Vírus WORM/VBNA.B.370 Data em que surgiu: 28/06/2010 Tipo: Worm Incluído na lista "In The Wild" Sim Nível de danos: Médio Nível de distribuição: Baixo Nível de risco: Baixo Ficheiro estático: Sim Tamanho: 69.632 Bytes MD5 checksum: fc5845e43fd492b43fdd39e53f615823 Versão VDF: 7.10.03.191 Versão IVDF: 7.10.08.209 - segunda-feira, 28 de junho de 2010
Vulgarmente Alias: • Kaspersky: Worm.Win32.VBNA.b • TrendMicro: WORM_VBNA.ABZ • Microsoft: Trojan:Win32/VB.AAG • AVG: VB.ADYE • Panda: W32/Autorun.JXY • VirusBuster: Worm.VBNA.TCJ • Eset: Win32/TrojanClicker.VB.NPD • AhnLab: Win32/Vbna.worm.69632.ARD • DrWeb: Trojan.MulDrop1.39253 • Fortinet: W32/VBNA.B!worm • Ikarus: Worm.Win32.VBNA Sistemas Operativos: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows 7 Efeitos secundários: • Baixa as definições de segurança • Altera o registo do Windows Registry (Registo do Windows) Altera as seguintes chaves de registo do Windows: – [HKLM\SOFTWARE\Microsoft\Security Center] Valor anterior: • "UACDisableNotify"=dword:00000000 Valor recente: • "UACDisableNotify"=dword:00000001 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] Valor anterior: • "EnableLUA"=dword:00000001 Valor recente: • "EnableLUA"=dword:00000000 – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] Valor anterior: • "DisableSR"=dword:00000000 Valor recente: • "DisableSR"=dword:00000001 – [HKLM\SYSTEM\ControlSet001\Services\sr] Valor recente: • "Start"=dword:00000004 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Valor recente: • "ShowSuperHidden"=dword:00000000 • "SuperHidden"=dword:00000001 • "Hidden"=dword:00000002 • "HideFileExt"=dword:00000003 – [HKCU\Software\Microsoft\Internet Explorer\Main] Valor recente: • "Start Page"="http://www.nuevaq.fm" • "Local Page"="http://www.nuevaq.fm" • "Search Page"="http://www.nuevaq.fm" • "Default_Search_URL"="http://www.nuevaq.fm" • "Default_Page_URL"="http://www.nuevaq.fm" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Netscape.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Safari.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\opera.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\chrome.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\helper.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\updater.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\crashreporter.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\firefox.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Filemon.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Procmon.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\procexp.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\portmon.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\prckiller.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\gpedit.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\boot.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zlh.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Regmon.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\fslaunch.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\cclaw.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ndntspst.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\nd98spst.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kis8.0.0.506latam.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\kav8.0.0.357es.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\WS2Fix.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\UCCLSID.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\VACFix.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\unzip.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\swsc.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\swxcacls.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Diskmon.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\SrchSTS.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\SmitfraudFix.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\IEDFix.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\HostsChk.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\GenericRenosFix.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\exit.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\dumphive.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Restart.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Process.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ntdetect.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\HJTInstall.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ChromeSetup.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Opera_964_int_Setup.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ GoogleToolbarInstaller_download_signed.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\fa-setup.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonealarm.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonalm2601.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zonalarm.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zauinst.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zatutorzauinst.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zatutor.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zapsetup3001.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\zapro.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\xscan.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\xpf202en.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wyvernworksfirewall.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wsbgate.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wrctrl.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wradmin.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wnt.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wmiav.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wmias.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winsfcm.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winservices.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winroute.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winrecon.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winppr32.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winmgm32.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe\"" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wink.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\winhlpp32.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wingate.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wimmun32.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\whoswatchingme.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wgfe95.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wfindv32.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webtrap.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webscanx.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\webscan.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\watchdog.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\w9x.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\w32dsm89.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vvstat.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswinperse.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswinntse.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vswin9xe.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsstat.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsscan40.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsmon.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsmain.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsisetup.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vshwin32.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsecomr.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vsched.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscenu6.02d30.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscan40.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vscan.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\vptray.exe] Valor recente: • "Debugger"="%WINDIR% \twunk_16.exe" Detalhes do ficheiro Linguagem de programação: O programa de malware está escrito em Visual Basic.
Descrição enviada por Alexandru Dinu em
quinta-feira, 12 de agosto de 2010 Descrição atualizada por Alexandru Dinu em
segunda-feira, 23 de agosto de 2010
Voltar
.
.
.
.