TIP: Click on subject to list as thread! ANSI
echo: dirty_dozen
to: ALL
from: KURT WISMER
date: 2006-09-24 00:49:00
subject: News, September 24 2006

[cut-n-paste from sophos.com]

Name   Troj/Clagger-AC

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Downloads code from the internet
    * Installs itself in the Registry

Prevalence (1-5) 3

Description
Troj/Clagger-AC is a downloader Trojan for the Windows platform.

Troj/Clagger-AC attempts to download and execute a number of files 
from remote websites.

Troj/Clagger-AC has been seen emailed as an attachment to emails with 
the following characteristics:

Subject lines:
Telekom
Telekom Nachzahlung September!
Telekom Rechnung Online Monat September 2006
Neue Telekom Rechnung 09.2006
Ihre Telekomrechnung 2006
Telekom Nachzahlung!
Rechnung Telekom
Telekom AG
Rechnung Online Monat September 2006

Message text:
Guten Tag,
die Gesamtsumme fur Ihre Rechnung im Monat August betragt: 200-1000 
Euro.

Sind Sie Unternehmer und benotigen unsere Rechnung zur Geltendmachung 
von
Vorsteuerabzug? Bitte beachten Sie dann, dass Sie seit 29.12.2004 die
Moglichkeit haben, Ihre Rechnung per E-Mail mit einer qualifizierten
elektronischen Signatur zu erhalten. Sie konnen diese im Bereich
"personliche Einstellungen" aktivieren.
Sollten Sie dem Finanzamt bisher eine von Ihnen zusatzlich beauftragte
Rechnung in Papierform zum Vorsteuerabzug vorgelegt haben, bitten wir
au?erdem zu beachten, dass wir Ihnen diese nur noch in Form eines
"Rechungsdoppels" bieten konnen, da nur so vermieden werden kann, 
dass T-Com
mehrere Rechnungsoriginale ausstellt.

Antworten auf Ihre weiteren Fragen zur digitalen Signatur finden Sie 
auch in
unseren FAQs unter dem Stichwort "Digitale Signatur".
======================================
RECHNUNG ONLINE - TIPP DES MONATS
Die neuen WunschDirWas Tarife sind jetzt da! Jetzt online anmelden 
unter
www.t-com.de/reo/WuenschDirWas und bis zu 10,- Euro sparen.
Die aktuellen Top-Angebote der Deutschen Telekom finden Sie unter:
www.t-com.de/aktuell.
======================================

Bei Fragen zu Rechnung Online oder zum Rechnungsinhalt klicken Sie 
bitte
unter www.t-com.de/rechnung (oben links) auf "Kontakt".

Mit freundlichen Gruen
Ihre T-Com
---------------------------------------------------

Attached file: Rechnung.pdf.zip, which unzips to Rechnung.pdf.exe

Advanced
Troj/Clagger-AC is a downloader Trojan for the Windows platform.

Troj/Clagger-AC attempts to download and execute a number of files 
from remote websites.

When first run Troj/Clagger-AC copies itself to \ipf.exe and 
creates the file \drivers\winut.dat.

The following registry entry is created to run ipf.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ifp
\ipf.exe

Troj/Clagger-AC has been seen emailed as an attachment to emails with 
the following characteristics:

Subject lines:
Telekom
Telekom Nachzahlung September!
Telekom Rechnung Online Monat September 2006
Neue Telekom Rechnung 09.2006
Ihre Telekomrechnung 2006
Telekom Nachzahlung!
Rechnung Telekom
Telekom AG
Rechnung Online Monat September 2006

Message text:
Guten Tag,
die Gesamtsumme fur Ihre Rechnung im Monat August betragt: 200-1000 
Euro.

Sind Sie Unternehmer und benotigen unsere Rechnung zur Geltendmachung 
von
Vorsteuerabzug? Bitte beachten Sie dann, dass Sie seit 29.12.2004 die
Moglichkeit haben, Ihre Rechnung per E-Mail mit einer qualifizierten
elektronischen Signatur zu erhalten. Sie konnen diese im Bereich
"personliche Einstellungen" aktivieren.
Sollten Sie dem Finanzamt bisher eine von Ihnen zusatzlich beauftragte
Rechnung in Papierform zum Vorsteuerabzug vorgelegt haben, bitten wir
au?erdem zu beachten, dass wir Ihnen diese nur noch in Form eines
"Rechungsdoppels" bieten konnen, da nur so vermieden werden kann, 
dass T-Com
mehrere Rechnungsoriginale ausstellt.

Antworten auf Ihre weiteren Fragen zur digitalen Signatur finden Sie 
auch in
unseren FAQs unter dem Stichwort "Digitale Signatur".
======================================
RECHNUNG ONLINE - TIPP DES MONATS
Die neuen WunschDirWas Tarife sind jetzt da! Jetzt online anmelden 
unter
www.t-com.de/reo/WuenschDirWas und bis zu 10,- Euro sparen.
Die aktuellen Top-Angebote der Deutschen Telekom finden Sie unter:
www.t-com.de/aktuell.
======================================

Bei Fragen zu Rechnung Online oder zum Rechnungsinhalt klicken Sie 
bitte
unter www.t-com.de/rechnung (oben links) auf "Kontakt".

Mit freundlichen Gruen
Ihre T-Com
---------------------------------------------------

Attached file: Rechnung.pdf.zip, which unzips to Rechnung.pdf.exe





Name   Troj/Tibdrop-A

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Drops more malware

Prevalence (1-5) 2

Description
Troj/Tibdrop-A is a Trojan for the Windows platform.

When Troj/Tibdrop-A is installed the following files are created:

\cc750.exe
\pp.bat





Name   Troj/Certif-R

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Steals information
    * Downloads code from the internet
    * Records keystrokes
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
Troj/Certif-R is a password stealing Trojan.

Advanced
Troj/Certif-R is a password stealing Trojan.

When first run the Trojan copies itself to \systray.com

The following registry entry is created to run systray.com on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
systray.com
\systray.com

The Trojan monitors system activity and collects user credentials 
typed into the windows of various online banking applications.

Troj/Certif-R also attemtps to upload all files with the extensions 
CRT, KEY and WAB found on the harddrive to a remote FTP server.





Name   Troj/Banloa-ANI

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Downloads code from the internet
    * Installs itself in the Registry

Aliases  
    * Trojan-Downloader.Win32.Banload.baq

Prevalence (1-5) 2

Description
Troj/Banloa-ANI is a Trojan for the Windows platform.

Advanced
Troj/Banloa-ANI is a Trojan for the Windows platform.

The Trojan includes functionality to access the internet and 
communicate with a remote server via HTTP.

When first run Troj/Banloa-ANI copies itself to \msng.exe.

The following registry entry is created to run msng.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
msng






Name   Troj/Lager-K

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Downloads code from the internet
    * Installs itself in the Registry

Aliases  
    * Trojan-Proxy.Win32.Lager.di
    * PAK_Generic.001

Prevalence (1-5) 2

Description
Troj/Lager-K is a Trojan for the Windows platform.

Troj/Lager-K includes functionality to access the internet and 
communicate with
a remote server via HTTP.

Advanced
Troj/Lager-K is a Trojan for the Windows platform.

Troj/Lager-K includes functionality to access the internet and 
communicate with
a remote server via HTTP.

When first run Troj/Lager-K copies itself to \taskdir.exe and creates the following files:

\taskdir.dll
\zlbw.dll

The file taskdir.dll is detected as Troj/HideDl-A. The file zlbw.dll 
is not malicious.

The following registry entry is created to run taskdir.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
taskdir
\taskdir.exe





Name   W32/Looked-S

Type  
    * Virus

How it spreads  
    * Network shares
    * Infected files

Affected operating systems  
    * Windows

Side effects  
    * Downloads code from the internet
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
W32/Looked-S is a Windows executable virus and network worm.

The virus includes functionality to access the internet and 
communicate with a remote server via HTTP.

Advanced
W32/Looked-S is a Windows executable virus and network worm.

The virus includes functionality to access the internet and 
communicate with a remote server via HTTP.

When first run W32/Looked-S copies itself to \rundl132.exe 
and \logo1_.exe and creates the file \Dll.dll. This 
file is also detected as W32/Looked-S.

The virus infects EXE files found on the infected computer. The virus 
also attempts to copy itself to remote network shares.

Many files with the name "_desktop.ini" are created, in various 
folders on the infected computer. These files are harmless text files.

The following registry entry is created in order to run the virus on 
startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
\rundl132.exe





Name   W32/Looked-T

Type  
    * Virus

How it spreads  
    * Network shares
    * Infected files

Affected operating systems  
    * Windows

Side effects  
    * Turns off anti-virus applications
    * Modifies data on the computer
    * Downloads code from the internet
    * Installs itself in the Registry
    * Leaves non-infected files on computer

Prevalence (1-5) 2

Description
W32/Looked-T is a Windows executable virus and network worm.

Advanced
W32/Looked-T is a Windows executable virus and network worm.

The virus includes functionalities to:

- access the internet and communicate with a remote server via HTTP
- disable AV related processes
- silently download, install and run new software

When first run W32/Looked-T copies itself to \rundl132.exe 
and creates the file \Dll.dll. This file is also detected as 
W32/Looked-T.

The virus infects EXE files found on the infected computer. The virus 
also attempts to copy itself to remote network shares.

Many files with the name "_desktop.ini" are created, in various 
folders on the infected computer. These files are harmless text files.

The following registry entry is created in order to run the virus on 
startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
\rundl132.exe





Name   W32/Rbot-FLL

Type  
    * Worm

How it spreads  
    * Network shares

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities

Aliases  
    * W32.Spybot.Worm

Prevalence (1-5) 2

Description
W32/Rbot-FLL is a worm and IRC backdoor Trojan for the Windows 
platform.

W32/Rbot-FLL spreads to other network computers by exploiting common 
buffer
overflow vulnerabilities, including: SRVSVC (MS06-040), Psyme, PNP 
(MS05-039)
and ASN.1 (MS04-007) and by copying itself to network shares 
protected by weak
passwords.

W32/Rbot-FLL runs continuously in the background, providing a 
backdoor server
which allows a remote intruder to gain access and control over the 
computer via
IRC channels.

Advanced
W32/Rbot-FLL is a worm and IRC backdoor Trojan for the Windows 
platform.

W32/Rbot-FLL spreads to other network computers by exploiting common 
buffer
overflow vulnerabilities, including: SRVSVC (MS06-040), Psyme, PNP 
(MS05-039)
and ASN.1 (MS04-007) and by copying itself to network shares 
protected by weak
passwords.

W32/Rbot-FLL runs continuously in the background, providing a 
backdoor server
which allows a remote intruder to gain access and control over the 
computer via
IRC channels.

When first run W32/Rbot-FLL copies itself to \.exe 
where
 can be any random filename.

The following registry entries are created to run .exe on 
startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
Windows Kernel System Service
.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Windows Kernel System Service
.exe

The following registry entry is changed to run wkssvr.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe .exe

(the default value for this registry entry is "Explorer.exe" which 
causes the
Microsoft file \Explorer.exe to be run on startup).

W32/Rbot-FLL sets the following registry entries, disabling the 
automatic
startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\wuauserv
Start
4

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start
4

Note: disabling autostart for the SharedAccess service deactivates 
the Microsoft
Internet Connection Firewall (ICF).

Registry entries are set as follows:

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
\userinit.exe,.exe

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
lmcompatibilitylevel
1

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1





Name   Troj/Banker-DLS

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Steals information
    * Forges the sender's email address
    * Uses its own emailing engine
    * Records keystrokes
    * Installs itself in the Registry
    * Monitors browser activity

Prevalence (1-5) 2

Description
Troj/Banker-DLS is a password stealing Trojan for the Windows platform.

The Trojan includes functionality to access the internet and 
communicate with a remote server via HTTP.

Advanced
Troj/Banker-DLS is a password stealing Trojan for the Windows platform.

The Trojan includes functionality to access the internet and 
communicate with a remote server via HTTP.

When first run Troj/Banker-DLS copies itself to \ImgPaint.exe 
and \ImgPaint.exe.

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ImgPaint






Name   Troj/Zlobns-Q

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Drops more malware

Aliases  
    * Trojan-Downloader.Win32.Zlob.aky
    * Win32/TrojanDownloader.Zlob.ACH

Prevalence (1-5) 2

Description
Troj/Zlobns-Q is a Trojan for the Windows platform.

Troj/Zlobns-Q installs a DLL component that may download other 
Trojans in the Zlob family. Troj/Zlobns-Q is likely to masquerade as 
a video codec installation file.





Name   Troj/Spammit-G

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Uses its own emailing engine
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
Troj/Spammit-G is a backdoor Trojan which allows an infected computer 
to send emails as instructed by a remote intruder.

Advanced
Troj/Spammit-G is a backdoor Trojan which allows an infected computer 
to send emails as instructed by a remote intruder.

The following registry entry is created to run Troj/Spammit-G on 
startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WINDOWS


The following registry entries are set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\ 
Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List

:*:Enabled:Server

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\ 
Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List

:*:Enabled:Server





Name   Troj/Banker-DMN

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Turns off anti-virus applications
    * Steals information
    * Installs itself in the Registry
    * Leaves non-infected files on computer

Prevalence (1-5) 2

Description
Troj/Banker-DMN is an internet banking Trojan for the Windows platform.

Advanced
Troj/Banker-DMN is an internet banking Trojan for the Windows platform.

Troj/Banker-DMN monitors the user's internet access and steals 
on-line banking details.

When Troj/Banker-DMN is installed the following files are created:

\agpbrdg0.dll - detected as Troj/Banker-DLD
\agpbrdg5.sys - detected as Troj/Haxdor-Gen
\ksl48.bin - can be safely deleted

The following registry entries are created to run code exported by 
agpbrdg0.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows 
NT\CurrentVersion\Winlogon\Notify\agpbrdg0
DllName
agpbrdg0.dll

HKLM\SOFTWARE\Microsoft\Windows 
NT\CurrentVersion\Winlogon\Notify\agpbrdg0
Startup
agpbrdg0

HKLM\SOFTWARE\Microsoft\Windows 
NT\CurrentVersion\Winlogon\Notify\agpbrdg0
Impersonate
1

Troj/Banker-DMN includes functionality to:

- modify the HOSTS file
- harvest the usernames and passwords from the Protected storage 
areas as well as from the Internet Account Manager

The Trojan also attempts to block access to anti-virus and security 
related websites including:

updates1.kaspersky-labs.com
customer.symantec.com
download.mcafee.com
downloads1.kaspersky-labs.com
downloads1.kaspersky-labs.com
downloads2.kaspersky-labs.com
avp.com
avp.ru
awaps.net
downloads3.kaspersky-labs.com
dispatch.mcafee.com
downloads4.kaspersky-labs.com
avp.ch
updates1.kaspersky-labs.com
updates2.kaspersky-labs.com
virustotal.com
updates3.kaspersky-labs.com
d-ru-2f.kaspersky-labs.com
updates3.kaspersky-labs.com
updates4.kaspersky-labs.com
updates5.kaspersky-labs.com
downloads-us1.kaspersky-labs.com
downloads-us2.kaspersky-labs.com
downloads-us3.kaspersky-labs.com
engine.awaps.net
f-secure.com
ftp.avp.ch
ftp.downloads2.kaspersky-labs.com
ftp.f-secure.com
ftp.kasperskylab.ru
ftp.kaspersky.ru
d-ru-1f.kaspersky-labs.com
d-eu-1f.kaspersky-labs.com
rads.mcafee.com
d-eu-2f.kaspersky-labs.com
liveupdate.symantec.com
d-us-1f.kaspersky-labs.com
ftp.sophos.com
ids.kaspersky-labs.com
kaspersky.com
kaspersky-labs.com
kaspersky.ru
liveupdate.symantecliveupdate.com
mast.mcafee.com
mcafee.com
my-etrust.com
networkassociates.com
phx.corporate-ir.net
securityresponse.symantec.com
service1.symantec.com
sophos.com
spd.atdmt.com
symantec.com
trendmicro.com
update.symantec.com
updates.symantec.com
us.mcafee.com





Name   Troj/Agent-DGY

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Steals information
    * Downloads code from the internet
    * Reduces system security

Prevalence (1-5) 2

Description
Troj/Agent-DGY is a Trojan for the windows platform.

Advanced
Troj/Agent-DGY is a Trojan for the windows platform.

When Troj/Agent-DGY is installed it creates the following files:

\ahug.exe
\ntdbg.exe
\RECOVER32.DLL
\rmass.exe
\gymspzd.dll

These files are detected as Troj/Agent-DGY.

\shc.tmp
\tmp.tmp

These files are harmless and may be deleted.

The following registry entries is created to run Troj/Agent-DGY on 
startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run



HKCU\Software\Microsoft\Windows\CurrentVersion\Run



Troj/Agent-DGY creates the following registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer
ShellState Backup Policy


HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
Connection Policy
Default Flags


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
SubshellState


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet 
Settings\Connection Policy
Default Flags


HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
NoAutoUpdate
00005200

Troj/Agent-DGY modifies the following registry entries:

HKLM\SOFTWARE\Microsoft\Security Center
AntiVirusDisableNotify

HKLM\SOFTWARE\Microsoft\Security Center
AntiVirusOverride

HKLM\SOFTWARE\Microsoft\Security Center
FirewallDisableNotify

HKLM\SOFTWARE\Microsoft\Security Center
UpdatesDisableNotify

Troj/Agent-DGY includes functionality to:

- download code from a remote website
- send information to a remote website

Troj/Agent-DGY will download a file detected as Dial/TlfLic-J.





Name   W32/Looked-V

Type  
    * Virus

How it spreads  
    * Network shares
    * Infected files

Affected operating systems  
    * Windows

Side effects  
    * Drops more malware

Aliases  
    * Worm.Win32.Viking.ad
    * W32/HLLP.Philis.aw

Prevalence (1-5) 2

Description
W32/Looked-V is a virus for the Windows platform.

The virus includes functionality to access the internet and 
communicate with a remote server via HTTP.

The virus infects EXE files found on the infected computer and 
attempts to spread to remote network shares with weak passwords.

Advanced
W32/Looked-V is a virus for the Windows platform.

The virus includes functionality to access the internet and 
communicate with a remote server via HTTP.

When first run W32/Looked-V copies itself to \rundl132.exe and \logo1_.exe and creates the 
file \Dll.dll. This file is detected as W32/Looked-S.

The virus infects EXE files found on the infected computer and 
attempts to spread to remote network shares with weak passwords.

Many files with the name "_desktop.ini" are created, in various 
folders on the infected computer. These files are harmless text files.

The following registry entry is created in order to run the virus on 
startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
\rundl132.exe





Name   Troj/IRCBot-RV

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Installs itself in the Registry
    * Leaves non-infected files on computer

Prevalence (1-5) 2

Description
Troj/IRCBot-RV is a Trojan for the Windows platform.

Advanced
Troj/IRCBot-RV is a Trojan for the Windows platform.

When first run Troj/IRCBot-RV copies itself to \scvhost.exe 
and creates the file \mswinsck.ocx. The file mswinsck.ocx is 
not malicious and can be removed safely.

The following registry entry is changed to run scvhost.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe scvhost.exe

(the default value for this registry entry is "Explorer.exe" which 
causes the Microsoft file \Explorer.exe to be run on startup).





Name   W32/Looked-W

Type  
    * Virus

How it spreads  
    * Network shares
    * Infected files

Affected operating systems  
    * Windows

Side effects  
    * Steals information
    * Downloads code from the internet
    * Installs itself in the Registry

Aliases  
    * Trojan-Downloader.Win32.Agent.awz

Prevalence (1-5) 2

Description
W32/Looked-W is a Windows executable virus and network worm.

The virus infects EXE files found on the infected computer. The virus 
also attempts to copy itself to remote network shares.

Advanced
W32/Looked-W is a Windows executable virus and network worm.

The virus infects EXE files found on the infected computer. The virus 
also attempts to copy itself to remote network shares.

When W32/Looked-W is installed the following files are created:

\Dll.dll - detected as W32/Looked-W
\Logo1_.exe - detected as W32/Looked-W
\rundl132.exe - detected as W32/Looked-W

The following registry entry is created to run rundl132.exe on startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
\rundl132.exe

Registry entries are created under:

HKLM\SOFTWARE\Soft\DownloadWWW\





Name   W32/Vanebot-M

Type  
    * Spyware Worm

How it spreads  
    * Network shares
    * Chat programs

Affected operating systems  
    * Windows

Side effects  
    * Steals credit card details
    * Turns off anti-virus applications
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Reduces system security
    * Records keystrokes
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities
    * Scans network for vulnerabilities

Aliases  
    * Backdoor.Win32.IRCBot.wo
    * W32/Spybot.worm.gen.e
    * W32.Spybot.Worm
    * WORM_SPYBOT.EX

Prevalence (1-5) 2

Description
W32/Vanebot-M is a worm for the Windows platform. W32/Vanebot-M also 
contains IRC backdoor Trojan functionality which allows a remote 
intruder to gain access and control over the computer.

W32/Vanebot-M spreads:
to computers vulnerable to common exploits, including SRVSVC (MS06-040)
to MSSQL servers protected by weak passwords
to network shares
via MSN Messenger
via Yahoo Instant Messenger

Advanced
W32/Vanebot-M is a worm for the Windows platform. W32/Vanebot-M also 
contains IRC backdoor Trojan functionality which allows a remote 
intruder to gain access and control over the computer.

W32/Vanebot-M spreads:
to computers vulnerable to common exploits, including SRVSVC (MS06-040)
to MSSQL servers protected by weak passwords
to network shares
via MSN Messenger
via Yahoo Instant Messenger

W32/Vanebot-M may spread with the filename redworld.exe, 
redworld2.exe or _redworld2.exe.

When first run W32/Vanebot-M copies itself to \dllcache\dragonage.exe.

The file dragonage.exe is registered as a new system driver service 
named "Dragon Age - Bioware", with a display name of "Dragon Age - 
Bioware" and a startup type of automatic, so that it is started 
automatically during system startup. Registry entries are created 
under:

HKLM\SYSTEM\CurrentControlSet\Services\Dragon Age - Bioware\

W32/Vanebot-M sets the following registry entries, disabling the 
automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\wuauserv
Start
4

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start
4

Note: disabling autostart for the SharedAccess service deactivates 
the Microsoft Internet Connection Firewall (ICF).

Registry entries are set as follows:

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
lmcompatibilitylevel
1

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1

W32/Vanebot-M attempts to terminate a number of processes related to 
security and anti-virus applications.





Name   W32/Vanebot-O

Type  
    * Spyware Worm

How it spreads  
    * Network shares
    * Chat programs

Affected operating systems  
    * Windows

Side effects  
    * Steals credit card details
    * Turns off anti-virus applications
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Reduces system security
    * Records keystrokes
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities
    * Used in DOS attacks
    * Scans network for vulnerabilities
    * Scans network for weak passwords

Aliases  
    * Backdoor.Win32.VanBot.e
    * W32.Spybot.Worm
    * BKDR_PCCLIENT.OX

Prevalence (1-5) 2

Description
W32/Vanebot-O is a worm with backdoor functionality which allows a 
remote intruder to gain access and control over the computer.

W32/Vanebot-O spreads to other network computers by exploiting common 
buffer overflow vulnerabilities, including SRVSVC (MS06-040) and 
Psyme. The worm also spreads to network shares and MSSQL servers 
protected by weak passwords. W32/Vanebot-O can spread via MSN 
Messenger and Yahoo Instant Messenger.

W32/Vanebot-O includes functionality to:

- set up a proxy server
- ownload and execute arbitrary files
- record keypresses
- steal information from Protected Storage
- port scanning
- access the internet and communicate with a remote server via HTTP
- take part in Distributed Denial of Service (DDoS) attacks

Advanced
W32/Vanebot-O is a worm with backdoor functionality which allows a 
remote intruder to gain access and control over the computer.

W32/Vanebot-O spreads to other network computers by exploiting common 
buffer overflow vulnerabilities, including SRVSVC (MS06-040) and 
Psyme. The worm also spreads to network shares and MSSQL servers 
protected by weak passwords. W32/Vanebot-O can spread via MSN 
Messenger and Yahoo Instant Messenger.

W32/Vanebot-O includes functionality to:

- set up a proxy server
- ownload and execute arbitrary files
- record keypresses
- steal information from Protected Storage
- port scanning
- access the internet and communicate with a remote server via HTTP
- take part in Distributed Denial of Service (DDoS) attacks

When first run W32/Vanebot-O copies itself to 
\dllcache\mswincom32.exe.

The file mswincom32.exe is registered as a new system driver service 
named "MSCommmand", with a display name of "MSCommmand"
and a startup 
type of automatic, so that it is started automatically during system 
startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\MSCommmand\

W32/Vanebot-O sets the following registry entries, disabling the 
automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\wuauserv
Start
4

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start
4

Note: disabling autostart for the SharedAccess service deactivates 
the Microsoft Internet Connection Firewall (ICF).

Registry entries are set as follows:

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
lmcompatibilitylevel
1

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1





Name   W32/Looked-Y

Type  
    * Virus

How it spreads  
    * Network shares
    * Infected files

Affected operating systems  
    * Windows

Side effects  
    * Modifies data on the computer
    * Drops more malware
    * Downloads code from the internet
    * Installs itself in the Registry
    * Leaves non-infected files on computer

Prevalence (1-5) 2

Description
W32/Looked-Y is a Windows executable virus and network worm.

Advanced
W32/Looked-Y is a Windows executable virus and network worm.

The virus includes functionalities to:

- access the internet and communicate with a remote server via HTTP
- disable AV related processes
- silently download, install and run new software

When first run W32/Looked-Y copies itself to \rundl132.exe 
and creates the file \Dll.dll. This file is also detected as 
W32/Looked-S.

The virus infects EXE files found on the infected computer. The virus 
also attempts to copy itself to remote network shares.

Many files with the name "_desktop.ini" are created, in various 
folders on the infected computer. These files are harmless text files.

The following registry entry is created in order to run the virus on 
startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
\rundl132.exe





Name   Troj/Sappit-B

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Turns off anti-virus applications
    * Modifies data on the computer
    * Steals information
    * Reduces system security

Prevalence (1-5) 2

Description
Troj/Sappit-B is a password stealing Trojan for the Windows platform.

Advanced
Troj/Sappit-B is a password stealing Trojan for the Windows platform.

Troj/Sappit-B attempts to steal Yahoo Messenger passwords, and can be 
configured to perform various operations, including:

- steal dialup passwords
- disable various AV software and Windows Firewall
- disable Windows tools such as TaskManager and Regedit
- Steal information such as computer name, IP address and operating 
system

This information is then sent via HTTP to a remote user.

Troj/Sappit-B is generated by a tool called Troj/SapKit-B.





Name   W32/Stration-AE

Type  
    * Worm

How it spreads  
    * Email attachments

Affected operating systems  
    * Windows

Side effects  
    * Drops more malware
    * Downloads code from the internet
    * Installs itself in the Registry

Aliases  
    * Email-Worm.Win32.Warezov.an

Prevalence (1-5) 2

Description
W32/Stration-AE is a worm for the Windows platform.

W32/Stration-AE spreads via email.

W32/Stration-AE includes functionality to download, install and run 
new software.

Advanced
W32/Stration-AE is a worm for the Windows platform.

W32/Stration-AE spreads via email.

W32/Stration-AE includes functionality to download, install and run 
new software.

When first run W32/Stration-AE copies itself to \tserv.exe 
and creates the following files:

\cmut449c14b7.dll
\e1.dll
\hpzl449c14b7.exe
\msji449c14b7.dll
\tserv.dll
\tserv.wax

The files tserv.dll and cmut449c14b7.dll are detected as 
W32/Strati-Gen.

The following registry entry is created to run tserv.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
tserv
\tserv.exe s





Name   W32/WinLose-A

Type  
    * Worm

How it spreads  
    * Infected files

Affected operating systems  
    * Windows

Side effects  
    * Turns off anti-virus applications
    * Installs itself in the Registry
    * Leaves non-infected files on computer
    * Modifies browser settings

Aliases  
    * Worm.Win32.VB.bw
    * Generic VB.c
    * Win32/VB.NGB
    * W32.SillyFDC

Prevalence (1-5) 2

Description
W32/WinLose-A is a worm for the Windows platform.

W32/WinLose-A will periodically attempt to spread itself to any 
available floppy disk or attached flash drives.

Advanced
W32/WinLose-A is a worm for the Windows platform.

When first run W32/WinLose-A copies itself to:

\AllMyLifeToLive.exe
\LiveForever.exe
\WelcomeToSystem.exe
C:\StillAlive.exe
\NewName.BAT

and creates the following files:

\WelcomeToSystem.html
\oeminfo.ini
\oemlogo.bmp

W32/WinLose-A will periodically attempt to spread itself to any 
available floppy disk or attached flash drives. If spreading is 
successful, one of the explorer's animated search assistants will be 
displayed in the middle of the screen.

When first run, W32/WinLose-A will display the following message box:

Title: EULA

Message:

Agreement (R).

You agree that this file will be transferred into any computer via 
FlashDisk and Floppy.
But I accepts no responsibility whatever arising from the use of this 
File.

The following registry entries are created to run LiveForever.exe and 
StillAlive.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ThinkDifferent
\LiveForever.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
IwillSurvive
\LiveForever.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ToBeFree
C:\StillAlive.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WinLogon
Shell
Explorer.exe C:\StillAlive.exe

(the default value is "Explorer.exe")

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
AlternateShell
C:\StillAlive.exe

(the default value is "cmd.exe")

The file NewName.BAT is registered as a new system driver service 
named "crlxss", with a display name of "Remote Protection File 
System" and a startup type of automatic, so that it is started 
automatically during system startup. Registry entries are created 
under:

HKLM\SYSTEM\CurrentControlSet\Services\crlxss\

W32/WinLose-A changes settings for Microsoft Internet Explorer, 
including the Start Page, by modifying values under:

HKCU\Software\Microsoft\Internet Explorer\Main\
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page

Registry entries are set as follows:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
0

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder
\SuperHidden
UncheckedValue
0





Name   Troj/WOW-HH

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Steals information
    * Installs itself in the Registry

Aliases  
    * Trojan-PSW.Win32.WOW.fo

Prevalence (1-5) 2

Description
Troj/WOW-HH is a password stealing Trojan for the Windows platform.

Advanced
Troj/WOW-HH is a password stealing Trojan for the Windows platform.

When first run Troj/WOW-HH copies itself to:

\inexplore.pif
\Internet Explorer\inexplore.com
\1.com
\Debug\DebugProgram.exe
\exerouter.exe
\exp10rer.com
\finders.com
\smss.exe
\command.pif
\dxdiag.com
\msconfig.com
\regedit.com
\rund1132.com

The file inexplore.com is registered as a COM object, creating 
registry entries under:

HKCR\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}

Troj/WOW-HH changes settings for Microsoft Internet Explorer by 
modifying values under:

HKCU\Software\Microsoft\Internet Explorer\Main\

Registry entries are set as follows:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
explorer.exe 1

HKCR\Drive\shell\find\command
(default)
\EXP10RER.com

HKCR\htmlfile\shell\opennew\command
(default)
\inexplore.pif" %1

HKCR\htmlfile\shell\print\command
(default)
rundll32.exe \mshtml.dll,PrintHTML "%1"

Registry entries are created under:

HKCU\Software\VB and VBA Program Settings\Microsoft Soft 
Debuger\Settings\





Name   Troj/Bancos-AWI

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Steals credit card details
    * Steals information
    * Uses its own emailing engine
    * Reduces system security
    * Records keystrokes
    * Installs itself in the Registry
    * Leaves non-infected files on computer

Aliases  
    * Trojan-Spy.Win32.Bancos.xp
    * TSPY_BANCOS.BMH

Prevalence (1-5) 2

Description
Troj/Bancos-AWI is an internet banking Trojan targeting Brazilian 
bank websites.

Troj/Bancos-AWH targets the users of several Brazilian banks by 
monitoring the user's internet activity, displaying fake login pages 
if the user visits certain predefined URLs, and logging details 
entered on the fake pages.

Advanced
Troj/Bancos-AWI is an internet banking Trojan targeting Brazilian 
bank websites.

Troj/Bancos-AWI targets the users of several Brazilian banks by 
monitoring the user's internet activity, displaying fake login pages 
if the user visits certain predefined URLs, and logging details 
entered on the fake pages.

When run Troj/Bancos-AWI displays a message box with the caption 
"FIND ERROR" and the message "Requerido Windows NT Server".

Once installed, Troj/Bancos-AWI steals confidential information 
relating to certain online banking applications by displaying fake 
login screens and sends stolen information to a remote user via 
email. Troj/Bancos-AWI also may attempt to steal information from the 
Protected Storage Area.

When first run Troj/Bancos-AWI copies itself to 
\tasklist32.exe and creates the file \winhlp32.dat.

The following registry entry is created to run tasklist32.exe on 
startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
TaskList
\tasklist32.exe





Name   Troj/WowPWS-Z

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Steals information
    * Downloads code from the internet
    * Installs itself in the Registry

Aliases  
    * Trojan-PSW.Win32.WOW.ih
    * TSPY_WOW.LW

Prevalence (1-5) 2

Description
Troj/WowPWS-Z is an information stealing Trojan for the Windows 
platform.

Advanced
Troj/WowPWS-Z is an information stealing Trojan for the Windows 
platform.

When run Troj/WowPWS-Z copies itself to

\Common Files\INTEXPLORE.pif
\Internet Explorer\INTEXPLORE.com
\EXERT.exe
\LSASS.exe
\Debug\DebugProgram.exe
\dxdiag.com
\MSCONFIG.COM
\regedit.com

Troj/WowPWS-Z sets the following registry entry to run itself on 
startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ToP
\LSASS.exe

Troj/WowPWS-Z also sets the following registry entries:

HKCU\Software\VB and VBA Program Settings\
Microsoft Soft Debuger\Settings
GUID
(F4V53Y-F9CBM2-1GYB1U-CPG8T6-EM6D9W)

HKCR\WindowFiles\DefaultIcon
(default)
"%1"

HKCR\WindowFiles\Shell\Open\Command
(default)
\EXERT.exe \"%1\" %*

HKLM\SOFTWARE\Clients\StartMenuInternet\INTEXPLORE.pif
LocalizedString
INTEXPLORE

HKLM\SOFTWARE\Clients\StartMenuInternet\INTEXPLORE.pif\shell\
open\command
(default)
\Common Files\INTEXPLORE.pif\





Name   Troj/Lineag-ABA

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Drops more malware
    * Uses its own emailing engine
    * Installs itself in the Registry

Aliases  
    * Trojan-PSW.Win32.Lineage.aja

Prevalence (1-5) 2

Description
Troj/Lineag-ABA is a Trojan for the Windows platform.

Troj/Lineag-ABA includes functionality to send notification messages 
to remote locations.

Advanced
Troj/Lineag-ABA is a Trojan for the Windows platform.

Troj/Lineag-ABA includes functionality to send notification messages 
to remote
locations.

When first run Troj/Lineag-ABA copies itself to \Intel\rundll32.exe and
creates the file \ztdll.dll.

The file ztdll.dll is detected as Troj/Lineag-Gen.

The following registry entry is created to run rundll32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
zt
\Intel\rundll32.exe

 
--- MultiMail/Win32 v0.43
* Origin: Try Our Web Based QWK: DOCSPLACE.ORG (1:123/140)
SEEN-BY: 633/267 270
@PATH: 123/140 500 379/1 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.