Nome del virus: WORM/VBNA.B.370 Scoperto: 28/06/2010 Tipo: Worm In circolazione (ITW): Si Numero delle infezioni segnalate: Medio Potenziale di propagazione: Basso Potenziale di danni: Basso File statico: Si Dimensione del file: 69.632 Byte Somma di controllo MD5: fc5845e43fd492b43fdd39e53f615823 Versione VDF: 7.10.03.191 Versione IVDF: 7.10.08.209 - lunedì 28 giugno 2010
Generale Alias: • Kaspersky: Worm.Win32.VBNA.b • TrendMicro: WORM_VBNA.ABZ • Microsoft: Trojan:Win32/VB.AAG • AVG: VB.ADYE • Panda: W32/Autorun.JXY • VirusBuster: Worm.VBNA.TCJ • Eset: Win32/TrojanClicker.VB.NPD • AhnLab: Win32/Vbna.worm.69632.ARD • DrWeb: Trojan.MulDrop1.39253 • Fortinet: W32/VBNA.B!worm • Ikarus: Worm.Win32.VBNA Piattaforme / Sistemi operativi: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows 7 Effetti secondari: • Abbassa le impostazioni di sicurezza • Modifica del registro Registro Vengono cambiate le seguenti chiavi di registro: – [HKLM\SOFTWARE\Microsoft\Security Center] Valore precedente: • "UACDisableNotify"=dword:00000000 Nuovo valore: • "UACDisableNotify"=dword:00000001 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] Valore precedente: • "EnableLUA"=dword:00000001 Nuovo valore: • "EnableLUA"=dword:00000000 – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] Valore precedente: • "DisableSR"=dword:00000000 Nuovo valore: • "DisableSR"=dword:00000001 – [HKLM\SYSTEM\ControlSet001\Services\sr] Nuovo valore: • "Start"=dword:00000004 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Nuovo valore: • "ShowSuperHidden"=dword:00000000 • "SuperHidden"=dword:00000001 • "Hidden"=dword:00000002 • "HideFileExt"=dword:00000003 – [HKCU\Software\Microsoft\Internet Explorer\Main] Nuovo valore: • "Start Page"="http://www.nuevaq.fm" • "Local Page"="http://www.nuevaq.fm" • "Search Page"="http://www.nuevaq.fm" • "Default_Search_URL"="http://www.nuevaq.fm" • "Default_Page_URL"="http://www.nuevaq.fm" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Netscape.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Safari.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\opera.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\chrome.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\helper.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\updater.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\crashreporter.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\firefox.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Filemon.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Procmon.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\procexp.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\portmon.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\prckiller.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\gpedit.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\boot.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zlh.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Regmon.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\fslaunch.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\cclaw.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ndntspst.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\nd98spst.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kis8.0.0.506latam.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kav8.0.0.357es.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\WS2Fix.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\UCCLSID.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\VACFix.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\unzip.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\swsc.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\swxcacls.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Diskmon.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\SrchSTS.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\SmitfraudFix.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\IEDFix.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\HostsChk.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\GenericRenosFix.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\exit.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\dumphive.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Restart.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Process.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ntdetect.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\HJTInstall.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ChromeSetup.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Opera_964_int_Setup.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ GoogleToolbarInstaller_download_signed.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\fa-setup.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonealarm.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonalm2601.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonalarm.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zauinst.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zatutorzauinst.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zatutor.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zapsetup3001.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zapro.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\xscan.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\xpf202en.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wyvernworksfirewall.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wsbgate.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wrctrl.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wradmin.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wnt.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wmiav.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wmias.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winsfcm.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winservices.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winroute.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winrecon.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winppr32.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winmgm32.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe\"" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wink.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winhlpp32.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wingate.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wimmun32.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\whoswatchingme.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wgfe95.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wfindv32.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webtrap.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webscanx.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webscan.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\watchdog.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\w9x.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\w32dsm89.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vvstat.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswinperse.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswinntse.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswin9xe.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsstat.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsscan40.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsmon.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsmain.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsisetup.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vshwin32.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsecomr.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsched.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscenu6.02d30.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscan40.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscan.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vptray.exe] Nuovo valore: • "Debugger"="%WINDIR% \twunk_16.exe" Dettagli del file Linguaggio di programmazione: Il malware è stato scritto in Visual Basic.
Descrizione inserita da Alexandru Dinu su giovedì 12 agosto 2010 Descrizione aggiornata da Alexandru Dinu su lunedì 23 agosto 2010
Indietro
.
.
.
.