Page 5 of 9

Alerts

Posted: Fri Jul 30, 2004 5:17 am
by Tami
W32.Mydoom.N@mm
Discovered on: July 29, 2004
Last Updated on: July 30, 2004 12:19:14 PM

W32.Mydoom.N@mm is a variant of W32.Mydoom.M@mm. It also is a mass-mailing worm that drops and executes a backdoor detected as Backdoor.Zincite.A, which listens on TCP port 1034. The worm uses its own SMTP engine to send itself to email addresses it finds on the infected computer.


The email contains a spoofed From address, and the Subject and Body text will vary. The attachment name will also vary.

This threat is packed with ASPack.

Type: Worm
Infection Length: 35,328 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Uses its own SMTP engine to send itself to the email addresses found in the files with certain extensions.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: The dropped Backdoor allows unauthorized remote access.
Distribution

Subject of email: Varies
Name of attachment: Varies with .cmd, .bat, .com, .exe, .pif, .scr, or .zip file extension.n/a
Size of attachment: Varies
Time stamp of attachment: n/a
Ports: TCP 1034
Shared drives: n/a
Target of infection: n/a


When W32.Mydoom.N@mm runs, it do the following,


Creates one of the following registry keys, which mark the computer as infected:

HKEY_LOCAL_MACHINE\Software\Microsoft\Daemon
HKEY_CURRENT_USER\Software\Microsoft\Daemon


Copies itself as %Windir%\java.exe.

Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.


Drops and executes %Windir%\services.exe, which is detected as Backdoor.Zincite.A. When executed, this file opens TCP port 1034 and listens for remote connections. The backdoor will also probe random IP addresses on port 1034 looking for other infected hosts.


Adds the values:

"Services" = "%Windir%\services.exe"
"JavaVM" = "%Windir%\java.exe"

to one of the registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm and backdoor load when Windows starts.


May create the following files for logging purposes:

%Temp%\zincite.log
%Temp%\<randomly named file>.log


Gathers email addresses from files with the following extensions:

.adb
.asp
.dbx
.ht*
.php
.pl
.sht
.tbb
.tx*
.wab


Queries the following search engines to harvest additional email addresses for possible distribution:

search.lycos.com
search.yahoo.com
www.altavista.com
www.google.com


When the worm finds an open Outlook window, it will attempt to send itself to the email addresses that it found.

The email has the following characteristics:

From:
The From address will be spoofed.

Subject: (One of the following)

hello
hi
error
status
test
report
delivery failed
Message could not be delivered
Mail System Error - Returned Mail
Delivery reports about your e-mail
Returned mail: see transcript for details
Returned mail: Data format error

Body:
The content contained in the body of the email will vary, based on a number of text options. One of each of the phrases or words in brackets, separated by a "|", will appear:

Dear user {<recipient's email address>|of <recipient's email domain>},{ {{M|m}ail {system|server} administrator|administration} of <recipient's email domain> would like to {inform you{ that{:|,}|}|let you know {that|the following}{.|:|,}}|||||}
{We have {detected|found|received reports} that y|Y}our {e{-|}mail |}account {has been|was} used to send a {large|huge} amount of {{unsolicited{ commercial|}|junk} e{-|}mail|spam}{ messages|} during {this|the {last|recent}} week.
{We suspect that|Probably,|Most likely|Obviously,} your computer {had been|was} {compromised|infected{ by a recent v{iru}s|}} and now {run|contain}s a {trojan{ed|}|hidden} proxy server.
{Please|We recommend {that you|you to}} follow {our |the |}instruction{s|} {in the {attachment|attached {text |}file} |}in order to keep your computer safe.
{{Virtually|Sincerely} yours|Best {wishe|regard}s|Have a nice day},
{<recipient's email domain> {user |technical |}support team.|The <recipient's email domain> {support |}team.}

{The|This|Your} message was{ undeliverable| not delivered} due to the following reason{(s)|}:
Your message {was not|could not be} delivered because the destination {computer|server} was
{not |un}reachable within the allowed queue period. The amount of time
a message is queued before it is returned depends on local configura-
tion parameters.
Most likely there is a network problem that prevented delivery, but
it is also possible that the computer is turned off, or does not
have a mail system running right now.
Your message {was not|could not be} delivered within <random number> days:
{{{Mail s|S}erver}|Host} <host used to send the email>} is not responding.
The following recipients {did|could} not receive this message:
<<recipient's email address>>
Please reply to postmaster@{<sender's email domain>|<recipient's email domain>}
if you feel this message to be in error.

The original message was received at [current time]{
| }from {<sender's email domain> ]|{<host used to send the email>]|]}}
----- The following addresses had permanent fatal errors -----
{<<recipient's email address>>|<recipient's email address>}
{----- Transcript of {the ||}session follows -----
... while talking to {host |{mail |}server ||||}{<recipient's email domain>.|<host used to send the email>]}:
{>>> MAIL F{rom|ROM}:[From address of mail]
<<< 50$d {[From address of mail]... |}{Refused|{Access d|D}enied|{User|Domain|Address} {unknown|blacklisted}}|554 <<recipient's email address>>... {Mail quota exceeded|Message is too
large}
554 <<recipient's email address>>... Service unavailable|550 5.1.2 <<recipient's email address>>... Host unknown (Name server: host not found)|554 {5.0.0 |}Service unavailable; ] blocked using {relays.osirusoft.com|bl.spamcop.net}{, reason: Blocked|}
Session aborted{, reason: lost connection|}|>>> RCPT To:<<recipient's email address>>
<<< 550 {MAILBOX NOT FOUND|5.1.1 <<recipient's email address>>... {User unknown|Invalid recipient|Not known here}}|>>> DATA
{<<< 400-aturner; %MAIL-E-OPENOUT, error opening !AS as output
|}{<<< 400-aturner; -RMS-E-CRE, ACP file create failed
|}{<<< 400-aturner; -SYSTEM-F-EXDISKQUOTA, disk quota exceeded
|}<<< 400}|}

The original message was included as attachment

{{The|Your} m|M}essage could not be delivered

Notes:
<recipient's email address> is the email address of the person receiving the email.
<recipient's email domain> is the domain of the receiver's email. For instance, if the email address is john_doe@example.com, the domain is "example.com."
<sender's email domain> is the domain of the sender's email. For instance, if the email address is john_doe@example.com, the domain is "example.com."
<host used to send the email> is name of the email server used by the infected computer. The worm gathers this information from the infected computer's registry.


Attachment:
The worm may generate an file name from a domain name of an email address gathered from the computer. For instance, if the worm finds an address john_doe@example.com on the infected computer, the attachment name could contain example.com.

The attachment name may also be one of the following:

readme
instruction
transcript
mail
letter
file
text
attachment
document
message

with one of the following extensions:
.cmd
.bat
.com
.exe
.pif
.scr
.zip

the attachment may have a second extension, which will be one of the following:
doc
txt
htm
html

Notes:
Approximately 30% of the time, the attachment will be zipped. In these cases the attachment may be compressed several times over.
There is a 15% chance the worm will attach a small junk file to the mail instead of a copy of itself.


The worm will not send itself to addresses that contain the following strings:
mailer-d
spam
abuse
master
sample
accou
privacycertific
bugs
listserv
submit
ntivi
support
admin
page
the.bat
gold-certs
feste
not
help
foo
soft
site
rating
you
your
someone
anyone
nothing
nobody
noone
info
winrar
winzip
rarsoft
sf.net
sourceforge
ripe.
arin.
google
gnu.
gmail
seclist
secur
bar.
foo.com
trend
update
uslis
domain
example
sophos
yahoo
spersk
panda
hotmail
msn.
msdn.
microsoft
sarc.
syma
avp

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Mydoom.N@mm.
Reverse the changes made to the registry.

To reverse the changes made to the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.


Click Start > Run.
Type regedit

Then click OK.


Navigate to each of the following keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

In the right pane, delete the values if exist:

"Services" = "%Windir%\services.exe"
"JavaVM" = "%Windir%\java.exe"


Navigate to the keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Daemon
HKEY_CURRENT_USER\Software\Microsoft\Daemon

and delete them.


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.n@mm.html\"]Symantec Source[/url]

Alerts

Posted: Sat Jul 31, 2004 2:58 am
by Tami
Trojan.Download.Inor.C
Discovered on: July 29, 2004
Last Updated on: July 31, 2004 09:23:31 AM

Trojan.Download.Inor.C is a variant of Trojan.Downloader.Inor.and Trojan.Download.Inor.B. This Trojan spreads as an .hta file. When this file is executed, it creates and runs the file named C:\i.exe.

When i.exe runs, it tries to download a file from a Web site.

Trojan.Download.Inor.C may be received by email as an attachment or as a link to a Web site, which contains a CGI script that drops the Trojan.


Also Known As: VBS/Inor [McAfee]
Variants: Trojan.Downloader.Inor, Trojan.Download.Inor.B
Type: Trojan Horse
Infection Length: 4,164 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When Trojan.Download.Inor.C is executed, it performs the following actions:


Attempts to download Svchost.exe from a predetermined Web site. The file that it tries to download may vary.

Drops the file named C:\i.exe and then runs it. (This file name is the default, but it may vary.)

Moves Svchost.exe into C:\%Windir% and runs it.

Note: %Windir% is a variable. The Trojan locates the Windows® installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan, and delete all of the files that are detected as Trojan.Download.Inor.C.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.download.inor.c.html\"]Symantec Source[/url]

Alerts

Posted: Sat Jul 31, 2004 3:00 am
by Tami
W32.Bugbros.C@mm
Discovered on: July 29, 2004
Last Updated on: July 31, 2004 10:29:06 AM

W32.Bugbros.C@mm is a minor variant of W32.Bugbros.B@mm. It is a simple mass-mailing worm that sends itself to all of the addresses in the Microsoft® Outlook® Address Book. The email has the following characteristics:

Subject: New products
Attachment: Twunk_64.exe


Also Known As: Bloodhound.W32.VBWORM, I-Worm.generic [Kaspersky], W32/Generic.a@MM [McAfee

Type: Worm
Infection Length: 24,576 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows CE, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends itself to all the addresses in the Microsoft Outlook Address Book.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution

Subject of email: New products
Name of attachment: Twunk_64.exe
Size of attachment: 24,576 bytes
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When W32.Bugbros.C@mm runs, it performs the following actions:


Copies itself as C:\Windows\Twunk_64.exe. This path is hard-coded and does not depend on system variables.


Creates the following email message:

From: support@microsoft.com
Subject: New products
Message:

"Hi,
Update your Windows PC with Microsoft Windows Panel.This tool is free and provided by Microsoft. For more info read the disclaimer when you run the program.
bye"

Attachment: Twunk_64.exe

Sends the message to all the addresses in the Microsoft Outlook Address Book.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Bugbros.C@mm.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbros.c@mm.html\"]Symantec Source[/url]

Alerts

Posted: Sun Aug 01, 2004 4:53 pm
by Tami
Updated:

Removal Tool:

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom@mm.removal.tool.html\"]Clickety[/url]

Alerts

Posted: Thu Aug 05, 2004 10:09 am
by Tami
W32.Rotor
Discovered on: July 31, 2004
Last Updated on: August 02, 2004 01:59:16 PM

W32.Rotor is a virus that appends itself to .exe and .scr files and contains backdoor functionality.

Type: Virus
Infection Length: 5360 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows CE

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: Infects .exe and .scr files.
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Can act as a backdoor.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: May attempt outgoing connection on TCP port 382.
Shared drives: Infects files on drives C through Z and shared network resources.
Target of infection: .exe and .scr files.


When a file infected with W32.Rotor runs, the virus does the following:


Searches for files with .exe or .scr extensions on drives C through Z and shared network resources.


Infects a random number of the files that it finds, appending itself in a new section called ".txt".

Note: The virus avoids infecting system files, skipping folders with names that start with "WINN", such as the WINNT folder.


Injects backdoor code into the Program Manager process (Progman.exe), if it is running.

Note: Windows 2000 and XP do not use Program Manager by default.


Attempts to contact a remote server on TCP port 382.


If a connection is established, the virus opens a command shell on the infected computer.


Returns control to the host file, allowing the executable to run.


Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as W32.Rotor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.rotor.html\"]Symantec Source[/url]

Alerts

Posted: Thu Aug 05, 2004 10:13 am
by Tami
PWSteal.Perfectspy
Discovered on: August 02, 2004
Last Updated on: August 04, 2004 02:03:11 PM

PWSteal.Perfectspy is a Trojan horse that silently installs Spyware.Perfect with predefined settings. This Trojan may arrive as the email attachment, Visa_warning.exe.

Type: Trojan Horse
Infection Length: 393,192 Bytes

Systems Affected: Windows 2000, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Attempts to steal information from browser windows with banking-related titles.
Compromises security settings: Attempts to end the processes of security products.
Distribution

Subject of email: n/a
Name of attachment: May be Visa_warning.exe
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When PWSteal.Perfectspy is executed, it does the following:


Creates the following files in the C:\Documents and Settings\<user_name>\Local Settings\Temp\RarSFX0 folder:
Sk.bin
inst.dat
Ms.dat
Stitle.dat
IEXPLORERhk.dll
IEXPLORERwb.dll
IEXPLORER.EXE
Visa_warning.exe
Winst.exe


Executes Winst.exe, which in turn terminates security product processes, and decrypts IEXPLORER.EXE, IEXPLORERhk.dll, and IEXPLORERwb.dll by "XOR"ing every byte with the predefined hex byte, 9A.


Executes the decrypted IEXPLORER.EXE, which is Spyware.Perfect, with predefined settings that trigger the Trojan when windows, which have the following words in the title bar, are opened:
bank
Bank
BANK
banque
Banque
BANQUE
banc
Banc
BANC
Visa
VISA

and sends a keylog to a predefined email address.

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as PWSteal.Perfectspy or Spyware.Perfect.

Note: Only products that support Expanded threats will detect Spyware.Perfect.


Delete the value that was added to the registry.

To delete the value from the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete any values that refer to the files detected as PWSteal.Perfectspy or Spyware.Perfect.


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.perfectspy.html\"]Symantec Source[/url]

Alerts

Posted: Thu Aug 05, 2004 10:17 am
by Tami
W32.Saros@mm
Discovered on: August 02, 2004
Last Updated on: August 04, 2004 11:57:41 AM

W32.Saros@mm is a worm that propagates through email, MIRC, and file-sharing networks.

Also Known As: I-Worm.Saros.a [Kaspersky]


Infection Length: 48,514

Systems Affected: Windows 2000, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Microsoft IIS, Novell Netware, OS/2, UNIX, Windows 3.x

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Sends an email to all the addresses in the MS Outlook address book.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Lowers MS Outlook security settings.
Distribution

Subject of email: Microsoft Outlook News
Name of attachment: \WINDOWS\system32\MSOutlookInternetUpdate.exe
Size of attachment: 48,514
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When W32.Saros@mm is run, it performs the following actions:


Attempts to create the following files, which are copies of itself:
WINDOWS\system32\NonYou.exe
WINDOWS\system32\Love-ScreenSaver.scr
WINDOWS\system32\MSOutlookInternetUpdate.exe
progra~1\Kazaa\My Shared Folder\Rosy.exe
progra~1\Kazaa\My Shared Folder\Pipponoto.exe
progra~1\Kazaa\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Kazaa\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Kazaa\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Kazaa\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Kazaa\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Kazaa\My Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Kazaa\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Kazaa\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Kazaa\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Rosy.exe
progra~1\Kazaa Lite\My Shared Folder\Pipponoto.exe
progra~1\Kazaa Lite\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Kazaa Lite\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Rosy.exe
progra~1\Kazaa Lite K++\My Shared Folder\Pipponoto.exe
progra~1\Kazaa Lite K++\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Haiducii - Dragostea din tei.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Kazaa Lite K++\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\ICQ\Shared Folder\Rosy.exe
progra~1\ICQ\Shared Folder\Pipponoto.exe
progra~1\ICQ\Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\ICQ\Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\ICQ\Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\ICQ\Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\ICQ\Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\ICQ\Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\ICQ\Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\ICQ\Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\ICQ\Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\Grokster\My Grokster\Rosy.exe
progra~1\Grokster\My Grokster\Pipponoto.exe
progra~1\Grokster\My Grokster\Anastacia - Left Outside Alone.mp3.exe
progra~1\Grokster\My Grokster\The Rasmus - In The Shadows.mp3.exe
progra~1\Grokster\My Grokster\50 Cent - In da Club.mp3.exe
progra~1\Grokster\My Grokster\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Grokster\My Grokster\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Grokster\My Grokster\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Grokster\My Grokster\Raf - In tutti i miei giorni.mp3.exe
progra~1\Grokster\My Grokster\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Grokster\My Grokster\Lionel Richie - Just For You.mp3.exe
progra~1\Bearshare\Shared\Rosy.exe
progra~1\Bearshare\Shared\Pipponoto.exe
progra~1\Bearshare\Shared\Anastacia - Left Outside Alone.mp3.exe
progra~1\Bearshare\Shared\The Rasmus - In The Shadows.mp3.exe
progra~1\Bearshare\Shared\50 Cent - In da Club.mp3.exe
progra~1\Bearshare\Shared\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Bearshare\Shared\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Bearshare\Shared\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Bearshare\Shared\Raf - In tutti i miei giorni.mp3.exe
progra~1\Bearshare\Shared\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Bearshare\Shared\Lionel Richie - Just For You.mp3.exe
progra~1\eDonkey2000\Incoming\Rosy.exe
progra~1\eDonkey2000\Incoming\Pipponoto.exe
progra~1\eDonkey2000\Incoming\Anastacia - Left Outside Alone.mp3.exe
progra~1\eDonkey2000\Incoming\The Rasmus - In The Shadows.mp3.exe
progra~1\eDonkey2000\Incoming\50 Cent - In da Club.mp3.exe
progra~1\eDonkey2000\Incoming\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\eDonkey2000\Incoming\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\eDonkey2000\Incoming\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\eDonkey2000\Incoming\Raf - In tutti i miei giorni.mp3.exe
progra~1\eDonkey2000\Incoming\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\eDonkey2000\Incoming\Lionel Richie - Just For You.mp3.exe
progra~1\eMule\Incoming\Rosy.exe
progra~1\eMule\Incoming\Pipponoto.exe
progra~1\eMule\Incoming\Anastacia - Left Outside Alone.mp3.exe
progra~1\eMule\Incoming\The Rasmus - In The Shadows.mp3.exe
progra~1\eMule\Incoming\50 Cent - In da Club.mp3.exe
progra~1\eMule\Incoming\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\eMule\Incoming\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\eMule\Incoming\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\eMule\Incoming\Raf - In tutti i miei giorni.mp3.exe
progra~1\eMule\Incoming\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\eMule\Incoming\Lionel Richie - Just For You.mp3.exe
progra~1\Morpheus\My Shared Folder\Rosy.exe
progra~1\Morpheus\My Shared Folder\Pipponoto.exe
progra~1\Morpheus\My Shared Folder\Anastacia - Left Outside Alone.mp3.exe
progra~1\Morpheus\My Shared Folder\The Rasmus - In The Shadows.mp3.exe
progra~1\Morpheus\My Shared Folder\50 Cent - In da Club.mp3.exe
progra~1\Morpheus\My Shared Folder\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Morpheus\My Shared Folder\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Morpheus\My Shared Folder\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Morpheus\My Shared Folder\Raf - In tutti i miei giorni.mp3.exe
progra~1\Morpheus\My Shared Folder\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Morpheus\My Shared Folder\Lionel Richie - Just For You.mp3.exe
progra~1\LimeWire\Shared\Rosy.exe
progra~1\LimeWire\Shared\Pipponoto.exe
progra~1\LimeWire\Shared\Anastacia - Left Outside Alone.mp3.exe
progra~1\LimeWire\Shared\The Rasmus - In The Shadows.mp3.exe
progra~1\LimeWire\Shared\50 Cent - In da Club.mp3.exe
progra~1\LimeWire\Shared\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\LimeWire\Shared\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\LimeWire\Shared\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\LimeWire\Shared\Raf - In tutti i miei giorni.mp3.exe
progra~1\LimeWire\Shared\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\LimeWire\Shared\Lionel Richie - Just For You.mp3.exe
progra~1\Tesla\Files\Rosy.exe
progra~1\Tesla\Files\Pipponoto.exe
progra~1\Tesla\Files\Anastacia - Left Outside Alone.mp3.exe
progra~1\Tesla\Files\The Rasmus - In The Shadows.mp3.exe
progra~1\Tesla\Files\50 Cent - In da Club.mp3.exe
progra~1\Tesla\Files\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\Tesla\Files\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\Tesla\Files\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\Tesla\Files\Raf - In tutti i miei giorni.mp3.exe
progra~1\Tesla\Files\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\Tesla\Files\Lionel Richie - Just For You.mp3.exe
progra~1\WinMX\Shared\Rosy.exe
progra~1\WinMX\Shared\Pipponoto.exe
progra~1\WinMX\Shared\Anastacia - Left Outside Alone.mp3.exe
progra~1\WinMX\Shared\The Rasmus - In The Shadows.mp3.exe
progra~1\WinMX\Shared\50 Cent - In da Club.mp3.exe
progra~1\WinMX\Shared\Vanessa Carltron - Ordinary Day.mp3.exe
progra~1\WinMX\Shared\Haiducii - Dragostea Din Tei.mp3.exe
progra~1\WinMX\Shared\Black Eyed Peas - Hey Mama.mp3.exe
progra~1\WinMX\Shared\Raf - In tutti i miei giorni.mp3.exe
progra~1\WinMX\Shared\Vasco Rossi - Buoni e cattivi.mp3.exe
progra~1\WinMX\Shared\Lionel Richie - Just For You.mp3.exe


Creates the file, \WINDOWS\system32\About.hta, which is a harmless HTML file.


Displays the message:

Title: Microsoft Windows Update
Text: Click Yes For Update Microsoft Outlook via E-mail


Creates and runs the file, \WINDOWS\system32\nstdnrdll32.vbs. This VBScript file performs the following actions:

Creates the following registry keys:

"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce\wincomp32\default" = "WINDOWS\system32\nstdnrdll32.vbs
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\nldr32\default" = "WINDOWS\system32\NonYou.exe"
"HKEY_CURRENT_USER\Software\Microsoft\Office\8.0\Outlook\Security\Level1Remove", "exe" "HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Security\Level1Remove", "exe" "HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Security\Level1Remove", "exe"


Creates the archive file, \WINDOWS\system32\Love-ScreenSaver.cab, which contains a copy of the worm.

Checks the system date, and if the day of the month is the 11th or 23rd, it will change the Internet Explorer start page to www.gedzac.tk, and open the file \WINDOWS\system32\About.hta in a Web browser.


Sends an email to all the entries in the Microsoft Outlook Address Book.

The email will have the following properties:

Subject: Microsoft Outlook News
Message: Microsoft Outlook Update / Bug Fixed - Contact: support@microsoft.com
Attachment: \WINDOWS\system32\MSOutlookInternetUpdate.exe


Opens the Web site www.windowsupdate.com.


Adds the line:

n2 = tdll32.dll

to the [rfiles] section of the file, \Program Files\mIRC\mirc.ini.


Opens the file:

Program Files\mIRC\tdll32.dll

and writes an IRC script to send the file, Love-ScreenSaver.cab, to other MIRC users.


Checks the system date. If the day of the month is the 11th or 23rd, it will display two messages:

Title: NonYou
Text: Rosy Ti Amo - Saro & Rosy Forever

Title: Gedzac Group 2004
Text:
NonYou.a Gedzac Labs Productions
Coded by Sarosoft - Dedicated to my Love Ros
Gedzac Group 2004 - http:/ /www.gedzac.tk
Gedzac
The Virus Crew

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode.
Run a full system scan and delete all the files detected as W32.Saros@mm.
Delete the value that was added to the registry.

To delete the value from the registry

WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Delete the keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce\wincomp32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\nldr32


Navigate to the following registry keys:

"HKEY_CURRENT_USER\Software\Microsoft\Office\8.0\Outlook\Security
"HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Security
"HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Security


In the right pane, delete the value:

"Level1Remove"="exe"


Exit the Registry Editor.

Restart the computer in normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.saros@mm.html\"]Symantec Source[/url]

Alerts

Posted: Thu Aug 05, 2004 10:20 am
by Tami
W32.Korgo.AD
Discovered on: August 02, 2004
Last Updated on: August 03, 2004 01:58:07 PM

W32.Korgo.AD is a worm that attempts to spread by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (described in Microsoft Security Bulletin [url=\"http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx\"]MS04-011[/url]) on TCP port 445.

Also Known As: W32/Korgo.worm.gen [McAfee]

Type: Worm
Infection Length: 11,776 bytes

Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT
CVE References: CAN-2003-0533

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: Network propagation routines may degrade overall network performance.
Causes system instability: n/a
Releases confidential info: Backdoor functionality allows unauthorized access.
Compromises security settings: Backdoor functionality may compromise security settings.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 445 and a random port.
Shared drives: n/a
Target of infection: Unpatched computers vulnerable to the Microsoft LSASS Windows exploit.


When W32.Korgo.AD is executed, it does the following:


Deletes the file, ftpupd.exe, from the folder in which the worm was executed.


Creates the following mutexes to ensure that only one instance of the worm is executed on the computer:

uterm19-2
uterm20
u8
u9
u10
u10x
u11
u11x
u12
u12x
u13
u13i
u13x
u14
u14x
u15
u15x
u16
u16x
u17
u17x
u18
u18x
u19


Deletes the values:

"avserve.exe"
"avserve2.exeUpdate"
"Bot Loader"
"Disk Defragmenter"
"MS Config v13"
"Service"
"System Restore Service"
"SysTray"
"Windows Security Manager"
"Windows Update"
"Windows Update Service"
"WinUpdate"

from the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Copies itself as %System%\<random filename>.exe.

Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the values:

"Client"="1"
"ID"="<random value>"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless


Adds the value:

"Cryptographic Service"="%System%\<random filename>.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Attempts to inject a function into Explorer.exe as a thread.

If successful, this threat will continue to run in the Explorer.exe process. All of the worm's subsequent actions will appear to be done by Explorer.exe, and the worm will not show when viewing the process list in the Windows Task Manager.

If unsuccessful, the worm will continue to run as its own process.


Opens a random TCP port, which the worm uses to send itself.


The worm attempts to contact one of the following domains and run a PHP script, passing it information about the compromised host:

adult-empire.com
asechka.ru
citi-bank.ru
color-bank.ru
crutop.nu
cvv.ru
fethard.biz
filesearch.ru
kavkaz.tv
kidos-bank.ru
konfiskat.org
master-x.com
mazafaka.ru
parex-bank.ru
roboxchange.com
www.redline.ru
xware.cjb.net

Depending on the response from the remote site, the worm may attempt to download and execute a file from a specified location.


Attempts to exploit the LSASS Windows vulnerability on TCP port 445 (described in Microsoft Security Bulletin MS04-011), against random IP addresses. If the worm successfully finds a vulnerable computer, the computer will attempt to reconnect to the infected computer to download the worm.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Korgo.AD.
Reverse the changes made to the registry.

To reverse the changes made to the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.

Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Cryptographic Service"="%System%\<random filename>.exe"


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wireless


In the right pane, delete the values, if they exist:

"Client"="1"
"ID" = "<random value>"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.ad.html\"]Symantec Source[/url]

Alerts

Posted: Thu Aug 05, 2004 10:28 am
by Tami
W32.Gaobot.BAJ
Discovered on: August 02, 2004
Last Updated on: August 02, 2004 03:20:05 PM

W32.Gaobot.BAJ is a worm that spreads through open network shares and through backdoors that the Mydoom family of worms open. It allows attackers to access an infected computer using a predetermined IRC channel.

Type: Worm
Infection Length: 136,218 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Steals CD keys from a number of computer games.
Compromises security settings: Gives the creator backdoor access to the computer via IRC.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: Connects to an IRC server on port 6667.
Shared drives: Attempts to authenitcate and copy itself to computers with weak passwords.
Target of infection: n/a


When W32.Gaobot.BAJ is executed, it performs the following actions:


Copies itself to %System%\wmon32.exe.


--------------------------------------------------------------------------------
Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
--------------------------------------------------------------------------------


Adds one of the values:

"WSAConfiguration"="wmon32.exe"

to the registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

so that the worm executes every time Windows starts.


Connects to a remote IRC server on port 6667 and listens for commands from the remote attacker, including the following:

Download and execute files
Scan the network
List, stop, and start processes
Control the file system (Delete, create, and list files)
Launch Denial of Service (DoS) attacks
Perform port redirection
Steal system information and email it to the attacker


Scans for other computers on the network, attempting to connect to shared resources using a list of usernames and passwords. If successful, it attempts to copy itself to the remote computer.


Scans for computers that have been infected by Mydoom variants. If it finds any, it uses the backdoor installed by Mydoom to copy itself onto the computer.


Steals CD keys of the following computer games:

Command & Conquer Generals
FIFA 2003
Need For Speed Hot Pursuit 2
Soldier of Fortune II - Double Helix
Neverwinter
Rainbow Six III RavenShield
Battlefield 1942 Road To Rome
Project IGI 2
Counter-Strike
Unreal Tournament 2003
Half-Life

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Gaobot.BAJ.
Delete the value that was added to the registry.

To delete the value from the registry


--------------------------------------------------------------------------------
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
--------------------------------------------------------------------------------

Click Start, and then click Run. (The Run dialog box appears.)
Type regedit

Then click OK. (The Registry Editor opens.)


Navigate to the keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices


In the right pane, delete the values, if present:

"WSAConfiguration"="wmon32.exe"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.baj.html\"]Symantec Source[/url]

Alerts

Posted: Thu Aug 05, 2004 10:34 am
by Tami
W32.Evaman.C@mm
Discovered on: August 03, 2004
Last Updated on: August 05, 2004 10:30:46 AM

W32.Evaman.C@mm is a mass-mailing worm that sends HTTP Get requests to the Web site, email.people.yahoo.com, to obtain email addresses. It also retrieves the email addresses from Windows Address Book files and from the files with the extensions .adb, .asp, .cfg, .dbx, .dhtm, .eml, .htm, .html, .jse, .jsp, .mmf, .msg, .ods, .php, .pl, .sht, .shtm, .shtml, .tbb, .txt, .wab, and .xml.
W32.Evaman.C@mm uses its own SMTP engine to send itself to the email addresses that it finds.

The email will have one of these subjects:

SN: New secure mail
Secure delivery
failed transaction
Re: hello (Secure-Mail)
Re: Extended Mail
Delivery Status (Secure)
Re: Server Reply
SN: Server Status

This threat is compressed with UPX.

Also Known As: WORM_MYDOOM.O [Trend Micro], W32/Mydoom.q@MM [McAfee], W32/MyDoom-Q [Sophos], I-Worm.Mydoom.o [Kaspersky], W32/Mydoom.P.worm [Panda]

Type: Worm
Infection Length: 21,504 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.evaman.c.removal.tool.html\"]Removal Tool[/url]

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Emails itself to addresses found on a Yahoo website and found on the infected system.
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: May deactivate antivirus and/or desktop firewall applications on the infected system.
Distribution

Subject of email: SN: New secure mail Secure delivery failed transaction Re: hello (Secure-Mail) Re: Extended Mail Delivery Status (Secure) Re: Server Reply SN: Server Status
Name of attachment: mail message attachment transcript text document file readme followed by one of the following: .exe -txt.exe -htm.exe -txt.scr
Size of attachment: 21,504 bytes, vary for zip
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When W32.Evaman.C@mm runs, it does the following:


May create a mutex "Northernlightmixed," which allows only one instance of the worm to run in memory.


Launches Notepad.exe.


Copies itself as one of the following:

%System%\winlibs.exe
%Temp%\winlibs.exe

Notes:
%System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

%Temp% is a variable.


Creates one of the following registry keys, which the worm uses as an infection marker:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\winlibs

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\winlibs


Adds the value:

"winlibs.exe" = "%System%\winlibs.exe"

to one of these registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you start Windows.


Terminates the process if any of its module base names contain one of the following:

uba
mc
Mc
av
AV
cc
sym
Sym
nv
can
scn
java
xp.exe
ecur
nti
erve
sss
iru
ort
SkyNet
KV


Attempts to log off the current user, shut down the system, or shut down and restart the system, if the current system time is later than January 1, 2006.


Sends random HTTP Get requests to the Web site, email.people.yahoo.com:80, to retrieve the email addresses.


Retrieves the email addresses from WAB files.


Retrieves the email addresses from the files with the extensions .adb, .asp, .cfg, .dbx, .dhtm, .eml, .htm, .html, .jse, .jsp, .mmf, .msg, .ods, .php, .pl, .sht, .shtm, .shtml, .tbb, .txt, .wab, or .xml on the folders:

%Windir%\Temporary Internet Files
%USERPROFILE%\Local Settings\Temporary Internet Files
%System% folder on all fixed and RAM drives from C through Y


Uses its own SMTP engine to send itself to the addresses that it finds.

The email has the following characteristics:

From: This is spoofed. The sender name may be one of the following:

mike
jennifer
david
linda
susan
nancy
pamela
eric
kevin
mary
jessica
patricia
barbara
karen
sarah
robert
john
daniel
jason
joe

The domain name will be the recipient's domain name.

Subject: The subject is one of the following:

SN: New secure mail
Secure delivery
failed transaction
Re: hello (Secure-Mail)
Re: Extended Mail
Delivery Status (Secure)
Re: Server Reply
SN: Server Status


Attachment: This is composed of one of the following strings:

mail
message
attachment
transcript
text
document
file
readme

followed by one of the following:

.exe
-txt.exe
-htm.exe
-txt.scr
zip


Message: The message is in the format:

<recipient domain name> :: <part 1><recipient email address>.

<part 2>

<part3><recipient domain name>.

where:

<part 1> is one of the following:

Automatically Secure Delivery: for
Mail Delivery Server System: for
Extended secure mail message available at:
Secure Mail Server Notification: for
New mail secure method implement: for

<part 2> is one of the following:

New policy requested by mail server to returned mail
as a secure compiled attachment /zipped.gif\' class=\'bbc_emoticon\' alt=\'(zip)\' />.
Now a new message is available as secure Zip file format.
Due to new policies on clients.
This message is available as a secure Zip file format
due to a new security policy.
For security measures this message has been packed as Zip format.
This is a newly added security feature.
New policy recommends to enclose all messages as Zip format.
Your message is available in this server notice.
You have received a message that implements secure delivery technology.
Message available as a secure Zip file.

<part 3> is one of the following:

This message is an automatically server notice
from Administration at
Server Notice: New security feature added. MSG:ID: 455sec86
from
New feature added for security reasons
from
Automatically server notice:,
Server reply from
New service policy for security added from


The worm does not send itself to the email addresses that contain any of the following:

.edu
Bug
ugs
bug
upport
ICROSOFT
icrosoft
oot
dmin
ymant
avp
ecur
@MM
ebmast
help
opho
inpris
omain
senet
panda
32.
@mm
msn
inux
umit
nfo
irus
buse
orton
cafee
spam
Spam
SPAM
ntivi
eport
user
inzip
inrar
rend
pdate
USER
ating
ample
ists
persk
ccoun
ompu
msdn
YOU
you
oogle
arsoft
otmail
sarc
soft
ware
.gov
.mil
cribe
list
eturn
omment
Sale
sale
CRIBE
gmail
ruslis
ibm
win

Removal Instructions:

Removal using the W32Evaman.C@mm Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of W32.Evaman.C@mm. Use this removal tool first, as it is the easiest way to remove this threat.

Manual Removal
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Evaman.C@mm.
Delete the values that were added to the registry.

To delete the values from the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.

Type regedit

Then click OK.


Navigate to each of the following keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value if it exists:

"Winlibs.exe"="%System%\Winlibs.exe"


Navigate to and delete the keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Winlibs

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Winlibs


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.evaman.c@mm.html\"]Symantec Source[/url]

Alerts

Posted: Thu Aug 05, 2004 10:26 pm
by Tami
W32.Myfip.A
Discovered on: August 04, 2004
Last Updated on: August 05, 2004 02:53:05 PM

W32.Myfip.A is a network-aware worm that steals files from infected computers.

Type: Worm
Infection Length: 24,500 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX


Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: Gathers and uploads .pdf files to an FTP server.
Compromises security settings: n/a
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: Copies itself to network shares.
Target of infection: n/a


When W32.Myfip.A is executed, it performs the following actions:


Creates the mutex "fjsy", so that only one version of the worm is executed on the computer.


Copies itself as Dfsvc.exe into the %System% folder.


Uses FTP to download a file, named ip.domain, from the domain net918.meibu.com.

This file contains a server name, username, and password used to access another FTP server.


Adds a value:

"Distributed File System"="Dfsvc.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm starts when Windows starts.


Searches the local computer for network directories. If the worm finds a network directory, it attempts to copy itself to the remote computer as Iloveyou.txt.exe. If the network directory requires authentication, the worm will attempt to connect as "Administrator", using one of the following passwords:

!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
###
***
@#$%^&
@@@
000000
00000000
0007
007
007007
0246
0249
111
123
1234
12345
123456
1234567
12345678
123456789
1a2b3c
1p2o3i
1q2w3e
1qw23e
1sanjose
2004
2222
369
4444
4runner
54321
654321
777
7777
888888
911
99999999
a12345
a1b2c3
a1b2c3d4
aaa
aaaaaa
abby
abc
abc123
abcd
abcd1234
abcde
abcdef
abcdefg
access
access
action
active
adam
adg
adm
adm
admin
Admin
admin123
admin123456
administrator
Administrator
administrator
administrator123
administrator123456
administratorpasswd
adminpasswd
adminpasswd
adminpwd
asdf
asdfg
asdfgh
asdfghjk
asdfjkl
asdfjkl;
bill
bin
daemon
dgj
doc
fgh
free
freedom
/censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' />
fuckyou
god
guest
hacker
job
kim
love
loveyou
lp
morris
mp3
mypass
mypass123
mypc
mypc123
newpass
nice
noaccess
nobody
parol
pass
passwd
Passwd
password
Password
pentium
pizza
planet
playboy
ppp
pw123
pwd
qwerty
root
rose
sex
sexy
/censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' />
shotgun
sos
spirit
spring
sprite
ssssss
storm
super
superman
support
sys
telecom
temp
test
test1
test123
upload
warez
xxx
xxxx
ytrewq
zxcvb
zxcvbnm


If the worm successfully connects to the network directory, it attempts to create following files:

\\Admin$\system32\temp.txt
\\Admin$\system32\Dfsvc.exe
\\Admin$\system32\dltksvc.exe


Registers the dltksvc.exe file as a service named "Distributed Link Tracking Extensions", which runs Dfsvc.exe with Administrator privileges.


Searches for .pdf files and sends them to the FTP server referenced in the file, ip.domain.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Myfip.A.
Delete the value that was added to the registry.

To delete the value from the registry


Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"Distributed File System"="Dfsvc.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.myfip.a.html\"]Symantec Source[/url]

Alerts

Posted: Thu Aug 05, 2004 10:29 pm
by Tami
Backdoor.Brador.A
Discovered on: August 05, 2004
Last Updated on: August 05, 2004 11:11:50 AM

Backdoor.Brador.A is the first Windows CE (Pocket PC) backdoor Trojan horse. The backdoor sends the IP address of the infected handheld to the attacker and opens TCP port 2989. The backdoor will work on Windows CE 2.0 or later.

The backdoor only affects ARM-based devices.

Type: Trojan Horse
Infection Length: 5632 bytes

Systems Affected: Windows CE
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

Damage

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: n/a
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Sends the attacker the IP address of the infected handheld.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: TCP port 2989
Shared drives: n/a
Target of infection: n/a


When Backdoor.Brador.A is launched, it performs the following actions:


Copies itself to Windows/StartUp/Svchost.exe (5632 bytes) so that it starts when Windows starts.


Continually attempts to send the attacker the IP address of the handheld by email until it succeeds.


Opens TCP port 2989 and waits for further instructions from the attacker.


Allows the attacker to remotely perform the following commands:

list the directory contents
upload a file
display a message box
download a file
execute the specified command

Removal Instructions:

Update the virus definitions.
Run a full system scan and delete all the files detected as Backdoor.Brador.A.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.brador.a.html\"]Symantec Source[/url]

Alerts

Posted: Mon Aug 09, 2004 7:08 am
by Tami
W32.Lovgate.AN@mm
Discovered on: August 07, 2004
Last Updated on: August 07, 2004 01:32:50 PM

W32.Lovgate.AN@mm is a mass mailing worm that propagates through open network shares and using the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (BID 8205). It prepends itself to .exe files.

Type: Worm
Infection Length: 129,536 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: Linux, Macintosh OS X, Novell Netware, OS/2, UNIX

Damage:

Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Yes
Deletes files: n/a
Modifies files: n/a
Degrades performance: Propagation through network shares may degrade network performance.
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: Installs backdoor component.
Distribution

Subject of email: n/a
Name of attachment: n/a
Size of attachment: n/a
Time stamp of attachment: n/a
Ports: n/a
Shared drives: n/a
Target of infection: n/a


When W32.Lovgate.AN@mm is run it does the following:


The worm creates a network share, "JAVA" which is mapped to "%Windir%\JAVA" It copies itself to all network shared folders using one or more of the following names:WinGate V5.0.10 Build.exe

WINISO 5.3.exe
Winamp skin_FinalFantasy.exe
i386.exe
Serv-U FTP Server 4.1.exe
Daemon Tools v3.41.exe
autoexec.bat
Windows 2000 sp4.ZIP.exe
Flash2X Flash Hunter v1.1.2.pif
Minilyrics_Std_2.7.233.pif
Support Tools.exe
Windows Media Player.zip.exe
Microsoft Office.exe
eMule-0.42e-VeryCD0407Install.exe
FoxMail V5.0.500.0.exe
EnterNet 500 V1.5 RC1.exe


When the worm is executed, it creates the following files:

%Windir%\Office.exe
%Windir%\Video.EXE
%System%\hxdef.exe
%System%\IEXPLORE.EXE
%System%\iexplorer.exe
%System%\real.exe
%System%\TkBellExe.exe
%System%\Update_OB.exe
%System%\Kernel66.dll, which is a hidden file.


The following files are also created which make up the worm's back door component:

%System%\msjdbc11.dll
%System%\MSSIGN30.DLL
%System%\ODBC16.dll
%System%\Lmmib20.dll


Next the worm will create upDate.exe in the root folder of all drives, except CDROM drives. The file attributes are set to system, hidden, and read_only.


The worm overwrites autorun.inf on each of these drives with the lines

[AUTORUN]
Open="C:\upDate.exe" /StartExplorer


The worm then creates an archive containing a copy of the worm with the following format in the root folder of all drives, unless the drive letter is A or B:

<filename>.RAR

Where <filename> may be one of the following:

Bakeup
ghost
email


It then creates the following registry entries so that it executes every time Windows starts:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"Microsoft Inc." = "iexplorer.exe..."
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"Program In Windows" = "%system%\IEXPLORE.EXE"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"WinHelp" = "%system%\TkBellExe.exe..."
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\runServices\"SystemTra" = "C:\WINDOWS\Video.EXE"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\"Soft Profile Inc" = "%system%\hxdef.exe..."
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\"Installed shell32.dll" = "Office.exe..."
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\"run" = "real.exe"
HKEY_CLASSES_ROOT\txtfile\shell\open\command\(Default) = "Update_OB.exe %1..."


The worm stops the following services:

Rising Realtime Monitor Service
Symantec AntiVirus Server
Symantec AntiVirus Client


The worm also terminates any processes with the following strings in their names:

rising
SkyNet
Symantec
McAfee
Gate
Rfw.exe
RavMon.exe
kill
NAV
Duba
KAV
KV


It scans all the drives, if the drive type is removable, mapped, or the drive type is fixed with a drive letter greater than E, it does the following on all the drives found:

Attempt to rename the extension on all the .exe files to .zmx.
Set the attributes to Hidden and System on these files.
Copy itself as the original file name.


Next the worm will inject a process-watching procedure as a thread into either Explorer.exe or Taskmgr.exe. This thread will attempt to launch %System32%\Iexplore.exe if it detects that the worm process has stopped.


The worm will then listen on port 6000. The backdoor procedures steal information of a compromised system and store it in the file, C:\Netlog.txt. The worm then emails the stolen information to the hacker.


Next the worm will extract the location of the KaZaA shared folder from the system registry. It will then create a copy of itself in the KaZaA shared folder as one of the following (with a .bat, .exe, .pif, or .scr file extension):

wrar320sc
REALONE
BlackIcePCPSetup_creak
Passware5.3
word_pass_creak
HEROSOFT
orcard_original_creak
rainbowcrack-1.1-win
W32Dasm
setup
<random file name>


Next the worm will scan all of the computers attached to the same network segment as the compromised system, the worm will attempt to authenticate to administrative shares on systems that are found, using the "Administrator" username combined with the following passwords:

Guest
Administrator
zxcv
yxcv
zzz
win
test123
test
temp123
temp
sybase
super
sex
secret
pwd
pw123
Password
owner
oracle
mypc123
mypc
mypass123
mypass
love
login
Login
Internet
home
godblessyou
god
enable
database
computer
alpha
admin123
Admin
abcd
aaa
88888888
2600
2004
2003
123asd
123abc
123456789
1234567
123123
121212
11111111
110
7
0
0
pass
54321
12345
password
passwd
server
sql
!@#$%^&*
!@#$%^&
!@#$%^
!@#$%
asdfgh
asdf
!@#$
1234
111
root
abc123
12345678
abcdefg
abcdef
abc
888888
666666
111111
admin
administrator
guest
654321
123456
321
123


If the worm successfully authenticates to a remote system, it will attempt to copy itself as:

\\<remote computer name>\admin$\system32\TelePhone.exe


It will then start the file as the service, "NetWork Associates Inc." which is mapped to "TelePhone.exe -exe_start."


The worm replies to any messages that arrive in the mailbox of certain MAPI-compliant email clients, which include Microsoft Outlook. For example, if the incoming email has the following properties:

Subject: <subject>
From: <sender>@<domain.com>
Message: <original message body>


The worm will attempt to send the following email:

Subject: Re: <subject>
To: <sender>@<domain.com>

Message body:
'<sender>' wrote:
====
> <original message body>
====

<domain.com> account auto-reply:

... ... more details,look to the attachment.

> Get your FREE <domain.com> account now! <


The attachment is one of the following:

MacroMedia.pif
Butterfly Garden.scr
Matrix Reloaded 3D.exe
s3msong.MP3.pif
MyIE.AVI.pif
WindowsXP Creak.exe
Macromedia Flash.scr
Photoshop.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
HyperSnap-DX v5.rar.exe
joke.exe
MSN Messenger.exe
FlashFXP.exe


The worm traverses the hard disk.

When it finds a .exe, it creates a viral file in %system%\temp.uuu and prepends this file as a virus to the .exe file.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Reverse the changes made to the registry.

Reversing the changes made to the registry

Before continuing, Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. For instructions, read the document, "How to make a backup of the Windows registry."

Click Start, and then click Run. (The Run dialog box appears.)
Type regedit

Then click OK. (The Registry Editor opens.)

Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\runServices\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\
HKEY_CLASSES_ROOT\txtfile\shell\open\command\


In the right pane, delete the values:

"Microsoft Inc." = "iexplorer.exe..."
"Program In Windows" = "%system%\IEXPLORE.EXE"
"Protected Storage" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"VFW Encoder/Decoder Settings" = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg..."
"WinHelp" = "%system%\TkBellExe.exe..."
"SystemTra" = "C:\WINDOWS\Video.EXE"
"Soft Profile Inc" = "%system%\hxdef.exe..."
"Installed shell32.dll" = "Office.exe..."
"run" = "real.exe"
(Default) = "Update_OB.exe %1..."


Exit the Registry Editor.

Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Lovgate.AN@mm.

Rename the .zmx files to the .exe files.

Renaming the .zmx files to the .exe files
As W32.HLLW.Lovgate.AN@mm modifies the .exe files, correct this for relevant programs to function correctly.

Follow the instructions for your operating system:

Windows 98/Me/2000

On the Windows desktop, click the Start button > Find or Search > Files or Folders.
In the Search Results window, set "Look in" to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Check "Include subfolders."
In the "Named" or "Search for..." box, type, or copy and paste, the following:

*.zmx


Click Find Now or Search Now.


Windows XP

On the Windows desktop, click the Start button > Search.
Click All files and folders.
In the "All or part of the file name" box, type, or copy and paste, the following:

*.zmx


Verify that "Look in" is set to the first removable, mapped, or fixed drive type with a drive letter greater than E.
Click "More advanced options."
Select "Search system folders."
Select "Search subfolders."
Select "Search hidden files and folders."
Click Search.


For every file that is found, right click it, select "Rename," and then change the .zmx extension to .exe.


Repeat step 6 for every removable, mapped, or fixed drive type with a drive letter greater than E.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.lovgate.an@mm.html\"]Symantec Source[/url]

Alerts

Posted: Mon Aug 09, 2004 7:14 am
by Josh
/shocking.gif\' class=\'bbc_emoticon\' alt=\'(ack)\' /> /shocking.gif\' class=\'bbc_emoticon\' alt=\'(ack)\' /> /shocking.gif\' class=\'bbc_emoticon\' alt=\'(ack)\' /> /shocking.gif\' class=\'bbc_emoticon\' alt=\'(ack)\' /> /shocking.gif\' class=\'bbc_emoticon\' alt=\'(ack)\' /> uhhh Wow..

~Josh /sp_ike.gif\' class=\'bbc_emoticon\' alt=\'(spike)\' />

Alerts

Posted: Mon Aug 09, 2004 7:23 am
by Vercz
[color=\"green\"]creepy :| [/color]