Latest Malware Descriptions

dilansri2

Member
Feb 12, 2008
3,998
20
0
Latest Malware Descriptions

Trojan-Downloader.VBS.Small.fp



Detection added: Oct 26 2007 14:46 GMT
Update released: Oct 26 2007 15:35 GMT
Description added: Mar 21 2008
Behavior: TrojanDownloader

Technical details

This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent. It is an HTML page which contains Visual Basic Script and Java Script scenarios. It is 7526 bytes in size.

Payload

Once launched, the Trojan decrypts and injects its code into the memory of processes which have the following mutexes in the system registry:
{BD96C556-65A3-11D0-983A-00C04FC29E36}
{AB9BCEDD-EC7E-47E1-9322-D4A210617116}
{0006F033-0000-0000-C000-000000000046}
{0006F03A-0000-0000-C000-000000000046}
{6e32070a-766d-4ee6-879c-c1fa91d2fc3}
{6414512B-B978-451D-A0D8-FCFDF33E833C}
{7F5B7F63-F06F-4331-8A26-339E03C0AE3D}
{06723E09-F4C2-43c8-8358-09FCD1DB0766}
{639F725F-1B2D-4831-A9FD-874847682010}
{BA018599-1DB3-44f9-83B4-461454C84BF8}
{D0C07D56-7C69-43F1-B4A0-25F5A11FAB19}
{E8CCCDDF-CA28-496b-B050-6C07C962476B}
The Trojan then uses a vulnerability in either the ActiveX XMLHTTP or the MSXML2.ServerXMLHTTP component to download a file from the following URL:
http://777.***23.cn/cc/999.exe
This file is 106484 bytes in size. It will be detected by Kaspersky Anti-Virus as Trojan-Spy.Win32.Pophot.zp.
The Trojan exploits a vulnerability in the “ADODB.Stream” ActiveX component to save the file to the current user’s Windows temporary directory as “999.exe”:
%Temp%\999.exe
The Trojan then creates a file called "999.vbs" in the same directory:
%Temp%\999.vbs
The Trojan writes code to launch "%Temp%\999.exe" to this file.
"%Temp%\999.vbs" will then be launched for execution.



Removal instructions
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
  1. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
  2. Delete the following files: %Temp%\999.exe
    %Temp%\999.vbs
  3. Delete the contents of %Temporary Internet Files%.
  4. Disable the vulnerable ActiveX object (see How to stop an ActiveX control from running in Internet Explorer
  5. Update your antivirus databases and perform a full scan of the computer
Backdoor.Win32.Vipdataend.ij

Detection added: Nov 05 2007 22:29 GMT
Update released: Nov 05 2007 23:35 GMT
Description: added Mar 21 2008
Behavior: Backdoor


Technical details
This Trojan provides a remote malicious user with access to the victim machine. This Trojan is a Windows PE EXE file. It is 435712 bytes in size.

Installation


The backdoor copies its executable file to the Windows system directory:
%System%\PiaO.exe
The Trojan also extracts the following .dll file from its body:
%System%\PiaO.dll
This file is 135168 bytes in size. It will be detected by Kaspersky Anti-Virus as Backdoor.Win32.Delf.ash.
In order to ensure that it is launched each time the system is started, the backdoor creates a service called "PiaO" and creates the following system registry key:
[HKLM\SYSTEM\CurrentControlSet\Services\PiaO]
Once installed, the backdoor will delete the original executable file.

Payload


The backdoor launches a copy of iexplore.exe and loads the .dll file to this process. The .dll file will download a script from the remote malicious user's site. The script determines which one of the following actions will be taken by the malicious program:
  1. Download a file from the designated URL and launch it
  2. Transmit information about the version of Windows and IE running on the victim machine to the remote malicious user's site
  3. Track which sites the user visits and send a log file containing this information to the remote malicious user's site.

Removal instructions


If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
  1. Use Task Manager to terminate the malicious program’s process.
  2. Delete the original backdoor file (the location will depend on how the program originally penetrated the victim machine).
  3. Delete the following system registrykey: [HKLM\SYSTEM\CurrentControlSet\Services\PiaO]
  4. Delete the following files: %System%\PiaO.exe
    %System%\PiaO.dll
  5. Update your antivirus databases and perform a full scan of the computer
Trojan-Downloader.Win32.Small.fxl

Detection added : Oct 05 2007 00:01 GMT
Update released: Oct 05 2007 00:50 GMT
Description added: Mar 21 2008
Behavior : TrojanDownloader

Technical details

This malicious program is a Trojan. It is a Windows PE EXE file. It is 12788 bytes in size.

Installation

When installing, the Trojan copies its executable file to the Windows system directory:
%System%\mssrv32.exe
In order to ensure that it is launched each time the system is started, the Trojan creates a service called "Microsoft security update service".

Payload


When launching, the Trojan injects its code into svchost.exe, a system process.
It then registers on the remote malicious user's site by opening the following URL.
http://85.***.***.26/sesso/stat.php
The header of the request to the server contains the version of Windows running on the victim machine.
The server responds to the request by sending commands which determine what the Trojan will then do. The commands are as follows:
  1. flood – flooding a designated server with a large number of packets. The types of attack are listed below:
    1. ICMP
    2. SYN
    3. HTTP
    4. UDP
  2. stop – this will immediately stop the packets being sent.
  3. die – deletes the Trojan file and the service it created.
  4. open – opens a specific link using Internet Explorer.
  5. get - downloads a file from a specified link and launches it for execution. Downloaded files are saved to %Temp% under a temporary name.
Removal instructions

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
  1. Use Task Manager to terminate the Trojan process.
  2. Delete the following service: "Microsoft security update service"
  3. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
  4. Delete the following file: %System%\mssrv32.exe
  5. Update your antivirus databases and perform a full scan of the computer
Trojan-Downloader.Win32.Small.fzu

Detection added: Oct 11 2007 09:20 GMT
Update released: Oct 11 2007 10:40 GMT
Description added: Mar 21 2008
Behavior: TrojanDownloader

Technical details

This malicious program is a Trojan. It is a Windows PE EXE file. It is 12402 bytes in size.

Installation


When installing, the Trojan copies its executable file to the Windows system directory:
%System%\mssrv32.exe
In order to ensure that it is launched each time the system is started, the Trojan creates a service called "Microsoft security update service".

Payload


When launching, the Trojan injects its code into svchost.exe, a system process.
It then registers on the remote malicious user's site by opening the following URL.
http://testiks*****net.ru/bots/stat.php
The header of the request to the server contains the version of Windows running on the victim machine.
The server responds to the request by sending commands which determine what the Trojan will then do. The commands are as follows:
  1. flood – flooding a designated server with a large number of packets. The types of attack are listed below:
    1. ICMP
    2. SYN
    3. HTTP
    4. UDP
  2. stop – this will immediately stop the packets being sent.
  3. die – deletes the Trojan file and the service it created.
  4. open – opens a specific link using Internet Explorer.
  5. get - downloads a file from a specified link and launches it for execution. Downloaded files are saved to %Temp% under a temporary name.
Removal instructions

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
  1. Use Task Manager to terminate the Trojan process.
  2. Delete the following service: "Microsoft security update service"
  3. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
  4. Delete the following file: %System%\mssrv32.exe
  5. Update your antivirus databases and perform a full scan of the computer
Trojan-Downloader.Win32.Small.fyn

Detection added: Oct 08 2007 15:55 GMT
Description added: Mar 21 2008
Behavior: TrojanDownloader

Technical details

This malicious program is a Trojan. It is a Windows PE EXE file. It is 23040 bytes in size.

Installation


When installing, the Trojan copies its executable file to the Windows system directory:
%System%\mssrv32.exe
In order to ensure that it is launched each time the system is started, the Trojan creates a service called "Microsoft security update service".

Payload


When launching, the Trojan injects its code into svchost.exe, a system process.
It then registers on the remote malicious user's site by opening the following URL.
http://85.***.***.26/sesso/stat.php
The header of the request to the server contains the version of Windows running on the victim machine.
The server responds to the request by sending commands which determine what the Trojan will then do. The commands are as follows:
  1. flood – flooding a designated server with a large number of packets. The types of attack are listed below:
    1. ICMP
    2. SYN
    3. HTTP
    4. UDP
  2. stop – this will immediately stop the packets being sent.
  3. die – deletes the Trojan file and the service it created.
  4. open – opens a specific link using Internet Explorer.
  5. get - downloads a file from a specified link and launches it for execution. Downloaded files are saved to %Temp% under a temporary name.
Removal instructions

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
  1. Use Task Manager to terminate the Trojan process.
  2. Delete the following service: "Microsoft security update service"
  3. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine). Delete the following file: %System%\mssrv32.exe
  4. Update your antivirus databases and perform a full scan of the computer

source www.viruslist.com

 
Last edited:

x-pert

Member
Jun 13, 2006
20,952
77
0
This is not the latest macho.. This is sort of old.

Like Oct or Nov last year (2007)

Anyway thx for sharing
 

dilansri2

Member
Feb 12, 2008
3,998
20
0
Trojan-Spy:W32/ZBot.HS



Name : Trojan-Spy:W32/ZBot.HS
Alias: ZBot.HS, Trojan-Spy:W32/Zbot.KZ
Type: Trojan-Spy
Category: Malware
Platform: W32
Date of Discovery: February 20, 2008

Summary
Trojan-Spy:W32/ZBot.HS is a trojan-spy.

Trojan-spy applications attempt to steal online banking login-information and other sensitive data from the infected computer. Update: New sample received on April 04, 2008, detected as Trojan-Spy:W32/Zbot.KZ.


Infection Vectors

ZBot variants target online banking.

Banks in multiple countries have been targeted. Various languages have been used in spam pushing the installation.

Trojan-Spy:W32/ZBot.HS was discovered on February 20th 2008. ZBot.HS targets a Finnish bank and utilized spam written in Finnish.

Several Finnish language spam messages were used to direct recipients to various websites. The websites supposedly contain a images that require an iPIX plug-in. The download link for the "plug-in" in fact downloads the ZBot trojan-spy.

Spam message example:

trojan-spy_w32_zbot_hs_04.jpg



Technical Details

Comprehensive analysis of this variant has been completed.

Upon execution the trojan copies itself to the following location:
  • %windir%\system32\ntos.exe
Note: %windir% represents the system's default Windows directory. The folder name may vary by language localization.

It then creates the following folder under the Windows system directory:
  • wsnpoem
ZBot.HS attempts to hide this folder using stealth techniques.

It creates the following files in the newly created folder:
  • audio.dll
  • video.dll
These files are written with encrypted data.

The trojan modifies the following registry entry to enable its automatic execution upon Windows startup:
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    "Userinit" = "%windir%\system32\userinit.exe,%windir%\system32\ntos.exe"
The trojan deletes cookies in the Internet Explorer URL cache.

It then injects malicious code into several active processes, particularly winlogon.exe and iexplorer.exe. The injected code starts listening for incoming TCP connections and downloads the following data file from a remote server:
  • file.bin
The remote server URL contains a top-level domain of ".ru". The server is hosted in Turkey as of February 21, 2008.

Logging online banking information is the primary payload of Trojan-Spy:W32/Zbot variants.

ZBot searches the following string by default:
  • https://onlineeast#.bankofamerica.com/cgi-bin/ias/*/GotoWelcome
Other targets are added through the file.bin configuration.

The file.bin of ZBot.HS targets a Finnish bank.

Browser activity is monitored for multiple ".fi" URL addresses. Finnish, Swedish, and English language versions are monitored.

If online banking activity is detected ZBot.HS will beginning logging information. ZBot.HS does not inject its own banking transactions.

ZBot also checks for running programs with firewall related processes:
  • outpost.exe
  • zlclient.exe
Exploit:W32/JetDb.C

Name : Exploit:W32/JetDb.C
Alias: Exploit-MSJet trojan (McAfee), TrojanDropper:W32/Jettop.C!Jetdb
Size: Approx 114,600 Bytes
Type: Exploit
Category: Malware
Platform: W32


Summary
This sample arrives together with a malicious MS Word document file as a package or attachment to email messages. The specially crafted file exploits a known Remote Code Execution vulnerability on Microsoft Jet Database Engine.

Disinfection of Exploits

Exploits are used by malicious programs, so please refer to disinfection of these malicious programs (worms, trojans, backdoors) for more information.

In some cases, Exploits (for example iFrame exploit) can be detected in e-mail files stored on a hard drive. In such a case it is recommended to delete those files.

It is very important to have all the security patches for your operating system updated to prevent security breaches and infections resulted from the use of exploits.


Detailed Description
This malware file arrives as a package usually with another maliciously crafted MS Word Document file to be executed.
When loaded, this malware wil then exploit a known Remote-Code-Execution vulnerability on MS Jet Database Engine.

A successful execution of the exploit will result to the file C:\SVCH0ST.EXE to be created and executed on the user's system.
 

Malinga

Well-known member
  • Jul 20, 2006
    61,301
    1,013
    113
    oya Trojan-Downloader parapureema thavath saamajikayek. oya ganayata vatena godak malware thiyanava. aluth ma ekanum hariyata ma danne nae. habai

    Trojan-Downloader.Win32.Small.hsl ookanum langadi handunagaththa ekak. ooka sambanda vistharath thaama hariyata naha :D
     

    dilansri2

    Member
    Feb 12, 2008
    3,998
    20
    0
    Malinga said:
    oya Trojan-Downloader parapureema thavath saamajikayek. oya ganayata vatena godak malware thiyanava. aluth ma ekanum hariyata ma danne nae. habai

    Trojan-Downloader.Win32.Small.hsl ookanum langadi handunagaththa ekak. ooka sambanda vistharath thaama hariyata naha :D

    ow ow

    Trojan-Downloader.Win32.Small.hsl gena thama description ekak naha

    Detection added : Jan 16 2008 19:21 GMT
    Update released: Jan 16 2008 22:27 GMT
    Behavior: TrojanDownloader

    onna oya tika thama hoyagena thiyenne
     

    dilansri2

    Member
    Feb 12, 2008
    3,998
    20
    0
    Trojan:W32/MonaGray.A

    Name : Trojan:W32/MonaGray.A
    Alias: Trojan.Win32.MonaGray.a, MonaRonaDona, Trojan.Win32.MonaGray.b, Trojan.Win32.MonaGray.c
    Type: Trojan
    Category: Malware
    Platform: W32

    Summary
    Trojan:W32/MonaGray.A is a trojan horse that attempts trick victims into downloading a misleading application called Unigray Antivirus.

    Unigray Antivirus is a "rogue" product and is detected as Rogue:W32/Unigray.A.

    rojan Disinfection

    Perform full computer check

    Follow the steps below:

    1. Open F-Secure
    2. Select the "Virus & Spy Protection" button
    3. Click the link for "Scan my computer..."
    4. Select "Perform full computer check" from the list
    5. Please note the path and filenames of the malware found
    6. Delete/Remove all files detected Note: Please make that your Automatic Updates are enabled and that the definition databases are current.

    Remove launch points and other malware entries from the Registry

    Follow the steps below:

    1. From the Start Menu; select Run; type "regedit" into the Open: field; click OK.
    2. Once the Registry Editor has launched, navigate to the following registry keys:

    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
      Locate and delete the value:
      "Windows" = {path and filename of the malware found}
    • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
      Locate and delete the value:
      "Window Title" = "MonaRonaDona"
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
      Locate and delete the value:
      "SD" = {random numbers}
    3. Restore any modified registy value if needed:

    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
      "DisableTaskMgr" = "1" to "DisableTaskMgr" = {previous value}

      Note: If you have Task Manager enabled on your system by default, you may simply delete the value:
      "DisableTaskMgr" = "1"
    Repeat the full computer check to make sure the malware was completely removed.