Latest Malware Descriptions
Trojan-Downloader.VBS.Small.fp
Detection added: Oct 26 2007 14:46 GMT
Update released: Oct 26 2007 15:35 GMT
Description added: Mar 21 2008
Behavior: TrojanDownloader
Technical details
This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent. It is an HTML page which contains Visual Basic Script and Java Script scenarios. It is 7526 bytes in size.
Payload
Once launched, the Trojan decrypts and injects its code into the memory of processes which have the following mutexes in the system registry:
{BD96C556-65A3-11D0-983A-00C04FC29E36}
{AB9BCEDD-EC7E-47E1-9322-D4A210617116}
{0006F033-0000-0000-C000-000000000046}
{0006F03A-0000-0000-C000-000000000046}
{6e32070a-766d-4ee6-879c-c1fa91d2fc3}
{6414512B-B978-451D-A0D8-FCFDF33E833C}
{7F5B7F63-F06F-4331-8A26-339E03C0AE3D}
{06723E09-F4C2-43c8-8358-09FCD1DB0766}
{639F725F-1B2D-4831-A9FD-874847682010}
{BA018599-1DB3-44f9-83B4-461454C84BF8}
{D0C07D56-7C69-43F1-B4A0-25F5A11FAB19}
{E8CCCDDF-CA28-496b-B050-6C07C962476B}
The Trojan then uses a vulnerability in either the ActiveX XMLHTTP or the MSXML2.ServerXMLHTTP component to download a file from the following URL:
http://777.***23.cn/cc/999.exe
This file is 106484 bytes in size. It will be detected by Kaspersky Anti-Virus as Trojan-Spy.Win32.Pophot.zp.
The Trojan exploits a vulnerability in the “ADODB.Stream” ActiveX component to save the file to the current user’s Windows temporary directory as “999.exe”:
%Temp%\999.exe
The Trojan then creates a file called "999.vbs" in the same directory:
%Temp%\999.vbs
The Trojan writes code to launch "%Temp%\999.exe" to this file.
"%Temp%\999.vbs" will then be launched for execution.
Removal instructions
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
Detection added: Nov 05 2007 22:29 GMT
Update released: Nov 05 2007 23:35 GMT
Description: added Mar 21 2008
Behavior: Backdoor
Technical details
This Trojan provides a remote malicious user with access to the victim machine. This Trojan is a Windows PE EXE file. It is 435712 bytes in size.
Installation
The backdoor copies its executable file to the Windows system directory:
%System%\PiaO.exe
The Trojan also extracts the following .dll file from its body:
%System%\PiaO.dll
This file is 135168 bytes in size. It will be detected by Kaspersky Anti-Virus as Backdoor.Win32.Delf.ash.
In order to ensure that it is launched each time the system is started, the backdoor creates a service called "PiaO" and creates the following system registry key:
[HKLM\SYSTEM\CurrentControlSet\Services\PiaO]
Once installed, the backdoor will delete the original executable file.
Payload
The backdoor launches a copy of iexplore.exe and loads the .dll file to this process. The .dll file will download a script from the remote malicious user's site. The script determines which one of the following actions will be taken by the malicious program:
Removal instructions
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
Detection added : Oct 05 2007 00:01 GMT
Update released: Oct 05 2007 00:50 GMT
Description added: Mar 21 2008
Behavior : TrojanDownloader
Technical details
This malicious program is a Trojan. It is a Windows PE EXE file. It is 12788 bytes in size.
Installation
When installing, the Trojan copies its executable file to the Windows system directory:
%System%\mssrv32.exe
In order to ensure that it is launched each time the system is started, the Trojan creates a service called "Microsoft security update service".
Payload
When launching, the Trojan injects its code into svchost.exe, a system process.
It then registers on the remote malicious user's site by opening the following URL.
http://85.***.***.26/sesso/stat.php
The header of the request to the server contains the version of Windows running on the victim machine.
The server responds to the request by sending commands which determine what the Trojan will then do. The commands are as follows:
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
Detection added: Oct 11 2007 09:20 GMT
Update released: Oct 11 2007 10:40 GMT
Description added: Mar 21 2008
Behavior: TrojanDownloader
Technical details
This malicious program is a Trojan. It is a Windows PE EXE file. It is 12402 bytes in size.
Installation
When installing, the Trojan copies its executable file to the Windows system directory:
%System%\mssrv32.exe
In order to ensure that it is launched each time the system is started, the Trojan creates a service called "Microsoft security update service".
Payload
When launching, the Trojan injects its code into svchost.exe, a system process.
It then registers on the remote malicious user's site by opening the following URL.
http://testiks*****net.ru/bots/stat.php
The header of the request to the server contains the version of Windows running on the victim machine.
The server responds to the request by sending commands which determine what the Trojan will then do. The commands are as follows:
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
Detection added: Oct 08 2007 15:55 GMT
Description added: Mar 21 2008
Behavior: TrojanDownloader
Technical details
This malicious program is a Trojan. It is a Windows PE EXE file. It is 23040 bytes in size.
Installation
When installing, the Trojan copies its executable file to the Windows system directory:
%System%\mssrv32.exe
In order to ensure that it is launched each time the system is started, the Trojan creates a service called "Microsoft security update service".
Payload
When launching, the Trojan injects its code into svchost.exe, a system process.
It then registers on the remote malicious user's site by opening the following URL.
http://85.***.***.26/sesso/stat.php
The header of the request to the server contains the version of Windows running on the victim machine.
The server responds to the request by sending commands which determine what the Trojan will then do. The commands are as follows:
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
source www.viruslist.com
Trojan-Downloader.VBS.Small.fp
Detection added: Oct 26 2007 14:46 GMT
Update released: Oct 26 2007 15:35 GMT
Description added: Mar 21 2008
Behavior: TrojanDownloader
Technical details
This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent. It is an HTML page which contains Visual Basic Script and Java Script scenarios. It is 7526 bytes in size.
Payload
Once launched, the Trojan decrypts and injects its code into the memory of processes which have the following mutexes in the system registry:
{BD96C556-65A3-11D0-983A-00C04FC29E36}
{AB9BCEDD-EC7E-47E1-9322-D4A210617116}
{0006F033-0000-0000-C000-000000000046}
{0006F03A-0000-0000-C000-000000000046}
{6e32070a-766d-4ee6-879c-c1fa91d2fc3}
{6414512B-B978-451D-A0D8-FCFDF33E833C}
{7F5B7F63-F06F-4331-8A26-339E03C0AE3D}
{06723E09-F4C2-43c8-8358-09FCD1DB0766}
{639F725F-1B2D-4831-A9FD-874847682010}
{BA018599-1DB3-44f9-83B4-461454C84BF8}
{D0C07D56-7C69-43F1-B4A0-25F5A11FAB19}
{E8CCCDDF-CA28-496b-B050-6C07C962476B}
The Trojan then uses a vulnerability in either the ActiveX XMLHTTP or the MSXML2.ServerXMLHTTP component to download a file from the following URL:
http://777.***23.cn/cc/999.exe
This file is 106484 bytes in size. It will be detected by Kaspersky Anti-Virus as Trojan-Spy.Win32.Pophot.zp.
The Trojan exploits a vulnerability in the “ADODB.Stream” ActiveX component to save the file to the current user’s Windows temporary directory as “999.exe”:
%Temp%\999.exe
The Trojan then creates a file called "999.vbs" in the same directory:
%Temp%\999.vbs
The Trojan writes code to launch "%Temp%\999.exe" to this file.
"%Temp%\999.vbs" will then be launched for execution.
Removal instructions
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
- Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
- Delete the following files: %Temp%\999.exe
%Temp%\999.vbs - Delete the contents of %Temporary Internet Files%.
- Disable the vulnerable ActiveX object (see How to stop an ActiveX control from running in Internet Explorer
- Update your antivirus databases and perform a full scan of the computer
Detection added: Nov 05 2007 22:29 GMT
Update released: Nov 05 2007 23:35 GMT
Description: added Mar 21 2008
Behavior: Backdoor
Technical details
This Trojan provides a remote malicious user with access to the victim machine. This Trojan is a Windows PE EXE file. It is 435712 bytes in size.
Installation
The backdoor copies its executable file to the Windows system directory:
%System%\PiaO.exe
The Trojan also extracts the following .dll file from its body:
%System%\PiaO.dll
This file is 135168 bytes in size. It will be detected by Kaspersky Anti-Virus as Backdoor.Win32.Delf.ash.
In order to ensure that it is launched each time the system is started, the backdoor creates a service called "PiaO" and creates the following system registry key:
[HKLM\SYSTEM\CurrentControlSet\Services\PiaO]
Once installed, the backdoor will delete the original executable file.
Payload
The backdoor launches a copy of iexplore.exe and loads the .dll file to this process. The .dll file will download a script from the remote malicious user's site. The script determines which one of the following actions will be taken by the malicious program:
- Download a file from the designated URL and launch it
- Transmit information about the version of Windows and IE running on the victim machine to the remote malicious user's site
- Track which sites the user visits and send a log file containing this information to the remote malicious user's site.
Removal instructions
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
- Use Task Manager to terminate the malicious program’s process.
- Delete the original backdoor file (the location will depend on how the program originally penetrated the victim machine).
- Delete the following system registrykey: [HKLM\SYSTEM\CurrentControlSet\Services\PiaO]
- Delete the following files: %System%\PiaO.exe
%System%\PiaO.dll - Update your antivirus databases and perform a full scan of the computer
Detection added : Oct 05 2007 00:01 GMT
Update released: Oct 05 2007 00:50 GMT
Description added: Mar 21 2008
Behavior : TrojanDownloader
Technical details
This malicious program is a Trojan. It is a Windows PE EXE file. It is 12788 bytes in size.
Installation
When installing, the Trojan copies its executable file to the Windows system directory:
%System%\mssrv32.exe
In order to ensure that it is launched each time the system is started, the Trojan creates a service called "Microsoft security update service".
Payload
When launching, the Trojan injects its code into svchost.exe, a system process.
It then registers on the remote malicious user's site by opening the following URL.
http://85.***.***.26/sesso/stat.php
The header of the request to the server contains the version of Windows running on the victim machine.
The server responds to the request by sending commands which determine what the Trojan will then do. The commands are as follows:
- flood – flooding a designated server with a large number of packets. The types of attack are listed below:
- ICMP
- SYN
- HTTP
- UDP
- stop – this will immediately stop the packets being sent.
- die – deletes the Trojan file and the service it created.
- open – opens a specific link using Internet Explorer.
- get - downloads a file from a specified link and launches it for execution. Downloaded files are saved to %Temp% under a temporary name.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
- Use Task Manager to terminate the Trojan process.
- Delete the following service: "Microsoft security update service"
- Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
- Delete the following file: %System%\mssrv32.exe
- Update your antivirus databases and perform a full scan of the computer
Detection added: Oct 11 2007 09:20 GMT
Update released: Oct 11 2007 10:40 GMT
Description added: Mar 21 2008
Behavior: TrojanDownloader
Technical details
This malicious program is a Trojan. It is a Windows PE EXE file. It is 12402 bytes in size.
Installation
When installing, the Trojan copies its executable file to the Windows system directory:
%System%\mssrv32.exe
In order to ensure that it is launched each time the system is started, the Trojan creates a service called "Microsoft security update service".
Payload
When launching, the Trojan injects its code into svchost.exe, a system process.
It then registers on the remote malicious user's site by opening the following URL.
http://testiks*****net.ru/bots/stat.php
The header of the request to the server contains the version of Windows running on the victim machine.
The server responds to the request by sending commands which determine what the Trojan will then do. The commands are as follows:
- flood – flooding a designated server with a large number of packets. The types of attack are listed below:
- ICMP
- SYN
- HTTP
- UDP
- stop – this will immediately stop the packets being sent.
- die – deletes the Trojan file and the service it created.
- open – opens a specific link using Internet Explorer.
- get - downloads a file from a specified link and launches it for execution. Downloaded files are saved to %Temp% under a temporary name.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
- Use Task Manager to terminate the Trojan process.
- Delete the following service: "Microsoft security update service"
- Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
- Delete the following file: %System%\mssrv32.exe
- Update your antivirus databases and perform a full scan of the computer
Detection added: Oct 08 2007 15:55 GMT
Description added: Mar 21 2008
Behavior: TrojanDownloader
Technical details
This malicious program is a Trojan. It is a Windows PE EXE file. It is 23040 bytes in size.
Installation
When installing, the Trojan copies its executable file to the Windows system directory:
%System%\mssrv32.exe
In order to ensure that it is launched each time the system is started, the Trojan creates a service called "Microsoft security update service".
Payload
When launching, the Trojan injects its code into svchost.exe, a system process.
It then registers on the remote malicious user's site by opening the following URL.
http://85.***.***.26/sesso/stat.php
The header of the request to the server contains the version of Windows running on the victim machine.
The server responds to the request by sending commands which determine what the Trojan will then do. The commands are as follows:
- flood – flooding a designated server with a large number of packets. The types of attack are listed below:
- ICMP
- SYN
- HTTP
- UDP
- stop – this will immediately stop the packets being sent.
- die – deletes the Trojan file and the service it created.
- open – opens a specific link using Internet Explorer.
- get - downloads a file from a specified link and launches it for execution. Downloaded files are saved to %Temp% under a temporary name.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
- Use Task Manager to terminate the Trojan process.
- Delete the following service: "Microsoft security update service"
- Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine). Delete the following file: %System%\mssrv32.exe
- Update your antivirus databases and perform a full scan of the computer
source www.viruslist.com
Last edited:
