Text 197, 1533 rader
Skriven 2007-07-23 00:10:00 av KURT WISMER
Ärende: News, July 23 2007
==========================
[cut-n-paste from sophos.com]
Name W32/Akbot-AS
Type
* Spyware Worm
How it spreads
* Network shares
Affected operating systems
* Windows
Side effects
* Allows others to access the computer
* Steals information
* Downloads code from the internet
* Reduces system security
* Installs itself in the Registry
* Exploits system or software vulnerabilities
Prevalence (1-5) 2
Description
W32/Akbot-AS is a worm for the Windows platform.
W32/Akbot-AS spreads to other network computers infected with W32/Sasser and to
other network computers by exploiting common buffer overflow vulnerabilities,
including MS04-007.
Advanced
W32/Akbot-AS is a worm for the Windows platform.
W32/Akbot-AS spreads to other network computers infected with W32/Sasser and to
other network computers by exploiting common buffer overflow vulnerabilities,
including MS04-007.
When first run W32/Akbot-AS copies itself to <System>\sslms.exe.
The following registry entry is created to run code exported by sslms.exe on
startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WinDll (sslms.exe)
rundll32.exe <System>\sslms.exe,start
Name W32/Baysur-B
Type
* Worm
How it spreads
* Removable storage devices
Affected operating systems
* Windows
Side effects
* Installs itself in the Registry
* Leaves non-infected files on computer
Aliases
* Virus.Win32.VB.dg
* Win32/VB.DG
* WORM_VB.DTH
Prevalence (1-5) 2
Description
W32/Baysur-B is a worm for the Windows platform.
W32/Baysur-B attempts to spread to removable drives.
Advanced
W32/Baysur-B is a worm for the Windows platform.
W32/Baysur-B attempts to spread to removable drives.
When first run the worm attempts to copy itself to the following locations:
<Startup>\Adobe Online.com
<Startup>\Adobe Update.com
W32/Baysur-B attempts to copy itself using the names of existing files and
folders on the computer but with an SCR or COM extension, and sometimes with an
extra space in the filename.
W32/Baysur-B also attempts to drop some of the following files:
<Windows>\Thumbs .db
<Startup>\Autoexec.bat
The file Autoexec.bat attempts to display the following lines on startup,
before prompting for user input:
81u3f4nt45y - 24.01.2007
Don't kill me, i'm just send message from your computer
Terima kasih telah menemaniku walaupun hanya sesaat, tapi bagiku sangat
berarti
Maafkan jika kebahagiaan yang kuminta adalah teman sepanjang hidupku
Seharusnya aku mengerti bahwa keberadaanku bukanlah disisimu, hanyalah
lamunan dalam sesal
Untuk kekasih yang tak kan pernah kumiliki 3r1k1m0
W32/Baysur-B attempts to delete the following registry entry:
HKCR\scrfile
AlwaysShowExt
W32/Baysur-B attempts to set the following registry entries:
HKCR\scrfile
FileFolder
NULL
HKCR\scrfile
InfoTip
NULL
HKCR\scrfile
NeverShowExt
NULL
HKCR\scrfile
TileInfo
NULL
HKCR\scrfile\shell\open\command
default
%1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
LegalNoticeCation
81u3f4nt45y - 24.01.2007 Surabaya
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
LegalNoticeText
"Surabaya in my birthday
Don't kill me, i'm just send message from your computer
Terima kasih telah menemaniku walaupun hanya sesaat, tapi bagiku sangat berarti
Maafkan jika kebahagiaan yang kuminta adalah teman sepanjang hidupku
Seharusnya aku mengerti bahwa keberadaanku bukanlah disisimu, hanyalah lamunan
dalam sesal
Untuk kekasih yang tak kan pernah kumiliki 3r1k1m0"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\NOHIDDEN
CheckedValue
2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\NOHIDDEN
DefaultValue
2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\NOHIDORSYS
CheckedValue
0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\NOHIDORSYS
DefaultValue
2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALL
CheckedValue
0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALL
DefaultValue
2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\HideFileExt
CheckedValue
1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\HideFileExt
DefaultValue
1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\HideFileExt
UncheckedValue
1
Name W32/Sohana-Y
Type
* Spyware Worm
How it spreads
* Removable storage devices
* Network shares
* Chat programs
Affected operating systems
* Windows
Side effects
* Allows others to access the computer
* Steals information
* Downloads code from the internet
* Reduces system security
* Records keystrokes
* Installs itself in the Registry
* Exploits system or software vulnerabilities
Aliases
* IM-Worm.Win32.Sohanad.am
* WORM_SOHANAD.BO
Prevalence (1-5) 2
Description
W32/Sohana-Y is a worm for the Windows platform.
W32/Sohana-Y spreads through instant messaging applications, removable media
and network shares.
W32/Sohana-Y includes functionality to access the internet and communicate with
a remote server via HTTP.
Advanced
W32/Sohana-Y is a worm for the Windows platform.
W32/Sohana-Y spreads through instant messaging applications, removable media
and network shares.
W32/Sohana-Y includes functionality to access the internet and communicate with
a remote server via HTTP.
When first run W32/Sohana-Y copies itself to:
<Windows>\SSCVIIHOST.exe
<System>\SSCVIIHOST.exe
<System>\blastclnnn.exe
and creates the following files:
<System>\autorun.ini
<System>\setting.ini
The file autorun.ini is detected as Mal/AutoInf-A.
The following registry entry is created to run W32/Sohana-Y on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo Messengger
<System>\SSCVIIHOST.exe
The following registry entry is changed to run W32/Sohana-Y on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe SSCVIIHOST.exe
The following registry entries are set, disabling system software:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
The following registry entry is set:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NofolderOptions
1
Name Troj/Hupigon-SL
Type
* Trojan
Affected operating systems
* Windows
Side effects
* Downloads code from the internet
* Installs itself in the Registry
Prevalence (1-5) 2
Description
Troj/Hupigon-SL is a Trojan for the Windows platform.
Name Troj/Riler-Y
Type
* Trojan
Affected operating systems
* Windows
Side effects
* Drops more malware
* Leaves non-infected files on computer
Prevalence (1-5) 2
Description
Troj/Riler-Y is a Trojan for the Windows platform.
Advanced
Troj/Riler-Y is a Trojan for the Windows platform.
When run Troj/Riler-Y creates the files:
<System>\toonjoke.dll - detected as Troj/Riler-Gen
<System>\feelcat.ini -can be safely removed
Troj/Riler-Y will install the file toonjoke.dll as a Windows Sockets 2
transport provider and reorder the WSC Chain such that it gets called first. As
a result, the Trojan may spy on the network traffic of applications.
Name W32/Sdbot-DGJ
Type
* Worm
Affected operating systems
* Windows
Side effects
* Installs itself in the Registry
Prevalence (1-5) 2
Description
W32/Sdbot-DGJ is a worm with backdoor functionality for the Windows platform.
Advanced
W32/Sdbot-DGJ is a worm with backdoor functionality for the Windows platform.
W32/Sdbot-DGJ includes functionality to access the internet and communicate
with a remote server via HTTP.
When first run W32/Sdbot-DGJ copies itself to:
<Windows>\nzbd.exe
<Program Files>\KaZaA\My Shared Folder\<filename.exe>
where <filename.exe> is the name of a file already found in that location.
The file nzbd.exe is registered as a new system driver service named "Windows
NZDB Service", with a display name of "Windows NZDB Service" and a startup type
of automatic, so that it is started automatically during system startup.
Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\Windows NZDB Service
The following registry entries are set, disabling system software:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
W32/Sdbot-DGJ sets the following registry entries, disabling the automatic
startup of other software:
HKLM\SYSTEM\CurrentControlSet\Services\Messenger
Start
4
HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry
Start
4
HKLM\SYSTEM\CurrentControlSet\Services\TlntSvr
Start
4
Registry entries are set as follows:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCScan
0
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall
0
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile
EnableFirewall
0
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
DoNotAllowXPSP2
1
HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCDisable
ffffff9d
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe %WINDIR%\nzbd.exe
Registry entries are created under:
HKLM\SOFTWARE\Microsoft\Security Center
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Name W32/Looked-DM
Type
* Virus
How it spreads
* Network shares
* Infected files
Affected operating systems
* Windows
Side effects
* Allows others to access the computer
* Downloads code from the internet
* Installs itself in the Registry
Aliases
* Trojan-Dropper.Win32.Small.axi
* Win32/Viking.DB
* PE_LOOKED.ABM-O
Prevalence (1-5) 2
Description
W32/Looked-DM is a prepending virus and network worm for the Windows platform.
W32/Looked-DM spreads via file sharing on P2P networks.
W32/Looked-DM runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer.
W32/Looked-DM includes functionality to access the internet and communicate
with a remote server via HTTP.
Advanced
W32/Looked-DM is a prepending virus and network worm for the Windows platform.
W32/Looked-DM spreads via file sharing on P2P networks.
W32/Looked-DM runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer.
W32/Looked-DM includes functionality to access the internet and communicate
with a remote server via HTTP.
When W32/Looked-DM is installed the following files are created:
<Windows>\Logo1_.exe
<Windows>\RichDll.dll
<Windows>\uninstall\\rundl132.exe
These files are all detected as W32/Looked-DM.
W32/Looked-DM may also create many files with the name "_desktop.ini" in
various folders on the infected computer. These files are harmless text files
and can be deleted
The worm changes the following registry entry in order to be run automatically
on startup:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\
load
<Windows>\uninstall\rundl132.exe
Registry entries are created under:
HKLM\SOFTWARE\Soft\DownloadWWW\
Name W32/Poebot-MN
Type
* Spyware Worm
How it spreads
* Network shares
Affected operating systems
* Windows
Side effects
* Allows others to access the computer
* Steals information
* Downloads code from the internet
* Installs itself in the Registry
* Exploits system or software vulnerabilities
Prevalence (1-5) 2
Description
W32/Poebot-MN is a worm with IRC backdoor functionality for the Windows
platform.
Advanced
W32/Poebot-MN is a worm with IRC backdoor functionality for the Windows
platform.
W32/Poebot-MN runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.
W32/Poebot-MN spreads to other network computers:
- by exploiting common buffer overflow vulnerabilities, including: LSASS
(MS04-011), SRVSVC (MS06-040), RPC-DCOM (MS04-012) and PNP (MS05-039)
- by networks protected by weak passwords
W32/Poebot-MN includes functionality to:
- download code from the internet
- steal information
When run W32/Poebot-MN copies itself to <System>\csrs.exe.
The following registry entry is set to run W32/Poebot-MN on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Client Server Runtime Process
<System>\csrs.exe
Name Troj/PSW-EF
Type
* Spyware Trojan
Affected operating systems
* Windows
Side effects
* Steals information
* Installs itself in the Registry
Prevalence (1-5) 2
Description
Troj/PSW-EF is a Trojan for the Windows platform.
Advanced
Troj/PSW-EF is a Trojan for the Windows platform.
When run Troj/PSW-EF copies itself to <System>\shareb.exe and creates the file
<Windows>\shareb32.dll. The file <Windows>\shareb32.dll is also detected as
Troj/PSW-EF.
Troj/PSW-EF installs the DLL as a Browser Helper Object creating the following
registry entries:
HKCR\CLSID\(FBF3B337-FEB6-403B-BBE2-2B67CB6563E3)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
(FBF3B337-FEB6-403B-BBE2-2B67CB6563E3)
Name W32/Loadme-A
Type
* Virus
Affected operating systems
* Windows
Side effects
* Modifies data on the computer
* Deletes files off the computer
* Installs itself in the Registry
Prevalence (1-5) 2
Description
W32/Loadme-A is a virus for the Windows platform.
Advanced
W32/Loadme-A is a virus for the Windows platform.
W32/Loadme-A will replace files found on the system with copies of itself.
Name W32/Tilebot-KB
Type
* Worm
How it spreads
* Network shares
* Peer-to-peer
Affected operating systems
* Windows
Side effects
* Allows others to access the computer
* Downloads code from the internet
* Reduces system security
* Installs itself in the Registry
* Exploits system or software vulnerabilities
Aliases
* Backdoor.Win32.SdBot.bhk
* WORM_SDBOT.FCZ
Prevalence (1-5) 2
Description
W32/Tilebot-KB is a worm for the Windows platform.
W32/Tilebot-KB spreads via network shares and P2P applications.
W32/Tilebot-KB includes functionality to access the internet and communicate to
a remote server via HTTP.
Advanced
W32/Tilebot-KB is a worm for the Windows platform.
W32/Tilebot-KB spreads via network shares and P2P applications.
W32/Tilebot-KB includes functionality to access the internet and communicate to
a remote server via HTTP.
When first run W32/Tilebot-KB copies itself to <Windows>\netserv.exe.
W32/Tilebot-KB registers itself as a new system driver service named "Windows
.NET Service" with a display name of "Windows .NET Service" and a startup type
of automatic, so that it is started automatically during system startup.
Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\Windows .NET Service\
W32/Tilebot-KB may replace the contents of these files to render them useless:
<System>\tftp.exe
<System>\ftp.exe
if so a backup of these files may be found here:
<System>\Microsoft\backup.ftp (originally ftp.exe)
<System>\Microsoft\backup.tftp (originally tftp.exe)
W32/Tilebot-KB modifies the number of outbound TCP connections by patching:
<System>\drivers\tcpip.sys
W32/Tilebot-KB sets the following registry entries to reduce system security:
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
DoNotAllowXPSP2
1
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile
EnableFirewall
0
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall
0
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N
HKLM\SOFTWARE\Microsoft\Security Center
AntiVirusOverride
1
HKLM\SOFTWARE\Microsoft\Security Center
FirewallOverride
1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe <Windows>\netserv.exe
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1
Name Troj/DropRk-A
Type
* Trojan
Affected operating systems
* Windows
Side effects
* Drops more malware
* Installs itself in the Registry
Prevalence (1-5) 2
Description
Troj/DropRk-A is a rootkit dropper Trojan for the Windows platform.
Advanced
Troj/DropRk-A is a rootkit dropper Trojan for the Windows platform.
When run Troj/DropRk-A copies itself to <Temp>\startdrv.exe and creates the
file <System>\drivers\runtime2.sys. The file runtime2.sys is detected as
Troj/Rootkit-BI.
Troj/DropRk-A then installs the rootkit runtim2.sys with a service name of
"runtime2" and a description of "runtime2" with a startup type of automatic.
Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RUNTIME2\
HKLM\SYSTEM\CurrentControlSet\Services\runtime2
The following registry entry is created to run startdrv.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
startdrv
<Temp>\startdrv.exe
Name Troj/Zapchas-DN
Type
* Trojan
Affected operating systems
* Windows
Side effects
* Allows others to access the computer
* Leaves non-infected files on computer
Prevalence (1-5) 2
Description
Troj/Zapchas-DN is a mIRC-based backdoor Trojan for the Windows platform.
Advanced
Troj/Zapchas-DN is a mIRC-based backdoor Trojan for the Windows platform.
When first run, Troj/Zapchas-DN creates the following files in
<System>\ShellExt:
greet.ini
aliases.ini
away.txt
channels.txt
conn.ini
control.ini
czvhost.exe
engine.ini
flood.txt
fullname.txt
add.txt
ident.txt
injuraturi.txt
IRC.ICO
kick.txt
mirc.ini
nick.txt
operator.ini
partmsg.ini
perform.ini
remote.ini
scr.ini
servers.ini
updater.ini
czvhost.exe is the legitimate mIRC IRC application. operator.ini and scr.ini
are also detected as Troj/Zapchas-DN. The remaining files are harmless and can
be deleted safely.
Troj/Zapchas-DN allows a remote user to control the infected computer via IRC
channels.
Name W32/Rubble-A
Type
* Worm
How it spreads
* Removable storage devices
Affected operating systems
* Windows
Side effects
* Deletes files off the computer
* Installs itself in the Registry
Prevalence (1-5) 2
Description
W32/Rubble-A is a worm for the Windows platform.
Advanced
W32/Rubble-A is a worm for the Windows platform.
When first run W32/Rubble-A copies itself to:
<System>\win32.exe
The following registry entry is created to run win32.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Load
<System>\win32.exe
W32/Rubble-A attempts to spread by scanning local drives, including removable
drives, and replacing any files found with itself, using the same name (with an
EXE extension). W32/Rubble-A thus deletes the files it replaces. In overwriting
important system files, W32/Rubble-A may also prevent a computer from rebooting
once infected.
Name W32/Sdbot-DGM
Type
* Spyware Worm
How it spreads
* Network shares
Affected operating systems
* Windows
Side effects
* Allows others to access the computer
* Steals information
* Downloads code from the internet
* Installs itself in the Registry
* Exploits system or software vulnerabilities
* Leaves non-infected files on computer
Prevalence (1-5) 2
Description
W32/Sdbot-DGM is a worm with IRC backdoor functionality for the Windows
platform.
Advanced
W32/Sdbot-DGM is a worm with IRC backdoor functionality for the Windows
platform.
W32/Sdbot-DGM runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.
W32/Sdbot-DGM spreads to other network computers:
- by exploiting common buffer over flow vulnerabilities, including: ASN.1
(MS04-007)
- by networks protected by weak passwords
W32/Sdbot-DGM includes functionality to:
- download code from the internet
- steal information
When run W32/Sdbot-DGM copies itself to <Windows>\MSTask.exe. W32/Sdbot-DGM
also creates the file <System>\trash1B9F4 which is not malicious and can be
safely removed.
W32/Sdbot-DGM also creates the file <System>\sfc_os.dll which is detected as
"Disabled System File Check DLL"
W32/Sdbot-DGM overwrites the files <System>\ftp.exe, <System>\tftp.exe with
non-malicious dummy files. These files can be safely removed.
W32/Sdbot-DGM registers the file <Windows>\MSTask.exe as a service with a
service name of "Windows Task Scheduler process", a description of "Windows
Task Scheduler process" and a startup type of automatic. Registry entries are
created under:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_TASK_SCHEDULER_PROCESS\
HKLM\SYSTEM\CurrentControlSet\Services\Windows Task Scheduler process\
The following registry entries are set:
HKLM\SOFTWARE\Microsoft\Security Center
AntiVirusDisableNotify
1
HKLM\SOFTWARE\Microsoft\Security Center
AntiVirusOverride
1
HKLM\SOFTWARE\Microsoft\Security Center
FirewallDisableNotify
1
HKLM\SOFTWARE\Microsoft\Security Center
FirewallOverride
1
HKLM\SOFTWARE\Microsoft\Security Center
UpdatesDisableNotify
1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCScan
0
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall
0
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile
EnableFirewall
0
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
DoNotAllowXPSP2
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Enterprise Security Manager
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Ghost
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Intruder Alert
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
LiveAdvisor
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
LiveUpdate
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
NetRecon
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton AntiVirus Product Updates
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton AntiVirus Virus Definitions
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton CleanSweep
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton Commander
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton Internet Security
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton SystemWorks
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton Utilities
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
PC Handyman and HealthyPC
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Rescue Disk
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
SymEvent
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Symantec Desktop Firewall
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Symantec Gateway Security IDS
1
HKLM\SOFTWARE\Symantec\LiveUpdate Admin
pcANYWHERE
1
HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters
AutoShareServer
0
HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters
AutoShareWks
0
HKLM\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters
AutoShareServer
0
HKLM\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters
AutoShareWks
0
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc
Start
4
Name W32/SillyFDC-AN
Type
* Worm
How it spreads
* Removable storage devices
Affected operating systems
* Windows
Side effects
* Installs itself in the Registry
Prevalence (1-5) 2
Description
W32/SillyFDC-AN is a worm for the Windows platform.
Advanced
W32/SillyFDC-AN is a worm for the Windows platform.
Once installed W32/SillyFDC-AN will copy itself to <System>\systeminit.exe.
W32/SillyFDC-AN spreads via removable shared drives by creating the file
autorun.inf and a copy of the worm to setup.exe on the removable drive. The
file autorun.inf is subsequently set to run the worm component upon connecting
the removable drive to another computer.
W32/SillyFDC-AN sets the following registry entries:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
systeminit
<System>\systeminit.exe
Registry entries are also created under:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun
0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoFind
1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableCMD
2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableRegistryTools
1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr
1
Name Troj/Banloa-CT
Type
* Trojan
Affected operating systems
* Windows
Side effects
* Downloads code from the internet
Prevalence (1-5) 2
Description
Troj/Banloa-CT is a Trojan for the Windows platform.
Name Mal/Click-C
Type
* Malicious Behavior
How it spreads
* Web browsing
Affected operating systems
* Windows
Side effects
* Opens links to websites
Aliases
* Clicker.Win32.Chimoz.u
Prevalence (1-5) 2
Description
Mal/Click-C is a Trojan for the Windows platform.
Advanced
Mal/Click-C is a Trojan for the Windows platform.
Name W32/Ircbot-WW
Type
* Spyware Worm
How it spreads
* Network shares
Affected operating systems
* Windows
Side effects
* Allows others to access the computer
* Steals information
* Downloads code from the internet
* Installs itself in the Registry
* Exploits system or software vulnerabilities
Aliases
* Backdoor.Win32.IRCBot.aco
Prevalence (1-5) 2
Description
W32/Ircbot-WW is a worm for the Windows platform.
W32/Ircbot-WW spreads through network shares.
Advanced
W32/Ircbot-WW is a worm for the Windows platform.
W32/Ircbot-WW spreads through network shares.
When first run W32/Ircbot-WW copies itself to:
<System>\u.exe
W32/Ircbot-WW creates the following registry entry to start itself:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Office Monitor Word Exel R
<System>\u.exe
W32/Ircbot-WW also sets the following registry entries:
HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1
Name W32/Sohana-Z
Type
* Spyware Worm
How it spreads
* Removable storage devices
* Network shares
* Chat programs
Affected operating systems
* Windows
Side effects
* Allows others to access the computer
* Steals information
* Downloads code from the internet
* Reduces system security
* Records keystrokes
* Installs itself in the Registry
* Exploits system or software vulnerabilities
Prevalence (1-5) 2
Description
W32/Sohana-Z is a worm for the Windows platform.
W32/Sohana-Z spreads through instant messaging applications, removable media
and network shares.
W32/Sohana-Z includes functionality to access the internet and communicate with
a remote server via HTTP.
Advanced
W32/Sohana-Z is a worm for the Windows platform.
W32/Sohana-Z spreads through instant messaging applications, removable media
and network shares.
W32/Sohana-Z includes functionality to access the internet and communicate with
a remote server via HTTP.
When first run W32/Sohana-Z copies itself to:
<Windows>\SCVHOST.exe
<System>\SCVHOST.exe
<System>\blastclnnn.exe
and creates the following files:
<System>\autorun.ini
The file autorun.ini is detected as Mal/AutoInf-A.
The following registry entry is created to run W32/Sohana-Z on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo Messengger
<System>\SCVHOST.exe
The following registry entry is changed to run W32/Sohana-Z on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe SCVHOST.exe
The following registry entries are set, disabling system software:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
The following registry entry is set:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NofolderOptions
1
Name W32/Sohana-Z
Type
* Spyware Worm
How it spreads
* Removable storage devices
* Network shares
* Chat programs
Affected operating systems
* Windows
Side effects
* Allows others to access the computer
* Steals information
* Downloads code from the internet
* Reduces system security
* Records keystrokes
* Installs itself in the Registry
* Exploits system or software vulnerabilities
Prevalence (1-5) 2
Description
W32/Sohana-Z is a worm for the Windows platform.
W32/Sohana-Z spreads through instant messaging applications, removable media
and network shares.
W32/Sohana-Z includes functionality to access the internet and communicate with
a remote server via HTTP.
Advanced
W32/Sohana-Z is a worm for the Windows platform.
W32/Sohana-Z spreads through instant messaging applications, removable media
and network shares.
W32/Sohana-Z includes functionality to access the internet and communicate with
a remote server via HTTP.
When first run W32/Sohana-Z copies itself to:
<Windows>\SCVHOST.exe
<System>\SCVHOST.exe
<System>\blastclnnn.exe
and creates the following files:
<System>\autorun.ini
The file autorun.ini is detected as Mal/AutoInf-A.
The following registry entry is created to run W32/Sohana-Z on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo Messengger
<System>\SCVHOST.exe
The following registry entry is changed to run W32/Sohana-Z on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe SCVHOST.exe
The following registry entries are set, disabling system software:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
The following registry entry is set:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NofolderOptions
1
Name W32/Frawrm-A
Type
* Worm
How it spreads
* Removable storage devices
* Network shares
Affected operating systems
* Windows
Side effects
* Installs itself in the Registry
Aliases
* Virus.Win32.AutoRun.bb
* Win32/Delf.NFG
* W32/Generic.worm.j
Prevalence (1-5) 2
Description
W32/Frawrm-A is a worm for the Windows platform.
Advanced
W32/Frawrm-A is a worm for the Windows platform.
W32/Frawrm-A spreads to other network computers and removable drives.
When first run W32/Frawrm-A copies itself to:
<Root>\recycler\systems.com
<System>\taskmger.com
and creates the file <Root>\autorun.inf.
Autorun.inf is detected as Mal/AutoInf-A.
The following registry entry is changed to run taskmger.com on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe taskmger.com
The following registry entries are set, disabling system software:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskmgr
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
Name W32/Rbot-GSJ
Type
* Worm
How it spreads
* Network shares
Affected operating systems
* Windows
Side effects
* Allows others to access the computer
* Downloads code from the internet
* Reduces system security
* Installs itself in the Registry
Prevalence (1-5) 2
Description
W32/Rbot-GSJ is a network worm for the Windows platform.
Advanced
W32/Rbot-GSJ is a network worm for the Windows platform.
W32/Rbot-GSJ runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.
When first run W32/Rbot-GSJ copies itself to <System>\rundll.exe.
The following registry entries are created to run rundll.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft
rundll.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Microsoft
rundll.exe
The following registry entry is set:
HKCU\Software\ASProtect
Microsoft
rundll.exe
--- MultiMail/Win32 v0.43
* Origin: Doc's Place BBS Fido Since 1991 docsplace.tzo.com (1:123/140)
|