&
!@#$%^
!@#$%
asdfgh
asdf
!@#$
1234
111
root
abc123
12345678
abcdefg
abcdef
abc
888888
666666
111111
admin
administrator
guest
654321
123456
321
123
Note: The worm will also attempt to log on as "Administrator" if a password is not set for the account on a remote computer.
If the worm successfully logs on to the remote computer, it will attempt to copy itself as:
\\<remote computer name>\admin$\system32\NetManager.exe
and to start the file as the service, "Windows Management NetWork Service Extensions," which is mapped to "NetManager.exe -exe_start."
Locates the Kazaa file-sharing folder though a registry key and copies itself to that folder as one of the following:
wrar320sc
REALONE
BlackIcePCPSetup_creak
Passware5.3
word_pass_creak
HEROSOFT
orcard_original_creak
rainbowcrack-1.1-win
W32Dasm
setup
<random file name>
with a .bat, .exe, .pif, or .scr file extension.
Retrieves the email addresses from the files with .txt, .pl, .wab, .adb, .tbb, .dbx, .asp, .php, .sht, and .htm file extensions in the following folders:
%Windir%\Local Settings
\Documents and Settings\<current user>\local settings
Temporary Internet Files folder
Retrieves the email addresses from the Windows Address Book files.
Uses its own SMTP engine to send itself to the email addresses that it finds.
The email has the following characteristics:
Subject: (One of the following)
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error
Message: (One of the following)
pass
Mail failed. For further assistance, please contact!
The message contains Unicode characters and has been sent as a binary attachment.
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.
Attachment: (One of the following)
document
readme
doc
text
file
data
test
message
body
with one of the following file extensions:
.bat
.cmd
.exe
.pif
.scr
Replies to all the incoming messages when they arrive in the mailbox of certain MAPI-compliant email clients, including Microsoft Outlook.
If the original email is:
Subject: <subject>
From: <sender>@<domain.com>
Message: <original message body>
the worm will attempt to send the following email:
Subject: Re: <subject>
To: <sender>@<domain.com>
Message:
'<sender>' wrote:
====
> <original message body>
====
<domain.com> account auto-reply:
If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about,don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;
... ... more look to the attachment.
> Get your FREE <domain.com> account now! <
Attachment: (One of the following)
the hardcore game-.pif
Sex in Office.rm.scr
Deutsch BloodPatch!.exe
s3msong.MP3.pif
Me_nude.AVI.pif
How to Crack all gamez.exe
Macromedia Flash.scr
SETUP.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
DSL Modem Uncapper.rar.exe
joke.pif
Britney spears nude.exe.txt.exe
I am For u.doc.exe
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Delete the values from the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values:
"Program in Windows"="%system%\iexplore.exe"
"Protected Storage"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"WinHelp"="%system%\WinHelp.exe"
Follow the steps for your operating system:
Windows 95/98/Me. Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices
In the right pane, delete the value:
"Systemtra"="%Windir%\Systra.exe"
Windows NT/2000/XP. Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
In the right pane, delete the value:
"run"="RAVMOND.exe"
Exit the Registry Editor
Edit the Win.ini file (Windows 95/98/Me).
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values:
"Program in Windows"="%system%\iexplore.exe"
"Protected Storage"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
"WinHelp"="%system%\WinHelp.exe"
Follow the steps for your operating system:
Windows 95/98/Me. Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices
In the right pane, delete the value:
"Systemtra"="%Windir%\Systra.exe"
Windows NT/2000/XP. Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
In the right pane, delete the value:
"run"="RAVMOND.exe"
Exit the Registry Editor
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lovgate.AK@mm.
Change the .zmx files back to .exe files.
To change the .zmx files to .exe files
Because W32.HLLW.Lovgate.AK@mm changes .exe file extensions to .zmx, you must either restore the .exe file extension or re-install the programs. (In many cases, it may be easier to re-install the software.)
Follow the instructions for your operating system:
Windows 98/Me/2000
On the Windows desktop, click the Start button > Find or Search > Files or Folders.
In the Search Results window, set "Look in" to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Check Include subfolders.
In the "Named" or "Search for..." box, type, or copy and paste, the following:
*.zmx
Click Find Now or Search Now.
Windows XP
On the Windows desktop, click the Start button > Search.
Click All files and folders.
In the "All or part of the file name" box, type, or copy and paste, the following:
*.zmx
Verify that "Look in" is set to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Click More advanced options.
Select Search system folders.
Select Search subfolders.
Select Search hidden files and folders.
Click Search.
For every file that is found, right-click it > Rename. Change the .zmx extension to .exe.
Repeat step 6 for every removable, mapped, or fixed drive type with a drive letter greater than E.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.ak@mm.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Backdoor.Berbew.I
Discovered on: July 28, 2004
Last Updated on: July 29, 2004 11:00:01 AM
Backdoor.Berbew.I attempts to steal cached passwords.
Also Known As: TrojanSpy.Win32.Qukart.gen[Kaspersky], W32/Berbew.G[Fprot]
Variants: Backdoor.Berbew.G
Type: Trojan Horse
Infection Length: 46,080 bytes, 6,657 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Attempts to steal cached passwords. Sends collected information to a predetermined URL.
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Backdoor.Berbew.I is executed, it performs the following actions:
Creates a mutex, "QueenKarton_13", which ensures that only one instance of the Trojan runs at once.
Creates the files:
%System%\<8 random characters>.exe
%System%\<8 random characters>.dll
Note: %System% is a variable. The Trojan locates the System folder and creates the file in that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates several <8 random characters>.htm files in the %Temp% folder.
Opens the <8 random characters>.htm files in Internet Explorer. Some of the files may access a predetermined URL at the domain, tat-neftbank.ru.
Adds the values:
"(Default)" = "<8 random characters>.dll"
"ThreadingModel" = "Apartment"
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{79FEACFF-FFCE-815E-A900-316290B5B738}\InProcServer32
Adds the value:
"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Adds the value:
"QueenKarton" = "D"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft
Modifies the value:
"1601" = "0"
in the registry keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
Modifies the value:
"GlobalUserOffline" = "0"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Adds the value:
"BrowseNewProcess" = "yes"
to the registry key:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
Collects passwords from the infected computer and intercepts data entered into the forms in Internet Explorer.
May create the following files in the %System% folder to save this password information and any downloaded configuration data:
dnkkq.dll
kkq32.vxd
kkq32.dll
Rtdx1<number>.dat
The stolen information is passed to the attacker by sending HTTP query strings. Configuration data may also be uploaded through the Web to a predetermined URL. at the domain, tat-neftbank.ru.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Berbew.I.
Delete the values that was added to the registry.
To delete the values from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CLASSES_ROOT\CLSID\{79FEACFF-FFCE-815E-A900-316290B5B738}\InProcServer32
In the left pane, delete the subkeys:
"(Default)" = "%System%/<8 random characters>.dll"
"ThreadingModel" = "Apartment"
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
In the right pane, delete the value:
"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft
In the right pane, delete the value:
"QueenKarton" = "D"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.berbew.i.html"]Symantec Source[/url]
Discovered on: July 28, 2004
Last Updated on: July 29, 2004 11:00:01 AM
Backdoor.Berbew.I attempts to steal cached passwords.
Also Known As: TrojanSpy.Win32.Qukart.gen[Kaspersky], W32/Berbew.G[Fprot]
Variants: Backdoor.Berbew.G
Type: Trojan Horse
Infection Length: 46,080 bytes, 6,657 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Attempts to steal cached passwords. Sends collected information to a predetermined URL.
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Backdoor.Berbew.I is executed, it performs the following actions:
Creates a mutex, "QueenKarton_13", which ensures that only one instance of the Trojan runs at once.
Creates the files:
%System%\<8 random characters>.exe
%System%\<8 random characters>.dll
Note: %System% is a variable. The Trojan locates the System folder and creates the file in that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates several <8 random characters>.htm files in the %Temp% folder.
Opens the <8 random characters>.htm files in Internet Explorer. Some of the files may access a predetermined URL at the domain, tat-neftbank.ru.
Adds the values:
"(Default)" = "<8 random characters>.dll"
"ThreadingModel" = "Apartment"
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{79FEACFF-FFCE-815E-A900-316290B5B738}\InProcServer32
Adds the value:
"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Adds the value:
"QueenKarton" = "D"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft
Modifies the value:
"1601" = "0"
in the registry keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
Modifies the value:
"GlobalUserOffline" = "0"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Adds the value:
"BrowseNewProcess" = "yes"
to the registry key:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
Collects passwords from the infected computer and intercepts data entered into the forms in Internet Explorer.
May create the following files in the %System% folder to save this password information and any downloaded configuration data:
dnkkq.dll
kkq32.vxd
kkq32.dll
Rtdx1<number>.dat
The stolen information is passed to the attacker by sending HTTP query strings. Configuration data may also be uploaded through the Web to a predetermined URL. at the domain, tat-neftbank.ru.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Berbew.I.
Delete the values that was added to the registry.
To delete the values from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CLASSES_ROOT\CLSID\{79FEACFF-FFCE-815E-A900-316290B5B738}\InProcServer32
In the left pane, delete the subkeys:
"(Default)" = "%System%/<8 random characters>.dll"
"ThreadingModel" = "Apartment"
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
In the right pane, delete the value:
"Web Event Logger" = "{79FEACFF-FFCE-815E-A900-316290B5B738}"
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft
In the right pane, delete the value:
"QueenKarton" = "D"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.berbew.i.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Mota.B@mm
Discovered on: July 27, 2004
Last Updated on: July 29, 2004 11:00:49 AM
W32.Mota.B@mm is a worm that propagates by sending itself to the email addresses gathered from the system.
Also Known As: W32/Mabutu.a@MM[McAfee]
Type: Worm
Infection Length: 32,768 bytes, 48,640 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Mails itself to the addresses gathered from an infected system.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may degrade system and network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: Varies
Name of attachment: Varies
Size of attachment: 32,768 bytes
Time stamp of attachment: n/a
Ports: Attempts to connect to IRC servers using port 6667.
Shared drives: n/a
Target of infection: n/a
When W32.Mota.B@mm runs, it does the following:
Copies itself as %Windir%\<random value>.exe (27,136 bytes).
Creates the following files:
%Windir%\<random value>.dll (39,936 bytes)
%WinDir%\CFG.DAT
Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and creates the files in that location.
Adds the value:
"winupdt"="RUNDLL32.EXE %Windir%\[random value].dll,_mainRD"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsfot\Windows\CurrentVersion\Run
so that the worm runs when you restart Windows.
Connects to one of following IRC servers using port 6667:
chat1.voila.fr
austin.tx.us.undernet.org
mesa.az.us.undernet.org
surrey.uk.eu.undernet.org
stockholm.se.eu.undernet.org
moscow.ru.eu.undernet.org
haarlem.nl.eu.undernet.org
amsterdam.nl.eu.undernet.org
amsterdam2.nl.eu.undernet.org
quebec.qu.ca.undernet.orggraz2.at.eu.undernet.org
toronto.on.ca.undernet.org
montreal.qu.ca.undernet.org
vancouver.bc.ca.undernet.org
graz.at.eu.undernet.org
london.uk.eu.undernet.org
brussels.be.eu.undernet.org
diemen.nl.eu.undernet.org
oslo.no.eu.undernet.org
flanders.be.eu.undernet.org
lulea.se.eu.undernet.org
los-angeles.ca.us.undernet.org
phoenix.az.us.undernet.org
washington.dc.us.undernet.org
atlanta.ga.us.undernet.org
manhattan.ks.us.undernet.org
baltimore.md.us.undernet.org
lasvegas.nv.us.undernet.org
newyork.ny.us.undernet.org
dallas.tx.us.undernet.org
saltlake.ut.us.undernet.org
arlington.va.us.undernet.org
auckland.nz.undernet.org
ann-arbor.mi.us.undernet.org
newbrunswick.nj.us.undernet.org
plano.tx.us.undernet.org
mclean.va.us.undernet.org
caen.fr.eu.undernet.org
Gathers the email addresses from the Windows Address Book and from the files that have file names containing any of the following strings:
HTM
HTML
WAB
TXT
Uses its own SMTP engine to send itself to the email addresses that it finds.
The email has the following characteristics:
From: The sender of the email may be spoofed.
Subject: The subject line may be one of the following:
Hi
Hello
Important
I'm in love
Sex
Wet girls
I'm nude
Fetishes
gutted
Ok
/censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' />
Attachment: The attachment may have one of the following extensions:
britney.jpg
jenifer.jpg
photo.jpg
creme_de_gruyere.jpg
details
document
message
followed with .scr or .txt.
The attachment may have multiple spaces.
For example, the attachment can be:
creme_de_gruyere.jpg(multiple spaces).SCR
The worm may also send a .zip file as the attachment.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode.
Run a full system scan and delete all the files detected as W32.Mota.B@mm.
Delete the value that was added to the registry.
To delete the value from the registry
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"RUNDLL32.EXE %Windir%\[random value].dll,_mainRD"
Exit the Registry Editor.
Restart the computer in normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mota.b@mm.html"]Symantec Source[/url]
Discovered on: July 27, 2004
Last Updated on: July 29, 2004 11:00:49 AM
W32.Mota.B@mm is a worm that propagates by sending itself to the email addresses gathered from the system.
Also Known As: W32/Mabutu.a@MM[McAfee]
Type: Worm
Infection Length: 32,768 bytes, 48,640 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Mails itself to the addresses gathered from an infected system.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may degrade system and network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: Varies
Name of attachment: Varies
Size of attachment: 32,768 bytes
Time stamp of attachment: n/a
Ports: Attempts to connect to IRC servers using port 6667.
Shared drives: n/a
Target of infection: n/a
When W32.Mota.B@mm runs, it does the following:
Copies itself as %Windir%\<random value>.exe (27,136 bytes).
Creates the following files:
%Windir%\<random value>.dll (39,936 bytes)
%WinDir%\CFG.DAT
Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and creates the files in that location.
Adds the value:
"winupdt"="RUNDLL32.EXE %Windir%\[random value].dll,_mainRD"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsfot\Windows\CurrentVersion\Run
so that the worm runs when you restart Windows.
Connects to one of following IRC servers using port 6667:
chat1.voila.fr
austin.tx.us.undernet.org
mesa.az.us.undernet.org
surrey.uk.eu.undernet.org
stockholm.se.eu.undernet.org
moscow.ru.eu.undernet.org
haarlem.nl.eu.undernet.org
amsterdam.nl.eu.undernet.org
amsterdam2.nl.eu.undernet.org
quebec.qu.ca.undernet.orggraz2.at.eu.undernet.org
toronto.on.ca.undernet.org
montreal.qu.ca.undernet.org
vancouver.bc.ca.undernet.org
graz.at.eu.undernet.org
london.uk.eu.undernet.org
brussels.be.eu.undernet.org
diemen.nl.eu.undernet.org
oslo.no.eu.undernet.org
flanders.be.eu.undernet.org
lulea.se.eu.undernet.org
los-angeles.ca.us.undernet.org
phoenix.az.us.undernet.org
washington.dc.us.undernet.org
atlanta.ga.us.undernet.org
manhattan.ks.us.undernet.org
baltimore.md.us.undernet.org
lasvegas.nv.us.undernet.org
newyork.ny.us.undernet.org
dallas.tx.us.undernet.org
saltlake.ut.us.undernet.org
arlington.va.us.undernet.org
auckland.nz.undernet.org
ann-arbor.mi.us.undernet.org
newbrunswick.nj.us.undernet.org
plano.tx.us.undernet.org
mclean.va.us.undernet.org
caen.fr.eu.undernet.org
Gathers the email addresses from the Windows Address Book and from the files that have file names containing any of the following strings:
HTM
HTML
WAB
TXT
Uses its own SMTP engine to send itself to the email addresses that it finds.
The email has the following characteristics:
From: The sender of the email may be spoofed.
Subject: The subject line may be one of the following:
Hi
Hello
Important
I'm in love
Sex
Wet girls
I'm nude
Fetishes
gutted
Ok
Attachment: The attachment may have one of the following extensions:
britney.jpg
jenifer.jpg
photo.jpg
creme_de_gruyere.jpg
details
document
message
followed with .scr or .txt.
The attachment may have multiple spaces.
For example, the attachment can be:
creme_de_gruyere.jpg(multiple spaces).SCR
The worm may also send a .zip file as the attachment.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode.
Run a full system scan and delete all the files detected as W32.Mota.B@mm.
Delete the value that was added to the registry.
To delete the value from the registry
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"RUNDLL32.EXE %Windir%\[random value].dll,_mainRD"
Exit the Registry Editor.
Restart the computer in normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mota.b@mm.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Backdoor.Moonlit
Discovered on: July 27, 2004
Last Updated on: July 29, 2004 10:56:02 AM
Backdoor.Moonlit is a Trojan horse program that can download and execute files, and may act as a proxy server.
Type: Trojan Horse
Infection Length: varies
Damage
Payload Trigger: n/a
Payload: Opens a backdoor.
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: varies.
Shared drives: n/a
Target of infection: n/a
Backdoor.Moonlit consists of a .exe file (the dropper) and a .dll file (the backdoor).
EXE component
Creates the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\MsMoney2003
Stops any processes that contain the following strings, and deletes the associated files:
_up
skynet
hkey.exe
msiwin84.exe
wmiprvsw.exe
avserve.exe
avserve2.exe
msblast.exe
wupdater.
sysupd.
belt.
wkufind.exe
ssgrate.exe
mra.exe
msbb.exe
Creates the following files:
%Temp%\tmp<random numbers>.dll (The backdoor .dll)
%System%\<random letters>.dll (The backdoor .dll with random data appended)
Loads the file, %System%\<random letters>.dll.
DLL component
Creates a new registry key:
HKEY_CLASSES_ROOT\CLSID\{<new CLSID>}
Adds the value:
(Default) = %System%\<random letters>.dll
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{<new CLSID>}
to associate the backdoor DLL with the new clsid.
Adds the value:
<random letters> = {<new CLSID>}
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
so the DLL is loaded when you start Windows.
Note: <random letters> matches the name of the DLL.
Continuously resets these values.
Listens on a random TCP port. Depending on the input, the Trojan may download and execute a file, or act as a proxy server.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Moonlit.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
In the right pane, look for the value:
"<random letters>"="{<random clsid>}"
where <random letters> matches one of the files from step 4. Note the <random clsid>, and then delete the entry.
Navigate to each of the following keys, and delete them:
HKEY_CLASSES_ROOT\CLSID\{<random clsid>}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\MsMoney2003
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.moonlit.html"]Symantec Source[/url]
Discovered on: July 27, 2004
Last Updated on: July 29, 2004 10:56:02 AM
Backdoor.Moonlit is a Trojan horse program that can download and execute files, and may act as a proxy server.
Type: Trojan Horse
Infection Length: varies
Damage
Payload Trigger: n/a
Payload: Opens a backdoor.
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: varies.
Shared drives: n/a
Target of infection: n/a
Backdoor.Moonlit consists of a .exe file (the dropper) and a .dll file (the backdoor).
EXE component
Creates the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\MsMoney2003
Stops any processes that contain the following strings, and deletes the associated files:
_up
skynet
hkey.exe
msiwin84.exe
wmiprvsw.exe
avserve.exe
avserve2.exe
msblast.exe
wupdater.
sysupd.
belt.
wkufind.exe
ssgrate.exe
mra.exe
msbb.exe
Creates the following files:
%Temp%\tmp<random numbers>.dll (The backdoor .dll)
%System%\<random letters>.dll (The backdoor .dll with random data appended)
Loads the file, %System%\<random letters>.dll.
DLL component
Creates a new registry key:
HKEY_CLASSES_ROOT\CLSID\{<new CLSID>}
Adds the value:
(Default) = %System%\<random letters>.dll
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{<new CLSID>}
to associate the backdoor DLL with the new clsid.
Adds the value:
<random letters> = {<new CLSID>}
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
so the DLL is loaded when you start Windows.
Note: <random letters> matches the name of the DLL.
Continuously resets these values.
Listens on a random TCP port. Depending on the input, the Trojan may download and execute a file, or act as a proxy server.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Moonlit.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
In the right pane, look for the value:
"<random letters>"="{<random clsid>}"
where <random letters> matches one of the files from step 4. Note the <random clsid>, and then delete the entry.
Navigate to each of the following keys, and delete them:
HKEY_CLASSES_ROOT\CLSID\{<random clsid>}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\MsMoney2003
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.moonlit.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W97M.Moridin
Discovered on: July 28, 2004
Last Updated on: July 29, 2004 12:11:45 PM
W97M.Moridin is a macro virus that infects Microsoft Word documents. It also disables macro virus protection, attempts to create an outgoing Pegasus Mail message, and attempts to run .exe components.
Also Known As: Moridin.b [Kaspersky], W97M/Moridin.gen [McAfee]
Type: Macro
Infection Length: 8,993
Systems Affected: Macintosh, Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Disables MS Word macro virus protection.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W97M.Moridinruns, it performs the following actions:
Infects the Normal.dot file. Once this is done, the virus will be triggered when a Microsoft Word document is opened.
Disables the Microsoft Word macro virus protection.
As a stealth technique, W97M.Moridin hides its code by hooking the ToolsMacro and ViewVBCode automacros. If you attempt to view the macros, the virus deletes its own code.
Creates the file, Impmori.drv, in the %System% or %Windir% folder. This file contains a copy of the virus code. The virus reads from this file when infecting other documents.
Creates a draft message in the Pegasus Mail program.
There is a 12.5% chance that this message will contain the text.:
Check this out!
There is a 87.5% chance that this message will contain the text:
BAAAAAAAM! You just got hit by an attachment, this is the attachment war! Hit someone, NOW!
Attempts to run the following files, which are likely to be malicious:
%Windir%\W32mori.exe
%Windir%\Advapi33.exe
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as W97M.Moridin.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w97m.moridin.html"]Symantec Source[/url]
Discovered on: July 28, 2004
Last Updated on: July 29, 2004 12:11:45 PM
W97M.Moridin is a macro virus that infects Microsoft Word documents. It also disables macro virus protection, attempts to create an outgoing Pegasus Mail message, and attempts to run .exe components.
Also Known As: Moridin.b [Kaspersky], W97M/Moridin.gen [McAfee]
Type: Macro
Infection Length: 8,993
Systems Affected: Macintosh, Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Disables MS Word macro virus protection.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W97M.Moridinruns, it performs the following actions:
Infects the Normal.dot file. Once this is done, the virus will be triggered when a Microsoft Word document is opened.
Disables the Microsoft Word macro virus protection.
As a stealth technique, W97M.Moridin hides its code by hooking the ToolsMacro and ViewVBCode automacros. If you attempt to view the macros, the virus deletes its own code.
Creates the file, Impmori.drv, in the %System% or %Windir% folder. This file contains a copy of the virus code. The virus reads from this file when infecting other documents.
Creates a draft message in the Pegasus Mail program.
There is a 12.5% chance that this message will contain the text.:
Check this out!
There is a 87.5% chance that this message will contain the text:
BAAAAAAAM! You just got hit by an attachment, this is the attachment war! Hit someone, NOW!
Attempts to run the following files, which are likely to be malicious:
%Windir%\W32mori.exe
%Windir%\Advapi33.exe
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as W97M.Moridin.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w97m.moridin.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Mydoom.N@mm
Discovered on: July 29, 2004
Last Updated on: July 30, 2004 12:19:14 PM
W32.Mydoom.N@mm is a variant of W32.Mydoom.M@mm. It also is a mass-mailing worm that drops and executes a backdoor detected as Backdoor.Zincite.A, which listens on TCP port 1034. The worm uses its own SMTP engine to send itself to email addresses it finds on the infected computer.
The email contains a spoofed From address, and the Subject and Body text will vary. The attachment name will also vary.
This threat is packed with ASPack.
Type: Worm
Infection Length: 35,328 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Uses its own SMTP engine to send itself to the email addresses found in the files with certain extensions.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: The dropped Backdoor allows unauthorized remote access.
Distribution
Subject of email: Varies
Name of attachment: Varies with .cmd, .bat, .com, .exe, .pif, .scr, or .zip file extension.n/a
Size of attachment: Varies
Time stamp of attachment: n/a
Ports: TCP 1034
Shared drives: n/a
Target of infection: n/a
When W32.Mydoom.N@mm runs, it do the following,
Creates one of the following registry keys, which mark the computer as infected:
HKEY_LOCAL_MACHINE\Software\Microsoft\Daemon
HKEY_CURRENT_USER\Software\Microsoft\Daemon
Copies itself as %Windir%\java.exe.
Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
Drops and executes %Windir%\services.exe, which is detected as Backdoor.Zincite.A. When executed, this file opens TCP port 1034 and listens for remote connections. The backdoor will also probe random IP addresses on port 1034 looking for other infected hosts.
Adds the values:
"Services" = "%Windir%\services.exe"
"JavaVM" = "%Windir%\java.exe"
to one of the registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm and backdoor load when Windows starts.
May create the following files for logging purposes:
%Temp%\zincite.log
%Temp%\<randomly named file>.log
Gathers email addresses from files with the following extensions:
.adb
.asp
.dbx
.ht*
.php
.pl
.sht
.tbb
.tx*
.wab
Queries the following search engines to harvest additional email addresses for possible distribution:
search.lycos.com
search.yahoo.com
www.altavista.com
www.google.com
When the worm finds an open Outlook window, it will attempt to send itself to the email addresses that it found.
The email has the following characteristics:
From:
The From address will be spoofed.
Subject: (One of the following)
hello
hi
error
status
test
report
delivery failed
Message could not be delivered
Mail System Error - Returned Mail
Delivery reports about your e-mail
Returned mail: see transcript for details
Returned mail: Data format error
Body:
The content contained in the body of the email will vary, based on a number of text options. One of each of the phrases or words in brackets, separated by a "|", will appear:
Dear user {<recipient's email address>|of <recipient's email domain>},{ {{M|m}ail {system|server} administrator|administration} of <recipient's email domain> would like to {inform you{ that{:|,}|}|let you know {that|the following}{.|:|,}}|||||}
{We have {detected|found|received reports} that y|Y}our {e{-|}mail |}account {has been|was} used to send a {large|huge} amount of {{unsolicited{ commercial|}|junk} e{-|}mail|spam}{ messages|} during {this|the {last|recent}} week.
{We suspect that|Probably,|Most likely|Obviously,} your computer {had been|was} {compromised|infected{ by a recent v{iru}s|}} and now {run|contain}s a {trojan{ed|}|hidden} proxy server.
{Please|We recommend {that you|you to}} follow {our |the |}instruction{s|} {in the {attachment|attached {text |}file} |}in order to keep your computer safe.
{{Virtually|Sincerely} yours|Best {wishe|regard}s|Have a nice day},
{<recipient's email domain> {user |technical |}support team.|The <recipient's email domain> {support |}team.}
{The|This|Your} message was{ undeliverable| not delivered} due to the following reason{(s)|}:
Your message {was not|could not be} delivered because the destination {computer|server} was
{not |un}reachable within the allowed queue period. The amount of time
a message is queued before it is returned depends on local configura-
tion parameters.
Most likely there is a network problem that prevented delivery, but
it is also possible that the computer is turned off, or does not
have a mail system running right now.
Your message {was not|could not be} delivered within <random number> days:
{{{Mail s|S}erver}|Host} <host used to send the email>} is not responding.
The following recipients {did|could} not receive this message:
<<recipient's email address>>
Please reply to postmaster@{<sender's email domain>|<recipient's email domain>}
if you feel this message to be in error.
The original message was received at [current time]{
| }from {<sender's email domain> ]|{<host used to send the email>]|]}}
----- The following addresses had permanent fatal errors -----
{<<recipient's email address>>|<recipient's email address>}
{----- Transcript of {the ||}session follows -----
... while talking to {host |{mail |}server ||||}{<recipient's email domain>.|<host used to send the email>]}:
{>>> MAIL F{rom|ROM}:[From address of mail]
<<< 50$d {[From address of mail]... |}{Refused|{Access d|D}enied|{User|Domain|Address} {unknown|blacklisted}}|554 <<recipient's email address>>... {Mail quota exceeded|Message is too
large}
554 <<recipient's email address>>... Service unavailable|550 5.1.2 <<recipient's email address>>... Host unknown (Name server: host not found)|554 {5.0.0 |}Service unavailable; ] blocked using {relays.osirusoft.com|bl.spamcop.net}{, reason: Blocked|}
Session aborted{, reason: lost connection|}|>>> RCPT To:<<recipient's email address>>
<<< 550 {MAILBOX NOT FOUND|5.1.1 <<recipient's email address>>... {User unknown|Invalid recipient|Not known here}}|>>> DATA
{<<< 400-aturner; %MAIL-E-OPENOUT, error opening !AS as output
|}{<<< 400-aturner; -RMS-E-CRE, ACP file create failed
|}{<<< 400-aturner; -SYSTEM-F-EXDISKQUOTA, disk quota exceeded
|}<<< 400}|}
The original message was included as attachment
{{The|Your} m|M}essage could not be delivered
Notes:
<recipient's email address> is the email address of the person receiving the email.
<recipient's email domain> is the domain of the receiver's email. For instance, if the email address is john_doe@example.com, the domain is "example.com."
<sender's email domain> is the domain of the sender's email. For instance, if the email address is john_doe@example.com, the domain is "example.com."
<host used to send the email> is name of the email server used by the infected computer. The worm gathers this information from the infected computer's registry.
Attachment:
The worm may generate an file name from a domain name of an email address gathered from the computer. For instance, if the worm finds an address john_doe@example.com on the infected computer, the attachment name could contain example.com.
The attachment name may also be one of the following:
readme
instruction
transcript
mail
letter
file
text
attachment
document
message
with one of the following extensions:
.cmd
.bat
.com
.exe
.pif
.scr
.zip
the attachment may have a second extension, which will be one of the following:
doc
txt
htm
html
Notes:
Approximately 30% of the time, the attachment will be zipped. In these cases the attachment may be compressed several times over.
There is a 15% chance the worm will attach a small junk file to the mail instead of a copy of itself.
The worm will not send itself to addresses that contain the following strings:
mailer-d
spam
abuse
master
sample
accou
privacycertific
bugs
listserv
submit
ntivi
support
admin
page
the.bat
gold-certs
feste
not
help
foo
soft
site
rating
you
your
someone
anyone
nothing
nobody
noone
info
winrar
winzip
rarsoft
sf.net
sourceforge
ripe.
arin.
google
gnu.
gmail
seclist
secur
bar.
foo.com
trend
update
uslis
domain
example
sophos
yahoo
spersk
panda
hotmail
msn.
msdn.
microsoft
sarc.
syma
avp
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Mydoom.N@mm.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to each of the following keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values if exist:
"Services" = "%Windir%\services.exe"
"JavaVM" = "%Windir%\java.exe"
Navigate to the keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Daemon
HKEY_CURRENT_USER\Software\Microsoft\Daemon
and delete them.
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.n@mm.html"]Symantec Source[/url]
Discovered on: July 29, 2004
Last Updated on: July 30, 2004 12:19:14 PM
W32.Mydoom.N@mm is a variant of W32.Mydoom.M@mm. It also is a mass-mailing worm that drops and executes a backdoor detected as Backdoor.Zincite.A, which listens on TCP port 1034. The worm uses its own SMTP engine to send itself to email addresses it finds on the infected computer.
The email contains a spoofed From address, and the Subject and Body text will vary. The attachment name will also vary.
This threat is packed with ASPack.
Type: Worm
Infection Length: 35,328 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Uses its own SMTP engine to send itself to the email addresses found in the files with certain extensions.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: The dropped Backdoor allows unauthorized remote access.
Distribution
Subject of email: Varies
Name of attachment: Varies with .cmd, .bat, .com, .exe, .pif, .scr, or .zip file extension.n/a
Size of attachment: Varies
Time stamp of attachment: n/a
Ports: TCP 1034
Shared drives: n/a
Target of infection: n/a
When W32.Mydoom.N@mm runs, it do the following,
Creates one of the following registry keys, which mark the computer as infected:
HKEY_LOCAL_MACHINE\Software\Microsoft\Daemon
HKEY_CURRENT_USER\Software\Microsoft\Daemon
Copies itself as %Windir%\java.exe.
Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
Drops and executes %Windir%\services.exe, which is detected as Backdoor.Zincite.A. When executed, this file opens TCP port 1034 and listens for remote connections. The backdoor will also probe random IP addresses on port 1034 looking for other infected hosts.
Adds the values:
"Services" = "%Windir%\services.exe"
"JavaVM" = "%Windir%\java.exe"
to one of the registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm and backdoor load when Windows starts.
May create the following files for logging purposes:
%Temp%\zincite.log
%Temp%\<randomly named file>.log
Gathers email addresses from files with the following extensions:
.adb
.asp
.dbx
.ht*
.php
.pl
.sht
.tbb
.tx*
.wab
Queries the following search engines to harvest additional email addresses for possible distribution:
search.lycos.com
search.yahoo.com
www.altavista.com
www.google.com
When the worm finds an open Outlook window, it will attempt to send itself to the email addresses that it found.
The email has the following characteristics:
From:
The From address will be spoofed.
Subject: (One of the following)
hello
hi
error
status
test
report
delivery failed
Message could not be delivered
Mail System Error - Returned Mail
Delivery reports about your e-mail
Returned mail: see transcript for details
Returned mail: Data format error
Body:
The content contained in the body of the email will vary, based on a number of text options. One of each of the phrases or words in brackets, separated by a "|", will appear:
Dear user {<recipient's email address>|of <recipient's email domain>},{ {{M|m}ail {system|server} administrator|administration} of <recipient's email domain> would like to {inform you{ that{:|,}|}|let you know {that|the following}{.|:|,}}|||||}
{We have {detected|found|received reports} that y|Y}our {e{-|}mail |}account {has been|was} used to send a {large|huge} amount of {{unsolicited{ commercial|}|junk} e{-|}mail|spam}{ messages|} during {this|the {last|recent}} week.
{We suspect that|Probably,|Most likely|Obviously,} your computer {had been|was} {compromised|infected{ by a recent v{iru}s|}} and now {run|contain}s a {trojan{ed|}|hidden} proxy server.
{Please|We recommend {that you|you to}} follow {our |the |}instruction{s|} {in the {attachment|attached {text |}file} |}in order to keep your computer safe.
{{Virtually|Sincerely} yours|Best {wishe|regard}s|Have a nice day},
{<recipient's email domain> {user |technical |}support team.|The <recipient's email domain> {support |}team.}
{The|This|Your} message was{ undeliverable| not delivered} due to the following reason{(s)|}:
Your message {was not|could not be} delivered because the destination {computer|server} was
{not |un}reachable within the allowed queue period. The amount of time
a message is queued before it is returned depends on local configura-
tion parameters.
Most likely there is a network problem that prevented delivery, but
it is also possible that the computer is turned off, or does not
have a mail system running right now.
Your message {was not|could not be} delivered within <random number> days:
{{{Mail s|S}erver}|Host} <host used to send the email>} is not responding.
The following recipients {did|could} not receive this message:
<<recipient's email address>>
Please reply to postmaster@{<sender's email domain>|<recipient's email domain>}
if you feel this message to be in error.
The original message was received at [current time]{
| }from {<sender's email domain> ]|{<host used to send the email>]|]}}
----- The following addresses had permanent fatal errors -----
{<<recipient's email address>>|<recipient's email address>}
{----- Transcript of {the ||}session follows -----
... while talking to {host |{mail |}server ||||}{<recipient's email domain>.|<host used to send the email>]}:
{>>> MAIL F{rom|ROM}:[From address of mail]
<<< 50$d {[From address of mail]... |}{Refused|{Access d|D}enied|{User|Domain|Address} {unknown|blacklisted}}|554 <<recipient's email address>>... {Mail quota exceeded|Message is too
large}
554 <<recipient's email address>>... Service unavailable|550 5.1.2 <<recipient's email address>>... Host unknown (Name server: host not found)|554 {5.0.0 |}Service unavailable; ] blocked using {relays.osirusoft.com|bl.spamcop.net}{, reason: Blocked|}
Session aborted{, reason: lost connection|}|>>> RCPT To:<<recipient's email address>>
<<< 550 {MAILBOX NOT FOUND|5.1.1 <<recipient's email address>>... {User unknown|Invalid recipient|Not known here}}|>>> DATA
{<<< 400-aturner; %MAIL-E-OPENOUT, error opening !AS as output
|}{<<< 400-aturner; -RMS-E-CRE, ACP file create failed
|}{<<< 400-aturner; -SYSTEM-F-EXDISKQUOTA, disk quota exceeded
|}<<< 400}|}
The original message was included as attachment
{{The|Your} m|M}essage could not be delivered
Notes:
<recipient's email address> is the email address of the person receiving the email.
<recipient's email domain> is the domain of the receiver's email. For instance, if the email address is john_doe@example.com, the domain is "example.com."
<sender's email domain> is the domain of the sender's email. For instance, if the email address is john_doe@example.com, the domain is "example.com."
<host used to send the email> is name of the email server used by the infected computer. The worm gathers this information from the infected computer's registry.
Attachment:
The worm may generate an file name from a domain name of an email address gathered from the computer. For instance, if the worm finds an address john_doe@example.com on the infected computer, the attachment name could contain example.com.
The attachment name may also be one of the following:
readme
instruction
transcript
letter
file
text
attachment
document
message
with one of the following extensions:
.cmd
.bat
.com
.exe
.pif
.scr
.zip
the attachment may have a second extension, which will be one of the following:
doc
txt
htm
html
Notes:
Approximately 30% of the time, the attachment will be zipped. In these cases the attachment may be compressed several times over.
There is a 15% chance the worm will attach a small junk file to the mail instead of a copy of itself.
The worm will not send itself to addresses that contain the following strings:
mailer-d
spam
abuse
master
sample
accou
privacycertific
bugs
listserv
submit
ntivi
support
admin
page
the.bat
gold-certs
feste
not
help
foo
soft
site
rating
you
your
someone
anyone
nothing
nobody
noone
info
winrar
winzip
rarsoft
sf.net
sourceforge
ripe.
arin.
gnu.
gmail
seclist
secur
bar.
foo.com
trend
update
uslis
domain
example
sophos
yahoo
spersk
panda
hotmail
msn.
msdn.
microsoft
sarc.
syma
avp
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Mydoom.N@mm.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to each of the following keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values if exist:
"Services" = "%Windir%\services.exe"
"JavaVM" = "%Windir%\java.exe"
Navigate to the keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Daemon
HKEY_CURRENT_USER\Software\Microsoft\Daemon
and delete them.
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.n@mm.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.Download.Inor.C
Discovered on: July 29, 2004
Last Updated on: July 31, 2004 09:23:31 AM
Trojan.Download.Inor.C is a variant of Trojan.Downloader.Inor.and Trojan.Download.Inor.B. This Trojan spreads as an .hta file. When this file is executed, it creates and runs the file named C:\i.exe.
When i.exe runs, it tries to download a file from a Web site.
Trojan.Download.Inor.C may be received by email as an attachment or as a link to a Web site, which contains a CGI script that drops the Trojan.
Also Known As: VBS/Inor [McAfee]
Variants: Trojan.Downloader.Inor, Trojan.Download.Inor.B
Type: Trojan Horse
Infection Length: 4,164 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.Download.Inor.C is executed, it performs the following actions:
Attempts to download Svchost.exe from a predetermined Web site. The file that it tries to download may vary.
Drops the file named C:\i.exe and then runs it. (This file name is the default, but it may vary.)
Moves Svchost.exe into C:\%Windir% and runs it.
Note: %Windir% is a variable. The Trojan locates the Windows® installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan, and delete all of the files that are detected as Trojan.Download.Inor.C.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.download.inor.c.html"]Symantec Source[/url]
Discovered on: July 29, 2004
Last Updated on: July 31, 2004 09:23:31 AM
Trojan.Download.Inor.C is a variant of Trojan.Downloader.Inor.and Trojan.Download.Inor.B. This Trojan spreads as an .hta file. When this file is executed, it creates and runs the file named C:\i.exe.
When i.exe runs, it tries to download a file from a Web site.
Trojan.Download.Inor.C may be received by email as an attachment or as a link to a Web site, which contains a CGI script that drops the Trojan.
Also Known As: VBS/Inor [McAfee]
Variants: Trojan.Downloader.Inor, Trojan.Download.Inor.B
Type: Trojan Horse
Infection Length: 4,164 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.Download.Inor.C is executed, it performs the following actions:
Attempts to download Svchost.exe from a predetermined Web site. The file that it tries to download may vary.
Drops the file named C:\i.exe and then runs it. (This file name is the default, but it may vary.)
Moves Svchost.exe into C:\%Windir% and runs it.
Note: %Windir% is a variable. The Trojan locates the Windows® installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan, and delete all of the files that are detected as Trojan.Download.Inor.C.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.download.inor.c.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Bugbros.C@mm
Discovered on: July 29, 2004
Last Updated on: July 31, 2004 10:29:06 AM
W32.Bugbros.C@mm is a minor variant of W32.Bugbros.B@mm. It is a simple mass-mailing worm that sends itself to all of the addresses in the Microsoft® Outlook® Address Book. The email has the following characteristics:
Subject: New products
Attachment: Twunk_64.exe
Also Known As: Bloodhound.W32.VBWORM, I-Worm.generic [Kaspersky], W32/Generic.a@MM [McAfee
Type: Worm
Infection Length: 24,576 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows CE, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to all the addresses in the Microsoft Outlook Address Book.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: New products
Name of attachment: Twunk_64.exe
Size of attachment: 24,576 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Bugbros.C@mm runs, it performs the following actions:
Copies itself as C:\Windows\Twunk_64.exe. This path is hard-coded and does not depend on system variables.
Creates the following email message:
From: support@microsoft.com
Subject: New products
Message:
"Hi,
Update your Windows PC with Microsoft Windows Panel.This tool is free and provided by Microsoft. For more info read the disclaimer when you run the program.
bye"
Attachment: Twunk_64.exe
Sends the message to all the addresses in the Microsoft Outlook Address Book.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Bugbros.C@mm.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbros.c@mm.html"]Symantec Source[/url]
Discovered on: July 29, 2004
Last Updated on: July 31, 2004 10:29:06 AM
W32.Bugbros.C@mm is a minor variant of W32.Bugbros.B@mm. It is a simple mass-mailing worm that sends itself to all of the addresses in the Microsoft® Outlook® Address Book. The email has the following characteristics:
Subject: New products
Attachment: Twunk_64.exe
Also Known As: Bloodhound.W32.VBWORM, I-Worm.generic [Kaspersky], W32/Generic.a@MM [McAfee
Type: Worm
Infection Length: 24,576 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows CE, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to all the addresses in the Microsoft Outlook Address Book.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: New products
Name of attachment: Twunk_64.exe
Size of attachment: 24,576 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Bugbros.C@mm runs, it performs the following actions:
Copies itself as C:\Windows\Twunk_64.exe. This path is hard-coded and does not depend on system variables.
Creates the following email message:
From: support@microsoft.com
Subject: New products
Message:
"Hi,
Update your Windows PC with Microsoft Windows Panel.This tool is free and provided by Microsoft. For more info read the disclaimer when you run the program.
bye"
Attachment: Twunk_64.exe
Sends the message to all the addresses in the Microsoft Outlook Address Book.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Bugbros.C@mm.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbros.c@mm.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Rotor
Discovered on: July 31, 2004
Last Updated on: August 02, 2004 01:59:16 PM
W32.Rotor is a virus that appends itself to .exe and .scr files and contains backdoor functionality.
Type: Virus
Infection Length: 5360 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows CE
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: Infects .exe and .scr files.
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Can act as a backdoor.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: May attempt outgoing connection on TCP port 382.
Shared drives: Infects files on drives C through Z and shared network resources.
Target of infection: .exe and .scr files.
When a file infected with W32.Rotor runs, the virus does the following:
Searches for files with .exe or .scr extensions on drives C through Z and shared network resources.
Infects a random number of the files that it finds, appending itself in a new section called ".txt".
Note: The virus avoids infecting system files, skipping folders with names that start with "WINN", such as the WINNT folder.
Injects backdoor code into the Program Manager process (Progman.exe), if it is running.
Note: Windows 2000 and XP do not use Program Manager by default.
Attempts to contact a remote server on TCP port 382.
If a connection is established, the virus opens a command shell on the infected computer.
Returns control to the host file, allowing the executable to run.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as W32.Rotor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.rotor.html"]Symantec Source[/url]
Discovered on: July 31, 2004
Last Updated on: August 02, 2004 01:59:16 PM
W32.Rotor is a virus that appends itself to .exe and .scr files and contains backdoor functionality.
Type: Virus
Infection Length: 5360 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows CE
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: Infects .exe and .scr files.
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Can act as a backdoor.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: May attempt outgoing connection on TCP port 382.
Shared drives: Infects files on drives C through Z and shared network resources.
Target of infection: .exe and .scr files.
When a file infected with W32.Rotor runs, the virus does the following:
Searches for files with .exe or .scr extensions on drives C through Z and shared network resources.
Infects a random number of the files that it finds, appending itself in a new section called ".txt".
Note: The virus avoids infecting system files, skipping folders with names that start with "WINN", such as the WINNT folder.
Injects backdoor code into the Program Manager process (Progman.exe), if it is running.
Note: Windows 2000 and XP do not use Program Manager by default.
Attempts to contact a remote server on TCP port 382.
If a connection is established, the virus opens a command shell on the infected computer.
Returns control to the host file, allowing the executable to run.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as W32.Rotor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.rotor.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
PWSteal.Perfectspy
Discovered on: August 02, 2004
Last Updated on: August 04, 2004 02:03:11 PM
PWSteal.Perfectspy is a Trojan horse that silently installs Spyware.Perfect with predefined settings. This Trojan may arrive as the email attachment, Visa_warning.exe.
Type: Trojan Horse
Infection Length: 393,192 Bytes
Systems Affected: Windows 2000, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Attempts to steal information from browser windows with banking-related titles.
Compromises security settings: Attempts to end the processes of security products.
Distribution
Subject of email: n/a
Name of attachment: May be Visa_warning.exe
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When PWSteal.Perfectspy is executed, it does the following:
Creates the following files in the C:\Documents and Settings\<user_name>\Local Settings\Temp\RarSFX0 folder:
Sk.bin
inst.dat
Ms.dat
Stitle.dat
IEXPLORERhk.dll
IEXPLORERwb.dll
IEXPLORER.EXE
Visa_warning.exe
Winst.exe
Executes Winst.exe, which in turn terminates security product processes, and decrypts IEXPLORER.EXE, IEXPLORERhk.dll, and IEXPLORERwb.dll by "XOR"ing every byte with the predefined hex byte, 9A.
Executes the decrypted IEXPLORER.EXE, which is Spyware.Perfect, with predefined settings that trigger the Trojan when windows, which have the following words in the title bar, are opened:
bank
Bank
BANK
banque
Banque
BANQUE
banc
Banc
BANC
Visa
VISA
and sends a keylog to a predefined email address.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as PWSteal.Perfectspy or Spyware.Perfect.
Note: Only products that support Expanded threats will detect Spyware.Perfect.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete any values that refer to the files detected as PWSteal.Perfectspy or Spyware.Perfect.
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.perfectspy.html"]Symantec Source[/url]
Discovered on: August 02, 2004
Last Updated on: August 04, 2004 02:03:11 PM
PWSteal.Perfectspy is a Trojan horse that silently installs Spyware.Perfect with predefined settings. This Trojan may arrive as the email attachment, Visa_warning.exe.
Type: Trojan Horse
Infection Length: 393,192 Bytes
Systems Affected: Windows 2000, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Attempts to steal information from browser windows with banking-related titles.
Compromises security settings: Attempts to end the processes of security products.
Distribution
Subject of email: n/a
Name of attachment: May be Visa_warning.exe
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When PWSteal.Perfectspy is executed, it does the following:
Creates the following files in the C:\Documents and Settings\<user_name>\Local Settings\Temp\RarSFX0 folder:
Sk.bin
inst.dat
Ms.dat
Stitle.dat
IEXPLORERhk.dll
IEXPLORERwb.dll
IEXPLORER.EXE
Visa_warning.exe
Winst.exe
Executes Winst.exe, which in turn terminates security product processes, and decrypts IEXPLORER.EXE, IEXPLORERhk.dll, and IEXPLORERwb.dll by "XOR"ing every byte with the predefined hex byte, 9A.
Executes the decrypted IEXPLORER.EXE, which is Spyware.Perfect, with predefined settings that trigger the Trojan when windows, which have the following words in the title bar, are opened:
bank
Bank
BANK
banque
Banque
BANQUE
banc
Banc
BANC
Visa
VISA
and sends a keylog to a predefined email address.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as PWSteal.Perfectspy or Spyware.Perfect.
Note: Only products that support Expanded threats will detect Spyware.Perfect.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete any values that refer to the files detected as PWSteal.Perfectspy or Spyware.Perfect.
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.perfectspy.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Saros@mm
Discovered on: August 02, 2004
Last Updated on: August 04, 2004 11:57:41 AM
W32.Saros@mm is a worm that propagates through email, MIRC, and file-sharing networks.
Also Known As: I-Worm.Saros.a [Kaspersky]
Infection Length: 48,514
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends an email to all the addresses in the MS Outlook address book.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Lowers MS Outlook security settings.
Distribution
Subject of email: Microsoft Outlook News
Name of attachment: \WINDOWS\system32\MSOutlookInternetUpdate.exe
Size of attachment: 48,514
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Saros@mm is run, it performs the following actions:
Attempts to create the following files, which are copies of itself:
WINDOWS\system32\NonYou.exe
WINDOWS\system32\Love-ScreenSaver.scr
WINDOWS\system32\MSOutlookInternetUpdate.exe
progra~1\Kazaa\My Shared Folder\Rosy.exe
progra~1\Kazaa\My Shared Folder\Pipponoto.exe
progra~1\Kazaa\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Kazaa\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Kazaa\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Kazaa\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Kazaa\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Kazaa\My Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Kazaa\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Kazaa\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Kazaa\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Rosy.exe
progra~1\Kazaa Lite\My Shared Folder\Pipponoto.exe
progra~1\Kazaa Lite\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Rosy.exe
progra~1\Kazaa Lite K++\My Shared Folder\Pipponoto.exe
progra~1\Kazaa Lite K++\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Haiducii - Dragostea din tei.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\ICQ\Shared Folder\Rosy.exe
progra~1\ICQ\Shared Folder\Pipponoto.exe
progra~1\ICQ\Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\ICQ\Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\ICQ\Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\ICQ\Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\ICQ\Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\ICQ\Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\ICQ\Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\ICQ\Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\ICQ\Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\Grokster\My Grokster\Rosy.exe
progra~1\Grokster\My Grokster\Pipponoto.exe
progra~1\Grokster\My Grokster\Anastacia - Left Outside Alone.mp3.exe
progra~1\Grokster\My Grokster\The Rasmus - In The Shadows.mp3.exe
progra~1\Grokster\My Grokster\50 Cent - In da Club.mp3.exe
progra~1\Grokster\My Grokster\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Grokster\My Grokster\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Grokster\My Grokster\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Grokster\My Grokster\Raf - In tutti i miei giorni.mp3.exe
progra~1\Grokster\My Grokster\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Grokster\My Grokster\Lionel Richie - Just For You.mp3.exe
progra~1\Bearshare\Shared\Rosy.exe
progra~1\Bearshare\Shared\Pipponoto.exe
progra~1\Bearshare\Shared\Anastacia - Left Outside Alone.mp3.exe
progra~1\Bearshare\Shared\The Rasmus - In The Shadows.mp3.exe
progra~1\Bearshare\Shared\50 Cent - In da Club.mp3.exe
progra~1\Bearshare\Shared\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Bearshare\Shared\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Bearshare\Shared\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Bearshare\Shared\Raf - In tutti i miei giorni.mp3.exe
progra~1\Bearshare\Shared\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Bearshare\Shared\Lionel Richie - Just For You.mp3.exe
progra~1\eDonkey2000\Incoming\Rosy.exe
progra~1\eDonkey2000\Incoming\Pipponoto.exe
progra~1\eDonkey2000\Incoming\Anastacia - Left Outside Alone.mp3.exe
progra~1\eDonkey2000\Incoming\The Rasmus - In The Shadows.mp3.exe
progra~1\eDonkey2000\Incoming\50 Cent - In da Club.mp3.exe
progra~1\eDonkey2000\Incoming\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\eDonkey2000\Incoming\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\eDonkey2000\Incoming\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\eDonkey2000\Incoming\Raf - In tutti i miei giorni.mp3.exe
progra~1\eDonkey2000\Incoming\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\eDonkey2000\Incoming\Lionel Richie - Just For You.mp3.exe
progra~1\eMule\Incoming\Rosy.exe
progra~1\eMule\Incoming\Pipponoto.exe
progra~1\eMule\Incoming\Anastacia - Left Outside Alone.mp3.exe
progra~1\eMule\Incoming\The Rasmus - In The Shadows.mp3.exe
progra~1\eMule\Incoming\50 Cent - In da Club.mp3.exe
progra~1\eMule\Incoming\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\eMule\Incoming\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\eMule\Incoming\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\eMule\Incoming\Raf - In tutti i miei giorni.mp3.exe
progra~1\eMule\Incoming\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\eMule\Incoming\Lionel Richie - Just For You.mp3.exe
progra~1\Morpheus\My Shared Folder\Rosy.exe
progra~1\Morpheus\My Shared Folder\Pipponoto.exe
progra~1\Morpheus\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Morpheus\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Morpheus\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Morpheus\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Morpheus\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Morpheus\My Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Morpheus\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Morpheus\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Morpheus\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\LimeWire\Shared\Rosy.exe
progra~1\LimeWire\Shared\Pipponoto.exe
progra~1\LimeWire\Shared\Anastacia - Left Outside Alone.mp3.exe
progra~1\LimeWire\Shared\The Rasmus - In The Shadows.mp3.exe
progra~1\LimeWire\Shared\50 Cent - In da Club.mp3.exe
progra~1\LimeWire\Shared\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\LimeWire\Shared\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\LimeWire\Shared\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\LimeWire\Shared\Raf - In tutti i miei giorni.mp3.exe
progra~1\LimeWire\Shared\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\LimeWire\Shared\Lionel Richie - Just For You.mp3.exe
progra~1\Tesla\Files\Rosy.exe
progra~1\Tesla\Files\Pipponoto.exe
progra~1\Tesla\Files\Anastacia - Left Outside Alone.mp3.exe
progra~1\Tesla\Files\The Rasmus - In The Shadows.mp3.exe
progra~1\Tesla\Files\50 Cent - In da Club.mp3.exe
progra~1\Tesla\Files\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Tesla\Files\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Tesla\Files\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Tesla\Files\Raf - In tutti i miei giorni.mp3.exe
progra~1\Tesla\Files\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Tesla\Files\Lionel Richie - Just For You.mp3.exe
progra~1\WinMX\Shared\Rosy.exe
progra~1\WinMX\Shared\Pipponoto.exe
progra~1\WinMX\Shared\Anastacia - Left Outside Alone.mp3.exe
progra~1\WinMX\Shared\The Rasmus - In The Shadows.mp3.exe
progra~1\WinMX\Shared\50 Cent - In da Club.mp3.exe
progra~1\WinMX\Shared\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\WinMX\Shared\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\WinMX\Shared\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\WinMX\Shared\Raf - In tutti i miei giorni.mp3.exe
progra~1\WinMX\Shared\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\WinMX\Shared\Lionel Richie - Just For You.mp3.exe
Creates the file, \WINDOWS\system32\About.hta, which is a harmless HTML file.
Displays the message:
Title: Microsoft Windows Update
Text: Click Yes For Update Microsoft Outlook via E-mail
Creates and runs the file, \WINDOWS\system32\nstdnrdll32.vbs. This VBScript file performs the following actions:
Creates the following registry keys:
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce\wincomp32\default" = "WINDOWS\system32\nstdnrdll32.vbs
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\nldr32\default" = "WINDOWS\system32\NonYou.exe"
"HKEY_CURRENT_USER\Software\Microsoft\Office\8.0\Outlook\Security\Level1Remove", "exe" "HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Security\Level1Remove", "exe" "HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Security\Level1Remove", "exe"
Creates the archive file, \WINDOWS\system32\Love-ScreenSaver.cab, which contains a copy of the worm.
Checks the system date, and if the day of the month is the 11th or 23rd, it will change the Internet Explorer start page to www.gedzac.tk, and open the file \WINDOWS\system32\About.hta in a Web browser.
Sends an email to all the entries in the Microsoft Outlook Address Book.
The email will have the following properties:
Subject: Microsoft Outlook News
Message: Microsoft Outlook Update / Bug Fixed - Contact: support@microsoft.com
Attachment: \WINDOWS\system32\MSOutlookInternetUpdate.exe
Opens the Web site www.windowsupdate.com.
Adds the line:
n2 = tdll32.dll
to the [rfiles] section of the file, \Program Files\mIRC\mirc.ini.
Opens the file:
Program Files\mIRC\tdll32.dll
and writes an IRC script to send the file, Love-ScreenSaver.cab, to other MIRC users.
Checks the system date. If the day of the month is the 11th or 23rd, it will display two messages:
Title: NonYou
Text: Rosy Ti Amo - Saro & Rosy Forever
Title: Gedzac Group 2004
Text:
NonYou.a Gedzac Labs Productions
Coded by Sarosoft - Dedicated to my Love Ros
Gedzac Group 2004 - http:/ /www.gedzac.tk
Gedzac
The Virus Crew
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode.
Run a full system scan and delete all the files detected as W32.Saros@mm.
Delete the value that was added to the registry.
To delete the value from the registry
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Delete the keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce\wincomp32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\nldr32
Navigate to the following registry keys:
"HKEY_CURRENT_USER\Software\Microsoft\Office\8.0\Outlook\Security
"HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Security
"HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Security
In the right pane, delete the value:
"Level1Remove"="exe"
Exit the Registry Editor.
Restart the computer in normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.saros@mm.html"]Symantec Source[/url]
Discovered on: August 02, 2004
Last Updated on: August 04, 2004 11:57:41 AM
W32.Saros@mm is a worm that propagates through email, MIRC, and file-sharing networks.
Also Known As: I-Worm.Saros.a [Kaspersky]
Infection Length: 48,514
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends an email to all the addresses in the MS Outlook address book.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Lowers MS Outlook security settings.
Distribution
Subject of email: Microsoft Outlook News
Name of attachment: \WINDOWS\system32\MSOutlookInternetUpdate.exe
Size of attachment: 48,514
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Saros@mm is run, it performs the following actions:
Attempts to create the following files, which are copies of itself:
WINDOWS\system32\NonYou.exe
WINDOWS\system32\Love-ScreenSaver.scr
WINDOWS\system32\MSOutlookInternetUpdate.exe
progra~1\Kazaa\My Shared Folder\Rosy.exe
progra~1\Kazaa\My Shared Folder\Pipponoto.exe
progra~1\Kazaa\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Kazaa\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Kazaa\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Kazaa\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Kazaa\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Kazaa\My Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Kazaa\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Kazaa\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Kazaa\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Rosy.exe
progra~1\Kazaa Lite\My Shared Folder\Pipponoto.exe
progra~1\Kazaa Lite\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Rosy.exe
progra~1\Kazaa Lite K++\My Shared Folder\Pipponoto.exe
progra~1\Kazaa Lite K++\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Haiducii - Dragostea din tei.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\ICQ\Shared Folder\Rosy.exe
progra~1\ICQ\Shared Folder\Pipponoto.exe
progra~1\ICQ\Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\ICQ\Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\ICQ\Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\ICQ\Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\ICQ\Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\ICQ\Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\ICQ\Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\ICQ\Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\ICQ\Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\Grokster\My Grokster\Rosy.exe
progra~1\Grokster\My Grokster\Pipponoto.exe
progra~1\Grokster\My Grokster\Anastacia - Left Outside Alone.mp3.exe
progra~1\Grokster\My Grokster\The Rasmus - In The Shadows.mp3.exe
progra~1\Grokster\My Grokster\50 Cent - In da Club.mp3.exe
progra~1\Grokster\My Grokster\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Grokster\My Grokster\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Grokster\My Grokster\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Grokster\My Grokster\Raf - In tutti i miei giorni.mp3.exe
progra~1\Grokster\My Grokster\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Grokster\My Grokster\Lionel Richie - Just For You.mp3.exe
progra~1\Bearshare\Shared\Rosy.exe
progra~1\Bearshare\Shared\Pipponoto.exe
progra~1\Bearshare\Shared\Anastacia - Left Outside Alone.mp3.exe
progra~1\Bearshare\Shared\The Rasmus - In The Shadows.mp3.exe
progra~1\Bearshare\Shared\50 Cent - In da Club.mp3.exe
progra~1\Bearshare\Shared\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Bearshare\Shared\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Bearshare\Shared\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Bearshare\Shared\Raf - In tutti i miei giorni.mp3.exe
progra~1\Bearshare\Shared\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Bearshare\Shared\Lionel Richie - Just For You.mp3.exe
progra~1\eDonkey2000\Incoming\Rosy.exe
progra~1\eDonkey2000\Incoming\Pipponoto.exe
progra~1\eDonkey2000\Incoming\Anastacia - Left Outside Alone.mp3.exe
progra~1\eDonkey2000\Incoming\The Rasmus - In The Shadows.mp3.exe
progra~1\eDonkey2000\Incoming\50 Cent - In da Club.mp3.exe
progra~1\eDonkey2000\Incoming\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\eDonkey2000\Incoming\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\eDonkey2000\Incoming\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\eDonkey2000\Incoming\Raf - In tutti i miei giorni.mp3.exe
progra~1\eDonkey2000\Incoming\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\eDonkey2000\Incoming\Lionel Richie - Just For You.mp3.exe
progra~1\eMule\Incoming\Rosy.exe
progra~1\eMule\Incoming\Pipponoto.exe
progra~1\eMule\Incoming\Anastacia - Left Outside Alone.mp3.exe
progra~1\eMule\Incoming\The Rasmus - In The Shadows.mp3.exe
progra~1\eMule\Incoming\50 Cent - In da Club.mp3.exe
progra~1\eMule\Incoming\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\eMule\Incoming\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\eMule\Incoming\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\eMule\Incoming\Raf - In tutti i miei giorni.mp3.exe
progra~1\eMule\Incoming\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\eMule\Incoming\Lionel Richie - Just For You.mp3.exe
progra~1\Morpheus\My Shared Folder\Rosy.exe
progra~1\Morpheus\My Shared Folder\Pipponoto.exe
progra~1\Morpheus\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Morpheus\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Morpheus\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Morpheus\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Morpheus\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Morpheus\My Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Morpheus\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Morpheus\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Morpheus\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\LimeWire\Shared\Rosy.exe
progra~1\LimeWire\Shared\Pipponoto.exe
progra~1\LimeWire\Shared\Anastacia - Left Outside Alone.mp3.exe
progra~1\LimeWire\Shared\The Rasmus - In The Shadows.mp3.exe
progra~1\LimeWire\Shared\50 Cent - In da Club.mp3.exe
progra~1\LimeWire\Shared\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\LimeWire\Shared\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\LimeWire\Shared\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\LimeWire\Shared\Raf - In tutti i miei giorni.mp3.exe
progra~1\LimeWire\Shared\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\LimeWire\Shared\Lionel Richie - Just For You.mp3.exe
progra~1\Tesla\Files\Rosy.exe
progra~1\Tesla\Files\Pipponoto.exe
progra~1\Tesla\Files\Anastacia - Left Outside Alone.mp3.exe
progra~1\Tesla\Files\The Rasmus - In The Shadows.mp3.exe
progra~1\Tesla\Files\50 Cent - In da Club.mp3.exe
progra~1\Tesla\Files\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Tesla\Files\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Tesla\Files\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Tesla\Files\Raf - In tutti i miei giorni.mp3.exe
progra~1\Tesla\Files\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Tesla\Files\Lionel Richie - Just For You.mp3.exe
progra~1\WinMX\Shared\Rosy.exe
progra~1\WinMX\Shared\Pipponoto.exe
progra~1\WinMX\Shared\Anastacia - Left Outside Alone.mp3.exe
progra~1\WinMX\Shared\The Rasmus - In The Shadows.mp3.exe
progra~1\WinMX\Shared\50 Cent - In da Club.mp3.exe
progra~1\WinMX\Shared\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\WinMX\Shared\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\WinMX\Shared\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\WinMX\Shared\Raf - In tutti i miei giorni.mp3.exe
progra~1\WinMX\Shared\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\WinMX\Shared\Lionel Richie - Just For You.mp3.exe
Creates the file, \WINDOWS\system32\About.hta, which is a harmless HTML file.
Displays the message:
Title: Microsoft Windows Update
Text: Click Yes For Update Microsoft Outlook via E-mail
Creates and runs the file, \WINDOWS\system32\nstdnrdll32.vbs. This VBScript file performs the following actions:
Creates the following registry keys:
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce\wincomp32\default" = "WINDOWS\system32\nstdnrdll32.vbs
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\nldr32\default" = "WINDOWS\system32\NonYou.exe"
"HKEY_CURRENT_USER\Software\Microsoft\Office\8.0\Outlook\Security\Level1Remove", "exe" "HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Security\Level1Remove", "exe" "HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Security\Level1Remove", "exe"
Creates the archive file, \WINDOWS\system32\Love-ScreenSaver.cab, which contains a copy of the worm.
Checks the system date, and if the day of the month is the 11th or 23rd, it will change the Internet Explorer start page to www.gedzac.tk, and open the file \WINDOWS\system32\About.hta in a Web browser.
Sends an email to all the entries in the Microsoft Outlook Address Book.
The email will have the following properties:
Subject: Microsoft Outlook News
Message: Microsoft Outlook Update / Bug Fixed - Contact: support@microsoft.com
Attachment: \WINDOWS\system32\MSOutlookInternetUpdate.exe
Opens the Web site www.windowsupdate.com.
Adds the line:
n2 = tdll32.dll
to the [rfiles] section of the file, \Program Files\mIRC\mirc.ini.
Opens the file:
Program Files\mIRC\tdll32.dll
and writes an IRC script to send the file, Love-ScreenSaver.cab, to other MIRC users.
Checks the system date. If the day of the month is the 11th or 23rd, it will display two messages:
Title: NonYou
Text: Rosy Ti Amo - Saro & Rosy Forever
Title: Gedzac Group 2004
Text:
NonYou.a Gedzac Labs Productions
Coded by Sarosoft - Dedicated to my Love Ros
Gedzac Group 2004 - http:/ /www.gedzac.tk
Gedzac
The Virus Crew
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode.
Run a full system scan and delete all the files detected as W32.Saros@mm.
Delete the value that was added to the registry.
To delete the value from the registry
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Delete the keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce\wincomp32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\nldr32
Navigate to the following registry keys:
"HKEY_CURRENT_USER\Software\Microsoft\Office\8.0\Outlook\Security
"HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Security
"HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Security
In the right pane, delete the value:
"Level1Remove"="exe"
Exit the Registry Editor.
Restart the computer in normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.saros@mm.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Korgo.AD
Discovered on: August 02, 2004
Last Updated on: August 03, 2004 01:58:07 PM
W32.Korgo.AD is a worm that attempts to spread by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (described in Microsoft Security Bulletin [url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx"]MS04-011[/url]) on TCP port 445.
Also Known As: W32/Korgo.worm.gen [McAfee]
Type: Worm
Infection Length: 11,776 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT
CVE References: CAN-2003-0533
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Network propagation routines may degrade overall network performance.
Causes system instability: n/a
Releases confidential info: Backdoor functionality allows unauthorized access.
Compromises security settings: Backdoor functionality may compromise security settings.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 445 and a random port.
Shared drives: n/a
Target of infection: Unpatched computers vulnerable to the Microsoft LSASS Windows exploit.
When W32.Korgo.AD is executed, it does the following:
Deletes the file, ftpupd.exe, from the folder in which the worm was executed.
Creates the following mutexes to ensure that only one instance of the worm is executed on the computer:
uterm19-2
uterm20
u8
u9
u10
u10x
u11
u11x
u12
u12x
u13
u13i
u13x
u14
u14x
u15
u15x
u16
u16x
u17
u17x
u18
u18x
u19
Deletes the values:
"avserve.exe"
"avserve2.exeUpdate"
"Bot Loader"
"Disk Defragmenter"
"MS Config v13"
"Service"
"System Restore Service"
"SysTray"
"Windows Security Manager"
"Windows Update"
"Windows Update Service"
"WinUpdate"
from the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Copies itself as %System%\<random filename>.exe.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the values:
"Client"="1"
"ID"="<random value>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
Adds the value:
"Cryptographic Service"="%System%\<random filename>.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Attempts to inject a function into Explorer.exe as a thread.
If successful, this threat will continue to run in the Explorer.exe process. All of the worm's subsequent actions will appear to be done by Explorer.exe, and the worm will not show when viewing the process list in the Windows Task Manager.
If unsuccessful, the worm will continue to run as its own process.
Opens a random TCP port, which the worm uses to send itself.
The worm attempts to contact one of the following domains and run a PHP script, passing it information about the compromised host:
adult-empire.com
asechka.ru
citi-bank.ru
color-bank.ru
crutop.nu
cvv.ru
fethard.biz
filesearch.ru
kavkaz.tv
kidos-bank.ru
konfiskat.org
master-x.com
mazafaka.ru
parex-bank.ru
roboxchange.com
www.redline.ru
xware.cjb.net
Depending on the response from the remote site, the worm may attempt to download and execute a file from a specified location.
Attempts to exploit the LSASS Windows vulnerability on TCP port 445 (described in Microsoft Security Bulletin MS04-011), against random IP addresses. If the worm successfully finds a vulnerable computer, the computer will attempt to reconnect to the infected computer to download the worm.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Korgo.AD.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Cryptographic Service"="%System%\<random filename>.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
In the right pane, delete the values, if they exist:
"Client"="1"
"ID" = "<random value>"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.ad.html"]Symantec Source[/url]
Discovered on: August 02, 2004
Last Updated on: August 03, 2004 01:58:07 PM
W32.Korgo.AD is a worm that attempts to spread by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (described in Microsoft Security Bulletin [url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx"]MS04-011[/url]) on TCP port 445.
Also Known As: W32/Korgo.worm.gen [McAfee]
Type: Worm
Infection Length: 11,776 bytes
Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT
CVE References: CAN-2003-0533
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Network propagation routines may degrade overall network performance.
Causes system instability: n/a
Releases confidential info: Backdoor functionality allows unauthorized access.
Compromises security settings: Backdoor functionality may compromise security settings.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 445 and a random port.
Shared drives: n/a
Target of infection: Unpatched computers vulnerable to the Microsoft LSASS Windows exploit.
When W32.Korgo.AD is executed, it does the following:
Deletes the file, ftpupd.exe, from the folder in which the worm was executed.
Creates the following mutexes to ensure that only one instance of the worm is executed on the computer:
uterm19-2
uterm20
u8
u9
u10
u10x
u11
u11x
u12
u12x
u13
u13i
u13x
u14
u14x
u15
u15x
u16
u16x
u17
u17x
u18
u18x
u19
Deletes the values:
"avserve.exe"
"avserve2.exeUpdate"
"Bot Loader"
"Disk Defragmenter"
"MS Config v13"
"Service"
"System Restore Service"
"SysTray"
"Windows Security Manager"
"Windows Update"
"Windows Update Service"
"WinUpdate"
from the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Copies itself as %System%\<random filename>.exe.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the values:
"Client"="1"
"ID"="<random value>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
Adds the value:
"Cryptographic Service"="%System%\<random filename>.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Attempts to inject a function into Explorer.exe as a thread.
If successful, this threat will continue to run in the Explorer.exe process. All of the worm's subsequent actions will appear to be done by Explorer.exe, and the worm will not show when viewing the process list in the Windows Task Manager.
If unsuccessful, the worm will continue to run as its own process.
Opens a random TCP port, which the worm uses to send itself.
The worm attempts to contact one of the following domains and run a PHP script, passing it information about the compromised host:
adult-empire.com
asechka.ru
citi-bank.ru
color-bank.ru
crutop.nu
cvv.ru
fethard.biz
filesearch.ru
kavkaz.tv
kidos-bank.ru
konfiskat.org
master-x.com
mazafaka.ru
parex-bank.ru
roboxchange.com
www.redline.ru
xware.cjb.net
Depending on the response from the remote site, the worm may attempt to download and execute a file from a specified location.
Attempts to exploit the LSASS Windows vulnerability on TCP port 445 (described in Microsoft Security Bulletin MS04-011), against random IP addresses. If the worm successfully finds a vulnerable computer, the computer will attempt to reconnect to the infected computer to download the worm.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Korgo.AD.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Cryptographic Service"="%System%\<random filename>.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless
In the right pane, delete the values, if they exist:
"Client"="1"
"ID" = "<random value>"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.ad.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Gaobot.BAJ
Discovered on: August 02, 2004
Last Updated on: August 02, 2004 03:20:05 PM
W32.Gaobot.BAJ is a worm that spreads through open network shares and through backdoors that the Mydoom family of worms open. It allows attackers to access an infected computer using a predetermined IRC channel.
Type: Worm
Infection Length: 136,218 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Steals CD keys from a number of computer games.
Compromises security settings: Gives the creator backdoor access to the computer via IRC.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: Connects to an IRC server on port 6667.
Shared drives: Attempts to authenitcate and copy itself to computers with weak passwords.
Target of infection: n/a
When W32.Gaobot.BAJ is executed, it performs the following actions:
Copies itself to %System%\wmon32.exe.
--------------------------------------------------------------------------------
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
--------------------------------------------------------------------------------
Adds one of the values:
"WSAConfiguration"="wmon32.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
so that the worm executes every time Windows starts.
Connects to a remote IRC server on port 6667 and listens for commands from the remote attacker, including the following:
Download and execute files
Scan the network
List, stop, and start processes
Control the file system (Delete, create, and list files)
Launch Denial of Service (DoS) attacks
Perform port redirection
Steal system information and email it to the attacker
Scans for other computers on the network, attempting to connect to shared resources using a list of usernames and passwords. If successful, it attempts to copy itself to the remote computer.
Scans for computers that have been infected by Mydoom variants. If it finds any, it uses the backdoor installed by Mydoom to copy itself onto the computer.
Steals CD keys of the following computer games:
Command & Conquer Generals
FIFA 2003
Need For Speed Hot Pursuit 2
Soldier of Fortune II - Double Helix
Neverwinter
Rainbow Six III RavenShield
Battlefield 1942 Road To Rome
Project IGI 2
Counter-Strike
Unreal Tournament 2003
Half-Life
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Gaobot.BAJ.
Delete the value that was added to the registry.
To delete the value from the registry
--------------------------------------------------------------------------------
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
--------------------------------------------------------------------------------
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
In the right pane, delete the values, if present:
"WSAConfiguration"="wmon32.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.baj.html"]Symantec Source[/url]
Discovered on: August 02, 2004
Last Updated on: August 02, 2004 03:20:05 PM
W32.Gaobot.BAJ is a worm that spreads through open network shares and through backdoors that the Mydoom family of worms open. It allows attackers to access an infected computer using a predetermined IRC channel.
Type: Worm
Infection Length: 136,218 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Steals CD keys from a number of computer games.
Compromises security settings: Gives the creator backdoor access to the computer via IRC.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: Connects to an IRC server on port 6667.
Shared drives: Attempts to authenitcate and copy itself to computers with weak passwords.
Target of infection: n/a
When W32.Gaobot.BAJ is executed, it performs the following actions:
Copies itself to %System%\wmon32.exe.
--------------------------------------------------------------------------------
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
--------------------------------------------------------------------------------
Adds one of the values:
"WSAConfiguration"="wmon32.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
so that the worm executes every time Windows starts.
Connects to a remote IRC server on port 6667 and listens for commands from the remote attacker, including the following:
Download and execute files
Scan the network
List, stop, and start processes
Control the file system (Delete, create, and list files)
Launch Denial of Service (DoS) attacks
Perform port redirection
Steal system information and email it to the attacker
Scans for other computers on the network, attempting to connect to shared resources using a list of usernames and passwords. If successful, it attempts to copy itself to the remote computer.
Scans for computers that have been infected by Mydoom variants. If it finds any, it uses the backdoor installed by Mydoom to copy itself onto the computer.
Steals CD keys of the following computer games:
Command & Conquer Generals
FIFA 2003
Need For Speed Hot Pursuit 2
Soldier of Fortune II - Double Helix
Neverwinter
Rainbow Six III RavenShield
Battlefield 1942 Road To Rome
Project IGI 2
Counter-Strike
Unreal Tournament 2003
Half-Life
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Gaobot.BAJ.
Delete the value that was added to the registry.
To delete the value from the registry
--------------------------------------------------------------------------------
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
--------------------------------------------------------------------------------
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
In the right pane, delete the values, if present:
"WSAConfiguration"="wmon32.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.baj.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Evaman.C@mm
Discovered on: August 03, 2004
Last Updated on: August 05, 2004 10:30:46 AM
W32.Evaman.C@mm is a mass-mailing worm that sends HTTP Get requests to the Web site, email.people.yahoo.com, to obtain email addresses. It also retrieves the email addresses from Windows Address Book files and from the files with the extensions .adb, .asp, .cfg, .dbx, .dhtm, .eml, .htm, .html, .jse, .jsp, .mmf, .msg, .ods, .php, .pl, .sht, .shtm, .shtml, .tbb, .txt, .wab, and .xml.
W32.Evaman.C@mm uses its own SMTP engine to send itself to the email addresses that it finds.
The email will have one of these subjects:
SN: New secure mail
Secure delivery
failed transaction
Re: hello (Secure-Mail)
Re: Extended Mail
Delivery Status (Secure)
Re: Server Reply
SN: Server Status
This threat is compressed with UPX.
Also Known As: WORM_MYDOOM.O [Trend Micro], W32/Mydoom.q@MM [McAfee], W32/MyDoom-Q [Sophos], I-Worm.Mydoom.o [Kaspersky], W32/Mydoom.P.worm [Panda]
Type: Worm
Infection Length: 21,504 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.evaman.c.removal.tool.html"]Removal Tool[/url]
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Emails itself to addresses found on a Yahoo website and found on the infected system.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: May deactivate antivirus and/or desktop firewall applications on the infected system.
Distribution
Subject of email: SN: New secure mail Secure delivery failed transaction Re: hello (Secure-Mail) Re: Extended Mail Delivery Status (Secure) Re: Server Reply SN: Server Status
Name of attachment: mail message attachment transcript text document file readme followed by one of the following: .exe -txt.exe -htm.exe -txt.scr
Size of attachment: 21,504 bytes, vary for zip
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Evaman.C@mm runs, it does the following:
May create a mutex "Northernlightmixed," which allows only one instance of the worm to run in memory.
Launches Notepad.exe.
Copies itself as one of the following:
%System%\winlibs.exe
%Temp%\winlibs.exe
Notes:
%System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Temp% is a variable.
Creates one of the following registry keys, which the worm uses as an infection marker:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\winlibs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\winlibs
Adds the value:
"winlibs.exe" = "%System%\winlibs.exe"
to one of these registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Terminates the process if any of its module base names contain one of the following:
uba
mc
Mc
av
AV
cc
sym
Sym
nv
can
scn
java
xp.exe
ecur
nti
erve
sss
iru
ort
SkyNet
KV
Attempts to log off the current user, shut down the system, or shut down and restart the system, if the current system time is later than January 1, 2006.
Sends random HTTP Get requests to the Web site, email.people.yahoo.com:80, to retrieve the email addresses.
Retrieves the email addresses from WAB files.
Retrieves the email addresses from the files with the extensions .adb, .asp, .cfg, .dbx, .dhtm, .eml, .htm, .html, .jse, .jsp, .mmf, .msg, .ods, .php, .pl, .sht, .shtm, .shtml, .tbb, .txt, .wab, or .xml on the folders:
%Windir%\Temporary Internet Files
%USERPROFILE%\Local Settings\Temporary Internet Files
%System% folder on all fixed and RAM drives from C through Y
Uses its own SMTP engine to send itself to the addresses that it finds.
The email has the following characteristics:
From: This is spoofed. The sender name may be one of the following:
mike
jennifer
david
linda
susan
nancy
pamela
eric
kevin
mary
jessica
patricia
barbara
karen
sarah
robert
john
daniel
jason
joe
The domain name will be the recipient's domain name.
Subject: The subject is one of the following:
SN: New secure mail
Secure delivery
failed transaction
Re: hello (Secure-Mail)
Re: Extended Mail
Delivery Status (Secure)
Re: Server Reply
SN: Server Status
Attachment: This is composed of one of the following strings:
mail
message
attachment
transcript
text
document
file
readme
followed by one of the following:
.exe
-txt.exe
-htm.exe
-txt.scr
zip
Message: The message is in the format:
<recipient domain name> :: <part 1><recipient email address>.
<part 2>
<part3><recipient domain name>.
where:
<part 1> is one of the following:
Automatically Secure Delivery: for
Mail Delivery Server System: for
Extended secure mail message available at:
Secure Mail Server Notification: for
New mail secure method implement: for
<part 2> is one of the following:
New policy requested by mail server to returned mail
as a secure compiled attachment
/zipped.gif\' class=\'bbc_emoticon\' alt=\'(zip)\' />.
Now a new message is available as secure Zip file format.
Due to new policies on clients.
This message is available as a secure Zip file format
due to a new security policy.
For security measures this message has been packed as Zip format.
This is a newly added security feature.
New policy recommends to enclose all messages as Zip format.
Your message is available in this server notice.
You have received a message that implements secure delivery technology.
Message available as a secure Zip file.
<part 3> is one of the following:
This message is an automatically server notice
from Administration at
Server Notice: New security feature added. MSG:ID: 455sec86
from
New feature added for security reasons
from
Automatically server notice:,
Server reply from
New service policy for security added from
The worm does not send itself to the email addresses that contain any of the following:
.edu
Bug
ugs
bug
upport
ICROSOFT
icrosoft
oot
dmin
ymant
avp
ecur
@MM
ebmast
help
opho
inpris
omain
senet
panda
32.
@mm
msn
inux
umit
nfo
irus
buse
orton
cafee
spam
Spam
SPAM
ntivi
eport
user
inzip
inrar
rend
pdate
USER
ating
ample
ists
persk
ccoun
ompu
msdn
YOU
you
oogle
arsoft
otmail
sarc
soft
ware
.gov
.mil
cribe
list
eturn
omment
Sale
sale
CRIBE
gmail
ruslis
ibm
win
Removal Instructions:
Removal using the W32Evaman.C@mm Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of W32.Evaman.C@mm. Use this removal tool first, as it is the easiest way to remove this threat.
Manual Removal
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Evaman.C@mm.
Delete the values that were added to the registry.
To delete the values from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to each of the following keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value if it exists:
"Winlibs.exe"="%System%\Winlibs.exe"
Navigate to and delete the keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Winlibs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Winlibs
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.evaman.c@mm.html"]Symantec Source[/url]
Discovered on: August 03, 2004
Last Updated on: August 05, 2004 10:30:46 AM
W32.Evaman.C@mm is a mass-mailing worm that sends HTTP Get requests to the Web site, email.people.yahoo.com, to obtain email addresses. It also retrieves the email addresses from Windows Address Book files and from the files with the extensions .adb, .asp, .cfg, .dbx, .dhtm, .eml, .htm, .html, .jse, .jsp, .mmf, .msg, .ods, .php, .pl, .sht, .shtm, .shtml, .tbb, .txt, .wab, and .xml.
W32.Evaman.C@mm uses its own SMTP engine to send itself to the email addresses that it finds.
The email will have one of these subjects:
SN: New secure mail
Secure delivery
failed transaction
Re: hello (Secure-Mail)
Re: Extended Mail
Delivery Status (Secure)
Re: Server Reply
SN: Server Status
This threat is compressed with UPX.
Also Known As: WORM_MYDOOM.O [Trend Micro], W32/Mydoom.q@MM [McAfee], W32/MyDoom-Q [Sophos], I-Worm.Mydoom.o [Kaspersky], W32/Mydoom.P.worm [Panda]
Type: Worm
Infection Length: 21,504 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.evaman.c.removal.tool.html"]Removal Tool[/url]
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Emails itself to addresses found on a Yahoo website and found on the infected system.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: May deactivate antivirus and/or desktop firewall applications on the infected system.
Distribution
Subject of email: SN: New secure mail Secure delivery failed transaction Re: hello (Secure-Mail) Re: Extended Mail Delivery Status (Secure) Re: Server Reply SN: Server Status
Name of attachment: mail message attachment transcript text document file readme followed by one of the following: .exe -txt.exe -htm.exe -txt.scr
Size of attachment: 21,504 bytes, vary for zip
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Evaman.C@mm runs, it does the following:
May create a mutex "Northernlightmixed," which allows only one instance of the worm to run in memory.
Launches Notepad.exe.
Copies itself as one of the following:
%System%\winlibs.exe
%Temp%\winlibs.exe
Notes:
%System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Temp% is a variable.
Creates one of the following registry keys, which the worm uses as an infection marker:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\winlibs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\winlibs
Adds the value:
"winlibs.exe" = "%System%\winlibs.exe"
to one of these registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Terminates the process if any of its module base names contain one of the following:
uba
mc
Mc
av
AV
cc
sym
Sym
nv
can
scn
java
xp.exe
ecur
nti
erve
sss
iru
ort
SkyNet
KV
Attempts to log off the current user, shut down the system, or shut down and restart the system, if the current system time is later than January 1, 2006.
Sends random HTTP Get requests to the Web site, email.people.yahoo.com:80, to retrieve the email addresses.
Retrieves the email addresses from WAB files.
Retrieves the email addresses from the files with the extensions .adb, .asp, .cfg, .dbx, .dhtm, .eml, .htm, .html, .jse, .jsp, .mmf, .msg, .ods, .php, .pl, .sht, .shtm, .shtml, .tbb, .txt, .wab, or .xml on the folders:
%Windir%\Temporary Internet Files
%USERPROFILE%\Local Settings\Temporary Internet Files
%System% folder on all fixed and RAM drives from C through Y
Uses its own SMTP engine to send itself to the addresses that it finds.
The email has the following characteristics:
From: This is spoofed. The sender name may be one of the following:
mike
jennifer
david
linda
susan
nancy
pamela
eric
kevin
mary
jessica
patricia
barbara
karen
sarah
robert
john
daniel
jason
joe
The domain name will be the recipient's domain name.
Subject: The subject is one of the following:
SN: New secure mail
Secure delivery
failed transaction
Re: hello (Secure-Mail)
Re: Extended Mail
Delivery Status (Secure)
Re: Server Reply
SN: Server Status
Attachment: This is composed of one of the following strings:
message
attachment
transcript
text
document
file
readme
followed by one of the following:
.exe
-txt.exe
-htm.exe
-txt.scr
zip
Message: The message is in the format:
<recipient domain name> :: <part 1><recipient email address>.
<part 2>
<part3><recipient domain name>.
where:
<part 1> is one of the following:
Automatically Secure Delivery: for
Mail Delivery Server System: for
Extended secure mail message available at:
Secure Mail Server Notification: for
New mail secure method implement: for
<part 2> is one of the following:
New policy requested by mail server to returned mail
as a secure compiled attachment
Now a new message is available as secure Zip file format.
Due to new policies on clients.
This message is available as a secure Zip file format
due to a new security policy.
For security measures this message has been packed as Zip format.
This is a newly added security feature.
New policy recommends to enclose all messages as Zip format.
Your message is available in this server notice.
You have received a message that implements secure delivery technology.
Message available as a secure Zip file.
<part 3> is one of the following:
This message is an automatically server notice
from Administration at
Server Notice: New security feature added. MSG:ID: 455sec86
from
New feature added for security reasons
from
Automatically server notice:,
Server reply from
New service policy for security added from
The worm does not send itself to the email addresses that contain any of the following:
.edu
Bug
ugs
bug
upport
ICROSOFT
icrosoft
oot
dmin
ymant
avp
ecur
@MM
ebmast
help
opho
inpris
omain
senet
panda
32.
@mm
msn
inux
umit
nfo
irus
buse
orton
cafee
spam
Spam
SPAM
ntivi
eport
user
inzip
inrar
rend
pdate
USER
ating
ample
ists
persk
ccoun
ompu
msdn
YOU
you
oogle
arsoft
otmail
sarc
soft
ware
.gov
.mil
cribe
list
eturn
omment
Sale
sale
CRIBE
gmail
ruslis
ibm
win
Removal Instructions:
Removal using the W32Evaman.C@mm Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of W32.Evaman.C@mm. Use this removal tool first, as it is the easiest way to remove this threat.
Manual Removal
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Evaman.C@mm.
Delete the values that were added to the registry.
To delete the values from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to each of the following keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value if it exists:
"Winlibs.exe"="%System%\Winlibs.exe"
Navigate to and delete the keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Winlibs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Winlibs
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.evaman.c@mm.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Myfip.A
Discovered on: August 04, 2004
Last Updated on: August 05, 2004 02:53:05 PM
W32.Myfip.A is a network-aware worm that steals files from infected computers.
Type: Worm
Infection Length: 24,500 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Gathers and uploads .pdf files to an FTP server.
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: Copies itself to network shares.
Target of infection: n/a
When W32.Myfip.A is executed, it performs the following actions:
Creates the mutex "fjsy", so that only one version of the worm is executed on the computer.
Copies itself as Dfsvc.exe into the %System% folder.
Uses FTP to download a file, named ip.domain, from the domain net918.meibu.com.
This file contains a server name, username, and password used to access another FTP server.
Adds a value:
"Distributed File System"="Dfsvc.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Searches the local computer for network directories. If the worm finds a network directory, it attempts to copy itself to the remote computer as Iloveyou.txt.exe. If the network directory requires authentication, the worm will attempt to connect as "Administrator", using one of the following passwords:
!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
###
***
@#$%^&
@@@
000000
00000000
0007
007
007007
0246
0249
111
123
1234
12345
123456
1234567
12345678
123456789
1a2b3c
1p2o3i
1q2w3e
1qw23e
1sanjose
2004
2222
369
4444
4runner
54321
654321
777
7777
888888
911
99999999
a12345
a1b2c3
a1b2c3d4
aaa
aaaaaa
abby
abc
abc123
abcd
abcd1234
abcde
abcdef
abcdefg
access
access
action
active
adam
adg
adm
adm
admin
Admin
admin123
admin123456
administrator
Administrator
administrator
administrator123
administrator123456
administratorpasswd
adminpasswd
adminpasswd
adminpwd
asdf
asdfg
asdfgh
asdfghjk
asdfjkl
asdfjkl;
bill
bin
daemon
dgj
doc
fgh
free
freedom
/censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' />
fuckyou
god
guest
hacker
job
kim
love
loveyou
lp
morris
mp3
mypass
mypass123
mypc
mypc123
newpass
nice
noaccess
nobody
parol
pass
passwd
Passwd
password
Password
pentium
pizza
planet
playboy
ppp
pw123
pwd
qwerty
root
rose
sex
sexy
/censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' />
shotgun
sos
spirit
spring
sprite
ssssss
storm
super
superman
support
sys
telecom
temp
test
test1
test123
upload
warez
xxx
xxxx
ytrewq
zxcvb
zxcvbnm
If the worm successfully connects to the network directory, it attempts to create following files:
\\Admin$\system32\temp.txt
\\Admin$\system32\Dfsvc.exe
\\Admin$\system32\dltksvc.exe
Registers the dltksvc.exe file as a service named "Distributed Link Tracking Extensions", which runs Dfsvc.exe with Administrator privileges.
Searches for .pdf files and sends them to the FTP server referenced in the file, ip.domain.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Myfip.A.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Distributed File System"="Dfsvc.exe"
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.myfip.a.html"]Symantec Source[/url]
Discovered on: August 04, 2004
Last Updated on: August 05, 2004 02:53:05 PM
W32.Myfip.A is a network-aware worm that steals files from infected computers.
Type: Worm
Infection Length: 24,500 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Gathers and uploads .pdf files to an FTP server.
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: Copies itself to network shares.
Target of infection: n/a
When W32.Myfip.A is executed, it performs the following actions:
Creates the mutex "fjsy", so that only one version of the worm is executed on the computer.
Copies itself as Dfsvc.exe into the %System% folder.
Uses FTP to download a file, named ip.domain, from the domain net918.meibu.com.
This file contains a server name, username, and password used to access another FTP server.
Adds a value:
"Distributed File System"="Dfsvc.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Searches the local computer for network directories. If the worm finds a network directory, it attempts to copy itself to the remote computer as Iloveyou.txt.exe. If the network directory requires authentication, the worm will attempt to connect as "Administrator", using one of the following passwords:
!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
###
***
@#$%^&
@@@
000000
00000000
0007
007
007007
0246
0249
111
123
1234
12345
123456
1234567
12345678
123456789
1a2b3c
1p2o3i
1q2w3e
1qw23e
1sanjose
2004
2222
369
4444
4runner
54321
654321
777
7777
888888
911
99999999
a12345
a1b2c3
a1b2c3d4
aaa
aaaaaa
abby
abc
abc123
abcd
abcd1234
abcde
abcdef
abcdefg
access
access
action
active
adam
adg
adm
adm
admin
Admin
admin123
admin123456
administrator
Administrator
administrator
administrator123
administrator123456
administratorpasswd
adminpasswd
adminpasswd
adminpwd
asdf
asdfg
asdfgh
asdfghjk
asdfjkl
asdfjkl;
bill
bin
daemon
dgj
doc
fgh
free
freedom
fuckyou
god
guest
hacker
job
kim
love
loveyou
lp
morris
mp3
mypass
mypass123
mypc
mypc123
newpass
nice
noaccess
nobody
parol
pass
passwd
Passwd
password
Password
pentium
pizza
planet
playboy
ppp
pw123
pwd
qwerty
root
rose
sex
sexy
shotgun
sos
spirit
spring
sprite
ssssss
storm
super
superman
support
sys
telecom
temp
test
test1
test123
upload
warez
xxx
xxxx
ytrewq
zxcvb
zxcvbnm
If the worm successfully connects to the network directory, it attempts to create following files:
\\Admin$\system32\temp.txt
\\Admin$\system32\Dfsvc.exe
\\Admin$\system32\dltksvc.exe
Registers the dltksvc.exe file as a service named "Distributed Link Tracking Extensions", which runs Dfsvc.exe with Administrator privileges.
Searches for .pdf files and sends them to the FTP server referenced in the file, ip.domain.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Myfip.A.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Distributed File System"="Dfsvc.exe"
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.myfip.a.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Backdoor.Brador.A
Discovered on: August 05, 2004
Last Updated on: August 05, 2004 11:11:50 AM
Backdoor.Brador.A is the first Windows CE (Pocket PC) backdoor Trojan horse. The backdoor sends the IP address of the infected handheld to the attacker and opens TCP port 2989. The backdoor will work on Windows CE 2.0 or later.
The backdoor only affects ARM-based devices.
Type: Trojan Horse
Infection Length: 5632 bytes
Systems Affected: Windows CE
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Sends the attacker the IP address of the infected handheld.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 2989
Shared drives: n/a
Target of infection: n/a
When Backdoor.Brador.A is launched, it performs the following actions:
Copies itself to Windows/StartUp/Svchost.exe (5632 bytes) so that it starts when Windows starts.
Continually attempts to send the attacker the IP address of the handheld by email until it succeeds.
Opens TCP port 2989 and waits for further instructions from the attacker.
Allows the attacker to remotely perform the following commands:
list the directory contents
upload a file
display a message box
download a file
execute the specified command
Removal Instructions:
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Brador.A.
[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.brador.a.html"]Symantec Source[/url]
Discovered on: August 05, 2004
Last Updated on: August 05, 2004 11:11:50 AM
Backdoor.Brador.A is the first Windows CE (Pocket PC) backdoor Trojan horse. The backdoor sends the IP address of the infected handheld to the attacker and opens TCP port 2989. The backdoor will work on Windows CE 2.0 or later.
The backdoor only affects ARM-based devices.
Type: Trojan Horse
Infection Length: 5632 bytes
Systems Affected: Windows CE
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Sends the attacker the IP address of the infected handheld.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 2989
Shared drives: n/a
Target of infection: n/a
When Backdoor.Brador.A is launched, it performs the following actions:
Copies itself to Windows/StartUp/Svchost.exe (5632 bytes) so that it starts when Windows starts.
Continually attempts to send the attacker the IP address of the handheld by email until it succeeds.
Opens TCP port 2989 and waits for further instructions from the attacker.
Allows the attacker to remotely perform the following commands:
list the directory contents
upload a file
display a message box
download a file
execute the specified command
Removal Instructions:
Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Brador.A.
[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.brador.a.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Lovgate.AN@mm
Discovered on: August 07, 2004
Last Updated on: August 07, 2004 01:32:50 PM
W32.Lovgate.AN@mm is a mass mailing worm that propagates through open network shares and using the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (BID 8205). It prepends itself to .exe files.
Type: Worm
Infection Length: 129,536 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: Linux, Macintosh OS X, Novell Netware, OS/2, UNIX
Damage:
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Yes
Deletes files: n/a
Modifies files: n/a
Degrades performance: Propagation through network shares may degrade network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Installs backdoor component.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Lovgate.AN@mm is run it does the following:
The worm creates a network share, "JAVA" which is mapped to "%Windir%\JAVA" It copies itself to all network shared folders using one or more of the following names:WinGate V5.0.10 Build.exe
WINISO 5.3.exe
Winamp skin_FinalFantasy.exe
i386.exe
Serv-U FTP Server 4.1.exe
Daemon Tools v3.41.exe
autoexec.bat
Windows 2000 sp4.ZIP.exe
Flash2X Flash Hunter v1.1.2.pif
Minilyrics_Std_2.7.233.pif
Support Tools.exe
Windows Media Player.zip.exe
Microsoft Office.exe
eMule-0.42e-VeryCD0407Install.exe
FoxMail V5.0.500.0.exe
EnterNet 500 V1.5 RC1.exe
When the worm is executed, it creates the following files:
%Windir%\Office.exe
%Windir%\Video.EXE
%System%\hxdef.exe
%System%\IEXPLORE.EXE
%System%\iexplorer.exe
%System%\real.exe
%System%\TkBellExe.exe
%System%\Update_OB.exe
%System%\Kernel66.dll, which is a hidden file.
The following files are also created which make up the worm's back door component:
%System%\msjdbc11.dll
%System%\MSSIGN30.DLL
%System%\ODBC16.dll
%System%\Lmmib20.dll
Next the worm will create upDate.exe in the root folder of all drives, except CDROM drives. The file attributes are set to system, hidden, and read_only.
The worm overwrites autorun.inf on each of these drives with the lines
[AUTORUN]
Open="C:\upDate.exe" /StartExplorer
The worm then creates an archive containing a copy of the worm with the following format in the root folder of all drives, unless the drive letter is A or B:
<filename>.RAR
Where <filename> may be one of the following:
Bakeup
ghost
email
It then creates the following registry entries so that it executes every time Windows starts:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"Microsoft Inc." = "iexplorer.exe..."
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"Program In Windows" = "%system%\IEXPLORE.EXE"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"WinHelp" = "%system%\TkBellExe.exe..."
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\runServices\"SystemTra" = "C:\WINDOWS\Video.EXE"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\"Soft Profile Inc" = "%system%\hxdef.exe..."
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\"Installed shell32.dll" = "Office.exe..."
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\"run" = "real.exe"
HKEY_CLASSES_ROOT\txtfile\shell\open\command\(Default) = "Update_OB.exe %1..."
The worm stops the following services:
Rising Realtime Monitor Service
Symantec AntiVirus Server
Symantec AntiVirus Client
The worm also terminates any processes with the following strings in their names:
rising
SkyNet
Symantec
McAfee
Gate
Rfw.exe
RavMon.exe
kill
NAV
Duba
KAV
KV
It scans all the drives, if the drive type is removable, mapped, or the drive type is fixed with a drive letter greater than E, it does the following on all the drives found:
Attempt to rename the extension on all the .exe files to .zmx.
Set the attributes to Hidden and System on these files.
Copy itself as the original file name.
Next the worm will inject a process-watching procedure as a thread into either Explorer.exe or Taskmgr.exe. This thread will attempt to launch %System32%\Iexplore.exe if it detects that the worm process has stopped.
The worm will then listen on port 6000. The backdoor procedures steal information of a compromised system and store it in the file, C:\Netlog.txt. The worm then emails the stolen information to the hacker.
Next the worm will extract the location of the KaZaA shared folder from the system registry. It will then create a copy of itself in the KaZaA shared folder as one of the following (with a .bat, .exe, .pif, or .scr file extension):
wrar320sc
REALONE
BlackIcePCPSetup_creak
Passware5.3
word_pass_creak
HEROSOFT
orcard_original_creak
rainbowcrack-1.1-win
W32Dasm
setup
<random file name>
Next the worm will scan all of the computers attached to the same network segment as the compromised system, the worm will attempt to authenticate to administrative shares on systems that are found, using the "Administrator" username combined with the following passwords:
Guest
Administrator
zxcv
yxcv
zzz
win
test123
test
temp123
temp
sybase
super
sex
secret
pwd
pw123
Password
owner
oracle
mypc123
mypc
mypass123
mypass
love
login
Login
Internet
home
godblessyou
god
enable
database
computer
alpha
admin123
Admin
abcd
aaa
88888888
2600
2004
2003
123asd
123abc
123456789
1234567
123123
121212
11111111
110
7
0
0
pass
54321
12345
password
passwd
server
sql
!@#$%^&*
!@#$%^&
!@#$%^
!@#$%
asdfgh
asdf
!@#$
1234
111
root
abc123
12345678
abcdefg
abcdef
abc
888888
666666
111111
admin
administrator
guest
654321
123456
321
123
If the worm successfully authenticates to a remote system, it will attempt to copy itself as:
\\<remote computer name>\admin$\system32\TelePhone.exe
It will then start the file as the service, "NetWork Associates Inc." which is mapped to "TelePhone.exe -exe_start."
The worm replies to any messages that arrive in the mailbox of certain MAPI-compliant email clients, which include Microsoft Outlook. For example, if the incoming email has the following properties:
Subject: <subject>
From: <sender>@<domain.com>
Message: <original message body>
The worm will attempt to send the following email:
Subject: Re: <subject>
To: <sender>@<domain.com>
Message body:
'<sender>' wrote:
====
> <original message body>
====
<domain.com> account auto-reply:
... ... more details,look to the attachment.
> Get your FREE <domain.com> account now! <
The attachment is one of the following:
MacroMedia.pif
Butterfly Garden.scr
Matrix Reloaded 3D.exe
s3msong.MP3.pif
MyIE.AVI.pif
WindowsXP Creak.exe
Macromedia Flash.scr
Photoshop.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
HyperSnap-DX v5.rar.exe
joke.exe
MSN Messenger.exe
FlashFXP.exe
The worm traverses the hard disk.
When it finds a .exe, it creates a viral file in %system%\temp.uuu and prepends this file as a virus to the .exe file.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Reverse the changes made to the registry.
Reversing the changes made to the registry
Before continuing, Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. For instructions, read the document, "How to make a backup of the Windows registry."
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\runServices\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\
HKEY_CLASSES_ROOT\txtfile\shell\open\command\
In the right pane, delete the values:
"Microsoft Inc." = "iexplorer.exe..."
"Program In Windows" = "%system%\IEXPLORE.EXE"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"WinHelp" = "%system%\TkBellExe.exe..."
"SystemTra" = "C:\WINDOWS\Video.EXE"
"Soft Profile Inc" = "%system%\hxdef.exe..."
"Installed shell32.dll" = "Office.exe..."
"run" = "real.exe"
(Default) = "Update_OB.exe %1..."
Exit the Registry Editor.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lovgate.AN@mm.
Rename the .zmx files to the .exe files.
Renaming the .zmx files to the .exe files
As W32.HLLW.Lovgate.AN@mm modifies the .exe files, correct this for relevant programs to function correctly.
Follow the instructions for your operating system:
Windows 98/Me/2000
On the Windows desktop, click the Start button > Find or Search > Files or Folders.
In the Search Results window, set "Look in" to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Check "Include subfolders."
In the "Named" or "Search for..." box, type, or copy and paste, the following:
*.zmx
Click Find Now or Search Now.
Windows XP
On the Windows desktop, click the Start button > Search.
Click All files and folders.
In the "All or part of the file name" box, type, or copy and paste, the following:
*.zmx
Verify that "Look in" is set to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Click "More advanced options."
Select "Search system folders."
Select "Search subfolders."
Select "Search hidden files and folders."
Click Search.
For every file that is found, right click it, select "Rename," and then change the .zmx extension to .exe.
Repeat step 6 for every removable, mapped, or fixed drive type with a drive letter greater than E.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.an@mm.html"]Symantec Source[/url]
Discovered on: August 07, 2004
Last Updated on: August 07, 2004 01:32:50 PM
W32.Lovgate.AN@mm is a mass mailing worm that propagates through open network shares and using the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (BID 8205). It prepends itself to .exe files.
Type: Worm
Infection Length: 129,536 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: Linux, Macintosh OS X, Novell Netware, OS/2, UNIX
Damage:
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Yes
Deletes files: n/a
Modifies files: n/a
Degrades performance: Propagation through network shares may degrade network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Installs backdoor component.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Lovgate.AN@mm is run it does the following:
The worm creates a network share, "JAVA" which is mapped to "%Windir%\JAVA" It copies itself to all network shared folders using one or more of the following names:WinGate V5.0.10 Build.exe
WINISO 5.3.exe
Winamp skin_FinalFantasy.exe
i386.exe
Serv-U FTP Server 4.1.exe
Daemon Tools v3.41.exe
autoexec.bat
Windows 2000 sp4.ZIP.exe
Flash2X Flash Hunter v1.1.2.pif
Minilyrics_Std_2.7.233.pif
Support Tools.exe
Windows Media Player.zip.exe
Microsoft Office.exe
eMule-0.42e-VeryCD0407Install.exe
FoxMail V5.0.500.0.exe
EnterNet 500 V1.5 RC1.exe
When the worm is executed, it creates the following files:
%Windir%\Office.exe
%Windir%\Video.EXE
%System%\hxdef.exe
%System%\IEXPLORE.EXE
%System%\iexplorer.exe
%System%\real.exe
%System%\TkBellExe.exe
%System%\Update_OB.exe
%System%\Kernel66.dll, which is a hidden file.
The following files are also created which make up the worm's back door component:
%System%\msjdbc11.dll
%System%\MSSIGN30.DLL
%System%\ODBC16.dll
%System%\Lmmib20.dll
Next the worm will create upDate.exe in the root folder of all drives, except CDROM drives. The file attributes are set to system, hidden, and read_only.
The worm overwrites autorun.inf on each of these drives with the lines
[AUTORUN]
Open="C:\upDate.exe" /StartExplorer
The worm then creates an archive containing a copy of the worm with the following format in the root folder of all drives, unless the drive letter is A or B:
<filename>.RAR
Where <filename> may be one of the following:
Bakeup
ghost
It then creates the following registry entries so that it executes every time Windows starts:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"Microsoft Inc." = "iexplorer.exe..."
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"Program In Windows" = "%system%\IEXPLORE.EXE"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"WinHelp" = "%system%\TkBellExe.exe..."
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\runServices\"SystemTra" = "C:\WINDOWS\Video.EXE"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\"Soft Profile Inc" = "%system%\hxdef.exe..."
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\"Installed shell32.dll" = "Office.exe..."
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\"run" = "real.exe"
HKEY_CLASSES_ROOT\txtfile\shell\open\command\(Default) = "Update_OB.exe %1..."
The worm stops the following services:
Rising Realtime Monitor Service
Symantec AntiVirus Server
Symantec AntiVirus Client
The worm also terminates any processes with the following strings in their names:
rising
SkyNet
Symantec
McAfee
Gate
Rfw.exe
RavMon.exe
kill
NAV
Duba
KAV
KV
It scans all the drives, if the drive type is removable, mapped, or the drive type is fixed with a drive letter greater than E, it does the following on all the drives found:
Attempt to rename the extension on all the .exe files to .zmx.
Set the attributes to Hidden and System on these files.
Copy itself as the original file name.
Next the worm will inject a process-watching procedure as a thread into either Explorer.exe or Taskmgr.exe. This thread will attempt to launch %System32%\Iexplore.exe if it detects that the worm process has stopped.
The worm will then listen on port 6000. The backdoor procedures steal information of a compromised system and store it in the file, C:\Netlog.txt. The worm then emails the stolen information to the hacker.
Next the worm will extract the location of the KaZaA shared folder from the system registry. It will then create a copy of itself in the KaZaA shared folder as one of the following (with a .bat, .exe, .pif, or .scr file extension):
wrar320sc
REALONE
BlackIcePCPSetup_creak
Passware5.3
word_pass_creak
HEROSOFT
orcard_original_creak
rainbowcrack-1.1-win
W32Dasm
setup
<random file name>
Next the worm will scan all of the computers attached to the same network segment as the compromised system, the worm will attempt to authenticate to administrative shares on systems that are found, using the "Administrator" username combined with the following passwords:
Guest
Administrator
zxcv
yxcv
zzz
win
test123
test
temp123
temp
sybase
super
sex
secret
pwd
pw123
Password
owner
oracle
mypc123
mypc
mypass123
mypass
love
login
Login
Internet
home
godblessyou
god
enable
database
computer
alpha
admin123
Admin
abcd
aaa
88888888
2600
2004
2003
123asd
123abc
123456789
1234567
123123
121212
11111111
110
7
0
0
pass
54321
12345
password
passwd
server
sql
!@#$%^&*
!@#$%^&
!@#$%^
!@#$%
asdfgh
asdf
!@#$
1234
111
root
abc123
12345678
abcdefg
abcdef
abc
888888
666666
111111
admin
administrator
guest
654321
123456
321
123
If the worm successfully authenticates to a remote system, it will attempt to copy itself as:
\\<remote computer name>\admin$\system32\TelePhone.exe
It will then start the file as the service, "NetWork Associates Inc." which is mapped to "TelePhone.exe -exe_start."
The worm replies to any messages that arrive in the mailbox of certain MAPI-compliant email clients, which include Microsoft Outlook. For example, if the incoming email has the following properties:
Subject: <subject>
From: <sender>@<domain.com>
Message: <original message body>
The worm will attempt to send the following email:
Subject: Re: <subject>
To: <sender>@<domain.com>
Message body:
'<sender>' wrote:
====
> <original message body>
====
<domain.com> account auto-reply:
... ... more details,look to the attachment.
> Get your FREE <domain.com> account now! <
The attachment is one of the following:
MacroMedia.pif
Butterfly Garden.scr
Matrix Reloaded 3D.exe
s3msong.MP3.pif
MyIE.AVI.pif
WindowsXP Creak.exe
Macromedia Flash.scr
Photoshop.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
HyperSnap-DX v5.rar.exe
joke.exe
MSN Messenger.exe
FlashFXP.exe
The worm traverses the hard disk.
When it finds a .exe, it creates a viral file in %system%\temp.uuu and prepends this file as a virus to the .exe file.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Reverse the changes made to the registry.
Reversing the changes made to the registry
Before continuing, Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. For instructions, read the document, "How to make a backup of the Windows registry."
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\runServices\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\
HKEY_CLASSES_ROOT\txtfile\shell\open\command\
In the right pane, delete the values:
"Microsoft Inc." = "iexplorer.exe..."
"Program In Windows" = "%system%\IEXPLORE.EXE"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"WinHelp" = "%system%\TkBellExe.exe..."
"SystemTra" = "C:\WINDOWS\Video.EXE"
"Soft Profile Inc" = "%system%\hxdef.exe..."
"Installed shell32.dll" = "Office.exe..."
"run" = "real.exe"
(Default) = "Update_OB.exe %1..."
Exit the Registry Editor.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lovgate.AN@mm.
Rename the .zmx files to the .exe files.
Renaming the .zmx files to the .exe files
As W32.HLLW.Lovgate.AN@mm modifies the .exe files, correct this for relevant programs to function correctly.
Follow the instructions for your operating system:
Windows 98/Me/2000
On the Windows desktop, click the Start button > Find or Search > Files or Folders.
In the Search Results window, set "Look in" to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Check "Include subfolders."
In the "Named" or "Search for..." box, type, or copy and paste, the following:
*.zmx
Click Find Now or Search Now.
Windows XP
On the Windows desktop, click the Start button > Search.
Click All files and folders.
In the "All or part of the file name" box, type, or copy and paste, the following:
*.zmx
Verify that "Look in" is set to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Click "More advanced options."
Select "Search system folders."
Select "Search subfolders."
Select "Search hidden files and folders."
Click Search.
For every file that is found, right click it, select "Rename," and then change the .zmx extension to .exe.
Repeat step 6 for every removable, mapped, or fixed drive type with a drive letter greater than E.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.an@mm.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
~Josh
[align=center]

“If you stop learning, you stop living.” ~Tami Quiring
“It's the rare man who understands the value of a single perfect rose.”
[/align]

“If you stop learning, you stop living.” ~Tami Quiring
“It's the rare man who understands the value of a single perfect rose.”
[/align]
Alerts
W32.Amus.A@mm
Discovered on: August 06, 2004
Last Updated on: August 07, 2004 12:44:25 PM
W32.Amus.A@mm is a mass-mailing worm that sends email with the subject "Listen and Smile" and the attachment "Masum.exe."
Also Known As: WORM_AMUS.A (Trend), Amus.A (Panda), Amus.A (F-Secure)
Type: Worm
Infection Length: 51,782 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows CE
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Yes
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: Listen and Smile
Name of attachment: Masum.exe
Size of attachment: 51,782 bytes
Time stamp of attachment: varies
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Amus.A@mm runs, it does the following:
Adds the value:
"Microzoft_Ofiz"="%Windir%\KdzEregli.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Adds the value:
"Who"="OnEmLi_DeGiL"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Masum
Copies itself to the %Windir% folder as:
Pire.exe
Pide.exe
My_Pictures.exe
Meydanbasi.exe
Messenger.exe
KdzEregli.exe
Cekirge.exe
Anti_Virus.exe
Ankara.exe
Adapazari.exe
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Copies itself as C:\Masum.exe.
Uses Microsoft Outlook to send itself to all the contacts in the Microsoft Outlook Address Book.
The email has the following characteristics:
Subject: Listen and Smile
Message Body: Hey. I beg your pardon. You must listen.
Attachment: Masum.exe
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Amus.A@mm.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Microzoft_Ofiz"="%Windir%\KdzEregli.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
In the right pane, delete the subkey:
Masum
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.amus.a@mm.html"]Symantec Source[/url]
Discovered on: August 06, 2004
Last Updated on: August 07, 2004 12:44:25 PM
W32.Amus.A@mm is a mass-mailing worm that sends email with the subject "Listen and Smile" and the attachment "Masum.exe."
Also Known As: WORM_AMUS.A (Trend), Amus.A (Panda), Amus.A (F-Secure)
Type: Worm
Infection Length: 51,782 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows CE
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Yes
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: Listen and Smile
Name of attachment: Masum.exe
Size of attachment: 51,782 bytes
Time stamp of attachment: varies
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Amus.A@mm runs, it does the following:
Adds the value:
"Microzoft_Ofiz"="%Windir%\KdzEregli.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Adds the value:
"Who"="OnEmLi_DeGiL"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Masum
Copies itself to the %Windir% folder as:
Pire.exe
Pide.exe
My_Pictures.exe
Meydanbasi.exe
Messenger.exe
KdzEregli.exe
Cekirge.exe
Anti_Virus.exe
Ankara.exe
Adapazari.exe
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Copies itself as C:\Masum.exe.
Uses Microsoft Outlook to send itself to all the contacts in the Microsoft Outlook Address Book.
The email has the following characteristics:
Subject: Listen and Smile
Message Body: Hey. I beg your pardon. You must listen.
Attachment: Masum.exe
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Amus.A@mm.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Microzoft_Ofiz"="%Windir%\KdzEregli.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
In the right pane, delete the subkey:
Masum
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.amus.a@mm.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
"Listen and Smile" eh?
/blum.gif\' class=\'bbc_emoticon\' alt=\':P\' /> I got that one today!
/biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' /> Glad I didn't open it =x
/shocking.gif\' class=\'bbc_emoticon\' alt=\'(ack)\' />
~Josh
/sp_ike.gif\' class=\'bbc_emoticon\' alt=\'(spike)\' />
~Josh
[align=center]

“If you stop learning, you stop living.” ~Tami Quiring
“It's the rare man who understands the value of a single perfect rose.”
[/align]

“If you stop learning, you stop living.” ~Tami Quiring
“It's the rare man who understands the value of a single perfect rose.”
[/align]
Alerts
W32.Beagle.AO@mm
Discovered on: August 09, 2004
Last Updated on: August 09, 2004 03:27:33 PM
W32.Beagle.AO@mm is a mass mailing worm that uses its own SMTP engine to spread. The email attachment is a Mitglieder-like downloader that brings the worm from external sources.
The worm also has a backdoor functionality, opening UDP and TCP port 80.
Note: Virus definitions version 60809aj (extended version 8/9/2004 rev. 36) and greater are required to detect this threat. The respective LiveUpdate definitions which contain protection are version 60809ak (8/9/2004 rev. 37).
Also Known As: W32/Bagle.aq@MM [McAfee], WORM_BAGLE.AC [Trend], Win32.Bagle.AG [Computer Associates]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: Varies with .zip file extension
Size of attachment: Varies
Time stamp of attachment: n/a
Ports: 80/tcp and 80/udp
Shared drives: n/a
Target of infection: n/a
When W32.Beagle.AO@mm runs, it does the following:
Copies itself as %System%\WINdirect.exe.
Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds a value:
"win_upd.exe"="%System%\WINdirect.exe"
to the registry keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that it runs when you restart Windows.
Creates a file, %System%\_dll.exe.
Injects %System%\_dll.exe as a thread into a process with a window class name of "Shell_TrayWnd." If successful, this threat will continue to run within the infected process. All the actions described in the next steps will appear to be done by the infected process, and the Trojan will not show when viewing the process list in the Windows Task Manager.
Terminates the following processes:
ATUPDATER.EXE
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE
sys_xp.exe
sysxp.exe
winxp.exe
Attempts to download files from the following Web sites as %Windir%\~.exe, and then run it:
134.102.228.45
196.12.49.27
213.188.129.72
64.62.172.118
abi-2004.org
advm1.gm.fh-koeln.de
alexey.pioneers.com.ru
alfinternational.ru
aus-Zeit.com
binn.ru
burn2k.ipupdater.com
carabi.ru
catalog.zelnet.ru
cavalierland.5u.com
celine.artics.ru
change.east.ru
colleen.ai.net
controltechniques.ru
dev.tikls.net
diablo.homelinux.com
dodgetheatre.com
dozenten.f1.fhtw-berlin.de
emnesty.w.interia.pl
emnezz.e-mania.pl
euroviolence.com
evadia.ru
fairy.dataforce.net
financial.washingtonpost.com
free.bestialityhost.com
gutemine.wu-wien.ac.at
herzog.cs.uni-magdeburg.de
home.profootball.ru
host.businessweek.com
host.wallstreetcity.com
host23.ipowerweb.com
hsr.zhp.org.pl
infokom.pl
kafka.punkt.pl
kooltokyo.ru
kypexin.ru
lars-s.privat.t-online.de
lottery.h11.ru
matzlinger.com
megion.ru
mmag.ru
molinero-berlin.de
momentum.ru
niebo.net
nominal.kaliningrad.ru
omegat.ru
ourcj.com
packages.debian.or.jp
pb195.slupsk.sdi.tpnet.pl
photo.gornet.ru
pixel.co.il
pocono.ru
polobeer.de
porno-mania.net
protek.ru
przeglad-tygodnik.pl
przeglad-tygodnik.pl
quotes.barchart.com
r2626r.de
rausis.latnet.lv
relay.great.ru
republika.pl
sacred.ru
sbuilder.ru
sec.polbox.pl
shadkhan.ru
silesianet.pl
silesianet.pl
slavarik.ru
sovea.de
spbbook.ru
strony.wp.pl
szm.sk
tarkosale.net
tdi-router.opola.pl
terramail.pl
thorpedo.us
traveldeals.sidestep.com
ultimate-best-hgh.0my.net
vip.pnet.pl
werel1.web-gratis.net
www.5100.ru
www.PlayGround.ru
www.aannemers-nederland.nl
www.abcdesign.ru
www.airnav.com
www.aktor.ru
www.ankil.ru
www.antykoncepcja.net
www.aphel.de
www.artics.ru
www.astoria-stuttgart.de
www.avant.ru
www.baltmatours.com
www.baltnet.ru
www.biratnagarmun.org.np
www.biysk.ru
www.boglen.com
www.bridesinrussia.com
www.busheron.ru
www.ccbootcamp.com
www.chat4adult.com
www.chelny.ru
www.ciachoo.pl
www.dami.com.pl
www.ddosers.net
www.dicto.ru
www.dilver.ru
www.dsmedia.ru
www.dynex.ru
www.elemental.ru
www.elit-line.ru
www.epski.gr
www.forbes.com
www.free-time.ru
www.gamma.vyborg.ru
www.gantke-net.com
www.gin.ru
www.glass-master.ru
www.glavriba.ru
www.gradinter.ru
www.hack-gegen-rechts.com
www.hbz-nrw.de
www.hgr.de
www.hgrstrailer.com
www.ifa-guide.co.uk
www.iluminati.kicks-ass.net
www.infognt.com
www.intellect.lvc
www.interfoodtd.ru
www.interrybflot.ru
www.inversorlatino.com
www.jewishgen.org
www.k2kapital.com
www.kefaloniaresorts.com
www.lamatec.com
www.landofcash.net
www.laserbuild.ru
www.math.kobe-u.ac.jp
www.mcschnaeppchen.com
www.mdmedia.org
www.met.pl
www.metacenter.ru
www.milm.ru
www.myrtoscorp.com
www.nefkom.net
www.neostrada.pl
www.neprifan.ru
www.netradar.com
www.no-abi2003.de
www.oldtownradio.com
www.omnicom.ru
www.oshweb.com
www.pakwerk.ru
www.perfectgirls.net
www.perfectjewel.com
www.peterstar.ru
www.pgipearls.com
www.phg.pl
www.porsa.ru
www.porta.de
www.rafani.cz
www.rastt.ru
www.republika.pl
www.republika.pl
www.rollenspielzirkel.de
www.rubikon.pl
www.rumbgeo.ru
www.rweb.ru
www.scli.ru
www.sdsauto.ru
www.sensi.com
www.silesianet.pl
www.sjgreatdeals.com
www.sposob.ru
www.strefa.pl
www.tanzen-in-sh.de
www.taom-clan.de
www.tayles.com
www.teatr-estrada.ru
www.teleline.ru
www.thepositivesideofsports.com
www.timelessimages.com
www.tuhart.net
www.vconsole.net
www.vendex.ru
www.virtmemb.com
www.vivamedia.ru
www.vrack.net
www.wapf.com
www.webpark.pl
www.webronet.com
www.webzdarma.cz
www.yarcity.ru
www.youbuynow.com
www.zeiss.ru
www.zelnet.ru
www.zhp.gdynia.pl
wynnsjammer.proboards18.com
yaguark.h10.ru
Note: %Windir% is a variable. The Trojan locates the Windows installation folder and saves the downloaded files to that location. By default, this is C:\Windows or C:\Winnt.
When the file which is downloaded is executed it performs the following actions:
Creates seven mutexes with the following names, which prevent some variants of W32.Netsky@mm from running:
MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_
Creates the following files:
%System%\windll.exe.
%System%\windll.exeopen, which is a copy of the worm with randomly appended data.
%System%\windll.exeopenopen, which is a copy of the worm with randomly appended data.
%System%\re_file.exe
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds a value:
"erthgdr"="%System%\windll.exe"
to the registry key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Deletes any values that contain the following strings:
"9XHtProtect"
"Antivirus"
"EasyAV"
"FirewallSvr"
"HtProtect"
"ICQ Net"
"ICQNet"
"Jammer2nd"
"KasperskyAVEng"
"MsInfo"
"My AV"
"NetDy"
"Norton Antivirus AV"
"PandaAVEngine"
"SkynetsRevenge"
"Special Firewall Service"
"SysMonXP"
"Tiny AV"
"Zone Labs Client Ex"
"service"
from the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Attempts to create copies of itself in any folder that contains the characters "shar". The files will have the following file names:
Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral,
/censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> cool, awesome!!.exe
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe
Searches for the email addresses in files that have the following extensions:
.adb
.asp
.cfg
.cgi
.dbx
.dhtm
.eml
.htm
.jsp
.mbx
.mdx
.mht
.mmf
.msg
.nch
.ods
.oft
.php
.pl
.sht
.shtm
.stm
.tbb
.txt
.uin
.wab
.wsh
.xls
.xml
Uses its own SMTP engine to send email messages to any addresses that it found.
The email may have the following characteristics:
From: <spoofed>
Subject: <empty>
Body: New price
Attachment: (One of the following)
08_price.zip
new__price.zip
new_price.zip
newprice.zip
price.zip
price2.zip
price_08.zip
price_new.zip
Note: The zip file contains an executable with the same name as the zip, and a Price.html. This is the executable which is responsible for downloading the mailer component. There is a mechanism in the code to password protect the zip file, but this does not work.
The worm will not send itself to addresses containing the following strings:
@avp.
@foo
@iana
@messagelab
@microsoft
abuse
admin
anyone@
bsd
bugs@
cafee
certific
contract@
feste
free-av
f-secur
gold-certs@
google
help@
icrosoft
info@
kasp
linux
listserv
local
news
nobody@
noone@
noreply
ntivi
panda
pgp
postmaster@
rating@
root@
samples
sopho
spam
support
unix
update
winrar
winzip
Opens a backdoor on TCP and UDP port 80, which allows the infected computer to be used as an email relay.
Creates the following registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ru1n
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AO@mm.
Delete the value that was added to the registry.
To delete the value from the registry
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values:
"win_upd2.exe" = "%System%\WINdirect.exe"
"erthgdr" = "%System%\windll.exe"
Navigate to the key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion
In the left pane, delete the subkey Ru1n
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ao@mm.html"]Symantec Source[/url]
Discovered on: August 09, 2004
Last Updated on: August 09, 2004 03:27:33 PM
W32.Beagle.AO@mm is a mass mailing worm that uses its own SMTP engine to spread. The email attachment is a Mitglieder-like downloader that brings the worm from external sources.
The worm also has a backdoor functionality, opening UDP and TCP port 80.
Note: Virus definitions version 60809aj (extended version 8/9/2004 rev. 36) and greater are required to detect this threat. The respective LiveUpdate definitions which contain protection are version 60809ak (8/9/2004 rev. 37).
Also Known As: W32/Bagle.aq@MM [McAfee], WORM_BAGLE.AC [Trend], Win32.Bagle.AG [Computer Associates]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: Varies with .zip file extension
Size of attachment: Varies
Time stamp of attachment: n/a
Ports: 80/tcp and 80/udp
Shared drives: n/a
Target of infection: n/a
When W32.Beagle.AO@mm runs, it does the following:
Copies itself as %System%\WINdirect.exe.
Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds a value:
"win_upd.exe"="%System%\WINdirect.exe"
to the registry keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that it runs when you restart Windows.
Creates a file, %System%\_dll.exe.
Injects %System%\_dll.exe as a thread into a process with a window class name of "Shell_TrayWnd." If successful, this threat will continue to run within the infected process. All the actions described in the next steps will appear to be done by the infected process, and the Trojan will not show when viewing the process list in the Windows Task Manager.
Terminates the following processes:
ATUPDATER.EXE
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
FIREWALL.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE
sys_xp.exe
sysxp.exe
winxp.exe
Attempts to download files from the following Web sites as %Windir%\~.exe, and then run it:
134.102.228.45
196.12.49.27
213.188.129.72
64.62.172.118
abi-2004.org
advm1.gm.fh-koeln.de
alexey.pioneers.com.ru
alfinternational.ru
aus-Zeit.com
binn.ru
burn2k.ipupdater.com
carabi.ru
catalog.zelnet.ru
cavalierland.5u.com
celine.artics.ru
change.east.ru
colleen.ai.net
controltechniques.ru
dev.tikls.net
diablo.homelinux.com
dodgetheatre.com
dozenten.f1.fhtw-berlin.de
emnesty.w.interia.pl
emnezz.e-mania.pl
euroviolence.com
evadia.ru
fairy.dataforce.net
financial.washingtonpost.com
free.bestialityhost.com
gutemine.wu-wien.ac.at
herzog.cs.uni-magdeburg.de
home.profootball.ru
host.businessweek.com
host.wallstreetcity.com
host23.ipowerweb.com
hsr.zhp.org.pl
infokom.pl
kafka.punkt.pl
kooltokyo.ru
kypexin.ru
lars-s.privat.t-online.de
lottery.h11.ru
matzlinger.com
megion.ru
mmag.ru
molinero-berlin.de
momentum.ru
niebo.net
nominal.kaliningrad.ru
omegat.ru
ourcj.com
packages.debian.or.jp
pb195.slupsk.sdi.tpnet.pl
photo.gornet.ru
pixel.co.il
pocono.ru
polobeer.de
porno-mania.net
protek.ru
przeglad-tygodnik.pl
przeglad-tygodnik.pl
quotes.barchart.com
r2626r.de
rausis.latnet.lv
relay.great.ru
republika.pl
sacred.ru
sbuilder.ru
sec.polbox.pl
shadkhan.ru
silesianet.pl
silesianet.pl
slavarik.ru
sovea.de
spbbook.ru
strony.wp.pl
szm.sk
tarkosale.net
tdi-router.opola.pl
terramail.pl
thorpedo.us
traveldeals.sidestep.com
ultimate-best-hgh.0my.net
vip.pnet.pl
werel1.web-gratis.net
www.5100.ru
www.PlayGround.ru
www.aannemers-nederland.nl
www.abcdesign.ru
www.airnav.com
www.aktor.ru
www.ankil.ru
www.antykoncepcja.net
www.aphel.de
www.artics.ru
www.astoria-stuttgart.de
www.avant.ru
www.baltmatours.com
www.baltnet.ru
www.biratnagarmun.org.np
www.biysk.ru
www.boglen.com
www.bridesinrussia.com
www.busheron.ru
www.ccbootcamp.com
www.chat4adult.com
www.chelny.ru
www.ciachoo.pl
www.dami.com.pl
www.ddosers.net
www.dicto.ru
www.dilver.ru
www.dsmedia.ru
www.dynex.ru
www.elemental.ru
www.elit-line.ru
www.epski.gr
www.forbes.com
www.free-time.ru
www.gamma.vyborg.ru
www.gantke-net.com
www.gin.ru
www.glass-master.ru
www.glavriba.ru
www.gradinter.ru
www.hack-gegen-rechts.com
www.hbz-nrw.de
www.hgr.de
www.hgrstrailer.com
www.ifa-guide.co.uk
www.iluminati.kicks-ass.net
www.infognt.com
www.intellect.lvc
www.interfoodtd.ru
www.interrybflot.ru
www.inversorlatino.com
www.jewishgen.org
www.k2kapital.com
www.kefaloniaresorts.com
www.lamatec.com
www.landofcash.net
www.laserbuild.ru
www.math.kobe-u.ac.jp
www.mcschnaeppchen.com
www.mdmedia.org
www.met.pl
www.metacenter.ru
www.milm.ru
www.myrtoscorp.com
www.nefkom.net
www.neostrada.pl
www.neprifan.ru
www.netradar.com
www.no-abi2003.de
www.oldtownradio.com
www.omnicom.ru
www.oshweb.com
www.pakwerk.ru
www.perfectgirls.net
www.perfectjewel.com
www.peterstar.ru
www.pgipearls.com
www.phg.pl
www.porsa.ru
www.porta.de
www.rafani.cz
www.rastt.ru
www.republika.pl
www.republika.pl
www.rollenspielzirkel.de
www.rubikon.pl
www.rumbgeo.ru
www.rweb.ru
www.scli.ru
www.sdsauto.ru
www.sensi.com
www.silesianet.pl
www.sjgreatdeals.com
www.sposob.ru
www.strefa.pl
www.tanzen-in-sh.de
www.taom-clan.de
www.tayles.com
www.teatr-estrada.ru
www.teleline.ru
www.thepositivesideofsports.com
www.timelessimages.com
www.tuhart.net
www.vconsole.net
www.vendex.ru
www.virtmemb.com
www.vivamedia.ru
www.vrack.net
www.wapf.com
www.webpark.pl
www.webronet.com
www.webzdarma.cz
www.yarcity.ru
www.youbuynow.com
www.zeiss.ru
www.zelnet.ru
www.zhp.gdynia.pl
wynnsjammer.proboards18.com
yaguark.h10.ru
Note: %Windir% is a variable. The Trojan locates the Windows installation folder and saves the downloaded files to that location. By default, this is C:\Windows or C:\Winnt.
When the file which is downloaded is executed it performs the following actions:
Creates seven mutexes with the following names, which prevent some variants of W32.Netsky@mm from running:
MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_
Creates the following files:
%System%\windll.exe.
%System%\windll.exeopen, which is a copy of the worm with randomly appended data.
%System%\windll.exeopenopen, which is a copy of the worm with randomly appended data.
%System%\re_file.exe
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds a value:
"erthgdr"="%System%\windll.exe"
to the registry key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Deletes any values that contain the following strings:
"9XHtProtect"
"Antivirus"
"EasyAV"
"FirewallSvr"
"HtProtect"
"ICQ Net"
"ICQNet"
"Jammer2nd"
"KasperskyAVEng"
"MsInfo"
"My AV"
"NetDy"
"Norton Antivirus AV"
"PandaAVEngine"
"SkynetsRevenge"
"Special Firewall Service"
"SysMonXP"
"Tiny AV"
"Zone Labs Client Ex"
"service"
from the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Attempts to create copies of itself in any folder that contains the characters "shar". The files will have the following file names:
Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral,
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe
Searches for the email addresses in files that have the following extensions:
.adb
.asp
.cfg
.cgi
.dbx
.dhtm
.eml
.htm
.jsp
.mbx
.mdx
.mht
.mmf
.msg
.nch
.ods
.oft
.php
.pl
.sht
.shtm
.stm
.tbb
.txt
.uin
.wab
.wsh
.xls
.xml
Uses its own SMTP engine to send email messages to any addresses that it found.
The email may have the following characteristics:
From: <spoofed>
Subject: <empty>
Body: New price
Attachment: (One of the following)
08_price.zip
new__price.zip
new_price.zip
newprice.zip
price.zip
price2.zip
price_08.zip
price_new.zip
Note: The zip file contains an executable with the same name as the zip, and a Price.html. This is the executable which is responsible for downloading the mailer component. There is a mechanism in the code to password protect the zip file, but this does not work.
The worm will not send itself to addresses containing the following strings:
@avp.
@foo
@iana
@messagelab
@microsoft
abuse
admin
anyone@
bsd
bugs@
cafee
certific
contract@
feste
free-av
f-secur
gold-certs@
help@
icrosoft
info@
kasp
linux
listserv
local
news
nobody@
noone@
noreply
ntivi
panda
pgp
postmaster@
rating@
root@
samples
sopho
spam
support
unix
update
winrar
winzip
Opens a backdoor on TCP and UDP port 80, which allows the infected computer to be used as an email relay.
Creates the following registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ru1n
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AO@mm.
Delete the value that was added to the registry.
To delete the value from the registry
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values:
"win_upd2.exe" = "%System%\WINdirect.exe"
"erthgdr" = "%System%\windll.exe"
Navigate to the key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion
In the left pane, delete the subkey Ru1n
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ao@mm.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.StartPage.G
Discovered on: August 09, 2004
Last Updated on: August 09, 2004 04:55:10 PM
Trojan.StartPage.G is a Trojan horse that downloads and runs an executable and attempts to change the Internet Explorer home page.
Type: Trojan Horse
Infection Length: 19,500 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.StartPage.G is executed, it performs the following actions:
Downloads and executes an .exe file.
Creates the following copies of itself:
%Windir%\system\taskmgr.exe
%Windir%\N0TEPAD.EXE
%Windir%\system\N0TEPAD.EXE
%Windir%\system32\N0TEPAD.EXE
%Windir%\system\windll.dll (A text file.)
Adds the value:
"taskmgr"="%Windows%\system\taskmgr.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when Windows starts.
Modifies the value to:
"MainStart Page"="about:blank"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
Adds the value:
"(Default)"="N0TEPAD.EXE %1"
to the registry key:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
so that when an user opens a text file, the Trojan will start.
Adds the value :
"AskUser"="0"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms
Adds the value :
"UseFormSuggest"="no"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Opens a Web page at the domain, www.ye.ah.to.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.StartPage.G.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"taskmgr"="%Windows%\system\taskmgr.exe"
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms
In the right pane, delete the value:
"AskUser"="0"
Naviage to the key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
In the right pane, delete the value:
"UseFormSuggest"="no"
Navigate to the key:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
In the right page, modify the value:
Windows 95/98/Me:
"(Default)"="WINDOWS\NOTEPAD.EXE %1"
Windows NT/2000/XP:
"(Default)"="%SystemRoot%\system32\NOTEPAD.EXE %1"
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.g.html"]Symantec Source[/url]
Discovered on: August 09, 2004
Last Updated on: August 09, 2004 04:55:10 PM
Trojan.StartPage.G is a Trojan horse that downloads and runs an executable and attempts to change the Internet Explorer home page.
Type: Trojan Horse
Infection Length: 19,500 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.StartPage.G is executed, it performs the following actions:
Downloads and executes an .exe file.
Creates the following copies of itself:
%Windir%\system\taskmgr.exe
%Windir%\N0TEPAD.EXE
%Windir%\system\N0TEPAD.EXE
%Windir%\system32\N0TEPAD.EXE
%Windir%\system\windll.dll (A text file.)
Adds the value:
"taskmgr"="%Windows%\system\taskmgr.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when Windows starts.
Modifies the value to:
"MainStart Page"="about:blank"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
Adds the value:
"(Default)"="N0TEPAD.EXE %1"
to the registry key:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
so that when an user opens a text file, the Trojan will start.
Adds the value :
"AskUser"="0"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms
Adds the value :
"UseFormSuggest"="no"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Opens a Web page at the domain, www.ye.ah.to.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.StartPage.G.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"taskmgr"="%Windows%\system\taskmgr.exe"
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms
In the right pane, delete the value:
"AskUser"="0"
Naviage to the key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
In the right pane, delete the value:
"UseFormSuggest"="no"
Navigate to the key:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
In the right page, modify the value:
Windows 95/98/Me:
"(Default)"="WINDOWS\NOTEPAD.EXE %1"
Windows NT/2000/XP:
"(Default)"="%SystemRoot%\system32\NOTEPAD.EXE %1"
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.g.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.StartPage.F
Discovered on: August 08, 2004
Last Updated on: August 09, 2004 04:55:15 PM
Trojan.StartPage.F is a program that changes the home page of Internet Explorer and installs a Browser Helper Object.
Also Known As: TROJ_STRTPAGE.CQ [Trend Micro], Troj/CWS-C [Sophos], StartPage-CQ.gen [McAfee], TrojanDownloader.Win32.Small.lc [Kaspersky]
Variants: Trojan.StartPage
Type: Trojan Horse
Infection Length: 52,736 bytes, 54,784 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.StartPage.F is executed, it performs the following actions:
Changes the home page of Internet Explorer to "homepage.com".
Redirects all URLs through "ehttp.cc"
May display a dialog box:
Serious Security Vulnerability Has Been Found
If the user clicks on the button, the program attempts to open a Web page on the domain, www.security-look.cc.
May launch pop-up windows containing pornographic material.
Deletes the registry key:
HKEY_LOCAL_MACHINE\Software\Classes\PROTOCOLS\Handler\ms-its
Creates the file, %Windir%/dpe.dll. This is a Browser Helper Object.
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Adds the value:
"AddClass" = "<Installation_Path>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
Adds the value:
"Host" = ""
to the registry keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Adds the values:
"Default_Search_URL" = "http://%68%6F%6D%..."
"Search Bar" = "http:/ /%68%6F%6D%..."
"Search Page" = "http:/ /%68%6F%6D%..."
"Start Page" = "http:/ /%68%6F%6D%..."
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
Adds the value:
"(Default)" = "http:/ /%65%68%74%74%70%2E%63%63/?"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
Adds the value:
"www" = "http:/ /%65%68%74%74%70%2E%63%63/?"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes
Adds the value:
"{834261E1-DD97-4177-853B-C907E5D5BD6E}" = ""
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Adds the following registry keys:
HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek
HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek.1
HKEY_CLASSES_ROOT\CLSID\{834261E1-DD97-4177-853B-C907E5D5BD6E}
HKEY_CLASSES_ROOT\TypeLib\{BD0022A3-A43F-4F44-B64F-53EA7575F097}
HKEY_CLASSES_ROOT\Interface\{B1E68D42-02C4-465B-8368-5ED9B732E22D}
HKEY_CLASSES_ROOT\Interface\{0B6EF17E-18E5-4449-86EA-64C82D596EAE}
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Close all open Internet Explorer windows
Run a full system scan and delete all the files detected as Trojan.StartPage.F.
Delete the value that was added to the registry.
Reset the Internet Explorer home page.
Reset the Internet Explorer search page.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values:
"AddClass" = "<Installation_Path>"
"Host" = ""
Navigate to the key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Host" = ""
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
In the left pane, delete the value:
{834261E1-DD97-4177-853B-C907E5D5BD6E}
Delete the following keys:
HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek
HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek.1
HKEY_CLASSES_ROOT\CLSID\{834261E1-DD97-4177-853B-C907E5D5BD6E}
HKEY_CLASSES_ROOT\TypeLib\{BD0022A3-A43F-4F44-B64F-53EA7575F097}
HKEY_CLASSES_ROOT\Interface\{B1E68D42-02C4-465B-8368-5ED9B732E22D}
HKEY_CLASSES_ROOT\Interface\{0B6EF17E-18E5-4449-86EA-64C82D596EAE}
Exit the Registry Editor.
To reset the Internet Explorer home page
Start Microsoft Internet Explorer.
Connect to the Internet, and then go to the page that you want to set as your home page.
Click Tools > Internet Options.
In the Home page section of the General tab, click Use Current > OK.
For additional information, or if this procedure does not work, read the Microsoft® Knowledge Base article, "Home Page Setting Changes Unexpectedly, or You Cannot Change Your Home Page Setting, Article ID 320159."
7. To reset the Internet Explorer Search page
Follow the instructions for your version of Windows.
Windows 98/Me/2000
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.
Windows XP
Because Windows XP is set by default to use animated characters in the search, how you do this can vary. Read all the instructions before you start.
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
Do one of the following:
If the pane that opens looks similar to this picture:
[img]http://www.killanet.net/uploads/trojan.startpage.f1.gif[/img]
click the word Customize. Then skip to step h.
If the pane that opens has the words "Search Companion" at the top, and the center looks similar to this picture:
[img]http://www.killanet.net/uploads/trojan.startpage.f2.gif[/img]
click the Change preferences link as shown above. Proceed with step d.
Click the Change Internet search behavior link.
Under "Internet Search Behavior," click With Classic Internet Search.
Click OK. Then close Internet Explorer. (Close the program for the change to take effect.)
Start Internet Explorer. When the search pane opens, it should now look similar to this:
[img]http://www.killanet.net/uploads/trojan.startpage.f3.gif[/img]
Click the word Customize, and then proceed with the next step.
In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.
Do one of the following:
If you were using (or want to continue using) the "Classic Internet Search" panel, stop here (or proceed with the next section).
If you want to go back to the "Search Companion" search (it usually has an animated character at the button), proceed with step n.
Click the word Customize again.
In the "Customize Search Settings" window, click Use Search Companion > OK.
Close Internet Explorer. The next time you open it, it will again use the Search Companion.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.f.html"]Symantec Source[/url]
Discovered on: August 08, 2004
Last Updated on: August 09, 2004 04:55:15 PM
Trojan.StartPage.F is a program that changes the home page of Internet Explorer and installs a Browser Helper Object.
Also Known As: TROJ_STRTPAGE.CQ [Trend Micro], Troj/CWS-C [Sophos], StartPage-CQ.gen [McAfee], TrojanDownloader.Win32.Small.lc [Kaspersky]
Variants: Trojan.StartPage
Type: Trojan Horse
Infection Length: 52,736 bytes, 54,784 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.StartPage.F is executed, it performs the following actions:
Changes the home page of Internet Explorer to "homepage.com".
Redirects all URLs through "ehttp.cc"
May display a dialog box:
Serious Security Vulnerability Has Been Found
If the user clicks on the button, the program attempts to open a Web page on the domain, www.security-look.cc.
May launch pop-up windows containing pornographic material.
Deletes the registry key:
HKEY_LOCAL_MACHINE\Software\Classes\PROTOCOLS\Handler\ms-its
Creates the file, %Windir%/dpe.dll. This is a Browser Helper Object.
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Adds the value:
"AddClass" = "<Installation_Path>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
Adds the value:
"Host" = ""
to the registry keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Adds the values:
"Default_Search_URL" = "http://%68%6F%6D%..."
"Search Bar" = "http:/ /%68%6F%6D%..."
"Search Page" = "http:/ /%68%6F%6D%..."
"Start Page" = "http:/ /%68%6F%6D%..."
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
Adds the value:
"(Default)" = "http:/ /%65%68%74%74%70%2E%63%63/?"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
Adds the value:
"www" = "http:/ /%65%68%74%74%70%2E%63%63/?"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes
Adds the value:
"{834261E1-DD97-4177-853B-C907E5D5BD6E}" = ""
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Adds the following registry keys:
HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek
HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek.1
HKEY_CLASSES_ROOT\CLSID\{834261E1-DD97-4177-853B-C907E5D5BD6E}
HKEY_CLASSES_ROOT\TypeLib\{BD0022A3-A43F-4F44-B64F-53EA7575F097}
HKEY_CLASSES_ROOT\Interface\{B1E68D42-02C4-465B-8368-5ED9B732E22D}
HKEY_CLASSES_ROOT\Interface\{0B6EF17E-18E5-4449-86EA-64C82D596EAE}
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Close all open Internet Explorer windows
Run a full system scan and delete all the files detected as Trojan.StartPage.F.
Delete the value that was added to the registry.
Reset the Internet Explorer home page.
Reset the Internet Explorer search page.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the values:
"AddClass" = "<Installation_Path>"
"Host" = ""
Navigate to the key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Host" = ""
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
In the left pane, delete the value:
{834261E1-DD97-4177-853B-C907E5D5BD6E}
Delete the following keys:
HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek
HKEY_CLASSES_ROOT\AnalyzeIE.DOMPeek.1
HKEY_CLASSES_ROOT\CLSID\{834261E1-DD97-4177-853B-C907E5D5BD6E}
HKEY_CLASSES_ROOT\TypeLib\{BD0022A3-A43F-4F44-B64F-53EA7575F097}
HKEY_CLASSES_ROOT\Interface\{B1E68D42-02C4-465B-8368-5ED9B732E22D}
HKEY_CLASSES_ROOT\Interface\{0B6EF17E-18E5-4449-86EA-64C82D596EAE}
Exit the Registry Editor.
To reset the Internet Explorer home page
Start Microsoft Internet Explorer.
Connect to the Internet, and then go to the page that you want to set as your home page.
Click Tools > Internet Options.
In the Home page section of the General tab, click Use Current > OK.
For additional information, or if this procedure does not work, read the Microsoft® Knowledge Base article, "Home Page Setting Changes Unexpectedly, or You Cannot Change Your Home Page Setting, Article ID 320159."
7. To reset the Internet Explorer Search page
Follow the instructions for your version of Windows.
Windows 98/Me/2000
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.
Windows XP
Because Windows XP is set by default to use animated characters in the search, how you do this can vary. Read all the instructions before you start.
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
Do one of the following:
If the pane that opens looks similar to this picture:
[img]http://www.killanet.net/uploads/trojan.startpage.f1.gif[/img]
click the word Customize. Then skip to step h.
If the pane that opens has the words "Search Companion" at the top, and the center looks similar to this picture:
[img]http://www.killanet.net/uploads/trojan.startpage.f2.gif[/img]
click the Change preferences link as shown above. Proceed with step d.
Click the Change Internet search behavior link.
Under "Internet Search Behavior," click With Classic Internet Search.
Click OK. Then close Internet Explorer. (Close the program for the change to take effect.)
Start Internet Explorer. When the search pane opens, it should now look similar to this:
[img]http://www.killanet.net/uploads/trojan.startpage.f3.gif[/img]
Click the word Customize, and then proceed with the next step.
In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.
Do one of the following:
If you were using (or want to continue using) the "Classic Internet Search" panel, stop here (or proceed with the next section).
If you want to go back to the "Search Companion" search (it usually has an animated character at the button), proceed with step n.
Click the word Customize again.
In the "Customize Search Settings" window, click Use Search Companion > OK.
Close Internet Explorer. The next time you open it, it will again use the Search Companion.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.f.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Mydoom.P@mm
Discovered on: August 09, 2004
Last Updated on: August 10, 2004 02:34:00 PM
W32.Mydoom.P@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses that it finds on an infected computer. The email contains a spoofed From address. The subject and message body vary, and the attachment has a .bat, .cmd, .exe, .pif, .scr, or .zip extension.
This threat is packed using UPX.
Also Known As: WORM_MYDOOM.R [Trend Micro], W32/Mydoom.r@MM [McAfee], W32/MyDoom-R [Sophos]
Type: Worm
Infection Length: 17,408 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Uses its own SMTP engine to send itself to the email addresses found in the files with certain extensions.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: Varies
Name of attachment: Varies with .bat, .cmd, .exe, .pif, .scr, or .zip file extension.
Size of attachment: 17,408 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Mydoom.P@mm is executed, it does the following:
Copies itself as %System%\Taskmon.exe.
Notes:
Taskmon.exe is a legitimate file in the Windows 95/98/Me operating systems, but is in the %Windir% folder, not the %System% folder. (By default, this is C:\Windows or C:\Winnt.) Do not delete the legitimate file in the %Windir% folder.
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the file, %Temp%\Message, and then opens it with Notepad.
Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
Creates a mutex, "SwebSipcSmtxS1", which allows only one instance of the worm to run in memory.
Creates the following registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version
Downloads a file from a predefined Web page as Zsdssfds.exe, and then runs the file.
Retrieves the email addresses from the files that have the following extensions on drives C through Y:
.pl
.abdh
.tbbg
.dbxn
.aspd
.phpq
.shtl
.htmb
.txt
.wab
Retrieves the email addresses from the Windows Address Book files.
Uses its own SMTP engine to send iteslf to the email addresses that it finds.
The email has the following characteristics:
From:
The From address is spoofed.
Subject: The subject may be one of the following:
test
hi
hello
Mail Delieery System
Mail transaction Failed
Server Report
Status
Error
Message: The message may be one of the following:
test
Mail transaction failed. Partial message is available.
The message contains Unicode characters and has been sent as a binary attachment.
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
Attachment: The attachment name may be one of the following:
document
readme
doc
body
text
file
data
test
messge
body
with one of the following extensions:
.bat
.cmd
.exe
.pif
.scr
.zip
It avoids sending itself to the email addresses that contains any of the following:
mozilla
utgers.ed
tanford.e
pgp
acketst
secur
isc.o
isi.e
ripe.
arin.
sendmail
rfc-ed
ietf
iana
usenet
fido
linux
kernel
google
ibm.com
fsf.
gnu
mit.e
bsd
math
unix
berkeley
foo.
.mil
gov.
.gov
ruslis
nodomai
mydomai
example
inpris
borlan
sopho
panda
hotmail
msn.
icrosof
syma
avp
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Mydoom.P@mm.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to and delete thekeys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.p@mm.html"]Symantec Security[/url]
Discovered on: August 09, 2004
Last Updated on: August 10, 2004 02:34:00 PM
W32.Mydoom.P@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses that it finds on an infected computer. The email contains a spoofed From address. The subject and message body vary, and the attachment has a .bat, .cmd, .exe, .pif, .scr, or .zip extension.
This threat is packed using UPX.
Also Known As: WORM_MYDOOM.R [Trend Micro], W32/Mydoom.r@MM [McAfee], W32/MyDoom-R [Sophos]
Type: Worm
Infection Length: 17,408 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Uses its own SMTP engine to send itself to the email addresses found in the files with certain extensions.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: Varies
Name of attachment: Varies with .bat, .cmd, .exe, .pif, .scr, or .zip file extension.
Size of attachment: 17,408 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Mydoom.P@mm is executed, it does the following:
Copies itself as %System%\Taskmon.exe.
Notes:
Taskmon.exe is a legitimate file in the Windows 95/98/Me operating systems, but is in the %Windir% folder, not the %System% folder. (By default, this is C:\Windows or C:\Winnt.) Do not delete the legitimate file in the %Windir% folder.
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the file, %Temp%\Message, and then opens it with Notepad.
Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
Creates a mutex, "SwebSipcSmtxS1", which allows only one instance of the worm to run in memory.
Creates the following registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version
Downloads a file from a predefined Web page as Zsdssfds.exe, and then runs the file.
Retrieves the email addresses from the files that have the following extensions on drives C through Y:
.pl
.abdh
.tbbg
.dbxn
.aspd
.phpq
.shtl
.htmb
.txt
.wab
Retrieves the email addresses from the Windows Address Book files.
Uses its own SMTP engine to send iteslf to the email addresses that it finds.
The email has the following characteristics:
From:
The From address is spoofed.
Subject: The subject may be one of the following:
test
hi
hello
Mail Delieery System
Mail transaction Failed
Server Report
Status
Error
Message: The message may be one of the following:
test
Mail transaction failed. Partial message is available.
The message contains Unicode characters and has been sent as a binary attachment.
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
Attachment: The attachment name may be one of the following:
document
readme
doc
body
text
file
data
test
messge
body
with one of the following extensions:
.bat
.cmd
.exe
.pif
.scr
.zip
It avoids sending itself to the email addresses that contains any of the following:
mozilla
utgers.ed
tanford.e
pgp
acketst
secur
isc.o
isi.e
ripe.
arin.
sendmail
rfc-ed
ietf
iana
usenet
fido
linux
kernel
ibm.com
fsf.
gnu
mit.e
bsd
math
unix
berkeley
foo.
.mil
gov.
.gov
ruslis
nodomai
mydomai
example
inpris
borlan
sopho
panda
hotmail
msn.
icrosof
syma
avp
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Mydoom.P@mm.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to and delete thekeys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32\Version
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.p@mm.html"]Symantec Security[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Backdoor.Beasty.I
Discovered on: August 10, 2004
Last Updated on: August 11, 2004 11:07:05 AM
Backdoor.Beasty.I is a backdoor Trojan horse that allows an attacker complete access to an infected computer. The Trojan listens on TCP port 9999 and notifies the attacker through ICQ.
Type: Trojan Horse
Infection Length: 30,935 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, OS/2, UNIX
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Opens a backdoor, allowing unauthorized remote access.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP 9999
Shared drives: n/a
Target of infection: n/a
When Backdoor.Beasty.I runs, it performs the following actions:
Displays the following message:
[img]http://www.killanet.net/uploads/beastyI.gif[/img]
Copies the following files to the %System% folder:
mspuep.com
mslg.blf
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Copies the file, e-gold.exe, to the %Windir% folder:
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Copies itself as %Windir%\msagent\msdrce.com.
Note: Under some operating systems, such as Windows 2000, the file may be copied to the %System% folder instead.
May add the value:
"COM Service"="%Windir%\msagent\msdrce.com"
to the registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
Creates the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CE4021-DE03-E3CC-EA32-40BB12E6015D}
Uses ICQ to notify the author that the Trojan is running.
Opens TCP port 9999 and waits for a commands from the attacker.
The attacker may perform any of the following actions on the compromised system:
Upload, download, and delete files
Manipulate file attributes (Hidden, System, Read-only)
Launch applications
Modify the registry
Kill processes
Perform screen captures
Perform various nuisance actions such as opening and closing the CD-ROM drive
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Beasty.I.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the following key and delete it:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CE4021-DE03-E3CC-EA32-40BB12E6015D}
Navigate to the following keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
KEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
In the right pane, delete the value, if present:
"COM Service"="%Windir%\msagent\msdrce.com"
Exit the Registry Editor
[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.beasty.i.html"]Symantec Source[/url]
Discovered on: August 10, 2004
Last Updated on: August 11, 2004 11:07:05 AM
Backdoor.Beasty.I is a backdoor Trojan horse that allows an attacker complete access to an infected computer. The Trojan listens on TCP port 9999 and notifies the attacker through ICQ.
Type: Trojan Horse
Infection Length: 30,935 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, OS/2, UNIX
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Opens a backdoor, allowing unauthorized remote access.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP 9999
Shared drives: n/a
Target of infection: n/a
When Backdoor.Beasty.I runs, it performs the following actions:
Displays the following message:
[img]http://www.killanet.net/uploads/beastyI.gif[/img]
Copies the following files to the %System% folder:
mspuep.com
mslg.blf
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Copies the file, e-gold.exe, to the %Windir% folder:
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Copies itself as %Windir%\msagent\msdrce.com.
Note: Under some operating systems, such as Windows 2000, the file may be copied to the %System% folder instead.
May add the value:
"COM Service"="%Windir%\msagent\msdrce.com"
to the registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
Creates the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CE4021-DE03-E3CC-EA32-40BB12E6015D}
Uses ICQ to notify the author that the Trojan is running.
Opens TCP port 9999 and waits for a commands from the attacker.
The attacker may perform any of the following actions on the compromised system:
Upload, download, and delete files
Manipulate file attributes (Hidden, System, Read-only)
Launch applications
Modify the registry
Kill processes
Perform screen captures
Perform various nuisance actions such as opening and closing the CD-ROM drive
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Beasty.I.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the following key and delete it:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CE4021-DE03-E3CC-EA32-40BB12E6015D}
Navigate to the following keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
KEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
In the right pane, delete the value, if present:
"COM Service"="%Windir%\msagent\msdrce.com"
Exit the Registry Editor
[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.beasty.i.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.Boxed.E
Discovered on: August 11, 2004
Last Updated on: August 12, 2004 10:00:44 AM
Trojan.Boxed.E is a Trojan horse that performs a Denial of Service (DoS) attack on certain Web sites. DoS attacks are used to deny legitimate users access to a Web site.
Type: Trojan Horse
Infection Length: 27,206 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: Replaces the existing hosts file.
Degrades performance: The Trojan's network activity can degrade system performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates services associated with antivirus programs.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.Boxed.E is executed, it performs the following actions:
Deletes the following services that are associated with antivirus software or variants of Trojan.Boxed.
kavsvc
SAVScan
Symantec Core LC
navapsvc
wuauserv
nwclntc
nwclntd
nwclnte
nwclntf
Creates the following registry keys installing itself as a service:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nwclntg
This Trojan uses "nwclntg" as its service name and "Network Client" as its service display name.
Note: This service will automatically run at startup.
Copies itself as %Windir%\system\winlogon.exe.
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Performs DoS attacks on the following Web sites:
logout.xpseek.com
secmemb.xpseek.com
mb.maybugs.com
members.maybugs.com
login.maybugs.com
secure.maybugs.com
mb.hvr-systems.cc
members.hvr-systems.cc
login.hvr-systems.cc
secure.hvr-systems.cc
mb.xpseek.com
members.xpseek.com
login.xpseek.com
secure.xpseek.com
mb.maybirds.org
members.maybirds.org
login.maybirds.org
secure.maybirds.org
Replaces the existing %System%\drivers\etc\hosts file with one that contains the following text, so that any attempts to connect to these Web sites fail:
127.0.0.1 localhost
127.0.0.1 ids.kaspersky-labs.com
127.0.0.1 downloads2.kaspersky-labs.com
127.0.0.1 downloads1.kaspersky-labs.com
127.0.0.1 downloads3.kaspersky-labs.com
127.0.0.1 downloads4.kaspersky-labs.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 update.symantec.com
127.0.0.1 download.mcafee.com
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com
127.0.0.1 www.grisoft.com
Note: %System% is a variable. The Trojan locates the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Removal Instructions:
Disable System Restore (Windows Me/XP).
Restart the computer in Safe mode or VGA mode.
Delete the registry key (Windows NT/2000/XP).
To delete the key from the registry (Windows NT/2000/XP)
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Delete the key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nwclntg
Exit the Registry Editor.
Restore the Hosts file.
To restore the Hosts file
Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.
Follow the instructions for your operating system:
Windows 95/98/Me/NT/2000
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
In the "Named" or "Search for..." box, type:
hosts
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file, except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
Windows XP
Click Start > Search.
Click All files and folders.
In the "All or part of the file name" box, type:
hosts
Verify that "Look in" is set to "Local Hard Drives" or to (C:).
Click More advanced options.
Check Search system folders.
Check Search subfolders.
Click Search.
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Boxed.E.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.boxed.e.html"]Symantec Source[/url]
Discovered on: August 11, 2004
Last Updated on: August 12, 2004 10:00:44 AM
Trojan.Boxed.E is a Trojan horse that performs a Denial of Service (DoS) attack on certain Web sites. DoS attacks are used to deny legitimate users access to a Web site.
Type: Trojan Horse
Infection Length: 27,206 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: Replaces the existing hosts file.
Degrades performance: The Trojan's network activity can degrade system performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Terminates services associated with antivirus programs.
Distribution
Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When Trojan.Boxed.E is executed, it performs the following actions:
Deletes the following services that are associated with antivirus software or variants of Trojan.Boxed.
kavsvc
SAVScan
Symantec Core LC
navapsvc
wuauserv
nwclntc
nwclntd
nwclnte
nwclntf
Creates the following registry keys installing itself as a service:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nwclntg
This Trojan uses "nwclntg" as its service name and "Network Client" as its service display name.
Note: This service will automatically run at startup.
Copies itself as %Windir%\system\winlogon.exe.
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Performs DoS attacks on the following Web sites:
logout.xpseek.com
secmemb.xpseek.com
mb.maybugs.com
members.maybugs.com
login.maybugs.com
secure.maybugs.com
mb.hvr-systems.cc
members.hvr-systems.cc
login.hvr-systems.cc
secure.hvr-systems.cc
mb.xpseek.com
members.xpseek.com
login.xpseek.com
secure.xpseek.com
mb.maybirds.org
members.maybirds.org
login.maybirds.org
secure.maybirds.org
Replaces the existing %System%\drivers\etc\hosts file with one that contains the following text, so that any attempts to connect to these Web sites fail:
127.0.0.1 localhost
127.0.0.1 ids.kaspersky-labs.com
127.0.0.1 downloads2.kaspersky-labs.com
127.0.0.1 downloads1.kaspersky-labs.com
127.0.0.1 downloads3.kaspersky-labs.com
127.0.0.1 downloads4.kaspersky-labs.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 update.symantec.com
127.0.0.1 download.mcafee.com
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com
127.0.0.1 www.grisoft.com
Note: %System% is a variable. The Trojan locates the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Removal Instructions:
Disable System Restore (Windows Me/XP).
Restart the computer in Safe mode or VGA mode.
Delete the registry key (Windows NT/2000/XP).
To delete the key from the registry (Windows NT/2000/XP)
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Delete the key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nwclntg
Exit the Registry Editor.
Restore the Hosts file.
To restore the Hosts file
Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.
Follow the instructions for your operating system:
Windows 95/98/Me/NT/2000
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
In the "Named" or "Search for..." box, type:
hosts
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file, except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
Windows XP
Click Start > Search.
Click All files and folders.
In the "All or part of the file name" box, type:
hosts
Verify that "Look in" is set to "Local Hard Drives" or to (C:).
Click More advanced options.
Check Search system folders.
Check Search subfolders.
Click Search.
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Boxed.E.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.boxed.e.html"]Symantec Source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Mydoom.Q@mm
Discovered on: August 16, 2004
Last Updated on: August 16, 2004 11:49:46 AM
W32.Mydoom.Q@mm is a mass-mailing worm that downloads an executable file and uses its own SMTP engine to send itself to the email addresses that it finds on the infected computer.
The downloaded file is detected as Backdoor.Nemog.
The email has the following characteristics:
From: <spoofed>
Subject: Photos
Attachment: photos_arc.exe
Notes:
Rapid Release definitions sequence number 34589 or later detect this threat.
Virus definitions version number 60816c (extended version 08/16/2004 rev. 3) or later detect this threat.
Also Known As: W32/Mydoom.s@MM [McAfee], W32/MyDoom-S [Sophos], Win32.Mydoom.S [Computer Associates], WORM_RATOS.A [Trend Micro]
Type: Worm
Infection Length: 27,136 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom@mm.removal.tool.html"]Removal Tool[/url]
Damage:
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to the email addresses that it finds on the infected computer.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Downloads and executes a Backdoor.Trojan.
Distribution
Subject of email: Photos
Name of attachment: photos_arc.exe
Size of attachment: 27136 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
Technical Details:
When W32.MyDoom.Q@mm runs it performs the following actions:
Creates a file %Temp%\Message and opens it in Notepad. This file contains garbage data.
Copies itself as the files:
%System%\winpsd.exe
%Windows%\rasor38a.dll
Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP)or C:\Winnt (Windows NT/2000).
Creates a mutex named "43jfds93872", so that only one copy of the worm will run on the infected computer.
Downloads a file from one of the following domains:
www.richcolour.com
zenandjuice.com
Note: The downloaded file is detected as Backdoor.Nemog and is saved as winvpn32.exe, and then executed.
Checks system time. If the time is after 21:11:11 on August 20th, 2004, the worm will exit.
Adds the value:
"winpsd"="%System%winpsd.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Adds the value:
"InstaledFlashhMx"="1"
to the registry key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer
as an infection marker, indicating that it has successfully downloaded and executed Backdoor.Nemog.
Creates the following key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32
The worm retrieves email addresses from files that have the following extensions.
.htm
.sht
.php
.asp
.dbx
.tbb
.adb
.wab
.pl
Retrieves email addresses from the Outlook address book.
The worm uses its own SMTP engine to send itself to the email addresses that it finds.
The email has the following characteristics:
From:
The From address is spoofed. It may use an email address of a user on the infected computer, or start with one of the following names:
john
alex
michael
james
mike
kevin
david
george
sam
andrew
jose
leo
maria
jim
brian
serg
mary
ray
tom
peter
robert
bob
jane
joe
dan
dave
matt
steve
smith
stan
bill
bob
jack
fred
ted
adam
brent
alice
anna
brenda
claudia
debby
helen
jerry
jimmy
julie
linda
sandra
the domain will be one of the following:
t-online.de
mail.com
yahoo.com
hotmail.com
The domain of the email address read from:
HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager
Subject: Photos
Message: LOL!
/bigwink.gif\' class=\'bbc_emoticon\' alt=\';)\' />)))
Attachment: photos_arc.exe
The worm will not send itself to email addresses that contain the following strings:
avpsyma
icrosof
msn.
hotmail
panda
sopho
borlan
inpris
example
mydomai
nodomai
ruslis
.gov
gov.
.mil
foo.
berkeley
unix
math
bsd
mit.e
gnu
fsf.
ibm.com
google
kernel
linux
fido
usenet
iana
ietf
rfc-ed
sendmail
arin.
ripe.
isi.e
isc.o
secur
acketst
pgp
tanford.e
utgers.ed
mozilla
be_loyal:
root
info
samples
postmaster
webmaster
noone
nobody
nothing
anyone
someone
your
you
bugs
rating
site
contact
soft
somebody
privacy
service
help
not
submit
feste
gold-certs
the.bat
page
admin
icrosoft
support
ntivi
unix
bsd
linux
listserv
certific
google
accoun
abuse
upport
www
spm
spam
www
secur
abuse
Symantec Gateway Security 2.0 - 5400 Series and Symantec Gateway Security 1.0 – 5300 Series
Antivirus component: An update for the Symantec Gateway Security AntiVirus engine to protect against the W32.MyDoom.Q@mm worm is now available. Symantec Gateway Security 5000 Series users are advised to run LiveUpdate.
IDS/IPS component: An update for the Symantec Gateway Security 5000 Series IDS/IPS engine is not expected.
Full application inspection firewall component: By default, when an SMTP rule is configured through the Policy Wizard, the SMTPd proxy on the security gateway will block infected systems from directly sending email to the Internet.
Symantec Enterprise Firewall 8.0
By default, when an SMTP rule is configured through the Policy Wizard, the SMTPd proxy on the security gateway will block infected systems from directly sending email to the Internet.
For Windows based firewalls, unique initial and ongoing system hardening protects the firewall operating system itself, which includes disabling the dx32hhec service created by the worm.
Symantec Enterprise Firewall 7.0.x and Symantec VelociRaptor 1.5
By default, when an SMTP rule is configured through the Policy Wizard, the SMTPd proxy on the security gateway will block infected systems from directly sending email to the Internet.
Symantec Clientless VPN Gateway 4400 Series
Symantec Clientless VPN Gateway v5.0 is not affected by this threat. To reduce risk of further propagation you should also include a rule that only allows mail access from authenticated remote users to your internal mail server.
Symantec Gateway Security 300 Series
Symantec Gateway Security 300 series is not affected by this threat. To reduce risk of further propagation you should also include a rule that only allows mail access from authenticated remote users to your internal mail server.
Symantec Firewall/VPN 100/200 Series
Symantec Gateway Security 100/200 series is not affected by this threat. To reduce risk of further propagation you should also include a rule that only allows mail access from authenticated remote users to your internal mail server.
Removal Instructions:
Removal using the Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of W32.Mydoom.Q@mm. This is the preferred method in most cases.
Manual Removal
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.MydoomQ@mm.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"winpsd"="%System%winpsd.exe"
Navigate to the key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer
In the right pane, delete the value:
"InstaledFlashhMx"="1"
Delete the following key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.q@mm.html"]source[/url]
Discovered on: August 16, 2004
Last Updated on: August 16, 2004 11:49:46 AM
W32.Mydoom.Q@mm is a mass-mailing worm that downloads an executable file and uses its own SMTP engine to send itself to the email addresses that it finds on the infected computer.
The downloaded file is detected as Backdoor.Nemog.
The email has the following characteristics:
From: <spoofed>
Subject: Photos
Attachment: photos_arc.exe
Notes:
Rapid Release definitions sequence number 34589 or later detect this threat.
Virus definitions version number 60816c (extended version 08/16/2004 rev. 3) or later detect this threat.
Also Known As: W32/Mydoom.s@MM [McAfee], W32/MyDoom-S [Sophos], Win32.Mydoom.S [Computer Associates], WORM_RATOS.A [Trend Micro]
Type: Worm
Infection Length: 27,136 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom@mm.removal.tool.html"]Removal Tool[/url]
Damage:
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to the email addresses that it finds on the infected computer.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Downloads and executes a Backdoor.Trojan.
Distribution
Subject of email: Photos
Name of attachment: photos_arc.exe
Size of attachment: 27136 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a
Technical Details:
When W32.MyDoom.Q@mm runs it performs the following actions:
Creates a file %Temp%\Message and opens it in Notepad. This file contains garbage data.
Copies itself as the files:
%System%\winpsd.exe
%Windows%\rasor38a.dll
Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP)or C:\Winnt (Windows NT/2000).
Creates a mutex named "43jfds93872", so that only one copy of the worm will run on the infected computer.
Downloads a file from one of the following domains:
www.richcolour.com
zenandjuice.com
Note: The downloaded file is detected as Backdoor.Nemog and is saved as winvpn32.exe, and then executed.
Checks system time. If the time is after 21:11:11 on August 20th, 2004, the worm will exit.
Adds the value:
"winpsd"="%System%winpsd.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Adds the value:
"InstaledFlashhMx"="1"
to the registry key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer
as an infection marker, indicating that it has successfully downloaded and executed Backdoor.Nemog.
Creates the following key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32
The worm retrieves email addresses from files that have the following extensions.
.htm
.sht
.php
.asp
.dbx
.tbb
.adb
.wab
.pl
Retrieves email addresses from the Outlook address book.
The worm uses its own SMTP engine to send itself to the email addresses that it finds.
The email has the following characteristics:
From:
The From address is spoofed. It may use an email address of a user on the infected computer, or start with one of the following names:
john
alex
michael
james
mike
kevin
david
george
sam
andrew
jose
leo
maria
jim
brian
serg
mary
ray
tom
peter
robert
bob
jane
joe
dan
dave
matt
steve
smith
stan
bill
bob
jack
fred
ted
adam
brent
alice
anna
brenda
claudia
debby
helen
jerry
jimmy
julie
linda
sandra
the domain will be one of the following:
t-online.de
mail.com
yahoo.com
hotmail.com
The domain of the email address read from:
HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager
Subject: Photos
Message: LOL!
Attachment: photos_arc.exe
The worm will not send itself to email addresses that contain the following strings:
avpsyma
icrosof
msn.
hotmail
panda
sopho
borlan
inpris
example
mydomai
nodomai
ruslis
.gov
gov.
.mil
foo.
berkeley
unix
math
bsd
mit.e
gnu
fsf.
ibm.com
kernel
linux
fido
usenet
iana
ietf
rfc-ed
sendmail
arin.
ripe.
isi.e
isc.o
secur
acketst
pgp
tanford.e
utgers.ed
mozilla
be_loyal:
root
info
samples
postmaster
webmaster
noone
nobody
nothing
anyone
someone
your
you
bugs
rating
site
contact
soft
somebody
privacy
service
help
not
submit
feste
gold-certs
the.bat
page
admin
icrosoft
support
ntivi
unix
bsd
linux
listserv
certific
accoun
abuse
upport
www
spm
spam
www
secur
abuse
Symantec Gateway Security 2.0 - 5400 Series and Symantec Gateway Security 1.0 – 5300 Series
Antivirus component: An update for the Symantec Gateway Security AntiVirus engine to protect against the W32.MyDoom.Q@mm worm is now available. Symantec Gateway Security 5000 Series users are advised to run LiveUpdate.
IDS/IPS component: An update for the Symantec Gateway Security 5000 Series IDS/IPS engine is not expected.
Full application inspection firewall component: By default, when an SMTP rule is configured through the Policy Wizard, the SMTPd proxy on the security gateway will block infected systems from directly sending email to the Internet.
Symantec Enterprise Firewall 8.0
By default, when an SMTP rule is configured through the Policy Wizard, the SMTPd proxy on the security gateway will block infected systems from directly sending email to the Internet.
For Windows based firewalls, unique initial and ongoing system hardening protects the firewall operating system itself, which includes disabling the dx32hhec service created by the worm.
Symantec Enterprise Firewall 7.0.x and Symantec VelociRaptor 1.5
By default, when an SMTP rule is configured through the Policy Wizard, the SMTPd proxy on the security gateway will block infected systems from directly sending email to the Internet.
Symantec Clientless VPN Gateway 4400 Series
Symantec Clientless VPN Gateway v5.0 is not affected by this threat. To reduce risk of further propagation you should also include a rule that only allows mail access from authenticated remote users to your internal mail server.
Symantec Gateway Security 300 Series
Symantec Gateway Security 300 series is not affected by this threat. To reduce risk of further propagation you should also include a rule that only allows mail access from authenticated remote users to your internal mail server.
Symantec Firewall/VPN 100/200 Series
Symantec Gateway Security 100/200 series is not affected by this threat. To reduce risk of further propagation you should also include a rule that only allows mail access from authenticated remote users to your internal mail server.
Removal Instructions:
Removal using the Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of W32.Mydoom.Q@mm. This is the preferred method in most cases.
Manual Removal
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.MydoomQ@mm.
Reverse the changes made to the registry.
To reverse the changes made to the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"winpsd"="%System%winpsd.exe"
Navigate to the key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer
In the right pane, delete the value:
"InstaledFlashhMx"="1"
Delete the following key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\ComDlg32
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.q@mm.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Backdoor.Nemog
Discovered on: August 16, 2004
Last Updated on: August 16, 2004 04:55:49 PM
Backdoor.Nemog is a Backdoor Trojan horse that allows an infected computer to be used as an email relay and HTTP proxy.
This backdoor is dropped by [url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.q@mm.html"]W32.Mydoom.Q@mm[/url].
Type: Trojan Horse
Infection Length: 139,776, 4,096
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When Backdoor.Nemog is executed, it performs the following actions:
Creates the following files:
%System%\dx32hhlp.exe
%System%\dx32hhec.sys
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following service so that it executes every time Windows starts:
dx32hhec
Hides its service and files by hooking the following APIs:
ZwQuerySystemInformation
ZwQueryDirectoryFile
and returning empty results when searching for the following string:
dx32hh
Adds the values:
"mutexadmin"="1"
"mutexname"="<random letters>"
"vers"="0x0001003d"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer
which the backdoor uses as an infection marker.
Gets the location of the Startup folder by querying the value of:
"Common Startup"
in the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
and then copies itself to that location as dx32hhlp.exe.
Attempts to contact eMule servers at the following IP addresses and port numbers:
62.241.53.2:4242
211.233.41.235:4661
81.23.250.167:4242
193.19.227.24:4661
66.98.192.99:3306
207.44.222.47:4661
213.158.119.104:4661
207.44.206.27:4661
62.241.53.4:4242
216.127.94.107:4661
67.15.18.45:3306
62.241.53.15:4242
64.246.54.12:3306
62.241.53.16:4242
211.214.161.107:4661
67.15.18.57:3306
66.98.144.100:4242
69.50.187.210:4661
66.111.43.80:4242
212.199.125.36:8080
66.90.68.2:6565
62.241.53.17:4242
69.50.228.50:4646
81.23.250.169:4242
69.57.132.8:4661
64.246.18.98:4661
218.78.211.62:4661
207.44.142.33:4242
64.246.16.11:4661
205.209.176.220:4661
80.64.179.46:4242
65.75.161.70:4661
Allows remote users to relay email through a randomly chosen TCP port.
Runs as an HTTP proxy on another randomly chosen TCP port.
Additional functionality allows the backdoor to:
Uninstall itself
Update itself
Download a file
Appends the following entries to the %System%\DRIVERS\ETC\HOSTS file , preventing access to certain security related Web sites:
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com
Removal Instructions:
Removal using the Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of W32.Mydoom.M@mm. This is the preferred method in most cases.
Manual Removal
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Nemog.
Delete the value from the registry key.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer
In the right pane, delete the value:
"mutexadmin"="1"
"mutexname"="<random letters>"
"vers"="0x0001003d"
Exit the Registry Editor.
Delete the lines added to the Hosts file.
To delete the added lines from the Windows Hosts file
Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.
Follow the instructions for your operating system:
Windows 95/98/Me/NT/2000
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
In the "Named" or "Search for..." box, type:
hosts
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file, except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
Windows XP
Click Start > Search.
Click All files and folders.
In the "All or part of the file name" box, type:
hosts
Verify that "Look in" is set to "Local Hard Drives" or to (C:).
Click More advanced options.
Check Search system folders.
Check Search subfolders.
Click Search.
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the Always use this program to open this program check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.nemog.html"]source[/url]
Discovered on: August 16, 2004
Last Updated on: August 16, 2004 04:55:49 PM
Backdoor.Nemog is a Backdoor Trojan horse that allows an infected computer to be used as an email relay and HTTP proxy.
This backdoor is dropped by [url="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.q@mm.html"]W32.Mydoom.Q@mm[/url].
Type: Trojan Horse
Infection Length: 139,776, 4,096
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When Backdoor.Nemog is executed, it performs the following actions:
Creates the following files:
%System%\dx32hhlp.exe
%System%\dx32hhec.sys
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following service so that it executes every time Windows starts:
dx32hhec
Hides its service and files by hooking the following APIs:
ZwQuerySystemInformation
ZwQueryDirectoryFile
and returning empty results when searching for the following string:
dx32hh
Adds the values:
"mutexadmin"="1"
"mutexname"="<random letters>"
"vers"="0x0001003d"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer
which the backdoor uses as an infection marker.
Gets the location of the Startup folder by querying the value of:
"Common Startup"
in the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
and then copies itself to that location as dx32hhlp.exe.
Attempts to contact eMule servers at the following IP addresses and port numbers:
62.241.53.2:4242
211.233.41.235:4661
81.23.250.167:4242
193.19.227.24:4661
66.98.192.99:3306
207.44.222.47:4661
213.158.119.104:4661
207.44.206.27:4661
62.241.53.4:4242
216.127.94.107:4661
67.15.18.45:3306
62.241.53.15:4242
64.246.54.12:3306
62.241.53.16:4242
211.214.161.107:4661
67.15.18.57:3306
66.98.144.100:4242
69.50.187.210:4661
66.111.43.80:4242
212.199.125.36:8080
66.90.68.2:6565
62.241.53.17:4242
69.50.228.50:4646
81.23.250.169:4242
69.57.132.8:4661
64.246.18.98:4661
218.78.211.62:4661
207.44.142.33:4242
64.246.16.11:4661
205.209.176.220:4661
80.64.179.46:4242
65.75.161.70:4661
Allows remote users to relay email through a randomly chosen TCP port.
Runs as an HTTP proxy on another randomly chosen TCP port.
Additional functionality allows the backdoor to:
Uninstall itself
Update itself
Download a file
Appends the following entries to the %System%\DRIVERS\ETC\HOSTS file , preventing access to certain security related Web sites:
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com
Removal Instructions:
Removal using the Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of W32.Mydoom.M@mm. This is the preferred method in most cases.
Manual Removal
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Backdoor.Nemog.
Delete the value from the registry key.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer
In the right pane, delete the value:
"mutexadmin"="1"
"mutexname"="<random letters>"
"vers"="0x0001003d"
Exit the Registry Editor.
Delete the lines added to the Hosts file.
To delete the added lines from the Windows Hosts file
Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.
Follow the instructions for your operating system:
Windows 95/98/Me/NT/2000
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
In the "Named" or "Search for..." box, type:
hosts
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file, except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
Windows XP
Click Start > Search.
Click All files and folders.
In the "All or part of the file name" box, type:
hosts
Verify that "Look in" is set to "Local Hard Drives" or to (C:).
Click More advanced options.
Check Search system folders.
Check Search subfolders.
Click Search.
Click Find Now or Search Now.
For each Hosts file that you find, right-click the file, and then click Open With.
Deselect the Always use this program to open this program check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries in the Hosts file except for the following line:
127.0.0.1 localhost
Close Notepad and save your changes when prompted.
[url="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.nemog.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Downloader.Harnig
Discovered on: August 13, 2004
Last Updated on: August 16, 2004 09:55:35 AM
Downloader.Harnig is a program that downloads Trojans, adware, and dialers, and terminates services associated with antivirus software.
Type: Trojan Horse
Infection Length: 5,120 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: Linux, Macintosh, Microsoft IIS, OS/2, UNIX, Windows 3.x
Technical Information:
When Downloader.Harnig runs, it performs the following actions:
Creates the following files:
%System%\secure32.txt
%Windir%\system.exe
%Windir%\system32\system32.dll
%Windir%\desktop.exe
%Windir%\toolbar.exe
%Windir%\mstasks1.exe (Detected as Backdoor.Jeem)
%Windir%\mstasks2.exe
%Windir%\test
%Windir%\seksdialer.exe
%Windir%\system32\wintime.exe
%Windir%\system32\dkdial.exe
%Windir%\system32\dial32.exe
%Windir%\Web\i_xx.gif(Where xx is a number between 01 and 20.)
%Windir%\Web\desktop.html
Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).
Adds the value:
"Wintime"="Wintime.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the downloader executes every time Windows starts.
Adds the value:
"ShellServiceObjectDelayLoadSystem"="{0A323FA1-38DE-44EC-B2FA-4002183C143E}"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Adds the value:
"(Default)"="%system%\system32.dll"
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{0A323FA1-38DE-44EC-B2FA-4002183C143E}\InProcServer32
Adds the values:
"MinLevel"="Code Download"
"Safety Warning Level"="SucceedSilent"
"Security_RunActiveXControls"="0x01000000"
"Security_RunScripts"="0x01000000"
"Trust Warning Level"="No Security"
to the registry keys:
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Adds an entry "New Dialup Connection" to the RAS phonebook and makes the entry the default. It then attempts to use the modem to dial a predetermined, high-cost phone number and establish a RAS connection.
Terminates the following processes:
MCUPDATE.EXE
CFIAUDIT.EXE
AVXQUAR.EXE
AUTOUPDATE.EXE
AUTOTRACE.EXE
AUTODOWN.EXE
AUPDATE.EXE
NUPGRADE.EXE
UPDATE.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
DRWEBUPW.EXE
LUALL.EXE
AVPUPD.EXE
AVWUPD32.EXE
ATUPDATER.EXE
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode
Run a full system scan and delete all the files detected as Downloader.Harnig.
Delete the values that were added to the registry.
Deleting the value from the registry
CAUTION: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, , "How to make a backup of the Windows registry," for instructions.
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the following key and delete it:
HKEY_CLASSES_ROOT\CLSID\{0A323FA1-38DE-44EC-B2FA-4002183C143E}
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Wintime"="Wintime.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
In the right pane, delete the value:
"ShellServiceObjectDelayLoadSystem"="{0A323FA1-38DE-44EC-B2FA-4002183C143E}"
Exit the Registry Editor.
Restore the security level of Microsoft Internet Explorer
Restoring the security level of Microsoft Internet Explorer
To restore the security level, complete the following steps:
Start Internet Explorer.
Click Tools, and then click Internet Options.
Select the Security tab.
Change the security settings to the level you desire.
[url="http://securityresponse.symantec.com/avcenter/venc/data/downloader.harnig.html"]source[/url]
Discovered on: August 13, 2004
Last Updated on: August 16, 2004 09:55:35 AM
Downloader.Harnig is a program that downloads Trojans, adware, and dialers, and terminates services associated with antivirus software.
Type: Trojan Horse
Infection Length: 5,120 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: Linux, Macintosh, Microsoft IIS, OS/2, UNIX, Windows 3.x
Technical Information:
When Downloader.Harnig runs, it performs the following actions:
Creates the following files:
%System%\secure32.txt
%Windir%\system.exe
%Windir%\system32\system32.dll
%Windir%\desktop.exe
%Windir%\toolbar.exe
%Windir%\mstasks1.exe (Detected as Backdoor.Jeem)
%Windir%\mstasks2.exe
%Windir%\test
%Windir%\seksdialer.exe
%Windir%\system32\wintime.exe
%Windir%\system32\dkdial.exe
%Windir%\system32\dial32.exe
%Windir%\Web\i_xx.gif(Where xx is a number between 01 and 20.)
%Windir%\Web\desktop.html
Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).
Adds the value:
"Wintime"="Wintime.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the downloader executes every time Windows starts.
Adds the value:
"ShellServiceObjectDelayLoadSystem"="{0A323FA1-38DE-44EC-B2FA-4002183C143E}"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Adds the value:
"(Default)"="%system%\system32.dll"
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{0A323FA1-38DE-44EC-B2FA-4002183C143E}\InProcServer32
Adds the values:
"MinLevel"="Code Download"
"Safety Warning Level"="SucceedSilent"
"Security_RunActiveXControls"="0x01000000"
"Security_RunScripts"="0x01000000"
"Trust Warning Level"="No Security"
to the registry keys:
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Adds an entry "New Dialup Connection" to the RAS phonebook and makes the entry the default. It then attempts to use the modem to dial a predetermined, high-cost phone number and establish a RAS connection.
Terminates the following processes:
MCUPDATE.EXE
CFIAUDIT.EXE
AVXQUAR.EXE
AUTOUPDATE.EXE
AUTOTRACE.EXE
AUTODOWN.EXE
AUPDATE.EXE
NUPGRADE.EXE
UPDATE.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
DRWEBUPW.EXE
LUALL.EXE
AVPUPD.EXE
AVWUPD32.EXE
ATUPDATER.EXE
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode
Run a full system scan and delete all the files detected as Downloader.Harnig.
Delete the values that were added to the registry.
Deleting the value from the registry
CAUTION: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, , "How to make a backup of the Windows registry," for instructions.
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the following key and delete it:
HKEY_CLASSES_ROOT\CLSID\{0A323FA1-38DE-44EC-B2FA-4002183C143E}
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Wintime"="Wintime.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
In the right pane, delete the value:
"ShellServiceObjectDelayLoadSystem"="{0A323FA1-38DE-44EC-B2FA-4002183C143E}"
Exit the Registry Editor.
Restore the security level of Microsoft Internet Explorer
Restoring the security level of Microsoft Internet Explorer
To restore the security level, complete the following steps:
Start Internet Explorer.
Click Tools, and then click Internet Options.
Select the Security tab.
Change the security settings to the level you desire.
[url="http://securityresponse.symantec.com/avcenter/venc/data/downloader.harnig.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.Cargao.B
Discovered on: August 13, 2004
Last Updated on: August 13, 2004 03:51:37 PM
Trojan.Cargao.B is a Trojan horse program that sends an email to all the addresses that it finds in the Microsoft Outlook address book. It also downloads and runs executable files from the Internet.
Type: Trojan Horse
Infection Length: 126,464 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Information:
A binder program may attach Trojan.Cargao.B to a legitimate file. The binder program allows the malicious file to be executed when the legitimate file is run, without the user's knowledge. The binder program drops both files into the %Temp% folder and then executes them.
Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
When Trojan.Cargao.B is executed, it performs the following actions:
Creates the following file:
C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS\appconn32.exe
Note: This file is usually 126,464 bytes in size, but due to a bug in the code, the file may expand to fill the hard disk.
Attempts to download the following files from the domain, virtualcards.serveftp.com, and then save them to the C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS\ folder:
lsacvn.exe
lsacvn.dll
appconn32.exe
cartao4596724064AC298.exe
Sends an email to the contacts that it finds in the Outlook address book.
Subject: (May contain the following text)
[sender name] te enviou um cart?o
where [sender name] is the sender's name in the email address. For example, "name" in name@example.com.
Body:
Contains HTML and includes links to many predetermined Web sites.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Cargao.B.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.cargao.b.html"]source[/url]
Discovered on: August 13, 2004
Last Updated on: August 13, 2004 03:51:37 PM
Trojan.Cargao.B is a Trojan horse program that sends an email to all the addresses that it finds in the Microsoft Outlook address book. It also downloads and runs executable files from the Internet.
Type: Trojan Horse
Infection Length: 126,464 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Information:
A binder program may attach Trojan.Cargao.B to a legitimate file. The binder program allows the malicious file to be executed when the legitimate file is run, without the user's knowledge. The binder program drops both files into the %Temp% folder and then executes them.
Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
When Trojan.Cargao.B is executed, it performs the following actions:
Creates the following file:
C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS\appconn32.exe
Note: This file is usually 126,464 bytes in size, but due to a bug in the code, the file may expand to fill the hard disk.
Attempts to download the following files from the domain, virtualcards.serveftp.com, and then save them to the C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS\ folder:
lsacvn.exe
lsacvn.dll
appconn32.exe
cartao4596724064AC298.exe
Sends an email to the contacts that it finds in the Outlook address book.
Subject: (May contain the following text)
[sender name] te enviou um cart?o
where [sender name] is the sender's name in the email address. For example, "name" in name@example.com.
Body:
Contains HTML and includes links to many predetermined Web sites.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Cargao.B.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.cargao.b.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
VBS.Mywav@mm
Discovered on: August 12, 2004
Last Updated on: August 16, 2004 04:05:22 PM
VBS.Mywav@mm is a mass-mailing worm that also infects .html files.
Type: Worm
Infection Length: 20,695 bytes, 20,691 bytes
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Technical Information:
When VBS.Mywav@mm is executed, it performs the following actions:
Displays a message containing the following text:
This page contained a graphic which require the ActiveX controls, Please reload or refresh the page and accept the ActiveX
Creates the following copies of itself:
c:\Greeting.htm (With file attributes set to Hidden.)
%Windir%\Myvwa.htm
%System%\AyaCute.htm
%Temp%\Normal.html
Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP)or C:\Winnt (Windows NT/2000).
%Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
Searches on all removable, fixed, and network drives for email addresses in files with the following extensions:
htm
.html
.hta
.hte
.htx
Sends an HTML-formatted email, containing VBScript, to the addresses found and all contacts in the Microsoft Outlook address book.
This file will create %System%\Lasiaf.html, if ActiveX is enabled on the computer, which contains a copy of the worm.
The email has the following characteristics:
Subject: (One of the following)
Here is your Greeting card from me
<--Lasiaf-Fait Accompli-Myvwa-->
Greeting Card From Me.. ;p
Important! Please reply my Greeting card.
Friendster.. i'm a new comer..
FWD:Would you be my wife?
RE:Your password in this Greeting card
Hye look at this News...
Product Key!
FWD:Selamat menyambut hari kemerdekaan
Re:Good Luck in your exam
Somebody realy need you...
What ? new virus
Tekanan Emosi... Adik beradik gaduh²
Body:
U r so cute... i like ur childish personality... Aya... ;p by -Lasiaf in confuse-
Greets to: Fait Accompli[myvwa],Nije,Dehe,Bae'i,Asmahani,Atira,Azha,Ema,Erma,Erna and U
Prepends itself to files with .htm or .html extensions on all removable, fixed, and network drives.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as VBS.Mywav@mm.
[url="http://securityresponse.symantec.com/avcenter/venc/data/vbs.mywav@mm.html"]source[/url]
Discovered on: August 12, 2004
Last Updated on: August 16, 2004 04:05:22 PM
VBS.Mywav@mm is a mass-mailing worm that also infects .html files.
Type: Worm
Infection Length: 20,695 bytes, 20,691 bytes
Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x
Technical Information:
When VBS.Mywav@mm is executed, it performs the following actions:
Displays a message containing the following text:
This page contained a graphic which require the ActiveX controls, Please reload or refresh the page and accept the ActiveX
Creates the following copies of itself:
c:\Greeting.htm (With file attributes set to Hidden.)
%Windir%\Myvwa.htm
%System%\AyaCute.htm
%Temp%\Normal.html
Notes:
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP)or C:\Winnt (Windows NT/2000).
%Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).
Searches on all removable, fixed, and network drives for email addresses in files with the following extensions:
htm
.html
.hta
.hte
.htx
Sends an HTML-formatted email, containing VBScript, to the addresses found and all contacts in the Microsoft Outlook address book.
This file will create %System%\Lasiaf.html, if ActiveX is enabled on the computer, which contains a copy of the worm.
The email has the following characteristics:
Subject: (One of the following)
Here is your Greeting card from me
<--Lasiaf-Fait Accompli-Myvwa-->
Greeting Card From Me.. ;p
Important! Please reply my Greeting card.
Friendster.. i'm a new comer..
FWD:Would you be my wife?
RE:Your password in this Greeting card
Hye look at this News...
Product Key!
FWD:Selamat menyambut hari kemerdekaan
Re:Good Luck in your exam
Somebody realy need you...
What ? new virus
Tekanan Emosi... Adik beradik gaduh²
Body:
U r so cute... i like ur childish personality... Aya... ;p by -Lasiaf in confuse-
Greets to: Fait Accompli[myvwa],Nije,Dehe,Bae'i,Asmahani,Atira,Azha,Ema,Erma,Erna and U
Prepends itself to files with .htm or .html extensions on all removable, fixed, and network drives.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as VBS.Mywav@mm.
[url="http://securityresponse.symantec.com/avcenter/venc/data/vbs.mywav@mm.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.Nullpos
Discovered on: August 12, 2004
Last Updated on: August 13, 2004 03:54:33 PM
Trojan.Nullpos is a Trojan horse program that modifies the screen saver settings to display a message written in Japanese. It also moves all the desktop icons to the "My Document" folder. The Trojan spreads using the Winny file-sharing network.
Infection Length: 315,392 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows CE
Technical Information:
When Trojan.Nullpos is executed, it performs the following actions:
Displays the message:
[img]http://www.killanet.net/uploads/nullpos1.gif[/img]
Copies the file, %System%TASKMGR.EXE, to the %Windows% folder.
Modifies the file, %System%\TASKMGR.EXE.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Moves all the shortcut icons on the desktop to the My Documents\<Japanese character string> folder.
Copies itself as %Windows%\bugfix\<Username>.wab.
Copies itself as %Windows%\bugfix\<Japanese character string>.zip.
Creates the file, %Windows%ss.reg.
Adds the values:
"ScreenSaveActive"="1"
"ScreenSaveTimeOut=60"
"SCRNSAVE.EXE"="%system%\ssmarque.scr"
to the registry key:
HKEY_CURRENT_USER\Control Panel\Desktop
Sets the values:
BackgroundColor=0 0
Speed=3
Text=<Japanese character string>
TextColor=255 0 0
Size=48
in the registry key:
HKEY_CURRENT_USER\Control Panel\Screen Saver.Marquee
This enables the following screen saver:
[img]http://www.killanet.net/uploads/trojan.nullpos2.gif[/img]
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as Trojan.Nullpos.
Reset the screen saver.
To reset the screen saver
Right-click on Windows desktop > Properties.
Click the Screen Saver tab and select the desired screen saver.
Click Apply > OK.
Copy the file %Windows%\TASKMGR.EXE to the %System% folder.
To copy the file %Windows%\TASKMGR.EXE to the %System% folder
Using Windows Explorer, locate the file Taskmgr.exe in the %Windir% folder and copy it to the %System% folder.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.nullpos.html"]source[/url]
Discovered on: August 12, 2004
Last Updated on: August 13, 2004 03:54:33 PM
Trojan.Nullpos is a Trojan horse program that modifies the screen saver settings to display a message written in Japanese. It also moves all the desktop icons to the "My Document" folder. The Trojan spreads using the Winny file-sharing network.
Infection Length: 315,392 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows CE
Technical Information:
When Trojan.Nullpos is executed, it performs the following actions:
Displays the message:
[img]http://www.killanet.net/uploads/nullpos1.gif[/img]
Copies the file, %System%TASKMGR.EXE, to the %Windows% folder.
Modifies the file, %System%\TASKMGR.EXE.
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Moves all the shortcut icons on the desktop to the My Documents\<Japanese character string> folder.
Copies itself as %Windows%\bugfix\<Username>.wab.
Copies itself as %Windows%\bugfix\<Japanese character string>.zip.
Creates the file, %Windows%ss.reg.
Adds the values:
"ScreenSaveActive"="1"
"ScreenSaveTimeOut=60"
"SCRNSAVE.EXE"="%system%\ssmarque.scr"
to the registry key:
HKEY_CURRENT_USER\Control Panel\Desktop
Sets the values:
BackgroundColor=0 0
Speed=3
Text=<Japanese character string>
TextColor=255 0 0
Size=48
in the registry key:
HKEY_CURRENT_USER\Control Panel\Screen Saver.Marquee
This enables the following screen saver:
[img]http://www.killanet.net/uploads/trojan.nullpos2.gif[/img]
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as Trojan.Nullpos.
Reset the screen saver.
To reset the screen saver
Right-click on Windows desktop > Properties.
Click the Screen Saver tab and select the desired screen saver.
Click Apply > OK.
Copy the file %Windows%\TASKMGR.EXE to the %System% folder.
To copy the file %Windows%\TASKMGR.EXE to the %System% folder
Using Windows Explorer, locate the file Taskmgr.exe in the %Windir% folder and copy it to the %System% folder.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.nullpos.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
PWSteal.Bancos.J
Discovered on: August 17, 2004
Last Updated on: August 18, 2004 11:22:52 AM
PWSteal.Bancos.J is a Trojan horse that mimics the online interfaces of certain Brazilian banks to try to steal account information.
Type: Trojan Horse
Infection Length: 482,816
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x
Technical Details:
When PWSteal.Bancos.J is executed, it performs the following actions:
Copies itself as %System%\Taskimgr.exe.
Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"CentralProcessor"="%system%\taskimgr.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
Terminates some antivirus products.
Monitors the active Internet Explorer windows, waiting for you to open a Web page that matches the characteristics of certain banking sites. When such a site is opened, the Trojan displays one of several logon screens, depending on the site that you visit.
If the URL includes http:/ /www.bancoreal.com.br, the logon screen may look like this:
[img]http://www.killanet.net/uploads/pwsteal.bancos.gif[/img]
If the URL includes http:/ /www.banespa.com.br/portal/bnp/script/templates/GCMRequest.do?page=583, the logon screen may look like this:
[img]http://www.killanet.net/uploads/pwsteal.bancos2.gif[/img]
Any entered information is emailed to the attacker.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as PWSteal.Bancos.J.
Reverse the changes made to the registry
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"CentralProcessor"="%system%\taskimgr.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.j.html"]source[/url]
Discovered on: August 17, 2004
Last Updated on: August 18, 2004 11:22:52 AM
PWSteal.Bancos.J is a Trojan horse that mimics the online interfaces of certain Brazilian banks to try to steal account information.
Type: Trojan Horse
Infection Length: 482,816
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x
Technical Details:
When PWSteal.Bancos.J is executed, it performs the following actions:
Copies itself as %System%\Taskimgr.exe.
Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the value:
"CentralProcessor"="%system%\taskimgr.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
Terminates some antivirus products.
Monitors the active Internet Explorer windows, waiting for you to open a Web page that matches the characteristics of certain banking sites. When such a site is opened, the Trojan displays one of several logon screens, depending on the site that you visit.
If the URL includes http:/ /www.bancoreal.com.br, the logon screen may look like this:
[img]http://www.killanet.net/uploads/pwsteal.bancos.gif[/img]
If the URL includes http:/ /www.banespa.com.br/portal/bnp/script/templates/GCMRequest.do?page=583, the logon screen may look like this:
[img]http://www.killanet.net/uploads/pwsteal.bancos2.gif[/img]
Any entered information is emailed to the attacker.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as PWSteal.Bancos.J.
Reverse the changes made to the registry
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"CentralProcessor"="%system%\taskimgr.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.j.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
PWSteal.Bancos.K
Discovered on: August 17, 2004
Last Updated on: August 18, 2004 02:43:35 PM
PWSteal.Bancos.K is a Trojan horse that mimics the online interfaces of certain Brazilian banks and attempts steal account information.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Microsoft IIS, Novell Netware, OS/2, UNIX
When the Trojan is executed, it performs the following actions:
Adds the value:
"winzip"="<path to trojan>"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan starts when Windows starts.
Monitors the active Internet Explorer windows, waiting for a Web page to be opened that matches the characteristics of certain banking sites. When such a site is opened, the Trojan displays one of several login screens, which are selected according to the URL or HTML page title.
If the Web page title is "Bradesco", it will display:
[img]http://www.killanet.net/uploads/pwsteal.bancos3.gif[/img]
If the Web page title is "Gerenciador Financeiro", it will display:
[img]http://www.killanet.net/uploads/pwsteal.bancos4.gif[/img]
If the Web page title is "Internet Banking CAIXA", it will display:
[img]http://www.killanet.net/uploads/pwsteal.bancos5.gif[/img]
If the URL is https:/ /www2.bancobrasil.com.br/aapf/aai/login.pbk, it will display:
[img]http://www.killanet.net/uploads/pwsteal.bancos6.gif[/img]
If the URL is https:/ /bankline.itau.com.br/GRIPNET/gracgi.exe, it will display:
[img]http://www.killanet.net/uploads/pwsteal.bancos7.gif[/img]
Sends the information entered into the form to a remote attacker via email.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as PWSteal.Bancos.K.
Reverse the changes made to the registry.
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"winzip"="<path to trojan>"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.k.html"]source[/url]
Discovered on: August 17, 2004
Last Updated on: August 18, 2004 02:43:35 PM
PWSteal.Bancos.K is a Trojan horse that mimics the online interfaces of certain Brazilian banks and attempts steal account information.
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Microsoft IIS, Novell Netware, OS/2, UNIX
When the Trojan is executed, it performs the following actions:
Adds the value:
"winzip"="<path to trojan>"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the Trojan starts when Windows starts.
Monitors the active Internet Explorer windows, waiting for a Web page to be opened that matches the characteristics of certain banking sites. When such a site is opened, the Trojan displays one of several login screens, which are selected according to the URL or HTML page title.
If the Web page title is "Bradesco", it will display:
[img]http://www.killanet.net/uploads/pwsteal.bancos3.gif[/img]
If the Web page title is "Gerenciador Financeiro", it will display:
[img]http://www.killanet.net/uploads/pwsteal.bancos4.gif[/img]
If the Web page title is "Internet Banking CAIXA", it will display:
[img]http://www.killanet.net/uploads/pwsteal.bancos5.gif[/img]
If the URL is https:/ /www2.bancobrasil.com.br/aapf/aai/login.pbk, it will display:
[img]http://www.killanet.net/uploads/pwsteal.bancos6.gif[/img]
If the URL is https:/ /bankline.itau.com.br/GRIPNET/gracgi.exe, it will display:
[img]http://www.killanet.net/uploads/pwsteal.bancos7.gif[/img]
Sends the information entered into the form to a remote attacker via email.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as PWSteal.Bancos.K.
Reverse the changes made to the registry.
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"winzip"="<path to trojan>"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.k.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
X97M.Ainesey.B
Discovered on: August 17, 2004
Last Updated on: August 18, 2004 03:45:59 PM
X97M.Ainesey.B is a macro virus that infects Microsoft Excel workbooks.
Type: Virus
Infection Length: 52,736 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When the virus is executed, it performs the following actions:
Searches all open Microsoft Excel workbooks and infects all worksheets.
Modifies the following values:
"Level"="1"
"DontTrustInstalledFiles"="0"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Excel\Security
which lowers the security settings of Microsoft Excel 9.0.
Modifies the following values:
"Level"="1"
"DontTrustInstalledFiles"="0"
"AccessVBOM"="1"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security
which lowers the security settings of Microsoft Excel 10.0.
Creates a corrupted file named MSIEXEC32.EXE in the %Windir% folder and tries to execute it.
Note:
Due to bugs in the code, the file will not successfully execute.
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Infects the Personal.xls file, so that the virus loads each time a Microsoft Excel workbook is opened.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as X97M.Ainesey.B.
Restore the security settings in Microsoft Excel.
Restoring security settings in Microsoft Excel
Start the Microsoft Excel application.
Click on the menu:
Tools -> Macro -> Security...
Choose the appropriate security level:
[img]http://www.killanet.net/uploads/excelrestore.gif[/img]
Exit the Excel application.
[url="http://securityresponse.symantec.com/avcenter/venc/data/x97m.ainesey.b.html"]source[/url]
Discovered on: August 17, 2004
Last Updated on: August 18, 2004 03:45:59 PM
X97M.Ainesey.B is a macro virus that infects Microsoft Excel workbooks.
Type: Virus
Infection Length: 52,736 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When the virus is executed, it performs the following actions:
Searches all open Microsoft Excel workbooks and infects all worksheets.
Modifies the following values:
"Level"="1"
"DontTrustInstalledFiles"="0"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Excel\Security
which lowers the security settings of Microsoft Excel 9.0.
Modifies the following values:
"Level"="1"
"DontTrustInstalledFiles"="0"
"AccessVBOM"="1"
in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security
which lowers the security settings of Microsoft Excel 10.0.
Creates a corrupted file named MSIEXEC32.EXE in the %Windir% folder and tries to execute it.
Note:
Due to bugs in the code, the file will not successfully execute.
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Infects the Personal.xls file, so that the virus loads each time a Microsoft Excel workbook is opened.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as X97M.Ainesey.B.
Restore the security settings in Microsoft Excel.
Restoring security settings in Microsoft Excel
Start the Microsoft Excel application.
Click on the menu:
Tools -> Macro -> Security...
Choose the appropriate security level:
[img]http://www.killanet.net/uploads/excelrestore.gif[/img]
Exit the Excel application.
[url="http://securityresponse.symantec.com/avcenter/venc/data/x97m.ainesey.b.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Neveg.B@mm
Discovered on: August 17, 2004
Last Updated on: August 17, 2004 03:46:46 PM
W32.Neveg.B@mm is a mass-mailing worm that performs denial of service (DoS) attacks on various web design Web sites.
The worm replicates via email, using its own SMTP engine, and also spreads through shared folders.
Also Known As: W32/Neveg.b@MM (McAfee)
Type: Worm
Infection Length: 51,270 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows CE
Technical Details:
When W32.Neveg.B@mm is executed, it performs the following actions:
Creates a mutex named "4D36E64A-W325-121E-BFC1-080C2BE11318", to ensure the only one instance of the worm runs in the computer.
Copies itself as %Windir%\system\services.exe.
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Adds the one of the following values:
".Prog" = "%Windir%\system\services.exe"
"BuildLab" = "%Windir%\system\services.exe"
"ccApps" = "%Windir%\system\services.exe"
"FriendlyTypeName" = "%Windir%\system\services.exe"
"Microsoft Visual SourceSafe" = "%Windir%\system\services.exe"
"RegDone" = "%Windir%\system\services.exe"
"TEXTCONV" = "%Windir%\system\services.exe"
"WMAudio" = "%Windir%\system\services.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start the Windows.
Searches for the email addresses in files with the following extensions, saving them in %System%\Setup32ea.bak:
.hlp
.xml
.xls
.wsh
.wab
.vbs
.uin
.txt
.tbb
.stm
.shtm
.sht
.rtf
.pl
.php
.oft
.ods
.nch
.msg
.mmf
.mht
.mdx
.mbx
.jsp
.html
.htm
.eml
.dhtm
.dbx
.cgi
.cfg
.asp
.adb
The worm avoids sending email to the addresses that contain the following strings:
.gbl
symant
norton
@mcaf
openbsd
freebsd
gnu.
.gov
.mil
microso
kaspers
Uses its own SMTP engine to send itself as an attachment to mail messages with one of the following names:
office.exe
notes.exe
doom3demo.exe
resume.exe
files.exe
request.exe
info.exe
details.exe
result.exe
results.exe
install.exe
setup.exe
test.exe
google.exe
se_files.exe
Performs a DoS attack on the following Web sites:
www.hvr-systems.cc
www.real-creative.de
www.2rebrand.com
www.designload.com
www.designgalaxy.net
www.procartoonz.com
www.designload.net
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Neveg.B@mm.
Reverse the changes made to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete any of these values:
".Prog" = "%Windir%\system\services.exe"
"BuildLab" = "%Windir%\system\services.exe"
"ccApps" = "%Windir%\system\services.exe"
"FriendlyTypeName" = "%Windir%\system\services.exe"
"Microsoft Visual SourceSafe" = "%Windir%\system\services.exe"
"RegDone" = "%Windir%\system\services.exe"
"TEXTCONV" = "%Windir%\system\services.exe"
"WMAudio" = "%Windir%\system\services.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.b@mm.html"]source[/url]
Discovered on: August 17, 2004
Last Updated on: August 17, 2004 03:46:46 PM
W32.Neveg.B@mm is a mass-mailing worm that performs denial of service (DoS) attacks on various web design Web sites.
The worm replicates via email, using its own SMTP engine, and also spreads through shared folders.
Also Known As: W32/Neveg.b@MM (McAfee)
Type: Worm
Infection Length: 51,270 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows CE
Technical Details:
When W32.Neveg.B@mm is executed, it performs the following actions:
Creates a mutex named "4D36E64A-W325-121E-BFC1-080C2BE11318", to ensure the only one instance of the worm runs in the computer.
Copies itself as %Windir%\system\services.exe.
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Adds the one of the following values:
".Prog" = "%Windir%\system\services.exe"
"BuildLab" = "%Windir%\system\services.exe"
"ccApps" = "%Windir%\system\services.exe"
"FriendlyTypeName" = "%Windir%\system\services.exe"
"Microsoft Visual SourceSafe" = "%Windir%\system\services.exe"
"RegDone" = "%Windir%\system\services.exe"
"TEXTCONV" = "%Windir%\system\services.exe"
"WMAudio" = "%Windir%\system\services.exe"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start the Windows.
Searches for the email addresses in files with the following extensions, saving them in %System%\Setup32ea.bak:
.hlp
.xml
.xls
.wsh
.wab
.vbs
.uin
.txt
.tbb
.stm
.shtm
.sht
.rtf
.pl
.php
.oft
.ods
.nch
.msg
.mmf
.mht
.mdx
.mbx
.jsp
.html
.htm
.eml
.dhtm
.dbx
.cgi
.cfg
.asp
.adb
The worm avoids sending email to the addresses that contain the following strings:
.gbl
symant
norton
@mcaf
openbsd
freebsd
gnu.
.gov
.mil
microso
kaspers
Uses its own SMTP engine to send itself as an attachment to mail messages with one of the following names:
office.exe
notes.exe
doom3demo.exe
resume.exe
files.exe
request.exe
info.exe
details.exe
result.exe
results.exe
install.exe
setup.exe
test.exe
google.exe
se_files.exe
Performs a DoS attack on the following Web sites:
www.hvr-systems.cc
www.real-creative.de
www.2rebrand.com
www.designload.com
www.designgalaxy.net
www.procartoonz.com
www.designload.net
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Neveg.B@mm.
Reverse the changes made to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete any of these values:
".Prog" = "%Windir%\system\services.exe"
"BuildLab" = "%Windir%\system\services.exe"
"ccApps" = "%Windir%\system\services.exe"
"FriendlyTypeName" = "%Windir%\system\services.exe"
"Microsoft Visual SourceSafe" = "%Windir%\system\services.exe"
"RegDone" = "%Windir%\system\services.exe"
"TEXTCONV" = "%Windir%\system\services.exe"
"WMAudio" = "%Windir%\system\services.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.b@mm.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
W32.Beagle.AP@mm
Discovered on: August 17, 2004
Last Updated on: August 19, 2004 02:16:18 PM
W32.Beagle.AP@mm is a mass-mailing worm that spreads via email, using its own SMTP engine.
Also Known As: WORM_BAGLE.AJ (Trend Micro)
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When the worm is executed, it performs the following actions:
Creates the following copies itself in the %System% folder:
drvddll.exe
drvddll.exeopen
drvddll.exeopenopen
drvddll.exeopenopenopen
Notes:
The above files may be zipped.
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the following value:
"drvddll.exe" = "%System%\drvddll.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Displays the following fake error message:
Error
Can't find a viewer associated with the file
Terminates the following processes:
AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET.EXE
CFINET32.EXE
CFINET32.EXE
CLEAN.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMGRDIAN.EXE
CMON016.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
drvsys.exe
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE
Attempts to run a PHP script, located on one of the following domains, to notify the attacker of infection:
2udar.ligakvn.de
3treepoint.com
abakan.strana.de
andimeisslein.de
ditec.um.es
fotos.schneider.bards.de
hardvision.ru
jakimov.golos.de
markusgimenez.de
mhv24.de
s318.evanzo-server.de
Spaceclub.de
tobimayer.de
vg.xtonne.de
vg.xtonne.de
villakinderbunt.de
virtualzone.de
www.ac-schnitzer.de
www.auma.de
www.autoscout24.de
www.avh.de
www.beckers-systems.de
www.berlinale.de
www.blauer-engel.de
www.bmbf.de
www.bruecke-osteuropa.de
www.bundesregierung.de
www.chugai.de
www.cicv.fr
www.dalnoboyshik.de
www.de-bug.de
www.degruyter.de
www.deutsch-als-fremdsprache.de
www.deutsches-museum.de
www.deutschland.de
www.dfg.de
www.documenta.de
www.dwd.de
www.embl-heidelberg.de
www.emis.de
www.eumetsat.de
www.exactaudiocopy.de
www.fernuni-hagen.de
www.fiz-karlsruhe.de
www.fracht-24.de
www.fu-berlin.de
www.gdch.de
www.go-amman.de
www.goethe.de
www.gospel-nations.de
www.gsi.de
www.hamann-motorsport.de
www.hamburg.de
www.heise.de
www.hotel-pension-spree.de
www.ifdesign.de
www.insel-ruegen-hotel.de
www.intermatgmbh.de
www.jura.uni-sb.de
www.kliniken.de
www.leipziger-messe.de
www.loveparade.de
www.low-spirit.de
www.mdz-moskau.de
www.mitsubishi-evs.de
www.mitsumi.de
www.mk-motorsport.de
www.mobile.de
www.nabu.de
www.neformal.de
www.neznakomez.de
www.paromi.de
www.partner-inform.de
www.php-resource.de
www.pri-wo-hamburg.de
www.red-dot.de
www.restarted-alliance.de
www.ruletka.de
www.russische-botschaft.de
www.siegenia-aubi.com
www.spiegel.de
www.sprach-zertifikat.de
www.teac.de
www.tecchannel.de
www.tekeli.de
www.tib.uni-hannover.de
www.turism.de
www.uni-oldenburg.de
www.uni-stuttgart.de
www.welt.de
www.windac.de
www.winfuture.de
www.www.mirko-becker.gmxhome.de
Creates the following mutexes to prevent Netsky variants from executing:
MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_
Searches for folders containing the string "shar" and drops a copy of itself to any folders found, using one of the following file names:
Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral,
/censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> cool, awesome!!.exe
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe
Sends itself to the email addresses that it gathers from the files with the following extensions:
.wab
.txt
.msg
.htm
.shtm
.stm
.xml
.dbx
.mbx
.mdx
.eml
.nch
.mmf
.ods
.cfg
.asp
.php
.pl
.wsh
.adb
.tbb
.sht
.xls
.oft
.uin
.cgi
.mht
.dhtm
.jsp
The worm will not send itself to the addresses containing the following strings:
@microsoft
rating@
f-secur
news
update
anyone@
bugs@
contract@
feste
gold-certs@
help@
info@
nobody@
noone@
kasp
admin
icrosoft
support
ntivi
unix
bsd
linux
listserv
certific
sopho
@foo
@iana
free-av
@messagelab
winzip
google
winrar
samples
abuse
panda
cafee
spam
pgp
@avp.
noreply
local
root@
postmaster@
The email message that the worm constructs typically has the following properties:
From: <spoofed>
Subject: (Blank or one of the following)
Re: Msg reply
Re: Hello
Re: Yahoo!
Re: Thank you!
Re: Thanks
/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
RE: Text message
Re: Document
Incoming message
Re: Incoming Message
RE: Incoming Msg
RE: Message Notify
Notification
Changes..
New changes
Hidden message
Fax Message Received
Protected message
RE: Protected message
Forum notify
Site changes
Re: Hi
Encrypted document
Body: (One of the following)
For security reasons attached file is password protected. The password is [bitmap image]
For security purposes the attached file is password protected. Password -- [bitmap image]
Note: Use password [bitmap image] to open archive.
Attached file is protected with the password for security reasons. Password is [bitmap image]
In order to read the attach you have to use the following password: [bitmap image]
Archive password: [bitmap image]
Password - [bitmap image]
Password: [bitmap image]
Attachment: (Composed of one of the following strings)
Information
Details
text_document
Readme
Document
Info
the_message
Details
MoreInfo
Message
You_will_answer_to_me
Half_Live
Counter_strike
Loves_money
the_message
Alive_condom
Joke
Toy
Nervous_illnesses
Manufacture
You_are_dismissed
with one of the following extensions:
.exe
.scr
.com
.zip
.vbs
.hta
.cpl
Opens a backdoor on an infected computer, listening on a random port. The backdoor will give the remote attacker the ability to:
Download and execute a file on an infected computer
Update the malware
Uninstall the malware
11. The worm may drop.vbs and .html files. They are detected as W32.Beagle.X@mm with Symantec AntiVirus products.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AP@mm.
Reverse the changes made to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"drvddll.exe" = "%System%\drvddll.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ap@mm.html"]source[/url]
Discovered on: August 17, 2004
Last Updated on: August 19, 2004 02:16:18 PM
W32.Beagle.AP@mm is a mass-mailing worm that spreads via email, using its own SMTP engine.
Also Known As: WORM_BAGLE.AJ (Trend Micro)
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
When the worm is executed, it performs the following actions:
Creates the following copies itself in the %System% folder:
drvddll.exe
drvddll.exeopen
drvddll.exeopenopen
drvddll.exeopenopenopen
Notes:
The above files may be zipped.
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Adds the following value:
"drvddll.exe" = "%System%\drvddll.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Displays the following fake error message:
Error
Can't find a viewer associated with the file
Terminates the following processes:
AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET.EXE
CFINET32.EXE
CFINET32.EXE
CLEAN.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMGRDIAN.EXE
CMON016.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
drvsys.exe
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE
Attempts to run a PHP script, located on one of the following domains, to notify the attacker of infection:
2udar.ligakvn.de
3treepoint.com
abakan.strana.de
andimeisslein.de
ditec.um.es
fotos.schneider.bards.de
hardvision.ru
jakimov.golos.de
markusgimenez.de
mhv24.de
s318.evanzo-server.de
Spaceclub.de
tobimayer.de
vg.xtonne.de
vg.xtonne.de
villakinderbunt.de
virtualzone.de
www.ac-schnitzer.de
www.auma.de
www.autoscout24.de
www.avh.de
www.beckers-systems.de
www.berlinale.de
www.blauer-engel.de
www.bmbf.de
www.bruecke-osteuropa.de
www.bundesregierung.de
www.chugai.de
www.cicv.fr
www.dalnoboyshik.de
www.de-bug.de
www.degruyter.de
www.deutsch-als-fremdsprache.de
www.deutsches-museum.de
www.deutschland.de
www.dfg.de
www.documenta.de
www.dwd.de
www.embl-heidelberg.de
www.emis.de
www.eumetsat.de
www.exactaudiocopy.de
www.fernuni-hagen.de
www.fiz-karlsruhe.de
www.fracht-24.de
www.fu-berlin.de
www.gdch.de
www.go-amman.de
www.goethe.de
www.gospel-nations.de
www.gsi.de
www.hamann-motorsport.de
www.hamburg.de
www.heise.de
www.hotel-pension-spree.de
www.ifdesign.de
www.insel-ruegen-hotel.de
www.intermatgmbh.de
www.jura.uni-sb.de
www.kliniken.de
www.leipziger-messe.de
www.loveparade.de
www.low-spirit.de
www.mdz-moskau.de
www.mitsubishi-evs.de
www.mitsumi.de
www.mk-motorsport.de
www.mobile.de
www.nabu.de
www.neformal.de
www.neznakomez.de
www.paromi.de
www.partner-inform.de
www.php-resource.de
www.pri-wo-hamburg.de
www.red-dot.de
www.restarted-alliance.de
www.ruletka.de
www.russische-botschaft.de
www.siegenia-aubi.com
www.spiegel.de
www.sprach-zertifikat.de
www.teac.de
www.tecchannel.de
www.tekeli.de
www.tib.uni-hannover.de
www.turism.de
www.uni-oldenburg.de
www.uni-stuttgart.de
www.welt.de
www.windac.de
www.winfuture.de
www.www.mirko-becker.gmxhome.de
Creates the following mutexes to prevent Netsky variants from executing:
MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_
Searches for folders containing the string "shar" and drops a copy of itself to any folders found, using one of the following file names:
Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral,
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe
Sends itself to the email addresses that it gathers from the files with the following extensions:
.wab
.txt
.msg
.htm
.shtm
.stm
.xml
.dbx
.mbx
.mdx
.eml
.nch
.mmf
.ods
.cfg
.asp
.php
.pl
.wsh
.adb
.tbb
.sht
.xls
.oft
.uin
.cgi
.mht
.dhtm
.jsp
The worm will not send itself to the addresses containing the following strings:
@microsoft
rating@
f-secur
news
update
anyone@
bugs@
contract@
feste
gold-certs@
help@
info@
nobody@
noone@
kasp
admin
icrosoft
support
ntivi
unix
bsd
linux
listserv
certific
sopho
@foo
@iana
free-av
@messagelab
winzip
winrar
samples
abuse
panda
cafee
spam
pgp
@avp.
noreply
local
root@
postmaster@
The email message that the worm constructs typically has the following properties:
From: <spoofed>
Subject: (Blank or one of the following)
Re: Msg reply
Re: Hello
Re: Yahoo!
Re: Thank you!
Re: Thanks
RE: Text message
Re: Document
Incoming message
Re: Incoming Message
RE: Incoming Msg
RE: Message Notify
Notification
Changes..
New changes
Hidden message
Fax Message Received
Protected message
RE: Protected message
Forum notify
Site changes
Re: Hi
Encrypted document
Body: (One of the following)
For security reasons attached file is password protected. The password is [bitmap image]
For security purposes the attached file is password protected. Password -- [bitmap image]
Note: Use password [bitmap image] to open archive.
Attached file is protected with the password for security reasons. Password is [bitmap image]
In order to read the attach you have to use the following password: [bitmap image]
Archive password: [bitmap image]
Password - [bitmap image]
Password: [bitmap image]
Attachment: (Composed of one of the following strings)
Information
Details
text_document
Readme
Document
Info
the_message
Details
MoreInfo
Message
You_will_answer_to_me
Half_Live
Counter_strike
Loves_money
the_message
Alive_condom
Joke
Toy
Nervous_illnesses
Manufacture
You_are_dismissed
with one of the following extensions:
.exe
.scr
.com
.zip
.vbs
.hta
.cpl
Opens a backdoor on an infected computer, listening on a random port. The backdoor will give the remote attacker the ability to:
Download and execute a file on an infected computer
Update the malware
Uninstall the malware
11. The worm may drop.vbs and .html files. They are detected as W32.Beagle.X@mm with Symantec AntiVirus products.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AP@mm.
Reverse the changes made to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"drvddll.exe" = "%System%\drvddll.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ap@mm.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trivial.818
Discovered on: August 18, 2004
Last Updated on: August 19, 2004 09:27:24 AM
Trivial.818 is a DOS virus that overwrites the first 818 bytes of .com and .exe files, preventing them from running correctly
Type: Virus
Systems Affected: Windows 95, Windows 98, Windows Me
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 2000, Windows NT, Windows XP
Technical Details:
When Trivial.818 is executed, it does the following:
Finds all .com and .exe files that are in the same directory as the virus.
Overwrites the first 818 bytes of these files with itself.
Infects .com and .exe files that are in directories that are above the one containing the virus.
Removal Instructions:
Update the virus definitions.
Run a full system scan and delete all the files detected as Trivial.818.
When all the infected files have been deleted, restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trivial.818.html"]source[/url]
Discovered on: August 18, 2004
Last Updated on: August 19, 2004 09:27:24 AM
Trivial.818 is a DOS virus that overwrites the first 818 bytes of .com and .exe files, preventing them from running correctly
Type: Virus
Systems Affected: Windows 95, Windows 98, Windows Me
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 2000, Windows NT, Windows XP
Technical Details:
When Trivial.818 is executed, it does the following:
Finds all .com and .exe files that are in the same directory as the virus.
Overwrites the first 818 bytes of these files with itself.
Infects .com and .exe files that are in directories that are above the one containing the virus.
Removal Instructions:
Update the virus definitions.
Run a full system scan and delete all the files detected as Trivial.818.
When all the infected files have been deleted, restart the computer in Normal mode.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trivial.818.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.Sconato
Discovered on: August 19, 2004
Last Updated on: August 20, 2004 03:24:42 PM
Trojan.Sconato is a Trojan horse program that installs a Browser Helper Object (BHO). The installed BHO captures keystrokes and emails them to the attacker.
This Trojan is packed with UPX.
Also Known As: Keylog-Sconato [McAfee], TROJ_SCONATO.A [Trend], Troj/Sconato-A [Sophos], Trj/Sconato.A [Panda], Trojan.Win32.Sconato.a [Kaspersky]
Type: Trojan Horse
Infection Length: 28,160 bytes, 28,672 bytes, 8,704 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, OS/2, UNIX
Technical Details:
When Trojan.Sconato is executed, it performs the following actions:
Creates the following file, which captures keystrokes:
%System%\winmgmt.dll (8,704 bytes)
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following file, which emails the data captured by winmgmt.dll to a Russian email address
%System%\sysconnect.dll (28,672 bytes)
Creates one of the following Microsoft Word files:
C:\Documents and Settings\<Username>\Local Settings\Temp\#3004-19-07-2004.doc (38,400 bytes)
C:\Documents and Settings\<Username>\Local Settings\Temp\nato.doc
Adds the value:
"(Default)"="%System%\sysconnect.dll"
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{%CLSID%}\InProcServer32
Note: %CLSID% is a variable that refers to the CLSID hex value the Trojan creates.
Adds the value:
"SysConnect"="{%CLSID%}"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Adds the value:
"InstallerParameters"=<hex number>
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Sconato.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
In the right pane, take note of the value of %CLSID%, which is a variable that refers to the CLSID hex value the Trojan creates.
delete the value:
"SysConnect"="{%CLSID%}"
Navigate to the key :
HKEY_CLASSES_ROOT\CLSID\{%CLSID%}
where the value of %CLSID% refers to the CLSID hex value the Trojan created,
delete the key.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer
In the right pane, delete the value:
"InstallerParameters"
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.sconato.html"]source[/url]
Discovered on: August 19, 2004
Last Updated on: August 20, 2004 03:24:42 PM
Trojan.Sconato is a Trojan horse program that installs a Browser Helper Object (BHO). The installed BHO captures keystrokes and emails them to the attacker.
This Trojan is packed with UPX.
Also Known As: Keylog-Sconato [McAfee], TROJ_SCONATO.A [Trend], Troj/Sconato-A [Sophos], Trj/Sconato.A [Panda], Trojan.Win32.Sconato.a [Kaspersky]
Type: Trojan Horse
Infection Length: 28,160 bytes, 28,672 bytes, 8,704 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, OS/2, UNIX
Technical Details:
When Trojan.Sconato is executed, it performs the following actions:
Creates the following file, which captures keystrokes:
%System%\winmgmt.dll (8,704 bytes)
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Creates the following file, which emails the data captured by winmgmt.dll to a Russian email address
%System%\sysconnect.dll (28,672 bytes)
Creates one of the following Microsoft Word files:
C:\Documents and Settings\<Username>\Local Settings\Temp\#3004-19-07-2004.doc (38,400 bytes)
C:\Documents and Settings\<Username>\Local Settings\Temp\nato.doc
Adds the value:
"(Default)"="%System%\sysconnect.dll"
to the registry key:
HKEY_CLASSES_ROOT\CLSID\{%CLSID%}\InProcServer32
Note: %CLSID% is a variable that refers to the CLSID hex value the Trojan creates.
Adds the value:
"SysConnect"="{%CLSID%}"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Adds the value:
"InstallerParameters"=<hex number>
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Sconato.
Delete the value that was added to the registry.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
In the right pane, take note of the value of %CLSID%, which is a variable that refers to the CLSID hex value the Trojan creates.
delete the value:
"SysConnect"="{%CLSID%}"
Navigate to the key :
HKEY_CLASSES_ROOT\CLSID\{%CLSID%}
where the value of %CLSID% refers to the CLSID hex value the Trojan created,
delete the key.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer
In the right pane, delete the value:
"InstallerParameters"
Exit the Registry Editor.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.sconato.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.Delsha
Discovered on: August 19, 2004
Last Updated on: August 20, 2004 02:07:24 PM
Trojan.Delsha is a Trojan horse program that disables the sharing permission of network-shared folders.
Type: Trojan Horse
Infection Length: 20,480 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows CE
Technical Details:
When Trojan.Delsha is executed, it deletes the following network shares:
a$
b$
c$
d$
e$
f$
g$
h$
i$
j$
k$
l$
m$
n$
o$
p$
q$
r$
s$
t$
u$
v$
w$
x$
z$
print$
admin$
ipc$
Shared Docs
My Documents
Note: This stops the folders from being available over the network but it does not delete them from the local hard drive.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Delsha.
Reset the shared folder options.
Start Microsoft Internet Explorer
Right-click the folder you want to share.
From the drop-down menu, select Properties.
In the dialog box, select the Sharing tab.
Select Share this folder and set desired configurations.
Click Apply
Click OK.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.delsha.html"]source[/url]
Discovered on: August 19, 2004
Last Updated on: August 20, 2004 02:07:24 PM
Trojan.Delsha is a Trojan horse program that disables the sharing permission of network-shared folders.
Type: Trojan Horse
Infection Length: 20,480 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows CE
Technical Details:
When Trojan.Delsha is executed, it deletes the following network shares:
a$
b$
c$
d$
e$
f$
g$
h$
i$
j$
k$
l$
m$
n$
o$
p$
q$
r$
s$
t$
u$
v$
w$
x$
z$
print$
admin$
ipc$
Shared Docs
My Documents
Note: This stops the folders from being available over the network but it does not delete them from the local hard drive.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Delsha.
Reset the shared folder options.
Start Microsoft Internet Explorer
Right-click the folder you want to share.
From the drop-down menu, select Properties.
In the dialog box, select the Sharing tab.
Select Share this folder and set desired configurations.
Click Apply
Click OK.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.delsha.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
X97M.Ainesey.C
Discovered on: August 19, 2004
Last Updated on: August 20, 2004 04:21:55 PM
X97M.Ainesey.C is a Microsoft Excel macro virus that infects Microsoft Excel workbooks, lowers Internet Explorer security settings, and drops a file containing a Trojan horse program onto the infected computer.
Type: Macro
Infection Length: 71,920 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
Once executed, X97M.Ainesey.C does the following:
Creates the following files:
%temp%\1.reg sets
%temp\2.reg sets
Sets the following registry entries, in order to lower the security settings of Microsoft Excel 9.0 and 10.0:
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security\Level=1
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security\DontTrustInstalledFiles=0
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security\AccessVBOM=1
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Excel\Security\Level=1
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Excel\Security\DontTrustInstalledFiles=0
Deletes the following files:
%temp%\1.reg sets
%temp\2.reg sets
Creates and executes the file %Windir%\MSIEXEC32.EXE.
Note: The file, MSIEXEC32.EXE, contains the virus W32.Ainesey.A@mm, and may also be infected with W32.ElKern.4926.
Searches all open Microsoft Excel workbooks and infects all worksheets.
Searches for a file named Personal.xls in the Excel startup folder, creating it if it does not already exist. The virus then infects Personal.xls, which causes the virus will be loaded each time a Microsoft Excel workbook is opened.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as X97M.Ainesey.C.
Restore the security settings in Microsoft Excel.
Start Microsoft Excel.
On the Tools menu:
Click Macro > Security.
Choose the appropriate security level:
[img]http://www.killanet.net/uploads/excelrestore.gif[/img]
Exit Microsoft Excel.
[url="http://securityresponse.symantec.com/avcenter/venc/data/x97m.ainesey.c.html"]source[/url]
Discovered on: August 19, 2004
Last Updated on: August 20, 2004 04:21:55 PM
X97M.Ainesey.C is a Microsoft Excel macro virus that infects Microsoft Excel workbooks, lowers Internet Explorer security settings, and drops a file containing a Trojan horse program onto the infected computer.
Type: Macro
Infection Length: 71,920 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical Details:
Once executed, X97M.Ainesey.C does the following:
Creates the following files:
%temp%\1.reg sets
%temp\2.reg sets
Sets the following registry entries, in order to lower the security settings of Microsoft Excel 9.0 and 10.0:
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security\Level=1
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security\DontTrustInstalledFiles=0
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security\AccessVBOM=1
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Excel\Security\Level=1
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Excel\Security\DontTrustInstalledFiles=0
Deletes the following files:
%temp%\1.reg sets
%temp\2.reg sets
Creates and executes the file %Windir%\MSIEXEC32.EXE.
Note: The file, MSIEXEC32.EXE, contains the virus W32.Ainesey.A@mm, and may also be infected with W32.ElKern.4926.
Searches all open Microsoft Excel workbooks and infects all worksheets.
Searches for a file named Personal.xls in the Excel startup folder, creating it if it does not already exist. The virus then infects Personal.xls, which causes the virus will be loaded each time a Microsoft Excel workbook is opened.
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as X97M.Ainesey.C.
Restore the security settings in Microsoft Excel.
Start Microsoft Excel.
On the Tools menu:
Click Macro > Security.
Choose the appropriate security level:
[img]http://www.killanet.net/uploads/excelrestore.gif[/img]
Exit Microsoft Excel.
[url="http://securityresponse.symantec.com/avcenter/venc/data/x97m.ainesey.c.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Download.Ject.B
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 05:09:58 PM
Download.Ject.B is a variant of Download.Ject that attempts to download and install a file by exploiting Internet Explorer vulnerabilities described in Microsoft Security Bulletin MS04-025. The Trojan is triggered by visiting a Web site that contains the exploit code.
Variants: Download.Ject
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Technical Details:
When Download.Ject.B is executed, it performs the following actions:
Attempts to tries to open the following websites:
drusearch.com
url.biz.ua
Downloads and executes one of the following files:
%System%\rundll32.vbe
help.chm
Notes:
Symantec antivirus products detect these files as Trojan.StartPage.H.
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Removal Instructions:
No removal required for the Download.Ject.B itself because it runs from a remote Web site. The detection indicates that it has been detected on the Web site and stopped.
However, if Download.Ject.B was successful in downloading Trojan.StartPage.H, it should be removed. For more information, read the [url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.h.html"]Trojan.StartPage.H[/url] writeup.
[url="http://securityresponse.symantec.com/avcenter/venc/data/download.ject.b.html"]source[/url]
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 05:09:58 PM
Download.Ject.B is a variant of Download.Ject that attempts to download and install a file by exploiting Internet Explorer vulnerabilities described in Microsoft Security Bulletin MS04-025. The Trojan is triggered by visiting a Web site that contains the exploit code.
Variants: Download.Ject
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
Technical Details:
When Download.Ject.B is executed, it performs the following actions:
Attempts to tries to open the following websites:
drusearch.com
url.biz.ua
Downloads and executes one of the following files:
%System%\rundll32.vbe
help.chm
Notes:
Symantec antivirus products detect these files as Trojan.StartPage.H.
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Removal Instructions:
No removal required for the Download.Ject.B itself because it runs from a remote Web site. The detection indicates that it has been detected on the Web site and stopped.
However, if Download.Ject.B was successful in downloading Trojan.StartPage.H, it should be removed. For more information, read the [url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.h.html"]Trojan.StartPage.H[/url] writeup.
[url="http://securityresponse.symantec.com/avcenter/venc/data/download.ject.b.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Alerts
Trojan.StartPage.H
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 05:08:39 PM
Trojan.StartPage.H is a variant of Trojan.StartPage that modifies the Internet Explorer home page without your permission.
Trojan.StartPage.H is downloaded by Download.Ject.B.
Variants: Trojan.StartPage
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
When Trojan.StartPage.H is executed, it performs the following actions:
Adds the values:
"Customize Search"="http:/ /targetsearch.info"
"Default_Search_URL"="http:/ /targetsearch.info"
"Local Page"="http:/ /targetsearch.info"
"Search Bar"="http:/ /targetsearch.info"
"Search Page"="http:/ /targetsearch.info"
"SearchURL"="http:/ /go.targetsearch.info/"
"Start Page"="http:/ /targetsearch.info"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Adds the values:
"Default_Page_URL"="http:/ /targetsearch.info"
"Default_Search_URL"="http:/ /targetsearch.info"
"Local Page"="http:/ /targetsearch.info"
"Search Bar"="http:/ /targetsearch.info/left.php"
"Search Page"="http:/ /targetsearch.info"
"Start Page"="http:/ /targetsearch.info"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
Adds the value:
"CustomizeSearch"="http:/ /targetsearch.info/left.php"
"SearchAssistant"="http:/ /targetsearch.info/left.php"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search
Adds the following entries to your Internet Explorer Favorites list:
Absoluagency: http:/ /absoluagency.com
Adult Search!: http:/ /adult.targetsearch.info
Real Search!: http:/ /targetsearch.info
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.StartPage.H.
Reset the Internet Explorer home page
Reset the Internet Explorer Search page
To reset the Internet Explorer home page
Start Microsoft Internet Explorer.
Connect to the Internet, and then go to the page that you want to set as your home page.
Click Tools > Internet Options.
In the Home page section of the General tab, click Use Current > OK.
For additional information, or if this procedure does not work, read the Microsoft® Knowledge Base article, [url="http://support.microsoft.com/default.aspx?scid=kb;en-us;320159"]"Home Page Setting Changes Unexpectedly, or You Cannot Change Your Home Page Setting, Article ID 320159." [/url]
To reset the Internet Explorer Search page
Follow the instructions for your version of Windows.
Windows 98/Me/2000
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.
Windows XP
Because Windows XP is set by default to use animated characters in the search, how you do this can vary. Read all the instructions before you start.
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
Do one of the following:
If the pane that opens looks similar to this picture:
[img]http://www.killanet.net/uploads/resetIE.gif[/img]
click the word Customize. Then skip to step h.
If the pane that opens has the words "Search Companion" at the top, and the center looks similar to this picture:
[img]http://www.killanet.net/uploads/resetIE1.gif[/img]
click the Change preferences link as shown above. Proceed with step d.
Click the Change Internet search behavior link.
Under "Internet Search Behavior," click With Classic Internet Search.
Click OK. Then close Internet Explorer. (Close the program for the change to take effect.)
Start Internet Explorer. When the search pane opens, it should now look similar to this:
[img]http://www.killanet.net/uploads/resetIE.gif[/img]
Click the word Customize, and then proceed with the next step.
In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.
Do one of the following:
If you were using (or want to continue using) the "Classic Internet Search" panel, stop here (or proceed with the next section).
If you want to go back to the "Search Companion" search (it usually has an animated character at the button), proceed with step n.
Click the word Customize again.
In the "Customize Search Settings" window, click Use Search Companion > OK.
Close Internet Explorer. The next time you open it, it will again use the Search Companion.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.h.html"]source[/url]
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 05:08:39 PM
Trojan.StartPage.H is a variant of Trojan.StartPage that modifies the Internet Explorer home page without your permission.
Trojan.StartPage.H is downloaded by Download.Ject.B.
Variants: Trojan.StartPage
Type: Trojan Horse
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX
When Trojan.StartPage.H is executed, it performs the following actions:
Adds the values:
"Customize Search"="http:/ /targetsearch.info"
"Default_Search_URL"="http:/ /targetsearch.info"
"Local Page"="http:/ /targetsearch.info"
"Search Bar"="http:/ /targetsearch.info"
"Search Page"="http:/ /targetsearch.info"
"SearchURL"="http:/ /go.targetsearch.info/"
"Start Page"="http:/ /targetsearch.info"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Adds the values:
"Default_Page_URL"="http:/ /targetsearch.info"
"Default_Search_URL"="http:/ /targetsearch.info"
"Local Page"="http:/ /targetsearch.info"
"Search Bar"="http:/ /targetsearch.info/left.php"
"Search Page"="http:/ /targetsearch.info"
"Start Page"="http:/ /targetsearch.info"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
Adds the value:
"CustomizeSearch"="http:/ /targetsearch.info/left.php"
"SearchAssistant"="http:/ /targetsearch.info/left.php"
to the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search
Adds the following entries to your Internet Explorer Favorites list:
Absoluagency: http:/ /absoluagency.com
Adult Search!: http:/ /adult.targetsearch.info
Real Search!: http:/ /targetsearch.info
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.StartPage.H.
Reset the Internet Explorer home page
Reset the Internet Explorer Search page
To reset the Internet Explorer home page
Start Microsoft Internet Explorer.
Connect to the Internet, and then go to the page that you want to set as your home page.
Click Tools > Internet Options.
In the Home page section of the General tab, click Use Current > OK.
For additional information, or if this procedure does not work, read the Microsoft® Knowledge Base article, [url="http://support.microsoft.com/default.aspx?scid=kb;en-us;320159"]"Home Page Setting Changes Unexpectedly, or You Cannot Change Your Home Page Setting, Article ID 320159." [/url]
To reset the Internet Explorer Search page
Follow the instructions for your version of Windows.
Windows 98/Me/2000
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.
Windows XP
Because Windows XP is set by default to use animated characters in the search, how you do this can vary. Read all the instructions before you start.
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
Do one of the following:
If the pane that opens looks similar to this picture:
[img]http://www.killanet.net/uploads/resetIE.gif[/img]
click the word Customize. Then skip to step h.
If the pane that opens has the words "Search Companion" at the top, and the center looks similar to this picture:
[img]http://www.killanet.net/uploads/resetIE1.gif[/img]
click the Change preferences link as shown above. Proceed with step d.
Click the Change Internet search behavior link.
Under "Internet Search Behavior," click With Classic Internet Search.
Click OK. Then close Internet Explorer. (Close the program for the change to take effect.)
Start Internet Explorer. When the search pane opens, it should now look similar to this:
[img]http://www.killanet.net/uploads/resetIE.gif[/img]
Click the word Customize, and then proceed with the next step.
In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.
Do one of the following:
If you were using (or want to continue using) the "Classic Internet Search" panel, stop here (or proceed with the next section).
If you want to go back to the "Search Companion" search (it usually has an animated character at the button), proceed with step n.
Click the word Customize again.
In the "Customize Search Settings" window, click Use Search Companion > OK.
Close Internet Explorer. The next time you open it, it will again use the Search Companion.
[url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.h.html"]source[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]



