Nume: TR/Autorun.27648 Descoperit pe data de: 19/05/2008 Tip: Troian ITW: Da Numar infectii raportate: Scazut Potential de raspandire: Scazut spre mediu Potential de distrugere: Mediu Fisier static: Da Marime: 27648 Bytes MD5: 25df082e988842e1604b5a893572a083 Versiune IVDF: 7.00.04.62 - segunda-feira, 19 de maio de 2008
General Metoda de raspandire: • Discuri de retea mapate Alias: • Mcafee: W32/Autorun.worm.f • Kaspersky: Worm.Win32.AutoRun.cpi • F-Secure: Worm.Win32.AutoRun.cpi • Sophos: W32/Autorun-BC • Grisoft: Worm/Generic.FNV • Eset: Win32/AutoRun.GR • Bitdefender: Worm.Autorun.Delf.H Sistem de operare: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Efecte secundare: • Inchide aplicatiile de securitate • Descarca fisiere • Creeaza fisiere • Reduce setarile de securitate • Modificari in registri Fisiere Se copiaza in urmatoarele locatii: • %WINDIR%\system.exe • %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Explorer.exe • %unitate disc% \auto.exe Sunt create fisierele: – %unitate disc% \autorun.inf Acesta este un fisier text care nu prezinta pericol si are urmatorul continut: • %cod care ruleaza fisierul malitios% Incearca sa descarce cateva fisiere: – Adresele sunt urmatoarele: • http://72.232.108.82/~grimsby/**********/button1.jpg • http://72.232.108.82/~grimsby/**********/button1.pdf • http://72.232.108.82/~grimsby/**********/button1.png • http://72.232.141.84/~cgitnet/**********/ChangeLog.pdf • http://72.232.141.84/~cgitnet/**********/ChangeLog.png • http://72.232.141.84/~cgitnet/**********/ChangeLog.txt • http://72.232.208.150/~aryacdc/**********/toc.gif • http://72.232.208.150/~aryacdc/**********/toc.pdf • http://72.232.208.150/~aryacdc/**********/toc.png • http://206.221.179.205/~ampedmed/Forums/**********/xand/upgrade.pdf • http://206.221.179.205/~ampedmed/Forums/**********/xand/upgrade.png • http://206.221.179.205/~ampedmed/Forums/**********/xand/upgrade.tpl • http://216.246.30.66/~mkshost/forums/**********/subSilver/upgrade.pdf • http://216.246.30.66/~mkshost/forums/**********/subSilver/upgrade.png • http://216.246.30.66/~mkshost/forums/**********/subSilver/upgrade.tpl La momentul realizarii descrierii, acest fisier nu era disponibil pentru o analiza ulterioara. Incearca se execute urmatorul fisier: – Numele fisierului: • %PROGRAM FILES%\Internet Explorer\iexplore.exe cu urmatorii parametri: http://70.86.197.82/~ohnishi/**********/test2.htm Registrii sistemului Se sterg urmatoarele chei din registri, inclusiv toate valorile si cheile subordnate: • [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] • [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] Urmatoarele chei sunt adaugate in registrii sistemului: – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Bkav2006.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\IEProt.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\bdss.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsserv.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\bdagent.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\xcommsvr.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\livesrv.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\worm2007.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\PFW.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Kav.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\KVOL.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\KVFW.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TBMon.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kav32.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kvwsc.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\CCAPP.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\EGHOST.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\KRegEx.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kavsvc.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\VPTray.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RAVMON.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\KavPFW.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\SHSTAT.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RavTask.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\TrojDie.kxp.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Iparmor.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\MAILMON.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\MCAGENT.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\KAVPLUS.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RavMonD.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Rtvscan.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Nvsvc32.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\KVMonXP.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Kvsrvxp.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\CCenter.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\KpopMon.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RfwMain.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\KWATCHUI.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\MCVSESCN.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\MSKAGENT.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kvolself.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\KVCenter.kxp.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kavstart.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RAVTIMER.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RRfwMain.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\FireTray.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\UpdaterUI.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\KVSrvXp_1.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\RavService.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\icesword.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\cmd.exe] • Debugger = system.exe – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\far.exe] • Debugger = system.exe Urmatoarele chei din registri sunt modificate: – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Vechea valoare: • Shell = Explorer.exe • Userinit = %SYSDIR%\userinit.exe Noua valoare: • Shell = Explorer.exe, System • Userinit = %SYSDIR%\userinit.exe, System – [HKCU\Software\Yahoo\pager\View\YMSGR_buzz] Noua valoare: • content url = http://clickmanu.com – [HKCU\Software\Yahoo\pager\View\YMSGR_Launchcast] Noua valoare: • content url = http://clickmanu.com Dezactivarea programelor Regedit si Task Manager: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] Noua valoare: • DisableTaskMgr = 1 • DisableRegistryTools = 1 – [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] Noua valoare: • DisableTaskMgr = 1 • DisableRegistryTools = 1 Pagina de start in Internet Explorer: – [HKCU\Software\Microsoft\Internet Explorer\Main] Vechea valoare: • Start Page = %setarile utilizatorului% Noua valoare: • Start Page = http://clickmanu.com Diverse setari in Explorer: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] Noua valoare: • NoDriveTypeAutoRun = dword:00000091 • NoRun = 1 • NoFolderOptions = 1 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Noua valoare: • Hidden = 2 • ShowSuperHidden = 0 • HideFileExt = 1 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ Folder\Hidden\SHOWALL] Noua valoare: • CheckedValue = 0 – [HKCU\Software\Microsoft\Command Processor] Noua valoare: • EnableExtensions = 0 – [HKCU\Software\Microsoft\Internet Explorer\New Windows] Noua valoare: • PopupMgr = 0 Terminarea proceselor Opreste executia proceselor care contin unul din urmatoarele siruri de caractere in numele de fisier: • Bkav2006.exe; IEProt.exe; bdss.exe; vsserv.exe; bdagent.exe; xcommsvr.exe; livesrv.exe; worm2007.exe; PFW.exe; Kav.exe; KVOL.exe; KVFW.exe; TBMon.exe; kav32.exe; kvwsc.exe; CCAPP.exe; EGHOST.exe; KRegEx.exe; kavsvc.exe; VPTray.exe; RAVMON.exe; KavPFW.exe; SHSTAT.exe; RavTask.exe; TrojDie.kxp.exe; Iparmor.exe; MAILMON.exe; MCAGENT.exe; KAVPLUS.exe; RavMonD.exe; Rtvscan.exe; Nvsvc32.exe; KVMonXP.exe; Kvsrvxp.exe; CCenter.exe; KpopMon.exe; RfwMain.exe; KWATCHUI.exe; MCVSESCN.exe; MSKAGENT.exe; kvolself.exe; KVCenter.kxp.exe; kavstart.exe; RAVTIMER.exe; RRfwMain.exe; FireTray.exe; UpdaterUI.exe; KVSrvXp_1.exe; RavService.exe; icesword.exe; cmd.exe; far.exe Lista cu serviciile dezactivate: • sharedaccess; RsCCenter; RsRavMon; KVWSC; KVSrvXP; McAfeeFramework; McShield; McTaskManager; navapsvc; wscsvc; KPfwSvc; SNDSrvc; ccProxy; ccEvtMgr; ccSetMgr; SPBBCSvc; Symantec Core LC; NPFMntor; MskService; FireSvc Detaliile fisierului Limbaj de programare: Limbaj de programare folosit: Delphi. Compresia fisierului: Pentru a ingreuna detectia si a reduce marimea fisierului, este folosit urmatorul program de arhivare: • UPX
Descrição enviada por Andrei Gherman em
sexta-feira, 13 de junho de 2008 Descrição atualizada por Andrei Gherman em
sexta-feira, 13 de junho de 2008
Voltar
.
.
.
.