Nume: WORM/VBNA.B.370 Descoperit pe data de: 28/06/2010 Tip: Vierme ITW: Da Numar infectii raportate: Mediu Potential de raspandire: Scazut Potential de distrugere: Scazut Fisier static: Da Marime: 69.632 Bytes MD5: fc5845e43fd492b43fdd39e53f615823 Versiune VDF: 7.10.03.191 Versiune IVDF: 7.10.08.209 - Montag, 28. Juni 2010
General Alias: • Kaspersky: Worm.Win32.VBNA.b • TrendMicro: WORM_VBNA.ABZ • Microsoft: Trojan:Win32/VB.AAG • AVG: VB.ADYE • Panda: W32/Autorun.JXY • VirusBuster: Worm.VBNA.TCJ • Eset: Win32/TrojanClicker.VB.NPD • AhnLab: Win32/Vbna.worm.69632.ARD • DrWeb: Trojan.MulDrop1.39253 • Fortinet: W32/VBNA.B!worm • Ikarus: Worm.Win32.VBNA Sistem de operare: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows 7 Efecte secundare: • Reduce setarile de securitate • Modificari in registri Registrii sistemului Urmatoarele chei din registri sunt modificate: – [HKLM\SOFTWARE\Microsoft\Security Center] Vechea valoare: • "UACDisableNotify"=dword:00000000 Noua valoare: • "UACDisableNotify"=dword:00000001 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] Vechea valoare: • "EnableLUA"=dword:00000001 Noua valoare: • "EnableLUA"=dword:00000000 – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] Vechea valoare: • "DisableSR"=dword:00000000 Noua valoare: • "DisableSR"=dword:00000001 – [HKLM\SYSTEM\ControlSet001\Services\sr] Noua valoare: • "Start"=dword:00000004 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Noua valoare: • "ShowSuperHidden"=dword:00000000 • "SuperHidden"=dword:00000001 • "Hidden"=dword:00000002 • "HideFileExt"=dword:00000003 – [HKCU\Software\Microsoft\Internet Explorer\Main] Noua valoare: • "Start Page"="http://www.nuevaq.fm" • "Local Page"="http://www.nuevaq.fm" • "Search Page"="http://www.nuevaq.fm" • "Default_Search_URL"="http://www.nuevaq.fm" • "Default_Page_URL"="http://www.nuevaq.fm" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Netscape.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Safari.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\opera.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\chrome.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\helper.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\updater.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\crashreporter.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\firefox.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Filemon.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Procmon.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\procexp.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\portmon.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\prckiller.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\gpedit.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\boot.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zlh.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Regmon.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\fslaunch.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\cclaw.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ndntspst.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\nd98spst.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kis8.0.0.506latam.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kav8.0.0.357es.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\WS2Fix.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\UCCLSID.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\VACFix.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\unzip.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\swsc.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\swxcacls.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Diskmon.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\SrchSTS.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\SmitfraudFix.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\IEDFix.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\HostsChk.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\GenericRenosFix.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\exit.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\dumphive.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Restart.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Process.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ntdetect.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\HJTInstall.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ChromeSetup.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Opera_964_int_Setup.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ GoogleToolbarInstaller_download_signed.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\fa-setup.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonealarm.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonalm2601.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonalarm.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zauinst.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zatutorzauinst.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zatutor.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zapsetup3001.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zapro.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\xscan.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\xpf202en.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wyvernworksfirewall.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wsbgate.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wrctrl.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wradmin.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wnt.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wmiav.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wmias.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winsfcm.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winservices.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winroute.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winrecon.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winppr32.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winmgm32.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe\"" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wink.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winhlpp32.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wingate.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wimmun32.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\whoswatchingme.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wgfe95.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wfindv32.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webtrap.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webscanx.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webscan.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\watchdog.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\w9x.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\w32dsm89.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vvstat.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswinperse.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswinntse.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswin9xe.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsstat.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsscan40.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsmon.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsmain.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsisetup.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vshwin32.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsecomr.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsched.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscenu6.02d30.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscan40.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscan.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vptray.exe] Noua valoare: • "Debugger"="%WINDIR%\twunk_16.exe" Detaliile fisierului Limbaj de programare: Limbaj de programare folosit: Visual Basic.
Die Beschreibung wurde erstellt von Alexandru Dinu am Donnerstag, 12. August 2010 Die Beschreibung wurde geändert von Alexandru Dinu am Montag, 23. August 2010
zurück
.
.
.
.