Page 7 of 9

Alerts

Posted: Thu Aug 19, 2004 2:11 pm
by Tami
PWSteal.Bancos.K
Discovered on: August 17, 2004
Last Updated on: August 18, 2004 02:43:35 PM

PWSteal.Bancos.K is a Trojan horse that mimics the online interfaces of certain Brazilian banks and attempts steal account information.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Microsoft IIS, Novell Netware, OS/2, UNIX

When the Trojan is executed, it performs the following actions:


Adds the value:

"winzip"="<path to trojan>"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan starts when Windows starts.


Monitors the active Internet Explorer windows, waiting for a Web page to be opened that matches the characteristics of certain banking sites. When such a site is opened, the Trojan displays one of several login screens, which are selected according to the URL or HTML page title.

If the Web page title is "Bradesco", it will display:

[img]http://www.killanet.net/uploads/pwsteal.bancos3.gif[/img]

If the Web page title is "Gerenciador Financeiro", it will display:

[img]http://www.killanet.net/uploads/pwsteal.bancos4.gif[/img]

If the Web page title is "Internet Banking CAIXA", it will display:

[img]http://www.killanet.net/uploads/pwsteal.bancos5.gif[/img]

If the URL is https:/ /www2.bancobrasil.com.br/aapf/aai/login.pbk, it will display:

[img]http://www.killanet.net/uploads/pwsteal.bancos6.gif[/img]

If the URL is https:/ /bankline.itau.com.br/GRIPNET/gracgi.exe, it will display:

[img]http://www.killanet.net/uploads/pwsteal.bancos7.gif[/img]

Sends the information entered into the form to a remote attacker via email.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as PWSteal.Bancos.K.
Reverse the changes made to the registry.

Click Start, and then click Run. (The Run dialog box appears.)
Type regedit

Then click OK. (The Registry Editor opens.)


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"winzip"="<path to trojan>"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.k.html\"]source[/url]

Alerts

Posted: Thu Aug 19, 2004 2:15 pm
by Tami
X97M.Ainesey.B
Discovered on: August 17, 2004
Last Updated on: August 18, 2004 03:45:59 PM

X97M.Ainesey.B is a macro virus that infects Microsoft Excel workbooks.

Type: Virus
Infection Length: 52,736 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

When the virus is executed, it performs the following actions:


Searches all open Microsoft Excel workbooks and infects all worksheets.


Modifies the following values:

"Level"="1"
"DontTrustInstalledFiles"="0"

in the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Excel\Security

which lowers the security settings of Microsoft Excel 9.0.


Modifies the following values:

"Level"="1"
"DontTrustInstalledFiles"="0"
"AccessVBOM"="1"

in the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security

which lowers the security settings of Microsoft Excel 10.0.


Creates a corrupted file named MSIEXEC32.EXE in the %Windir% folder and tries to execute it.

Note:
Due to bugs in the code, the file will not successfully execute.
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.


Infects the Personal.xls file, so that the virus loads each time a Microsoft Excel workbook is opened.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as X97M.Ainesey.B.
Restore the security settings in Microsoft Excel.

Restoring security settings in Microsoft Excel

Start the Microsoft Excel application.


Click on the menu:

Tools -> Macro -> Security...


Choose the appropriate security level:

[img]http://www.killanet.net/uploads/excelrestore.gif[/img]


Exit the Excel application.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/x97m.ainesey.b.html\"]source[/url]

Alerts

Posted: Thu Aug 19, 2004 2:18 pm
by Tami
W32.Neveg.B@mm
Discovered on: August 17, 2004
Last Updated on: August 17, 2004 03:46:46 PM

W32.Neveg.B@mm is a mass-mailing worm that performs denial of service (DoS) attacks on various web design Web sites.

The worm replicates via email, using its own SMTP engine, and also spreads through shared folders.

Also Known As: W32/Neveg.b@MM (McAfee)

Type: Worm
Infection Length: 51,270 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows CE

Technical Details:

When W32.Neveg.B@mm is executed, it performs the following actions:


Creates a mutex named "4D36E64A-W325-121E-BFC1-080C2BE11318", to ensure the only one instance of the worm runs in the computer.


Copies itself as %Windir%\system\services.exe.

Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.


Adds the one of the following values:

".Prog" = "%Windir%\system\services.exe"
"BuildLab" = "%Windir%\system\services.exe"
"ccApps" = "%Windir%\system\services.exe"
"FriendlyTypeName" = "%Windir%\system\services.exe"
"Microsoft Visual SourceSafe" = "%Windir%\system\services.exe"
"RegDone" = "%Windir%\system\services.exe"
"TEXTCONV" = "%Windir%\system\services.exe"
"WMAudio" = "%Windir%\system\services.exe"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you start the Windows.

Searches for the email addresses in files with the following extensions, saving them in %System%\Setup32ea.bak:

.hlp
.xml
.xls
.wsh
.wab
.vbs
.uin
.txt
.tbb
.stm
.shtm
.sht
.rtf
.pl
.php
.oft
.ods
.nch
.msg
.mmf
.mht
.mdx
.mbx
.jsp
.html
.htm
.eml
.dhtm
.dbx
.cgi
.cfg
.asp
.adb


The worm avoids sending email to the addresses that contain the following strings:

.gbl
symant
norton
@mcaf
openbsd
freebsd
gnu.
.gov
.mil
microso
kaspers


Uses its own SMTP engine to send itself as an attachment to mail messages with one of the following names:

office.exe
notes.exe
doom3demo.exe
resume.exe
files.exe
request.exe
info.exe
details.exe
result.exe
results.exe
install.exe
setup.exe
test.exe
google.exe
se_files.exe


Performs a DoS attack on the following Web sites:

www.hvr-systems.cc
www.real-creative.de
www.2rebrand.com
www.designload.com
www.designgalaxy.net
www.procartoonz.com
www.designload.net

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Neveg.B@mm.
Reverse the changes made to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete any of these values:

".Prog" = "%Windir%\system\services.exe"
"BuildLab" = "%Windir%\system\services.exe"
"ccApps" = "%Windir%\system\services.exe"
"FriendlyTypeName" = "%Windir%\system\services.exe"
"Microsoft Visual SourceSafe" = "%Windir%\system\services.exe"
"RegDone" = "%Windir%\system\services.exe"
"TEXTCONV" = "%Windir%\system\services.exe"
"WMAudio" = "%Windir%\system\services.exe"


Exit the Registry Editor.

Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.b@mm.html\"]source[/url]

Alerts

Posted: Thu Aug 19, 2004 2:26 pm
by Tami
W32.Beagle.AP@mm
Discovered on: August 17, 2004
Last Updated on: August 19, 2004 02:16:18 PM

W32.Beagle.AP@mm is a mass-mailing worm that spreads via email, using its own SMTP engine.

Also Known As: WORM_BAGLE.AJ (Trend Micro)

Type: Worm

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

When the worm is executed, it performs the following actions:


Creates the following copies itself in the %System% folder:

drvddll.exe
drvddll.exeopen
drvddll.exeopenopen
drvddll.exeopenopenopen

Notes:
The above files may be zipped.
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds the following value:

"drvddll.exe" = "%System%\drvddll.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm starts when Windows starts.


Displays the following fake error message:

Error
Can't find a viewer associated with the file

Terminates the following processes:

AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET.EXE
CFINET32.EXE
CFINET32.EXE
CLEAN.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMGRDIAN.EXE
CMON016.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
drvsys.exe
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE


Attempts to run a PHP script, located on one of the following domains, to notify the attacker of infection:

2udar.ligakvn.de
3treepoint.com
abakan.strana.de
andimeisslein.de
ditec.um.es
fotos.schneider.bards.de
hardvision.ru
jakimov.golos.de
markusgimenez.de
mhv24.de
s318.evanzo-server.de
Spaceclub.de
tobimayer.de
vg.xtonne.de
vg.xtonne.de
villakinderbunt.de
virtualzone.de
www.ac-schnitzer.de
www.auma.de
www.autoscout24.de
www.avh.de
www.beckers-systems.de
www.berlinale.de
www.blauer-engel.de
www.bmbf.de
www.bruecke-osteuropa.de
www.bundesregierung.de
www.chugai.de
www.cicv.fr
www.dalnoboyshik.de
www.de-bug.de
www.degruyter.de
www.deutsch-als-fremdsprache.de
www.deutsches-museum.de
www.deutschland.de
www.dfg.de
www.documenta.de
www.dwd.de
www.embl-heidelberg.de
www.emis.de
www.eumetsat.de
www.exactaudiocopy.de
www.fernuni-hagen.de
www.fiz-karlsruhe.de
www.fracht-24.de
www.fu-berlin.de
www.gdch.de
www.go-amman.de
www.goethe.de
www.gospel-nations.de
www.gsi.de
www.hamann-motorsport.de
www.hamburg.de
www.heise.de
www.hotel-pension-spree.de
www.ifdesign.de
www.insel-ruegen-hotel.de
www.intermatgmbh.de
www.jura.uni-sb.de
www.kliniken.de
www.leipziger-messe.de
www.loveparade.de
www.low-spirit.de
www.mdz-moskau.de
www.mitsubishi-evs.de
www.mitsumi.de
www.mk-motorsport.de
www.mobile.de
www.nabu.de
www.neformal.de
www.neznakomez.de
www.paromi.de
www.partner-inform.de
www.php-resource.de
www.pri-wo-hamburg.de
www.red-dot.de
www.restarted-alliance.de
www.ruletka.de
www.russische-botschaft.de
www.siegenia-aubi.com
www.spiegel.de
www.sprach-zertifikat.de
www.teac.de
www.tecchannel.de
www.tekeli.de
www.tib.uni-hannover.de
www.turism.de
www.uni-oldenburg.de
www.uni-stuttgart.de
www.welt.de
www.windac.de
www.winfuture.de
www.www.mirko-becker.gmxhome.de

Creates the following mutexes to prevent Netsky variants from executing:

MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_


Searches for folders containing the string "shar" and drops a copy of itself to any folders found, using one of the following file names:

Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral, /censored.gif\' class=\'bbc_emoticon\' alt=\'(cens)\' /> cool, awesome!!.exe
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe

Sends itself to the email addresses that it gathers from the files with the following extensions:

.wab
.txt
.msg
.htm
.shtm
.stm
.xml
.dbx
.mbx
.mdx
.eml
.nch
.mmf
.ods
.cfg
.asp
.php
.pl
.wsh
.adb
.tbb
.sht
.xls
.oft
.uin
.cgi
.mht
.dhtm
.jsp

The worm will not send itself to the addresses containing the following strings:

@microsoft
rating@
f-secur
news
update
anyone@
bugs@
contract@
feste
gold-certs@
help@
info@
nobody@
noone@
kasp
admin
icrosoft
support
ntivi
unix
bsd
linux
listserv
certific
sopho
@foo
@iana
free-av
@messagelab
winzip
google
winrar
samples
abuse
panda
cafee
spam
pgp
@avp.
noreply
local
root@
postmaster@


The email message that the worm constructs typically has the following properties:

From: <spoofed>

Subject: (Blank or one of the following)
Re: Msg reply
Re: Hello
Re: Yahoo!
Re: Thank you!
Re: Thanks /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
RE: Text message
Re: Document
Incoming message
Re: Incoming Message
RE: Incoming Msg
RE: Message Notify
Notification
Changes..
New changes
Hidden message
Fax Message Received
Protected message
RE: Protected message
Forum notify
Site changes
Re: Hi
Encrypted document


Body: (One of the following)

For security reasons attached file is password protected. The password is [bitmap image]
For security purposes the attached file is password protected. Password -- [bitmap image]
Note: Use password [bitmap image] to open archive.
Attached file is protected with the password for security reasons. Password is [bitmap image]
In order to read the attach you have to use the following password: [bitmap image]
Archive password: [bitmap image]
Password - [bitmap image]
Password: [bitmap image]

Attachment: (Composed of one of the following strings)

Information
Details
text_document
Readme
Document
Info
the_message
Details
MoreInfo
Message
You_will_answer_to_me
Half_Live
Counter_strike
Loves_money
the_message
Alive_condom
Joke
Toy
Nervous_illnesses
Manufacture
You_are_dismissed

with one of the following extensions:

.exe
.scr
.com
.zip
.vbs
.hta
.cpl


Opens a backdoor on an infected computer, listening on a random port. The backdoor will give the remote attacker the ability to:

Download and execute a file on an infected computer
Update the malware
Uninstall the malware

11. The worm may drop.vbs and .html files. They are detected as W32.Beagle.X@mm with Symantec AntiVirus products.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as W32.Beagle.AP@mm.
Reverse the changes made to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"drvddll.exe" = "%System%\drvddll.exe"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ap@mm.html\"]source[/url]

Alerts

Posted: Thu Aug 19, 2004 2:29 pm
by Tami
Trivial.818
Discovered on: August 18, 2004
Last Updated on: August 19, 2004 09:27:24 AM

Trivial.818 is a DOS virus that overwrites the first 818 bytes of .com and .exe files, preventing them from running correctly

Type: Virus

Systems Affected: Windows 95, Windows 98, Windows Me
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 2000, Windows NT, Windows XP

Technical Details:

When Trivial.818 is executed, it does the following:


Finds all .com and .exe files that are in the same directory as the virus.

Overwrites the first 818 bytes of these files with itself.

Infects .com and .exe files that are in directories that are above the one containing the virus.

Removal Instructions:

Update the virus definitions.
Run a full system scan and delete all the files detected as Trivial.818.
When all the infected files have been deleted, restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trivial.818.html\"]source[/url]

Alerts

Posted: Sat Aug 21, 2004 7:10 am
by Tami
Trojan.Sconato
Discovered on: August 19, 2004
Last Updated on: August 20, 2004 03:24:42 PM

Trojan.Sconato is a Trojan horse program that installs a Browser Helper Object (BHO). The installed BHO captures keystrokes and emails them to the attacker.

This Trojan is packed with UPX.


Also Known As: Keylog-Sconato [McAfee], TROJ_SCONATO.A [Trend], Troj/Sconato-A [Sophos], Trj/Sconato.A [Panda], Trojan.Win32.Sconato.a [Kaspersky]

Type: Trojan Horse
Infection Length: 28,160 bytes, 28,672 bytes, 8,704 bytes



Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, OS/2, UNIX

Technical Details:

When Trojan.Sconato is executed, it performs the following actions:


Creates the following file, which captures keystrokes:

%System%\winmgmt.dll (8,704 bytes)

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the following file, which emails the data captured by winmgmt.dll to a Russian email address

%System%\sysconnect.dll (28,672 bytes)


Creates one of the following Microsoft Word files:

C:\Documents and Settings\<Username>\Local Settings\Temp\#3004-19-07-2004.doc (38,400 bytes)
C:\Documents and Settings\<Username>\Local Settings\Temp\nato.doc


Adds the value:

"(Default)"="%System%\sysconnect.dll"

to the registry key:

HKEY_CLASSES_ROOT\CLSID\{%CLSID%}\InProcServer32

Note: %CLSID% is a variable that refers to the CLSID hex value the Trojan creates.


Adds the value:
"SysConnect"="{%CLSID%}"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad


Adds the value:

"InstallerParameters"=<hex number>

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Sconato.
Delete the value that was added to the registry.

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad


In the right pane, take note of the value of %CLSID%, which is a variable that refers to the CLSID hex value the Trojan creates.

delete the value:

"SysConnect"="{%CLSID%}"


Navigate to the key :

HKEY_CLASSES_ROOT\CLSID\{%CLSID%}

where the value of %CLSID% refers to the CLSID hex value the Trojan created,

delete the key.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer


In the right pane, delete the value:

"InstallerParameters"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.sconato.html\"]source[/url]

Alerts

Posted: Sat Aug 21, 2004 7:13 am
by Tami
Trojan.Delsha
Discovered on: August 19, 2004
Last Updated on: August 20, 2004 02:07:24 PM

Trojan.Delsha is a Trojan horse program that disables the sharing permission of network-shared folders.



Type: Trojan Horse
Infection Length: 20,480 bytes



Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows CE

Technical Details:

When Trojan.Delsha is executed, it deletes the following network shares:


a$
b$
c$
d$
e$
f$
g$
h$
i$
j$
k$
l$
m$
n$
o$
p$
q$
r$
s$
t$
u$
v$
w$
x$
z$
print$
admin$
ipc$
Shared Docs
My Documents

Note: This stops the folders from being available over the network but it does not delete them from the local hard drive.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Delsha.
Reset the shared folder options.

Start Microsoft Internet Explorer
Right-click the folder you want to share.
From the drop-down menu, select Properties.
In the dialog box, select the Sharing tab.
Select Share this folder and set desired configurations.
Click Apply
Click OK.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.delsha.html\"]source[/url]

Alerts

Posted: Sat Aug 21, 2004 7:16 am
by Tami
X97M.Ainesey.C
Discovered on: August 19, 2004
Last Updated on: August 20, 2004 04:21:55 PM

X97M.Ainesey.C is a Microsoft Excel macro virus that infects Microsoft Excel workbooks, lowers Internet Explorer security settings, and drops a file containing a Trojan horse program onto the infected computer.



Type: Macro
Infection Length: 71,920 bytes



Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

Once executed, X97M.Ainesey.C does the following:


Creates the following files:

%temp%\1.reg sets
%temp\2.reg sets


Sets the following registry entries, in order to lower the security settings of Microsoft Excel 9.0 and 10.0:
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security\Level=1
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security\DontTrustInstalledFiles=0
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Excel\Security\AccessVBOM=1
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Excel\Security\Level=1
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Excel\Security\DontTrustInstalledFiles=0


Deletes the following files:

%temp%\1.reg sets
%temp\2.reg sets


Creates and executes the file %Windir%\MSIEXEC32.EXE.

Note: The file, MSIEXEC32.EXE, contains the virus W32.Ainesey.A@mm, and may also be infected with W32.ElKern.4926.


Searches all open Microsoft Excel workbooks and infects all worksheets.

Searches for a file named Personal.xls in the Excel startup folder, creating it if it does not already exist. The virus then infects Personal.xls, which causes the virus will be loaded each time a Microsoft Excel workbook is opened.

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and repair all the files detected as X97M.Ainesey.C.
Restore the security settings in Microsoft Excel.

Start Microsoft Excel.

On the Tools menu:

Click Macro > Security.


Choose the appropriate security level:

[img]http://www.killanet.net/uploads/excelrestore.gif[/img]

Exit Microsoft Excel.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/x97m.ainesey.c.html\"]source[/url]

Alerts

Posted: Tue Aug 24, 2004 3:24 am
by Tami
Download.Ject.B
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 05:09:58 PM

Download.Ject.B is a variant of Download.Ject that attempts to download and install a file by exploiting Internet Explorer vulnerabilities described in Microsoft Security Bulletin MS04-025. The Trojan is triggered by visiting a Web site that contains the exploit code.


Variants: Download.Ject
Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Technical Details:

When Download.Ject.B is executed, it performs the following actions:


Attempts to tries to open the following websites:

drusearch.com
url.biz.ua


Downloads and executes one of the following files:

%System%\rundll32.vbe
help.chm

Notes:
Symantec antivirus products detect these files as Trojan.StartPage.H.
%System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Removal Instructions:

No removal required for the Download.Ject.B itself because it runs from a remote Web site. The detection indicates that it has been detected on the Web site and stopped.

However, if Download.Ject.B was successful in downloading Trojan.StartPage.H, it should be removed. For more information, read the [url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.h.html\"]Trojan.StartPage.H[/url] writeup.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/download.ject.b.html\"]source[/url]

Alerts

Posted: Tue Aug 24, 2004 3:36 am
by Tami
Trojan.StartPage.H
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 05:08:39 PM

Trojan.StartPage.H is a variant of Trojan.StartPage that modifies the Internet Explorer home page without your permission.

Trojan.StartPage.H is downloaded by Download.Ject.B.

Variants: Trojan.StartPage
Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

When Trojan.StartPage.H is executed, it performs the following actions:


Adds the values:

"Customize Search"="http:/ /targetsearch.info"
"Default_Search_URL"="http:/ /targetsearch.info"
"Local Page"="http:/ /targetsearch.info"
"Search Bar"="http:/ /targetsearch.info"
"Search Page"="http:/ /targetsearch.info"
"SearchURL"="http:/ /go.targetsearch.info/"
"Start Page"="http:/ /targetsearch.info"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main


Adds the values:

"Default_Page_URL"="http:/ /targetsearch.info"
"Default_Search_URL"="http:/ /targetsearch.info"
"Local Page"="http:/ /targetsearch.info"
"Search Bar"="http:/ /targetsearch.info/left.php"
"Search Page"="http:/ /targetsearch.info"
"Start Page"="http:/ /targetsearch.info"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main


Adds the value:

"CustomizeSearch"="http:/ /targetsearch.info/left.php"
"SearchAssistant"="http:/ /targetsearch.info/left.php"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search


Adds the following entries to your Internet Explorer Favorites list:

Absoluagency: http:/ /absoluagency.com
Adult Search!: http:/ /adult.targetsearch.info
Real Search!: http:/ /targetsearch.info

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.StartPage.H.
Reset the Internet Explorer home page
Reset the Internet Explorer Search page

To reset the Internet Explorer home page
Start Microsoft Internet Explorer.
Connect to the Internet, and then go to the page that you want to set as your home page.
Click Tools > Internet Options.
In the Home page section of the General tab, click Use Current > OK.

For additional information, or if this procedure does not work, read the Microsoft® Knowledge Base article, [url=\"http://support.microsoft.com/default.aspx?scid=kb;en-us;320159\"]"Home Page Setting Changes Unexpectedly, or You Cannot Change Your Home Page Setting, Article ID 320159." [/url]

To reset the Internet Explorer Search page
Follow the instructions for your version of Windows.

Windows 98/Me/2000
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.

Windows XP
Because Windows XP is set by default to use animated characters in the search, how you do this can vary. Read all the instructions before you start.
Start Microsoft Internet Explorer.
Click the Search button on the toolbar.
Do one of the following:
If the pane that opens looks similar to this picture:

[img]http://www.killanet.net/uploads/resetIE.gif[/img]

click the word Customize. Then skip to step h.


If the pane that opens has the words "Search Companion" at the top, and the center looks similar to this picture:

[img]http://www.killanet.net/uploads/resetIE1.gif[/img]

click the Change preferences link as shown above. Proceed with step d.


Click the Change Internet search behavior link.
Under "Internet Search Behavior," click With Classic Internet Search.
Click OK. Then close Internet Explorer. (Close the program for the change to take effect.)
Start Internet Explorer. When the search pane opens, it should now look similar to this:

[img]http://www.killanet.net/uploads/resetIE.gif[/img]

Click the word Customize, and then proceed with the next step.


In the Search pane, click Customize.
Click Reset.
Click Autosearch Settings.
Select a search site from the drop-down list, and then click OK.
Click OK.
Do one of the following:
If you were using (or want to continue using) the "Classic Internet Search" panel, stop here (or proceed with the next section).
If you want to go back to the "Search Companion" search (it usually has an animated character at the button), proceed with step n.


Click the word Customize again.
In the "Customize Search Settings" window, click Use Search Companion > OK.
Close Internet Explorer. The next time you open it, it will again use the Search Companion.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.h.html\"]source[/url]

Alerts

Posted: Tue Aug 24, 2004 3:39 am
by Tami
W64.Shruggle.1318
Discovered on: August 20, 2004
Last Updated on: August 24, 2004 09:06:24 AM

W64.Shruggle.1318 is a direct-action file infector, similar to W64.Rugrat.3344, which infects AMD64 Windows Portable Executable (PE) files. It is a fairly simple proof-of-concept virus; however, it is the first known virus to attack 64-bit Windows executables on AMD64 systems.

The virus is written in AMD64 assembly code.

Type: Virus
Infection Length: 1318 bytes

Systems Affected: Windows 64-bit (AMD64)
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 2000, Windows 3.x, Windows 64-bit (IA64), Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

Technical Details:

When W64.Shruggle.1318 is executed, it searches 64-bit executable files that are in same folder, and all subfolders, as the one from which the virus was executed. When it finds a 64-bit executable file, the virus appends itself to the file, including .dll files.

Note: The virus does not infect 32-bit Portable Executable files, and it will not run natively on 32-bit Windows platforms. However, it can be run on a 32-bit computer that is using 64-bit simulation software.


Removal Instructions:

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


Update the virus definitions.
Run a full system scan, and delete all of the files that are detected as W64.Shruggle.1318.

Additional information:

The virus uses a small number of Win64 APIs from the following three libraries:

Ntdll.dll
Sfc_os.dll
Kernel32.dll

From Ntdll.dll, the virus uses the following functions:
LdrGetDllHandle()
RtlAddVectoredExceptionHandler()
RtlRemoveVectoredExceptionHandler()

The virus supports vectored exception handling to avoid crashing during infections.

The SfcIsFileProtected() function of Sfc_os.dll is used to avoid infecting executables that are protected by the System File Checker (SFC).

The following sixteen functions are used from Kernel32.dll to implement a standard file infection of a AMD64 Portable Executable image:
CreateFileMappingA()
CreateFileW()
CloseHandle()
FindFirstFileW()
FindNextFileW
FindClose()
GetFullPathNameW()
GetTickCount()
GlobalAlloc()
GlobalFree()
LoadLibraryA()
MapViewOfFile()
SetCurrentDirectoryW()
SetFileAttributesW()
SetFileTime()
UnmapViewOfFile()

The virus carries the following string, which is never displayed, within itself:

Shrug - roy g biv

The file infection routine is standard. The last section of the executable is marked as executable, the virus body is inserted into the last section, and a random number of bytes are appended to the end of the virus body.

The virus author is also the author of a number of other proof-of-concept viruses. These are collected under the name [url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.chiton.gen.html\"]W32.Chiton.gen[/url].

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w64.shruggle.1318.html\"]source[/url]

Alerts

Posted: Tue Aug 24, 2004 3:44 am
by Tami
[b]Trojan.Mitglieder.O
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 04:44:15 PM [/b]

Trojan.Mitglieder.O is a Trojan horse that allows an infected computer to be used as an email relay.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: Linux, Macintosh OS X, Novell Netware, OS/2, UNIX

When Trojan.Mitglieder.O runs, it does the following:


Copies itself as the following files:

%System%\foõ.exe
%System%\norat.exe
%System%\winerdir.exe.

Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds a value:

"ssgrate.exe"="%System%\winerdir.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\WindowsCurrentVersion\Run

so that the worm runs when you restart Windows.


Adds the values:

"port" = "0x000097e3"
"uid" = "[random number]"
"wdrn" = "0x00000001"

to the registry key:

HKEY_CURRENT_USER\Software\DateTime8


Attempts to injects itself as a thread into the Explorer.exe process.


Opens and listens on TCP port 28883.

Note: This functionality is usually employed to send unsolicited commercial email.


Terminates the following processes:

AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET.EXE
CFINET32.EXE
CFINET32.EXE
CLEAN.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMGRDIAN.EXE
CMON016.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
Drvddll.exe
drvsys.exe
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE


Attempts to run a PHP script on one of the following domains, passing details about the infected host to the Web server:

artesproduction.com
avistrade.ru
bernlocher.de
blackwidow.nsk.ru
comdat.de
dabigbadboy.de
die-cliquee.de
egogo.ru
gaz-service.ru
gnet30.gamesnet.de
hannes-wacker.de
investexpo.ru
komtel.spb.ru
mc-figga.de
mir-auto.ru
mir-vesov.ru
monomah-city.ru
multi-gaming.com
partiyazerna.1gb.ru
plastikp.ru
prizmapr.ru
promco.ru
pvcps.ru
rdwufa.ru
roszvetmet.com
schiffsparty.de
service6.valuehost.ru
shop-of-innovations.de
sound-cell.de
st-agnes.de
stroyindustry.ru
tpoint.ru
unbound.de
vladzernoproduct.ru
web298.server7.webplus24.de
www.13tw22rigobert.de
www.admlaw.ru
www.deadlygames.de
www.emil-zittau.de
www.etype.hostingcity.net
www.eurostretch.ru
www.ferienwohnung-in-masuren.de
www.gasterixx.de
www.gay-traffic.de
www.hhc-online.de
www.komandor.ru
www.levada.ru
www.lowenbrau.ru
www.metzgerei-gebhart.de
www.mirage.ru
www.ordendeslichts.de
www.progame.de
www.psnr.ru
www.thomas-we.de

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Mitglieder.N.
Reverse the changes made to the registry.

To reverse the changes made to the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.


Type regedit

Then click OK.


Navigate to the following key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"ssgrate.exe"="%System%\winerdir.exe"


Navigate to the key:

HKEY_CURRENT_USER\Software\DateTime8


In the right pane, delete the values:

"port" = "0x000097e3"
"uid" = "[random number]"
"wdrn" = "0x00000001"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.mitglieder.o.html\"]Source[/url]

[b]Trojan.Mitglieder.N
Discovered on: August 20, 2004
Last Updated on: August 23, 2004 04:44:42 PM [/b]

Trojan.Mitglieder.N is a Trojan horse that allows an infected computer to be used as an email relay.

Also Known As: W32/Bagle.ak!proxy [McAfee]

Type: Trojan Horse
Infection Length: 17,920 bytes, 1,536 bytes, 26,112 bytes

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

When Trojan.Mitglieder.N runs, it does the following:


Copies itself as the following files:

%System%\fi?.exe
%System%\nopat.exe
%System%\sysdoor.exe.

Note: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Adds a value:

"ssgrate.exe"="%System%\sysdoor.exe"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\WindowsCurrentVersion\Run

so that the Trojan runs when you restart Windows.


Adds the values:

"port" = "0x000070d2"
"uid" = "[random number]"
"wdrn" = "0x00000001"

to the registry key:

HKEY_CURRENT_USER\Software\DateTime8


Attempts to injects itself as a thread into the Explorer.exe process.


Opens and listens on TCP port 28882.

Note: This functionality is usually employed to send unsolicited commercial email.


Terminates the following processes:

AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET.EXE
CFINET32.EXE
CFINET32.EXE
CLEAN.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMGRDIAN.EXE
CMON016.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
Drvddll.exe
drvsys.exe
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE


Attempts to run a PHP script on one of the following domains, passing details about the infected host to the Web server:

artesproduction.com
avistrade.ru
bernlocher.de
blackwidow.nsk.ru
comdat.de
dabigbadboy.de
die-cliquee.de
egogo.ru
gaz-service.ru
gnet30.gamesnet.de
hannes-wacker.de
investexpo.ru
komtel.spb.ru
mc-figga.de
mir-auto.ru
mir-vesov.ru
monomah-city.ru
multi-gaming.com
partiyazerna.1gb.ru
plastikp.ru
prizmapr.ru
promco.ru
pvcps.ru
rdwufa.ru
roszvetmet.com
schiffsparty.de
service6.valuehost.ru
shop-of-innovations.de
sound-cell.de
st-agnes.de
stroyindustry.ru
tpoint.ru
unbound.de
vladzernoproduct.ru
web298.server7.webplus24.de
www.13tw22rigobert.de
www.admlaw.ru
www.deadlygames.de
www.emil-zittau.de
www.etype.hostingcity.net
www.eurostretch.ru
www.ferienwohnung-in-masuren.de
www.gasterixx.de
www.gay-traffic.de
www.hhc-online.de
www.komandor.ru
www.levada.ru
www.lowenbrau.ru
www.metzgerei-gebhart.de
www.mirage.ru
www.ordendeslichts.de
www.progame.de
www.psnr.ru
www.thomas-we.de

Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan and delete all the files detected as Trojan.Mitglieder.N.
Reverse the changes made to the registry.

To reverse the changes made to the registry

Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

Click Start > Run.


Type regedit

Then click OK.


Navigate to the following key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"ssgrate.exe"="%System%\sysdoor.exe"


Navigate to the key:

HKEY_CURRENT_USER\Software\DateTime8\


In the right pane, delete the values:

"port" = "0x000070d2"
"uid" = "[random number]"
"wdrn" = "0x00000001"


Exit the Registry Editor.


Restart the computer in Normal mode.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/trojan.mitglieder.n.html\"]Source[/url]

Alerts

Posted: Wed Aug 25, 2004 11:05 am
by Tami
W32.Sasser.G
Discovered on: August 23, 2004
Last Updated on: August 24, 2004 04:53:59 PM

W32.Sasser.G is a variant of [url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.html\"]W32.Sasser.Worm[/url] that attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin [url=\"http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx\"]MS04-011[/url]. The worm spreads by scanning random IP addresses and drops [url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.ac@mm.html\"]W32.Netsky.AC@mm[/url].

Variants: W32.Sasser.Worm
Type: Worm
Infection Length: 58,880 bytes

Systems Affected: Windows 2000, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003

Technical Details:

When W32.Sasser.G runs, it does the following:


Attempts to create mutexes named "PinaasoSky" and "Jobaka3", exiting if it fails. This ensures that no more than one instance of the worm can run on a computer at any time.


Copies itself as one of the following files:

%Windir%\avserve3.exe.
%Windir%\wserver.exe

Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.


Drops and executes the following files:

%Windir%\skynet.cpl
%Windir%\comp.cpl

Note: These files are detected as W32.Netsky.AC@mm.


Adds one of the following values:

"avserve3.exe"="%Windir%\avserv3.exe"
"wserver"="%Windir%\wserver.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you start Windows.


Prevents any attempts to shut down or restart the computer.


Starts an FTP server on TCP port 5554. This server is used to spread the worm to other hosts.


Retrieves the IP addresses of the infected computer.


Generates a second IP address, based on one of the IP addresses retrieved from the infected computer.


Connects to the generated IP address on TCP port 445 to determine whether a remote computer is online.


If a connection is made to a remote computer, the worm will send shell code to it, which may cause it to open a remote shell on TCP port 9996.


Uses the shell on the remote computer to reconnect to the infected computer's FTP server and retrieve a copy of the worm. This copy will have a name consisting of four or five numbers, followed by _up.exe. For example, 74354_up.exe.


Creates a file at C:\win2.log that contains the IP address of the computer that the worm most recently attempted to infect, as well as the number of infected computers.

Note: The Lsass.exe process will crash after the worm exploits the Windows LSASS vulnerability. Windows will display the alert and shut down the system in one minute.

Removal Instructions:

Before you begin:
If you are running Windows 2000 or XP, and have not yet done so, you must patch for the vulnerability described in Microsoft Security Bulletin MS04-011. If you do not, it is likely that your computer will continue to be reinfected.

What to do if the computer shuts down before you can patch or get the tool
This threat can cause Windows to keep shutting down and restarting. This can prevent you from installing the Microsoft patch or downloading the tool described below.


--------------------------------------------------------------------------------
Notes:
You may have to try this several times, as you only have about 20 seconds to do steps 3 to 6.
This will not work on Windows 2000.
--------------------------------------------------------------------------------


To prevent the shut down, do the following:

Disconnect the computer from the network/Internet connection. (Disconnect the cable if necessary.)
Restart the computer.
As soon as Windows opens and you see the Windows desktop, click Start > Run.
Type:

cmd

and press Enter.


Type:

shutdown -i

and press Enter.


In the Remote Shutdown Dialog that opens, do the following:

Click Add, type your computer name into the Add Computers dialog box, and then click OK.
In the "Display warning for" field, type 9999.
Type the following text in the Comment box:

Delay Lsass.exe shutdown.


Click OK.


Reconnect the network/Internet connection.
Connect to the Internet, and get the patch. Then continue with the steps described below.

When you have patched your computer and removed the threat, you can re-enable the 20 second default warning if you wish.


The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

End the malicious process (Windows NT/2000/XP).
Disable System Restore (Windows XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Sasser.G.
Reverse the change made to the registry.

For details on each of these steps, read the following instructions.

1. To end the malicious process
On Windows NT/2000/XP computers, you must first end the malicious process. Follow these instructions:
Press Ctrl+Alt+Delete once.
Click Task Manager.
Click the Processes tab.
Double-click the Image Name column header to alphabetically sort the processes.
Scroll through the list and look for the following processes:
napatch.exe
any process with a name consisting of four or five numbers, followed by _up.exe (for example, 74354_up.exe).


If you find any such process, click it, and then click End Process.
Exit the Task Manager.

To Edit The Registry:

Click Start, and then click Run. (The Run dialog box appears.)
Type regedit

Then click OK. (The Registry Editor opens.)


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the values, if present:

"avserve3.exe"="%Windir%\avserve3.exe"
"wserver"="%Windir%\wserver.exe"


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.g.html\"]source[/url]

Alerts

Posted: Thu Aug 26, 2004 1:09 am
by Tami
Backdoor.Berbew.J
Discovered on: August 24, 2004
Last Updated on: August 25, 2004 03:09:02 PM

Backdoor.Berbew.J is a Trojan horse program that attempts to steal cached passwords from an infected computer. It may also display fake windows to gather confidential information from the user.

Type: Trojan Horse

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

Technical Details:

When the Trojan is executed, it performs the following actions:


Creates a mutex named "Engel_12", which ensures that only one instance of the Trojan is running on the infected computer at one time.


Drops the following files:
%System%\[8 random characters].exe
%System%\[8 random characters].dll

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


Creates the following files, which are used for saving password information and any downloaded configuration data for the Trojan:

%System%\Engl32.dat
%System%\Rtdx1[random number].htm
%System%\engl32.vxd
%System%\Rtdx1[random number].dat
%System%\ccct32.dat


Creates several .htm files in the %Temp% directory, named [8 random characters].htm. The Trojan may then open these files in Internet Explorer.

Note: %Temp% is a variable that refers to the Windows temporary folder. By default, this is C:\Windows\TEMP (Windows 95/98/Me/XP) or C:\WINNT\Temp (Windows NT/2000).


Adds the value:

"WebEvent Logger"="{79ECA078-17FF-726B-E811-213280E5C831}"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

so that the Trojan starts when Windows starts.


Creates the following registry key:

HKEY_CLASSES_ROOT\CLSID\{79ECA078-17FF-726B-E811-213280E5C831}

which causes %System%\[8 random characters].dll to be called as a browser help object by Internet Explorer.


Adds the value:

"MGR" = "D-REPORTS-[8 random letters]"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\IE4

to prevent Internet Explorer from asking users if they are sure that they want to submit unencrypted form data.


Adds the value:

"1601"="0x0"

to the registry keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4

to prevent Internet Explorer from asking users if they are sure that they want to submit unencrypted form data.


Adds the value:

"GlobalUserOffline" = "0x0"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings

to prevent Internet Explorer from asking users if they wish to work offline, when using Internet Explorer and not connected to the Internet.


Adds the value:

"BrowseNewProcess" = "Yes"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings

to enable Windows Explorer to access the Internet.


Adds the value:

"AutoSuggest" = "Yes"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AutoComplete

to disable autocomplete in Internet Explorer.


Adds the value:

"Use FormSuggest" = "Yes"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main

to disable autocomplete in Internet Explorer.


Adds the value:

"FormSuggest Passwords" = "Yes"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main

to disable autocomplete in Internet Explorer.


Adds the value:

"FormSuggest PW Ask" = "Yes"

to the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Explorer\Main

to disable autocomplete in Internet Explorer.


Opens the following:
a rootshell on TCP port 23232.
an FTP server on TCP port 32121.
backdoors on TCP ports 12065 and 28253.


Collects passwords from the infected computer and intercepts data entered into forms in Internet Explorer.
Sends the information gathered to a remote attacker.


Uploads configuration data through the web to a URL in the domain pidorasam.net .

Removal Instructions:

Disable System Restore (Windows Me/XP).

Update the virus definitions.

To restart the computer in Safe mode or VGA mode.

Run a full system scan and delete all the files detected as Backdoor.Berbew.J.

To restore the Internet Security settings:

Start Internet Explorer.
b. Click Tools, click Internet Options, and then click the Security tab.
c. Set the desired level for every zone. (The easiest way to do this is to click Default Level for each one.)

Delete the value that was added to the registry:

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad


In the right pane, delete the value:

"Web Event Logger"="{79ECA078-17FF-726B-E811-213280E5C831}"


Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\IE4


In the right pane, delete the value:

"MGR" = "D-REPORTS-[8 random letters]"


Navigate to the key:

HKEY_CLASSES_ROOT\CLSID\{79ECA078-17FF-726B-E811-213280E5C831}

delete the key.


Exit the Registry Editor.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/backdoor.berbew.j.html\"]source[/url]

Alerts

Posted: Thu Aug 26, 2004 1:38 pm
by Tami
VBS.Voodoo.C
Discovered on: August 24, 2004
Last Updated on: August 26, 2004 10:06:25 AM

VBS.Voodoo.C is a virus written in Visual Basic Script (VBS). It prepends itself to the files that have .asp, .htm, .hta, .htx, .html, and .htt file extensions.

Also Known As: VBS.Voodoo.B [Kaspersky], VBS/Reality [McAfee]
Variants: VBS.Voodoo.A
Type: Virus

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX

Technical Details:

When VBS.Voodoo.C is executed, it performs the following actions:


Modifies the value:

"1201"=0

in the registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0

so that the security protection that Microsoft Internet Explorer provides is lowered to a level that is less safe.


Infects .asp, .htm, .hta, .htx, .html, and .htt (html template) files that are located in:

The same folder as the virus.
The parent folder of the currently infecting folder, and recursively up to the root folder.
The following locations:
C:\My Documents
C:\Windows\Desktop
C:\Inetpub\wwwroot


May add the value:

"RegisteredOwner"="BLASTER"

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RegisteredOwner


May create the following entry in your Internet Explorer Favorites list:

Blaster.URL: http:/ /www.coderz.net


Removal Instructions:

Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as VBS.Voodoo.C.

[url=\"http://securityresponse.symantec.com/avcenter/venc/data/vbs.voodoo.c.html\"]source[/url]