Nume: Worm/Tearec.A Descoperit pe data de: 12/10/2006 Tip: Vierme ITW: Da Numar infectii raportate: Scazut Potential de raspandire: Mediu spre ridicat Potential de distrugere: Mediu Fisier static: Da Marime: 94.154 Bytes MD5: 1c237c5af9c4c344eaac451b2ef5459c Versiune VDF: 6.36.00.97 Versiune IVDF: 6.36.00.113 - segunda-feira, 16 de outubro de 2006
General Metode de raspandire: • Email • Reteaua locala Alias: • Kaspersky: Email-Worm.Win32.Nyxem.e • TrendMicro: WORM_NYXEM.AA • F-Secure: Email-Worm.Win32.Nyxem.e • Sophos: W32/Nyxem-H • Panda: W32/Tearec.B.worm • Eset: Win32/Nyxem.NAA worm • Bitdefender: Win32.Nyxem.H@mm Sistem de operare: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Efecte secundare: • Inchide aplicatiile de securitate • Utilizeaza propriul motor de email • Reduce setarile de securitate • Modificari in registri Imediat dupa lansarea in executie, pe ecran este afisat: Fisiere Se copiaza in urmatoarele locatii: • %WINDIR%\Rundll16.exe • %SYSDIR%\scanregw.exe • C:\WINZIP_TMP.exe • %SYSDIR%\Update.exe • %SYSDIR%\Winzip.exe • %ALLUSERSPROFILE%\Start Menu\Programs\Startup\WinZip Quick Pick.exe Suprascrie urmatoarele fisiere. Sincronizarea integrata va determina activarea in urmatorul moment: Daca ziua este: 3 – %toate directoarele% Extensiile fisierului: • .HTM • .DBX • .EML • .MSG • .OFT • .NWS • .VCF • .MBX Cu urmatorul continut: • DATA Error [47 0F 94 93 F4 K5] Sterge urmatoarele fisiere: • %PROGRAM FILES%\DAP\*.dll • %PROGRAM FILES%\BearShare\*.dll • %PROGRAM FILES%\Symantec\LiveUpdate\*.* • %PROGRAM FILES%\Trend Micro\PC-cillin 2003\*.exe • %PROGRAM FILES%\Symantec\Common Files\Symantec Shared\*.* • %PROGRAM FILES%\Norton AntiVirus\*.exe • %PROGRAM FILES%\Alwil Software\Avast4\*.exe • %PROGRAM FILES%\McAfee.com\VSO\*.exe • %PROGRAM FILES%\McAfee.com\Agent\*.* • %PROGRAM FILES%\McAfee.com\shared\*.* • %PROGRAM FILES%\Trend Micro\PC-cillin 2002\*.exe • %PROGRAM FILES%\Trend Micro\Internet Security\*.exe • %PROGRAM FILES%\NavNT\*.exe • %PROGRAM FILES%\Kaspersky Lab\Kaspersky Anti-Virus Personal\*.ppl • %PROGRAM FILES%\Kaspersky Lab\Kaspersky Anti-Virus Personal\*.exe • %PROGRAM FILES%\Grisoft\AVG7\*.dll • %PROGRAM FILES%\TREND MICRO\OfficeScan\*.dll • %PROGRAM FILES%\Trend Micro\OfficeScan Client\*.exe • %PROGRAM FILES%\LimeWire\LimeWire 4.2.6\LimeWire.jar • %PROGRAM FILES%\Morpheus\*.dll • %PROGRAM FILES%\CA\eTrust EZ Armor\eTrust EZ Antivirus\*.* • %PROGRAM FILES%\Common Files\symantec shared\*.* • %PROGRAM FILES%\Kaspersky Lab\Kaspersky Anti-Virus Personal\*.* • %PROGRAM FILES%\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\*.* • %PROGRAM FILES%\McAfee.com\Agent\*.* • %PROGRAM FILES%\McAfee.com\shared\*.* • %PROGRAM FILES%\McAfee.com\VSO\*.* • %PROGRAM FILES%\NavNT\*.* • %PROGRAM FILES%\Norton AntiVirus\*.* • %PROGRAM FILES%\Panda Software\Panda Antivirus 6.0\*.* • %PROGRAM FILES%\Panda Software\Panda Antivirus Platinum\*.* • %PROGRAM FILES%\Symantec\LiveUpdate\*.* • %PROGRAM FILES%\Trend Micro\Internet Security\*.* • %PROGRAM FILES%\Trend Micro\PC-cillin 2002\*.* • %PROGRAM FILES%\Trend Micro\PC-cillin 2003 \*.* Registrii sistemului Urmatoarea cheie este adaugata in registri pentru a rula procesul la repornirea sistemului: – HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run • ScanRegistry = "scanregw.exe /scan" Valorile urmatoarelor chei sunt sterse din registrii sistemului: – HKLM\Software\Microsoft\Windows\CurrentVersion\Run • CleanUp • SECUR • NPROTECT • ccApp • ScriptBlocking • MCUpdateExe • VirusScan Online • MCAgentExe • VSOCheckTask • McRegWiz • MPFExe • MSKAGENTEXE • MSKDetectorExe • McVsRte • PCClient.exe • PCCIOMON.exe • pccguide.exe • Pop3trap.exe • PccPfw • tmproxy • McAfeeVirusScanService • NAV Agent • PCCClient.exe • SSDPSRV • rtvscn95 • defwatch • vptray • ScanInicio • APVXDWIN • KAVPersonal50 • kaspersky • TM Outbreak Agent • AVG7_Run • AVG_CC • Avgserv9.exe • AVGW • AVG7_CC • AVG7_EMC • Vet Alert • VetTray • OfficeScanNT Monitor • avast! • PANDA • DownloadAccelerator • BearShare – HKCU\Software\Microsoft\Windows\CurrentVersion\Run • CleanUp • SECUR • NPROTECT • ccApp • ScriptBlocking • MCUpdateExe • VirusScan Online • MCAgentExe • VSOCheckTask • McRegWiz • MPFExe • MSKAGENTEXE • MSKDetectorExe • McVsRte • PCClient.exe • PCCIOMON.exe • pccguide.exe • Pop3trap.exe • PccPfw • tmproxy • McAfeeVirusScanService • NAV Agent • PCCClient.exe • SSDPSRV • rtvscn95 • defwatch • vptray • ScanInicio • APVXDWIN • KAVPersonal50 • kaspersky • TM Outbreak Agent • AVG7_Run • AVG_CC • Avgserv9.exe • AVGW • AVG7_CC • AVG7_EMC • Vet Alert • VetTray • OfficeScanNT Monitor • avast! • PANDA • DownloadAccelerator • BearShare Se sterg urmatoarele chei din registri, inclusiv toate valorile si cheile subordnate: • Software\INTEL\LANDesk\VirusProtect6\CurrentVersion • SOFTWARE\Symantec\InstalledApps • SOFTWARE\KasperskyLab\InstalledProducts\Kaspersky Anti-Virus Personal • SOFTWARE\KasperskyLab\Components\101 • SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Iface.exe • SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Panda Antivirus 6.0 Platinum Urmatoarele chei din registri sunt modificate: Diverse setari in Explorer: – HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Noua valoare: • "WebView"=dword:00000000 • "ShowSuperHidden"=dword:00000000 Diverse setari in Explorer: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ CabinetState] Noua valoare: • "FullPath" = dword:00000001 Email Are un motor SMTP integrat. Va fi facuta o conexiune directa cu serverul destinatar. Iata caracteristicile lui: Catre: – Adrese de email gasite pe sistem. – Adrese de email obtinute din WAB (Windows Address Book) –Adrese de email obtinute din Yahoo! Messenger –Catre: Adrese de email obtinute din MSN Messenger Subiect: Unul din urmatoarele: • Word file; eBook.pdf; the file; Part 1 of 6 Video clipe; You Must View This Videoclip!; Miss Lebanon 2006; Re: Sex Video; My photos; The Best Videoclip Ever; School girl fantasies gone bad; A Great Video; Fuckin Kama Sutra pics; Arab sex DSC-00465.jpg; give me a kiss; *Hot Movie*; Fw: Funny :); Fwd: Photo; Fwd: image.jpg; Fw: Sexy; Re:; Fw:; Fw: Picturs; Fw: DSC-00465.jpg Uneori subiectul poate lipsi. Corpul email-ului: Corpul email-ului este unul din textele: • ----- forwarded message ----- • ???????????????????????????? ????????????? ?????? ??????????? • >> forwarded message • DSC-00465.jpg DSC-00466.jpg DSC-00467.jpg • forwarded message attached. • Fuckin Kama Sutra pics • hello, i send the file. bye • hi i send the details bye • Hot XXX Yahoo Groups • how are you? i send the details. OK ? • i attached the details. Thank you • i just any one see my photos. It's Free :) • Note: forwarded message attached. • photo photo2 photo3 • Please see the file. • ready to be FUCKED :) • VIDEOS! FREE! (US$ 0,00) • What? Atasament: Numele fisierului atasat este unul din urmatoarele: • 007.pif; 04.pif; 392315089702606E-02,.scR; 677.pif; Adults_9,zip.sCR; Arab sex DSC-00465.jpg; ATT01.zip.sCR; Attachments[001],B64.sCr; Clipe,zip.sCr; document.pif; DSC-00465.Pif; DSC-00465.pIf; DSC-00465.Pif; DSC-00465.pIf; eBook.pdf; eBook.PIF; image04.pif; image04.pif; New Video,zip; New_Document_file.pif; photo.pif; Photos,zip.sCR; School.pif; SeX,zip.scR; Sex.mim; Video_part.mim; WinZip,zip.scR; WinZip.BHX; WinZip.zip.sCR; Word XP.zip.sCR; Word.zip.sCR Atasamentul este o copie malware. Email Cautare adrese: Cauta adrese de email in urmatoarele fisiere: • *.doc; *.xls; *.mdb; *.mde; *.ppt; *.pps; *.zip; *.rar; *.pdf; *.psd; *.dmp Adrese evitate: Nu trimite email-uri la adrese care contin unul din urmatoarele siruri de caractere: • SYMANTEC; KASPERSKY; VIRUS; MCAFEE; TREND MICRO; PANDA; NORTON; FIX; HOTMAIL.COM; HELO; SECUR; SCRIBE; SPAM; ANTI; CILLIN; CA.COM; KASPER; TRUST; AVG; GROUPS.MSN; NOMAIL.YAHOO.COM; EEYE; MICROSOFT; @HOTMAIL; gmail.com; myway.com; @HOTPOP; @YAHOOGROUPS; @yahoo.com Rezolvarea adreselor internet: Se poate conecta la serverul DNS: • ns1.%domeniul destinatarului din adresa de email% Reţea Pentru a-si asigura raspandirea, programul malware incearca sa contacteze alte sisteme, asa cum este descris in continuare: Creeaza copii malware in urmatoarele share-uri de retea: • ADMIN$ • C$ Foloseste urmatoarele date de logare, pentru a controla sistemul la distanta: – Utilizatorul: • administrator Activare de la distanta: –Incearca sa activeze de la distanta malware-ul pe sistemul recent infectat. Pentru aceasta, apeleaza functia NetScheduleJobAdd. Terminarea proceselor Sunt inchise procesele care au titlul ferestri unul din urmatoarele: • SYMANTEC • SCAN • KASPERSKY • VIRUS • MCAFEE • TREND MICRO • NORTON • REMOVAL • FIX Backdoor Servere contactate: • http://webstats.web.rcn.net/**********?df=778247 Astfel se pot transmite informatii. Aceasta se face prin metoda HTTP POST, folosind un script CGI. Trimte informatii despre: • Statusul actual al malware-ului Detaliile fisierului Limbaj de programare: Limbaj de programare folosit: Visual Basic. Compresia fisierului: Pentru a ingreuna detectia si a reduce marimea fisierului, este folosit urmatorul program de arhivare: • UPX
Descrição enviada por Alexandru Dinu em
quarta-feira, 14 de novembro de 2007 Descrição atualizada por Alexandru Dinu em
sexta-feira, 16 de novembro de 2007
Voltar
.
.
.
.