Nume: ADSPY/Boran.I.17 Descoperit pe data de: 05/10/2006 Tip: Troian ITW: Nu Numar infectii raportate: Scazut Potential de raspandire: Scazut Potential de distrugere: Scazut spre mediu Fisier static: Da Marime: 9.728 Bytes MD5: 29987dbd0Ec36ff87cd572f0d75c2c5a Versiune VDF: 6.35.01.51 - Friday, August 4, 2006Versiune IVDF: 6.35.01.51 - Friday, August 4, 2006
General Metoda de raspandire: • Nu are rutina proprie de raspandire Alias: • TrendMicro: PAK_Generic.001 • Eset: Win32/Adware.Boran Sistem de operare: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Efecte secundare: • Creeaza fisiere • Modificari in registri Fisiere Creeaza urmatorul director: • %directorul de activare malware% \updmms Sunt create fisierele: – %directorul de activare malware% \updmms\mmsass.cab – %directorul de activare malware% \updmms\mmsstate.ini – %directorul de activare malware% \updmms\update.ini – %directorul de activare malware% \mms.ini Registrii sistemului Inregistreaza un browser helper object (BHO) prin adaugarea urmatoarei chei in registri: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{6671A431-5C3D-463d-A7CF-5587F9B7E191}] • @="Vision" Urmatoarele chei sunt adaugate in registrii sistemului: – [HKCR\CLSID\{6671A431-5C3D-463d-A7CF-5587F9B7E191}] • @="MMSAssist BHO" – [HKCR\CLSID\{6671A431-5C3D-463d-A7CF-5587F9B7E191}\InprocServer32] • @="%directorul de activare malware% \%fisier executat% " • "ThreadingModel"="Apartment" – [HKCR\CLSID\{6671A431-5C3D-463d-A7CF-5587F9B7E191}\ProgID] • @="MMSBho.MMSAssist.1" – [HKCR\CLSID\{6671A431-5C3D-463d-A7CF-5587F9B7E191}\Programmable] – [HKCR\CLSID\{6671A431-5C3D-463d-A7CF-5587F9B7E191}\TypeLib] • @="{077525AC-C681-4139-8C3E-B582BDD375C7}" – [HKCR\CLSID\{6671A431-5C3D-463d-A7CF-5587F9B7E191}\ VersionIndependentProgID] • @="MMSBho.MMSAssist" – [HKCR\TypeLib\{077525AC-C681-4139-8C3E-B582BDD375C7}\1.0] • @="MMSBho 1.0 Type Library" – [HKCR\TypeLib\{077525AC-C681-4139-8C3E-B582BDD375C7}\1.0\0\win32] • @="%directorul de activare malware% \%fisier executat% l" – [HKCR\TypeLib\{077525AC-C681-4139-8C3E-B582BDD375C7}\1.0\FLAGS] • @="0" – [HKCR\TypeLib\{077525AC-C681-4139-8C3E-B582BDD375C7}\1.0\HELPDIR] • @="%directorul de activare malware% " – [HKCR\Interface\{74289A79-E652-4A57-A6B9-EE64AD532A8D}] • @="IMMSAssist" – [HKCR\Interface\{74289A79-E652-4A57-A6B9-EE64AD532A8D}\ ProxyStubClsid] • @="{00020424-0000-0000-C000-000000000046}" – [HKCR\Interface\{74289A79-E652-4A57-A6B9-EE64AD532A8D}\ ProxyStubClsid32] • @="{00020424-0000-0000-C000-000000000046}" – [HKCR\Interface\{74289A79-E652-4A57-A6B9-EE64AD532A8D}\TypeLib] • @="{077525AC-C681-4139-8C3E-B582BDD375C7}" • "Version"="1.0" – [HKCR\MMSBho.MMSAssist] • @="MMSAssist BHO" – [HKCR\MMSBho.MMSAssist\CLSID] • @="{6671A431-5C3D-463d-A7CF-5587F9B7E191}" – [HKCR\MMSBho.MMSAssist\CurVer] • @="MMSBho.MMSAssist.1" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad] • "Vision"="{6671A431-5C3D-463d-A7CF-5587F9B7E191}" – [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\ {6671A433-5C3D-463d-A7CF-5587F9B7E191}] • "CLSID"="{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}" • "ClsidExtension"="{6671A432-5C3D-463d-A7CF-5587F9B7E191}" • "MenuText"="%combinatie de caractere aleatoare% " • "MenuStatusBar"="%combinatie de caractere aleatoare% " – [HKCU\Software\Microsoft\Internet Explorer\MenuExt\ >>%combinatie de caractere aleatoare% <<] • @="res://%directorul de activare malware% \%fisier executat% /mms.htm" – [HKLM\SOFTWARE\mmsassist] • "mmsassist"="1.2.0.3" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ Vision Communicate] • "DisplayName"="Vision Communicate" • "UninstallString"="%SYSDIR%\rundll32.exe %directorul de activare malware% \%fisier executat% ,Uninstall" Detaliile fisierului Limbaj de programare: Limbaj de programare folosit: C (compilat cu Microsoft Visual C++). Compresia fisierului: Pentru a ingreuna detectia si a reduce marimea fisierului, este folosit urmatorul program de arhivare: • UPX
Description inserted by Monica Ghitun on Thursday, October 5, 2006 Description updated by Andrei Ivanes on Thursday, October 26, 2006
Back
.
.
.
.