Nume: TR/Click.Small.HR Descoperit pe data de: 23/08/2005 Tip: Troian ITW: Nu Numar infectii raportate: Scazut Potential de raspandire: Scazut Potential de distrugere: Scazut spre mediu Fisier static: Da Marime: 20.480 Bytes MD5: aab0b0d92b441763d45cff47c9224bcb Versiune VDF: 6.31.1.140
General Metoda de raspandire: • Nu are rutina proprie de raspandire Alias: • Symantec: PWSteal.Lemir • Kaspersky: Trojan-Clicker.Win32.Small.hr • Panda: Trj/Agent.AIA • Bitdefender: Trojan.Clicker.Small.HR Sistem de operare: • Windows 95 • Windows 98 • Windows 98 SE • Windows 2000 • Windows XP Efecte secundare: • Inchide aplicatiile de securitate • Modificari in registri Fisiere Se copiaza in urmatoarea locatie: • %SYSDIR%\iexplore.exe Sterge copia initiala a virusului. Este creat fisierul: – %WINDIR%\deleteme.bat Fisierul este executat dupa ce a fost creat. Fisierul batch este folosit pentru stergerea unui fisier. Registrii sistemului Urmatoarea cheie este adaugata in registri pentru a rula procesul la repornirea sistemului: – HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run • "Microsoft"="%SYSDIR%\iexplore.exe" Valorile urmatoarelor chei sunt sterse din registrii sistemului: – HKLM\SoftWare\Microsoft\Windows\CurrentVersion\Run • RavMon • KAVPersonal50 • RavTimer • KvMonXP • iDuba Personal FireWall • KAVRun • KpopMon • Kulansyn • KavPFW • KvXP • ccApp • SSC_UserPrompt • NAV CfgWiz • MCAgentExe • McRegWiz • MCUpdateExe • MSKAGENTEXE • MSKDetectorExe • VirusScan Online • VSOCheckTask • McAfeeUpdaterUI • Network Associates Error Reporting Service • ShStatEXE • KavStart • Services • KWatch9x – HKCU\SoftWare\Microsoft\Windows\CurrentVersion\Run • iDuba Personal FireWall • KavPFW • KvXP Urmatoarele chei sunt adaugate in registrii sistemului: – HKLM\SYSTEM\CurrentControlSet\Services\RsRavMon • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\RsCCenter • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\kavsvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\KVSrvXP • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\wscsvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\SNDSrvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\ccProxy • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\ccEvtMgr • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\ccSetMgr • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\SPBBCSvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\Symantec Core LC • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\navapsvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\NPFMntor • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\MskService • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\FireSvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\McShield • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\McTaskManager • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\McAfeeFramework • Start=dword:00000004 Terminarea proceselor Lista cu procesele oprite: • CCAPP.EXE; EGHOST.EXE; explor.exe; FireTray.exe; Iparmor.exe; KATMain.EX; KAV32.EXE; KAVPFW.EXE; KAVPLUS.EXE; KAVStart.exe; KmailMon.EXE; KPOPMON.EXE; KRegEx.exe; KVCENTER.KXP; KvDetech.exe; KVFW.EXE; KVMonXP.KXP; KVOL.exe; kvolself.exe; KVXP.KXP; KWatch9x.exe; KWATCHUI.EXE; MAILMON.EXE; MCAGENT.EXE; MCVSESCN.EXE; MSKAGENT.EXE; RAV.EXE; RAVMON.EXE; RAVTIMER.EXE; SHSTAT.EXE; SOFTOK.EXE; TBMon.exe; TrojanDetector.EXE; TrojDie.kxp; UpdaterUI.exe; windox.exe Procesele cu urmatoarele caracteristici sunt oprite: • Titlu: Symantec AntiVirus Numele clasei: KV2004 • Titlu: RavMon.exe Numele clasei: RavMonClass • Titlu: ZoneAlarm Numele clasei: ZAFrameWnd • Titlu: %caractere dublu-byte% Numele clasei: Tapplication • Titlu: %caractere dublu-byte% Numele clasei: TForm1 • Titlu: %aleator% Numele clasei: TfLockDownMain • Titlu: %aleator% Numele clasei: KvXP_ExpertFrame • Titlu: %aleator% Numele clasei: WHXMDI0 Lista cu serviciile dezactivate: • ccEvtMgr; ccProxy; ccSetMgr; FireSvc; kavsvc; KPfwSvc; KVSrvXP; KWatchSvc; McAfeeFramework; McShield; McTaskManager; MskService; navapsvc; NPFMntor; RsCCenter; RsRavMon; SNDSrvc; SPBBCSvc; Symantec Core LC; wscsvc Detaliile fisierului Limbaj de programare: Limbaj de programare folosit: Delphi. Compresia fisierului: Pentru a ingreuna detectia si a reduce marimea fisierului, este folosit urmatorul program de arhivare: • UPX
Descripción insertada por Irina Boldea el martes 23 de agosto de 2005 Descripción actualizada por Irina Boldea el lunes 29 de agosto de 2005
Volver
.
.
.
.