Nume: TR/VB.asp Descoperit pe data de: 13/09/2006 Tip: Troian ITW: Nu Numar infectii raportate: Scazut Potential de raspandire: Scazut Potential de distrugere: Scazut Fisier static: Da Marime: 122.888 Bytes MD5: a098d5775d734e760d25f449dba5768d Versiune VDF: 6.35.01.218 Versiune IVDF: 6.35.01.222
General Metoda de raspandire: • Nu are rutina proprie de raspandire Alias: • Kaspersky: Trojan.Win32.VB.asp • F-Secure: Trojan.Win32.VB.asp • Sophos: Troj/VB-CRY • VirusBuster: Trojan.VB.YAZ • Eset: Win32/VB.ASP • Bitdefender: Trojan.VB.ASP Sistem de operare: • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Efecte secundare: • Modificari in registri Fisiere Se copiaza in urmatoarele locatii: • %SYSDIR%\SMHOST.exe • %SYSDIR%\WLOGON.exe • %directorul curent% \%fisier executat% Registrii sistemului Urmatoarele chei sunt adaugate in registri pentru a rula procesul la repornirea sistemului: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "RPCall"="%SYSDIR%\SMHOST.EXE /register" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Run] • "System handler"="%SYSDIR%\WLOGON.EXE /register" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Vechea valoare: • "ReportBootOk"="1" • "Shell"="Explorer.exe" • "System"="" • "Userinit"="%SYSDIR%\userinit.exe," • "SFCDisable"=dword:00000000 • "SFCScan"=%setarile utilizatorului% Noua valoare: • "ReportBootOk"="0" • "Shell"="explorer.exe %SYSDIR%\SMHOST.EXE" • "System"="%SYSDIR%\SMHOST.EXE" • "Userinit"="%SYSDIR%\userinit.exe,%SYSDIR%\WLOGON.EXE, " • "SFCDisable"=dword:ffffff9d • "SFCScan"=dword:00000000 – [HKCU\Software\Microsoft\Command Processor] Vechea valoare: • "EnableExtensions"=dword:00000001 • "AutoRun"=%setarile utilizatorului% Noua valoare: • "EnableExtensions"=dword:00000000 • "AutoRun"="echo off|%SYSDIR%\WLOGON.EXE|cls" – [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] Vechea valoare: • "load"=%setarile utilizatorului% Noua valoare: • "load"="%SYSDIR%\SMHOST.EXE" Diverse setari in Explorer: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Vechea valoare: • "Hidden"=%setarile utilizatorului% • "HideFileExt"=%setarile utilizatorului% • "ShowSuperHidden"=%setarile utilizatorului% Noua valoare: • "Hidden"=dword:00000002 • "HideFileExt"=dword:00000001 • "ShowSuperHidden"=dword:00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ CabinetState] Vechea valoare: • "FullPath"=%setarile utilizatorului% • "FullPathAddress"=%setarile utilizatorului% Noua valoare: • "FullPath"=dword:00000001 • "FullPathAddress"=dword:00000001 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ SystemFileProtection] Vechea valoare: • "ShowPopups"=%setarile utilizatorului% Noua valoare: • "ShowPopups"=dword:00000000 Detaliile fisierului Limbaj de programare: Limbaj de programare folosit: Visual Basic.
Description inserted by Adriana Popa on Friday, November 10, 2006 Description updated by Adriana Popa on Friday, November 10, 2006
Back
.
.
.
.