- Сообщения
- 1,048
- Реакции
- 80
- Репутация
- 102
вот после чего эта тварь завелась скажу приватно тому кто мне ее впер. собственно, проявился запрос от файервола по поводу tftp.exe пущать/не пущать. думаю "интересно что далее" далее мне по этому протоколу передают файлик winole.exe и это файло в свою очередь тоже начинает куда то ломиться, естествеено файл получил запрет.
далее, svhost.exe начал жрать порядка 80% ресурсов, файл windows/system32/winole.exe удалить не получаеться, занят процессом. черт с ним, загружаюсь под safe_mode выношу эту гнусь, правлю группу автозагрузки (естественно он уже и туда прописался). перезагружаю винды, честно купленные винды молвят, с момента активации конфигурация была значительно изменена, пошли регистрироваться ... вообщем поимел легкую головную боль, поскольку деяние сего виреза описано оч скудно. а именно.
Цитата
Also Known As
Type
Backdoor
Systems Affected
Win32
Resident in System Memory
No
Origin
others
Encryption
No
Discovered on
09/23/2004
How it spread
Network
Infection symptoms
DoS attack, Changes registry, Accessing certain IRC server, Opens the specific port
Specific date of infections
None
Destructivity/ Distribution Potential
*** / ***
ViRobot version able to
detect/repair
Able to detect/repair
[ViRobot version: 09/23/2004]
Technical description
[Summary]
Backdoor.Win32.IRBot_Gen is the name that detects unknown Bot system applied from ViRobot engine update (Sep. 23,
2004).Backdoor.Win32.IRCBot_Gen is the name that contains the following Bot series.
- Backdoor.Win32.IRCBot
- Worm.Win32.Agobot
- Backdoor.Win32.RBot
- Backdoor.Win32.MyBot
- Backdoor.Win32.SdBot
- Worm.Win32.SpyBot
ViRobot detects/repairs unknown Bot series but there are some cases that it doesn't detect if the variants change a lot.
ViRobot engine is constantly updated so you should maintain the latest version.
[Infection method]
The spreading method is changed and added under the variants besides the typical spreading method arranged as below.
1. It takes an advantage of the following Windows Security Vulnerability.
- RPC DCOM Vulnerability(MS03-026, TCP/135) : Vulnerability information(Korean) | Vulnerability information(English)
- RPC DCOM2 Vulnerability(MS03-039, TCP/135) : Vulnerability information(Korean) | Vulnerability information(English)
- RPC Locator Vulnerability(MS03-001, TCP/445) : Vulnerability information(Korean) | Vulnerability information(English)
- WebDAV Vulnerability(MS03-007, TCP/80, IIS are only relevant to a user)
: Vulnerability information(Korean) | Vulnerability information(English)
* Notes : Only IIS user who uses WebDAV is relevant, but above Windows 2000 is automatically enabled. Therefore MS03-007 patch or above
Service pack 4 should be applied if you use Windows 2000 or above even though you don't use IIS. (Apply MS03-013 due to the problem in MS03-
007 security patch.)
- NetBIOS Vulnerability(MS03-034, TCP/137,138,139) : Vulnerability information(Korean) | Vulnerability information(English)
2. It takes an advantage of IPC$(Manager) Password Vulnerability(Infection caused by the password that is easy to inferred).
The reason why the malignant code can use IPC$ share is because System Manager Password isn't set or simply set. Therefore the password
should be set long enough to protect against illegal access.
[Infection path]
The typical symptoms of Bot which is known currently are as the following.
1. Random TCP port is opened. After Bot connects to the specified IRC channel without a user's permission, it becomes the agent that receives
commands from a hacker to execute the following functions.
- Close process
- Execute HTTP, ICMP, SYN, UDP flood
- Upload/download and execute file from the specified url or server
- Update installed backdoor
- Send backdoor file to another IRC channel
- Delete installed backdoor(include registry modification)
- Expose system information of infected PC, Windows product CDKey, AOL password and famous game CDKey
- Steal email address saved in computer
2. After it connects to IRC server, it attempts to DoS(Denial of Service) attack specified URL by a hacker's commands.
3. The following network share is removed by a hacker's command.
- admin$
- ipc$
- d$
- c$
4. Worm modifies "(Windows system folder)\drivers\etc\hosts" of infected computer to make user hard to connect to the websites related to
anti-virus. Worm set the following path with 127.0.0.1 to be black-hole routing.
(hosts file modified by worm is detected/repaired as "HOSTS.Noconnt.A" in ViRobot.)
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com
5. Information such as Windows product CDKey and game CDKey are exposed in the infected system by a hacker's command.
- Windows Product ID
- Hidden & Dangerous 2
- Chrome
- SOF2
- Soldier of Fortune II - Double Helix
- Neverwinter
- Nox
- Tiberian Sun
- Red Alert 2
- Red Alert
- IGI 2 Retail
- Command & Conquer Generals
- Battlefield 1942 Secret Weapons of WWII
- Battlefield 1942 The Road to Rome
- Battlefield 1942
- Nascar 2002
- NHL 2003
- NHL 2002
- FIFA 2003
- FIFA 2002
- NFSHP2
- The Gladiators
- UT2003
- LoMaM
- Counter-Strike
- Half-Life
- Retrieves email addresses from the files that have http, Wab extentions
6. Worm terminates several processes that have a vaccine and a firewall.
[Others]
- The function that detects unknown Bot doesn't support in real-time monitor.
Version 1 : AM 10:16 2004-10-05 (GMT+9)
The first version of analysis report is completed.
How to repair
[How to repair]
* The following phenomenon can generate so please be well aware of the contents as shown below.
1. When rebboting after repairing Backdoor.Win32.IRCBot_Gen and when message box that says it doesn't have relevant file.
Action : Check the following line of registry and delete the registry value recorded relevant file.
- HKEY_LOCAL_MACHINE\
SOFTWARE\
Microsoft\
Windows\
CurrentVersion\
Run
Name : (Search for the key value that has the same contents with the message box appears that it doesn't have a file when rebooting.)
- HKEY_LOCAL_MACHINE\
SOFTWARE\
Microsoft\
Windows\
CurrentVersion\
RunServices
Name : (Search for the key value that has the same contents with the message box appears that it doesn't have a file when rebooting.)
2. When reinfection after repairing Backdoor.Win32.IRCBot_Gen
- Repairing has been already done but reinfection occurs because Vulnerability still exists. Important security vulnerability of Windows
should be installed to prevent against reinfection.
How to patch : Install all inportant updates via Start->Windows update.
3. If there is other questions, apply virus sample to Hauri virus report center to get detailed analysis.
далее, svhost.exe начал жрать порядка 80% ресурсов, файл windows/system32/winole.exe удалить не получаеться, занят процессом. черт с ним, загружаюсь под safe_mode выношу эту гнусь, правлю группу автозагрузки (естественно он уже и туда прописался). перезагружаю винды, честно купленные винды молвят, с момента активации конфигурация была значительно изменена, пошли регистрироваться ... вообщем поимел легкую головную боль, поскольку деяние сего виреза описано оч скудно. а именно.
Цитата
Also Known As
Type
Backdoor
Systems Affected
Win32
Resident in System Memory
No
Origin
others
Encryption
No
Discovered on
09/23/2004
How it spread
Network
Infection symptoms
DoS attack, Changes registry, Accessing certain IRC server, Opens the specific port
Specific date of infections
None
Destructivity/ Distribution Potential
*** / ***
ViRobot version able to
detect/repair
Able to detect/repair
[ViRobot version: 09/23/2004]
Technical description
[Summary]
Backdoor.Win32.IRBot_Gen is the name that detects unknown Bot system applied from ViRobot engine update (Sep. 23,
2004).Backdoor.Win32.IRCBot_Gen is the name that contains the following Bot series.
- Backdoor.Win32.IRCBot
- Worm.Win32.Agobot
- Backdoor.Win32.RBot
- Backdoor.Win32.MyBot
- Backdoor.Win32.SdBot
- Worm.Win32.SpyBot
ViRobot detects/repairs unknown Bot series but there are some cases that it doesn't detect if the variants change a lot.
ViRobot engine is constantly updated so you should maintain the latest version.
[Infection method]
The spreading method is changed and added under the variants besides the typical spreading method arranged as below.
1. It takes an advantage of the following Windows Security Vulnerability.
- RPC DCOM Vulnerability(MS03-026, TCP/135) : Vulnerability information(Korean) | Vulnerability information(English)
- RPC DCOM2 Vulnerability(MS03-039, TCP/135) : Vulnerability information(Korean) | Vulnerability information(English)
- RPC Locator Vulnerability(MS03-001, TCP/445) : Vulnerability information(Korean) | Vulnerability information(English)
- WebDAV Vulnerability(MS03-007, TCP/80, IIS are only relevant to a user)
: Vulnerability information(Korean) | Vulnerability information(English)
* Notes : Only IIS user who uses WebDAV is relevant, but above Windows 2000 is automatically enabled. Therefore MS03-007 patch or above
Service pack 4 should be applied if you use Windows 2000 or above even though you don't use IIS. (Apply MS03-013 due to the problem in MS03-
007 security patch.)
- NetBIOS Vulnerability(MS03-034, TCP/137,138,139) : Vulnerability information(Korean) | Vulnerability information(English)
2. It takes an advantage of IPC$(Manager) Password Vulnerability(Infection caused by the password that is easy to inferred).
The reason why the malignant code can use IPC$ share is because System Manager Password isn't set or simply set. Therefore the password
should be set long enough to protect against illegal access.
[Infection path]
The typical symptoms of Bot which is known currently are as the following.
1. Random TCP port is opened. After Bot connects to the specified IRC channel without a user's permission, it becomes the agent that receives
commands from a hacker to execute the following functions.
- Close process
- Execute HTTP, ICMP, SYN, UDP flood
- Upload/download and execute file from the specified url or server
- Update installed backdoor
- Send backdoor file to another IRC channel
- Delete installed backdoor(include registry modification)
- Expose system information of infected PC, Windows product CDKey, AOL password and famous game CDKey
- Steal email address saved in computer
2. After it connects to IRC server, it attempts to DoS(Denial of Service) attack specified URL by a hacker's commands.
3. The following network share is removed by a hacker's command.
- admin$
- ipc$
- d$
- c$
4. Worm modifies "(Windows system folder)\drivers\etc\hosts" of infected computer to make user hard to connect to the websites related to
anti-virus. Worm set the following path with 127.0.0.1 to be black-hole routing.
(hosts file modified by worm is detected/repaired as "HOSTS.Noconnt.A" in ViRobot.)
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com
5. Information such as Windows product CDKey and game CDKey are exposed in the infected system by a hacker's command.
- Windows Product ID
- Hidden & Dangerous 2
- Chrome
- SOF2
- Soldier of Fortune II - Double Helix
- Neverwinter
- Nox
- Tiberian Sun
- Red Alert 2
- Red Alert
- IGI 2 Retail
- Command & Conquer Generals
- Battlefield 1942 Secret Weapons of WWII
- Battlefield 1942 The Road to Rome
- Battlefield 1942
- Nascar 2002
- NHL 2003
- NHL 2002
- FIFA 2003
- FIFA 2002
- NFSHP2
- The Gladiators
- UT2003
- LoMaM
- Counter-Strike
- Half-Life
- Retrieves email addresses from the files that have http, Wab extentions
6. Worm terminates several processes that have a vaccine and a firewall.
[Others]
- The function that detects unknown Bot doesn't support in real-time monitor.
Version 1 : AM 10:16 2004-10-05 (GMT+9)
The first version of analysis report is completed.
How to repair
[How to repair]
* The following phenomenon can generate so please be well aware of the contents as shown below.
1. When rebboting after repairing Backdoor.Win32.IRCBot_Gen and when message box that says it doesn't have relevant file.
Action : Check the following line of registry and delete the registry value recorded relevant file.
- HKEY_LOCAL_MACHINE\
SOFTWARE\
Microsoft\
Windows\
CurrentVersion\
Run
Name : (Search for the key value that has the same contents with the message box appears that it doesn't have a file when rebooting.)
- HKEY_LOCAL_MACHINE\
SOFTWARE\
Microsoft\
Windows\
CurrentVersion\
RunServices
Name : (Search for the key value that has the same contents with the message box appears that it doesn't have a file when rebooting.)
2. When reinfection after repairing Backdoor.Win32.IRCBot_Gen
- Repairing has been already done but reinfection occurs because Vulnerability still exists. Important security vulnerability of Windows
should be installed to prevent against reinfection.
How to patch : Install all inportant updates via Start->Windows update.
3. If there is other questions, apply virus sample to Hauri virus report center to get detailed analysis.