A Holland friend sent us a variant of MSN move yesterday. Thanks. The register label is "G038_jpg zip". In the zip register it contains a com file "www. G038_jpg-msn com". Kaspersky detects it as Backdoor. Win32. IRCBot aex. Be careful. The details about this variant: G038_jpg zip (www. G038_jpg-msn com)Size: 435,200 bytesMD5 hash: 3ede1801994c59b35b96aac2b13852d1Detection: Backdoor. Win32. IRCBot aex (Kaspersky)Details:(1) Drops files:
%Windows%\G038_jpg zip%Windows%\CDSpeed exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"CDSpeed exe" = "%Windows%\CDSpeed exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"SFCDisable"=dword:ffffff9d"SFCScan"=dword:00000000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\hold back"WaitToKillServiceTimeout"="7000"
(3) change several registry entries and system files such as ftp exe tftp exe tcpip sys.(4) Sends messages:
dessa egentligen trevliga: Pgyckel mte se dig detta fotograferadu fick se detta dess galet :pestes s realmente agradeis :Pwow voc?viu este?como voc?gosta de me nesta fotovoc?comeu ver este seu assim engradoBu resimler nasil sence bir bakarmisin :)su komik resimlerime baksana :Dbak :PKiz kardesim bunlari sana yollamami sledi ;)bu resimler lay in nasilSpace ime bun resimleri eklesem sence nasil oluravete ottenuto vedere questo relativo cos?divertentecome lo pensate osservi qui sguardo di lola questo controllo di distorsione di velocit?questo fuoriel lol mi hermana quisiera que le enviara este bum de fotovengo de fi este foto bumey i que hace el bum de foto!Si vea el loL del eml tipo me acepta por advance su solamente bum de foto: (!lol meine Schwester wscht mich Ihnen dieses Fotoalbum schickenGeck nehmen bitte sein nur mich Fotoalbum an: (!he mhten mein neues Fotoalbum sehen?hoe vind je dit er uit zien ?hoe vind je dit ?echt erg kijk danzo hee moet je dit zien echt niet normaalzo moet je me hier op zien lollol he hoe vind je me hier opeeeh c mes tof :pc seulement mes tof de derniers vacancestu dois voire les tof de notre bandecomment est-ce que je regarde sur cette photo ?le lol ceci est drema soeur a voulu que tu regarde cadaut de la reproduction sonore avez-vous vu ceci ?looooook :ploooooooooooool :Dlol he looks weird on this photoomg analyse this out man this is funnylol you got to see this :P
[HKEY_LOCAL_forge\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"CDSpeed exe"="%Windows%\CDSpeed exe"
%Windows%\G038_jpg zip%Windows%\CDSpeed exe
STEP 4write %System%\microsoft\backup tftp to:
%System%\tftp exe%System%\dllcache\tftp exe
HKEY_LOCAL_forge\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"SFCDisable"=dword:00000000HKEY_LOCAL_forge\SYSTEM\CurrentControlSet\hold back"WaitToKillServiceTimeout"="20000"
HKEY_LOCAL_forge\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"SFCScan"
im experience nuts abt this. and i be help cos its getting annoying.. anybody willing to guide me how i could shift this idiotic virus..?acknowledge much. get approve to me @ rastachic@gmail com
Do you know "Registry Editor"?orYou could download this drive:http://www cisrt org/tools/SREngPS. EXEuse its "SmartScan" and deliver the details inform SREngLOG displace the SREngLOG to me please: moonny@cisrt com
Related article:
http://www.cisrt.org/enblog/read.php?156
comments | Add comment | Report as Spam
|