Nume:TR/Juan.E trojan
Descoperit pe data de:01/02/2007
Tip:Troian
ITW:Nu
Numar infectii raportate:Scazut
Potential de raspandire:Scazut
Potential de distrugere:Scazut spre mediu
Fisier static:Da
Marime:44.165 Bytes
MD5:83292296d7d1340C59528035fb89ded8
Versiune VDF:6.37.01.10 - Thursday, February 1, 2007
Versiune IVDF:6.37.01.10 - Thursday, February 1, 2007

 General Metoda de raspandire:
   • Nu are rutina proprie de raspandire


Alias:
   •  Kaspersky: Trojan.Win32.BHO.g
   •  F-Secure: Trojan.Win32.BHO.g
   •  Eset: Win32/BHO.G


Sistem de operare:
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


Efecte secundare:
   • Sustrage informatii

 Registrii sistemului Inregistreaza un browser helper object (BHO) prin adaugarea urmatoarelor chei in registri:

– [HKCR\CLSID\{68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50}\InprocServer32]
   • @="%directorul de activare malware%\%dll malware%
   • "ThreadingModel"="Both"

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
   Browser Helper Objects\{68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50}]

 Backdoor Servere contactate:
Unul dintre:
   • http://65.243.**********
   • http://24.244.**********
   • http://66.220.**********
   • http://64.225.**********

Astfel se pot transmite informatii. Aceasta se face printr-o interogare HTTP GET intr-un script PHP.


Trimte informatii despre:
    • Informatiile colectate, descrise in sectiunea
    • adresele vizitate

 Furt de informatii – O rutina de logare este pornita dupa ce unul din urmatoarele site-uri este vizitat:
   • allyoursearch.com; thefreedictionary.com; searchfeed.com;
      www.neon.org.uk; www.sensis.com.au; mygeek.com; clearsearch.com;
      search.gohip.com; usseek.com; findwhat.com; websearch.com;
      revquest.com; 7search.com; ditto.com; mysearch.myway.com;
      mywebsearch.com; destinationadult.com; instafinder.com;
      uk.overture.com; exactsearch.net; findsearch.net; perfectnav.com;
      scoutcrawl.com; genieknows.com; navisearch.net; what2find.com;
      sirsearch.com; crawlbar.com; overture.com; inquire.com; netster.com;
      www.grip.com; www.ukindex.co.uk; lb1.netster.com; zeal.com; seeq.com;
      uk.searchengine.com; url.searchuk.com; www.excite.co.jp;
      search.dmoz.org; www.goclick.com; wikipedia.org; search.about.com;
      galaxysearch.com; wesearchall.com; sex.com; www.london-pages.co.uk;
      vachercher.lycos.fr; search.netscape.com; search.netzero.net;
      search.lycos.co.uk; cgi.search123.com; search.asiaco.com;
      query.nytimes.com; search.aol.co.uk; search.lycos.com;
      www.250000.co.uk; search.aol.com; suche.lycos.de; zoek.lycos.nl;
      vivisimo.com; kanoodle.com; comcast.net; hotbot.com; jayde.com;
      mamma.com; o.co.uk; mirago.de; searchmiracle.com; coolwebsearch.com;
      search.looksmart.com; www.infoseek.co.jp; dogpile.com; sqwire.com;
      vaclick.epilot.com; searchscout.com; apps5.oingo.com;
      fr.search.yahoo.com; au.search.yahoo.com; uk.search.yahoo.com;
      kr.search.yahoo.com; ca.search.yahoo.com; tw.search.yahoo.com;
      de.search.yahoo.com; hk.search.yahoo.com; search.yahoo.co.jp;
      search.yahoo.com; search.sympatico.msn.ca; search.earthlink.net;
      search.wanadoo.co.uk; search.xtramsn.co.nz; www.recherche.aol.fr;
      www.google.com.tw; search.msn.com.hk; www.google.com.hk;
      www.google.com.au; au.altavista.com; fr.altavista.com;
      de.altavista.com; nz.altavista.com; nl.altavista.com;
      uk.altavista.com; search.msn.co.uk; search.msn.com; shoprogers.com;
      reference.com; web.ask.co.uk; go.google.com; alltheweb.com;
      search.msn.fr; gigablast.com; altavista.com; google.com.mx;
      goguides.org; google.co.uk; cp.ah-ha.com; ask.com/web; wisenut.com;
      s.teoma.com; google.com; google.be; bbc.co.uk; google.fr; google.it;
      google.ca; google.de; alexa.com; google.es

 Detaliile fisierului Limbaj de programare:
Limbaj de programare folosit: C (compilat cu Microsoft Visual C++).
Pentru a ingreuna detectia si a reduce marimea fisierului, este folosit urmatorul program de arhivare:
   • UPX

Description inserted by Ernest Szocs on Thursday, February 22, 2007
Description updated by Ernest Szocs on Thursday, February 22, 2007

Back . . . .