Need help? Ask the community or hire an expert.
Go to Avira Answers
Nume:TR/Spy.Zb.ae.118784
Descoperit pe data de:14/05/2010
Tip:Troian
ITW:Da
Numar infectii raportate:Scazut spre mediu
Potential de raspandire:Scazut spre mediu
Potential de distrugere:Scazut spre mediu
Fisier static:Da
Marime:118.784 Bytes
MD5:4dc14290fb2cb22e11e3a1d24aa09dc1
Versiune VDF:7.10.03.22
Versiune IVDF:7.10.07.108 - vineri, 14 mai 2010

 General Metoda de raspandire:
   • Peer to Peer


Alias:
   •  Bitdefender: Trojan.Generic.4448808
   •  Panda: Trj/Sinowal.XHI
   •  Eset: Win32/Spy.Zbot.YW


Sistem de operare:
   • Windows 2000
   • Windows XP
   • Windows 2003


Efecte secundare:
   • Creeaza fisiere malware
   • Modificari in registri
   • Profita de vulnerabilitatile softului
      •  CVE-2007-1204
      •  MS07-019

 Fisiere Se copiaza in urmatoarea locatie:
   • %SYSDIR%\sdra64.exe



Sunt create fisierele:

%SYSDIR%\lowsec\user.ds
%SYSDIR%\lowsec\local.ds
%SYSDIR%\lowsec\user.ds.lll

 Registrii sistemului Creeaza urmatoarea valoare, pentru a trece de Windows XP firewall:

– [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
   FirewallPolicy\StandardProfile]
   • "EnableFirewall"=dword:0x00000000



Urmatoarele chei sunt adaugate in registrii sistemului:

– [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\
   Protected Storage System Provider\S-1-5-20]
   • "Migrate"=dword:0x00000002

– [HKEY_USERS\S-1-5-20\Software\Microsoft\
   Protected Storage System Provider\S-1-5-20\Data 2\Windows]
   • "Value"=hex:01,00,00,00,1C,00,00,00,03,00,00,00,6D,DB,FE,19,ED,B6,6C,F2,56,86,31,BD,12,FB,6F,BB,00,86,57,A4,41,28,EB,06,10,00,00,00,89,3D,50,AD,A5,CF,68,A8,24,AE,9C,50,4F,CE,FB,3C,14,00,00,00,C6,6E,5C,0C,61,D1,67,62,E7,97,8F,47,ED,6F,87,F9,41,C0,9B,C5

– [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\
   Network]
   • "UID"="%numele computerului%_7875768FCFF3ECE1"

– [HKEY_USERS\.DEFAULT\software\microsoft\windows\currentversion\
   explorer\{4776C4DC-E894-7C06-2148-5D73CEF5F905}]
   • "{3039636B-5F3D-6C64-6675-696870667265}"=hex:F7,09,F2,0D
   • "{33373039-3132-3864-6B30-303233343434}"=hex:F7,09,F2,0D
   • "{6E633338-267E-2A79-6830-386668666866}"=hex:F7,09,F2,0D

– [HKEY_USERS\.DEFAULT\Software\Microsoft\
   Protected Storage System Provider\S-1-5-18\Data 2\Windows]
   • "Value"=hex:01,00,00,00,1C,00,00,00,03,00,00,00,2C,3F,19,91,9B,FA,E1,E9,3C,EC,47,57,9D,58,B0,8C,CE,E0,C2,55,B3,A0,92,BF,10,00,00,00,88,F2,ED,F5,9C,51,81,3E,99,80,43,85,7D,A5,4F,7D,14,00,00,00,86,B4,0A,71,D5,43,63,CA,5C,FF,9F,0E,13,1B,E5,E6,EF,AA,5D,4A

– [HKEY_USERS\.DEFAULT\software\microsoft\windows\currentversion\
   explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}]
   • "{3039636B-5F3D-6C64-6675-696870667265}"=hex:F7,09,F2,0D
   • "{33373039-3132-3864-6B30-303233343434}"=hex:F7,09,F2,0D
   • "{6E633338-267E-2A79-6830-386668666866}"=hex:F7,09,F2,0D

– [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\
   Protected Storage System Provider\S-1-5-18]
   • "Migrate"=dword:0x00000002

– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network]
   • "UID"="%numele computerului%_7875768FCFF3ECE1"

– [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\
   Network]
   • "UID"="%numele computerului%_7875768FCFF3ECE1"



Urmatoarele chei din registri sunt modificate:

– [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\
   Winlogon]
   Noua valoare:
   • "ParseAutoexec"="1"

– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   Noua valoare:
   • "userinit"="%SYSDIR%\userinit.exe,%SYSDIR%\sdra64.exe,"

– [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\
   Winlogon]
   Noua valoare:
   • "ParseAutoexec"="1"

 P2P  Pentru a infecta alte sisteme din retele Peer-to-Peer, efectueaza urmatarele operatii:   Extrage fisierele partajate, folosind urmatoarele chei de registru:
   • software\flashfxp\3
   • software\ghisler\total commander
   • software\ipswitch\ws_ftp
   • software\far\plugins\ftp\hosts
   • software\far2\plugins\ftp\hosts
   • software\martin prikryl\winscp 2\sessions
   • software\ftpware\coreftp\sites
   • software\smartftp\client 2.0\settings\general\favorites


 Furt de informatii Incearca sa obtina urmatoarele informatii:

– O rutina de logare este pornita dupa ce un site este vizitat:
   • https://onlineeast.bankofamerica.com/cgi-bin/ias/*/GotoWelcome

 Injectarea codului malware in alte procese – Se injecteaza ca un thread remote intr-un proces.

    Numele procesului:
   • winlogon.exe



– Se injecteaza ca un thread remote intr-un proces.

    Numele procesului:
   • svchost.exe



– Se injecteaza ca un thread remote intr-un proces.

Este injectat in toate procesele.


 Alte informatii Acceseaza resurse de pe internet:
   • http://www.oomseekerss.ru/img/**********


Mutex:
Creeaza urmatorii mutecsi:
   • _AVIRA_2110
   • _AVIRA_2109
   • _AVIRA_2108
   • _AVIRA_2101
   • _AVIRA_21099

 Detaliile fisierului Limbaj de programare:
Limbaj de programare folosit: C (compilat cu Microsoft Visual C++).


Compresia fisierului:
Pentru a ingreuna detectia si a reduce marimea fisierului, este folosit un program de compresie runtime.

Description inserted by Petre Galan on Friday, February 4, 2011
Description updated by Petre Galan on Friday, February 4, 2011

Back . . . .