Nume: TR/Agent.tcn Descoperit pe data de: 06/06/2009 Tip: Troian ITW: Da Numar infectii raportate: Scazut Potential de raspandire: Scazut Potential de distrugere: Scazut Fisier static: Nu Versiune VDF: 7.01.04.64
General • Nu are rutina proprie de raspandire • Kaspersky: Backdoor.Win32.Agent.ahrt • F-Secure: Backdoor.Win32.Agent.ahrt • Sophos: Mal/Generic-A • Bitdefender: Trojan.VB.NZF • Sustrage informatii Fisiere Se copiaza in urmatoarele locatii: • %WINDIR%\systemserv32.exe • C:\multi_keygen_for_532_games.exe • %PROGRAM FILES%\appleJuice\incoming\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Bearshare\Shared\multi_keygen_for_532_games.exe • %PROGRAM FILES%\eDonkey2000\Incoming\multi_keygen_for_532_games.exe • %PROGRAM FILES%\emule\incoming\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Gnucleus\Downloads\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Grokster\My Grokster\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Kazaa Lite K++\My Shared Folder\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Kazaa Lite\My Shared Folder\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Kazaa\My Shared Folder\multi_keygen_for_532_games.exe • %PROGRAM FILES%\KMD\My Shared Folder\multi_keygen_for_532_games.exe • %PROGRAM FILES%\limewire\Shared\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Morpheus\My Shared Folder\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Overnet\incoming\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Rapigator\Share\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Shareaza\Downloads\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Swaptor\Download\multi_keygen_for_532_games.exe • %PROGRAM FILES%\Tesla\Files\multi_keygen_for_532_games.exe • %PROGRAM FILES%\WinMX\My Shared Folder\multi_keygen_for_532_games.exe • %PROGRAM FILES%\XoloX\Downloads\multi_keygen_for_532_games.exe – Un fisier care contine adrese de e-mail: • %WINDIR%\wkernel32.sys Registrii sistemului Urmatoarea cheie este adaugata in registri pentru a rula procesul la repornirea sistemului: – SystemService32 • %WINDIR%\systemserv32.exe Backdoor Servere contactate: • http://blog.infolinux.ro/**************** Aceasta se face printr-o interogare HTTP GET intr-un script PHP. Trimte informatii despre: • Adresele de email colectate • Numele sistemului Furt de informatii Incearca sa obtina urmatoarele informatii: – Urmatorul CD-key: • Steam – Parolele din urmatoarele programe: • Firefox • Steam – Monitorizeaza reteaua folosind un sniffer si cauta urmatoarele siruri de caractere: • :.login; :,login; :!login; :@login; :$login; :%login; :^login; :&login; :*login; :-login; :+login; :/login; :\login; :=login; :?login; :'login; :`login; :~login; : login; :.auth; :,auth; :!auth; :@auth; :$auth; :%auth; :^auth; :&auth; :*auth; :-auth; :+auth; :/auth; :\auth; :=auth; :?auth; :'auth; :`auth; :~auth; : auth; :.hashin; :!hashin; :$hashin; :%hashin; :.secure; :!secure; :.syn Detaliile fisierului Limbaj de programare: Limbaj de programare folosit: Visual Basic.
Descrição enviada por Serban Ghiuta em
terça-feira, 28 de julho de 2009 Descrição atualizada por Serban Ghiuta em
quarta-feira, 29 de julho de 2009
Voltar
.
.
.
.