Nombre: WORM/VBNA.B.370 Descubierto: 28/06/2010 Tipo: Gusano En circulación (ITW): Sí Número de infecciones comunicadas: Medio Potencial de propagación: Bajo Potencial dañino: Bajo Fichero estático: Sí Tamaño: 69.632 Bytes Suma de control MD5: fc5845e43fd492b43fdd39e53f615823 Versión del VDF: 7.10.03.191 Versión del IVDF: 7.10.08.209 - lunes 28 de junio de 2010
General Alias: • Kaspersky: Worm.Win32.VBNA.b • TrendMicro: WORM_VBNA.ABZ • Microsoft: Trojan:Win32/VB.AAG • AVG: VB.ADYE • Panda: W32/Autorun.JXY • VirusBuster: Worm.VBNA.TCJ • Eset: Win32/TrojanClicker.VB.NPD • AhnLab: Win32/Vbna.worm.69632.ARD • DrWeb: Trojan.MulDrop1.39253 • Fortinet: W32/VBNA.B!worm • Ikarus: Worm.Win32.VBNA Plataformas / Sistemas operativos: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows 7 Efectos secundarios: • Reduce las opciones de seguridad • Modificaciones en el registro Registro Modifica las siguientes claves del registro: – [HKLM\SOFTWARE\Microsoft\Security Center] Valor anterior: • "UACDisableNotify"=dword:00000000 Nuevo valor: • "UACDisableNotify"=dword:00000001 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] Valor anterior: • "EnableLUA"=dword:00000001 Nuevo valor: • "EnableLUA"=dword:00000000 – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] Valor anterior: • "DisableSR"=dword:00000000 Nuevo valor: • "DisableSR"=dword:00000001 – [HKLM\SYSTEM\ControlSet001\Services\sr] Nuevo valor: • "Start"=dword:00000004 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Nuevo valor: • "ShowSuperHidden"=dword:00000000 • "SuperHidden"=dword:00000001 • "Hidden"=dword:00000002 • "HideFileExt"=dword:00000003 – [HKCU\Software\Microsoft\Internet Explorer\Main] Nuevo valor: • "Start Page"="http://www.nuevaq.fm" • "Local Page"="http://www.nuevaq.fm" • "Search Page"="http://www.nuevaq.fm" • "Default_Search_URL"="http://www.nuevaq.fm" • "Default_Page_URL"="http://www.nuevaq.fm" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Netscape.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Safari.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\opera.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\chrome.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\helper.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\updater.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\crashreporter.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\firefox.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Filemon.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Procmon.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\procexp.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\portmon.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\prckiller.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\gpedit.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\boot.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zlh.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Regmon.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\fslaunch.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\cclaw.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ndntspst.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\nd98spst.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kis8.0.0.506latam.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kav8.0.0.357es.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\WS2Fix.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\UCCLSID.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\VACFix.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\unzip.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\swsc.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\swxcacls.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Diskmon.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\SrchSTS.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\SmitfraudFix.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\IEDFix.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\HostsChk.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\GenericRenosFix.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\exit.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\dumphive.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Restart.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Process.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ntdetect.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\HJTInstall.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ChromeSetup.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Opera_964_int_Setup.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ GoogleToolbarInstaller_download_signed.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\fa-setup.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonealarm.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonalm2601.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonalarm.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zauinst.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zatutorzauinst.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zatutor.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zapsetup3001.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zapro.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\xscan.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\xpf202en.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wyvernworksfirewall.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wsbgate.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wrctrl.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wradmin.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wnt.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wmiav.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wmias.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winsfcm.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winservices.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winroute.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winrecon.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winppr32.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winmgm32.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe\"" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wink.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winhlpp32.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wingate.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wimmun32.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\whoswatchingme.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wgfe95.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wfindv32.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webtrap.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webscanx.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webscan.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\watchdog.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\w9x.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\w32dsm89.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vvstat.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswinperse.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswinntse.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswin9xe.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsstat.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsscan40.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsmon.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsmain.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsisetup.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vshwin32.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsecomr.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsched.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscenu6.02d30.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscan40.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscan.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vptray.exe] Nuevo valor: • "Debugger"="%WINDIR% \twunk_16.exe" Datos del fichero Lenguaje de programación: El programa de malware ha sido escrito en Visual Basic.
Descripción insertada por Alexandru Dinu el jueves 12 de agosto de 2010 Descripción actualizada por Alexandru Dinu el lunes 23 de agosto de 2010
Volver
.
.
.
.