TIP: Click on subject to list as thread! ANSI
echo: dirty_dozen
to: ALL
from: KURT WISMER
date: 2004-05-15 16:00:00
subject: News, May 15 2004

[cut-n-paste from sophos.com]

W32/Wallon-A

Aliases
W32/Wallon.worm

Type
Win32 worm

Detection
Sophos has received several reports of this worm from the wild.

Description
W32/Wallon-A is an email worm. The worm sends mail containing a 
deceptive link. The link appears to direct the user to 
drs.yahoo.com//NEWS but in fact points to a location on 
another website.

The website that the user is directed to utilises Trojan downloaders and 
exploits to download and run a copy of W32/Wallon-A.

The Trojans used and installed during the infection process are:
Troj/Psyme-V, Troj/StartPa-HF, Troj/Dloader-JK and Dial/Top69-A.





W32/Spybot-TA

Type
Win32 worm

Detection
At the time of writing, Sophos has received just one report of this worm 
from the wild.

Description
W32/Spybot-TA is a peer-to-peer (P2P) worm with backdoor Trojan 
functionality.

W32/Spybot-TA attempts to move itself to AUTOSCRLL.EXE in the Windows 
System folder and creates entries in the registry at the following 
locations to run itself on system restart:

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\
Auto Scroll Loader = AUTOSCRLL.EXE

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Auto Scroll Loader = AUTOSCRLL.EXE

W32/Spybot-TA copies itself to a folder called KAZAABACKUPFILES in the 
Windows System folder with the following filenames:

AVP_Crack.exe
AquaNox2 Crack.exe
Battlefield1942_bloodpatch.exe
C&C Generals_crack.exe
FIFA2003 crack.exe
NBA2003_crack.exe
Porn.exe
UT2003_bloodpatch.exe
Unreal2_bloodpatch.exe
zoneallarm_pro_crack.exe

W32/Spybot-TA then sets the following registry entry to enable sharing 
of these files with KaZaA:

HKCU\Software\Kazaa\LocalContent\
Dir0 = 012345:C:\\kazaabackupfiles\

W32/Spybot-TA also attempts to copy itself to the startup folder of 
attached network drives and can be used to record the keystrokes on the 
compromised machine, effectively acting as a keylogger. This worm can 
also be used to initiate SYNFlood attacks.

W32/Spybot-TA remains resident, running in the background as a service
process and listening for commands from remote users via IRC channels.

W32/Spybot-TA attempts to terminate various monitoring programs 
including the following:

'NETSTAT.EXE'
'TASKMGR.EXE'
'MSCONFIG.EXE'
'REGEDIT.EXE'.





W32/Sober-G

Aliases
I-Worm.Sober.g, W32/Sober.g{at}MM

Type
Win32 worm

Detection
Sophos has received several reports of this worm from the wild.

Description
W32/Sober-G is a mass mailing worm that sends itself to email addresses 
harvested from the infected computer. When started it copies itself to 
the Windows system folder and sets the following registry entry so as to 
auto-start on user logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
logcrypt = \.exe %1

When first run the worm creates a TXT file called in the Temp folder and 
displays its contents using NOTEPAD.EXE. The text file begins with the 
text:

File not found
Special -UnZip Data- Module is missing
Open with Notepad?
Converted_
notepad

The worm copies itself to the Windows system folder as an EXE file with 
a name that is constructed from the following:

sys, host, dir, expolrer, win, run, log, 32, disc, crypt, data, diag, 
spool, service, smss32

W32/Sober-G also creates the following files used to store harvested 
information in the Windows system folder:
bcegfds.lll
cvqaikxt.apk
datsobex.wwr
wincheck32.dats
winexpoder.dats
winzweier.dats
xdatxzap.zxp
zhcarxxi.vvx

W32/Sober-G harvests email addresses from files with the following 
extensions:

PMR, STM, SLK, INBOX, IMB, CSV, BAK, IMH, XHTML, IMM, IMH, CMS, NWS, 
VCF, CTL, DHTM, CGI, PP, PPT, MSG, JSP, OFT, VBS, UIN, LDB, ABC, PST, 
CFG, MDW, MBX, MDX, MDA, ADP, NAB, FDB, VAP, DSP, ADE, SLN, DSW, MDE, 
FRM, BAS, ADR, CLS, INI, LDIF, LOG, MDB, XML, WSH, TBB, ABX, ABD, ADB, 
PL, RTF, MMF, DOC, ODS, NCH, XLS, NSF, TXT, WAB, EML, HLP, MHT, NFO, 
PHP, ASP, SHTML, DBX

Emails sent by the worm have the following characteristics:

Subject lines:

hi there
hey dude!
wazzup!!!
yeah dude :P
Details
Oh God i'ts
damn!
#
Registration confirmation
Confirmation
Your Password
Your mail account
Delivery failure notice
Faulty mail delivery
Mail delivery failed
Mailing Error
Illegal signs in E-Mail
Invalid mail length
Mail Delivery failure
mail delivery status
Warning!
error in dbase
DBase Error
ups, i've got your mail
Sorry, that's your mail
why do you do that?

Message texts:

I was surprised, too! :-( Who could suspect something like that?

All OK :) see, what i've found!

hi its me i've found a shity virus on my pc. check your pc, too! follow 
the steps in this article. bye

I 've told you!:-) sometime I grab your passwords!

I hope you accept the result! Follow the instructions to read the 
message.
Please read the document

Registration confirmation
Confirmation
Your Password
Your mail account
Your password was changed successfully.
Protected message is attached.
++++ Service: http://www.
++++ Mail To: User-info

*** Auto Mail Delivery System ***
67.28.114.32_failed_after_I_sent_the_message./Remote_host_said
:_554_delivery_error:_dd_Sorry_your_message_cannot_be_delivered.
_This_account_has_been_disabled_ or_discontinued_[#102]._-_mta134.mail.dcn.com
** End of Transmission The original message is a separate attachment.
--- Web: http://www.
--- Mail To: UserHelp

Read the attachment for details.
Bad Gateway: The message has been attached.
+++ A service of +++ http://www. Mail

The attached file has a randomly generated name and a ZIP extension.





W32/Sdbot-IK

Aliases
W32/Sdbot.worm.gen.b, WORM_SDBOT.KW

Type
Win32 worm

Detection
Sophos has received several reports of this worm from the wild.

Description
W32/Sdbot-IK is a worm which attempts to spread to remote network shares. 
It also contains backdoor Trojan functionality, allowing unauthorised 
remote access to the infected computer via IRC channels while running in 
the background as a service process.

W32/Sdbot-IK copies itself to the Windows system folder as WNETMGR.EXE
and as COOL.EXE and creates entries in the registry at the following 
locations so as to run itself on system startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft System Checkup

HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services\
Microsoft System Checkup

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NT Logging Service

W32/Sdbot-IK spreads to network shares with weak passwords as a result 
of the backdoor Trojan element receiving the appropriate command from a 
remote user.

W32/Sdbot-IK attempts to clear the Security system log file.

W32/Sdbot-IK attempts to download and execute several files to the Temp 
folder, but at the time of writing none of these were available.

W32/Sdbot-IK attempts to terminate and disable various anti-virus and 
security related programs and services.

W32/Sdbot-IK also modifies the HOSTS file located at
%WINDOWS%\System32\Drivers\etc\HOSTS, mapping selected anti-virus 
websites to the loopback address 127.0.0.1 in an attempt to prevent 
access to these sites. Typically the following mappings will be appended 
to the HOSTS file:

127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com





W32/Sasser-A

Aliases
W32/Sasser.worm, Win32/Sasser.A, W32.Sasser.Worm, WORM_SASSER.A

Type
Win32 worm

Detection
Sophos has received several reports of this worm from the wild.

Description
W32/Sasser-A worm is a self-executing network worm, which travels from 
infected machines via the internet, exploiting a Microsoft Windows 
vulnerability MS04-011, and instructs vulnerable systems to download and 
execute the viral code.

It does not spread via email.

Infected computers may run more slowly than normal and shut down 
intermittently.

W32/Sasser-A attempts to connect to computers through ports TCP/9996 and 
TCP/445. If the Windows computers are not patched against the LSASS 
vulnerability, an FTP script is downloaded and executed, which connects 
to port 5554 and downloads a copy of the worm via FTP (File Transfer 
Protocol).

The worm copies itself to the Windows folder with the filename 
avserve.exe and sets the following registry key to auto-start on user 
logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\avserve = avserve.exe

The Microsoft vulnerability was first reported on 13 April, and 
Microsoft have issued protection, which can be downloaded from Microsoft 
Security Bulletin MS04-011.

Further reading: Information on the Sasser internet worm





W32/Rbot-I

Aliases
Backdoor.SdBot.jg, W32/Sdbot.worm.gen.g, W32.Randex.gen

Type
Win32 worm

Detection
At the time of writing, Sophos has received just one report of this worm 
from the wild.

Description
W32/Rbot-I is a worm which attempts to spread to remote network shares. 
It also contains backdoor Trojan functionality, allowing unauthorised 
remote access to the infected computer via IRC channels while running in 
the background as a service process.

W32/Rbot-I spreads to network shares with weak passwords as a result of 
the backdoor Trojan element receiving the appropriate command from a 
remote user.

W32/Rbot-I copies itself to the Windows system folder as NAVMGRD.EXE.

W32/Rbot-I creates entries in the registry at the following locations to 
run itself on system startup and sets them every 60 seconds that it is 
running:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

W32/Rbot-I set the following registry entries every 120 seconds:

HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = "N"
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = "1"

W32/Rbot-I also tries to delete network shares on the host computer 
including C$, D$ and ADMIN$ every 120 seconds.





W32/Agobot-ZH

Type
Win32 worm

Detection
At the time of writing, Sophos has received just one report of this worm 
from the wild.

Description
W32/Agobot-ZH copies itself to network shares with weak passwords and 
attempts to spread to computers using the DCOM RPC and RPC locator 
vulnerabilities.

These vulnerabilities allow the worm to execute its code on target 
computers with system level privileges. For further information on these 
vulnerabilities and for details on how to patch the computer against 
such attacks please see Microsoft security bulletins MS03-026 and 
MS03-001.

When first run W32/Agobot-ZH copies itself to the Windows system folder 
with the filename wintcp.exe and creates the following registry entries 
so that the worm is run when Windows starts up:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Windows TCP/IP = wintcp.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
Windows TCP/IP = wintcp.exe

W32/Agobot-ZH connects to a remote IRC server and joins a specific 
channel. The backdoor functionality of the worm can then be accessed by 
an attacker using the IRC network.

The worm also attempts to terminate and disable various security related 
programs.





W32/Agobot-QA

Aliases
Backdoor.Agobot.gen, W32/Polybot.gen!irc, W32.Gaobot.gen!poly

Type
Win32 worm

Detection
At the time of writing, Sophos has received just one report of this worm 
from the wild.

Description
W32/Agobot-QA is an IRC backdoor Trojan and network worm which 
establishes an IRC channel to a remote server in order to grant an 
intruder access to the compromised machine.

This worm will move itself into the Windows System32 folder under the 
filename SYSTEMC.EXE and may create the following registry entries so 
that it can execute automatically on system restart:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
SysStrt = systemc.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
SysStrt = systemc.exe

The following registry branches will also be created:

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYSTEM_START\
HKLM\SYSTEM\CurrentControlSet\Services\System Start\

W32/Agobot-QA may also attempt to collect email addresses from the 
Windows Address Book and send itself to these email addresses using its 
own SMTP engine with itself included as an executable attachment.

W32/Agobot-QA may attempt to terminate anti-virus and other 
security-related processes, in addition to other viruses, worms or 
Trojans. For example:
_AVPM
_AVPCC
_AVP32
ZONEALARM
ZONALM2601
ZATUTOR
ZAPSETUP3001
ZAPRO
XPF202EN
WYVERNWORKSFIREWALL
WUPDT
WUPDATER
WSBGATE
WRCTRL
WRADMIN
WNT
WNAD
WKUFIND
WINUPDATE
WINTSK32
WINSTART001
WINSTART
WINSSK32
WINSERVN
WINRECON
WINPPR32
WINNET
WINMAIN
WINLOGIN
WININITX
WININIT
WININETD
WINDOWS
WINDOW
WINACTIVE
WIN32US
WIN32
WIN-BUGSFIX
WIMMUN32
WHOSWATCHINGME
WGFE95
WFINDV32
WEBTRAP
WEBSCANX
WEBDAV
WATCHDOG
W9X
W32DSM89
VSWINPERSE
VSWINNTSE
VSWIN9XE
VSSTAT
VSMON
VSMAIN
VSISETUP
VSHWIN32
VSECOMR
VSCHED
VSCENU6.02D30
VSCAN40
VPTRAY
VPFW30S
VPC42
VPC32
VNPC3000
VNLAN300
VIRUSMDPERSONALFIREWALL
VIR-HELP
VFSETUP
VETTRAY
VET95
VET32
VCSETUP
VBWINNTW
VBWIN9X
VBUST
VBCONS
VBCMSERV
UTPOST
UPGRAD
UPDAT
UNDOBOOT
TVTMD
TVMD
TSADBOT
TROJANTRAP3
TRJSETUP
TRJSCAN
TRICKLER
TRACERT
TITANINXP
TITANIN
TGBOB
TFAK5
TFAK
TEEKIDS
TDS2-NT
TDS2-98
TDS-3
TCM
TCA
TC
TBSCAN
TAUMON
TASKMON
TASKMO
TASKMG
SYSUPD
SYSTEM32
SYSTEM
SYSEDIT
SYMTRAY
SYMPROXYSVC
SWEEPNET.SWEEPSRV.SYS.SWNETSUP
SWEEP95
SVSHOST
SVCHOSTS
SVCHOSTC
SVC
SUPPORTER5
SUPPORT
SUPFTRL
STCLOADER
START
ST2
SSG_4104
SSGRATE
SS3EDIT
SRNG
SREXE
SPYXX
SPOOLSV32
SPOOLCV
SPOLER
SPHINX
SPF
SPERM
SOFI
SOAP
SMSS32
SMS
SMC
SHOWBEHIND
SHN
UPDATE
SHELLSPYINSTALL
SH
SGSSFW32
SFC
SETUP_FLOWPROTECTOR_US
SETUPVAMEEVAL
SERVLCES
SERVLCE
SERVICE
SERV95
SD
SCVHOST
SCRSVR
SCRSCAN
SCANPM
SCAN95
SCAN32
SCAM32
SC
SBSERV
SAVENOW
SAVE
SAHAGENT
SAFEWEB
RUXDLL32
RUNDLL16
RUNDLL
RUN32DLL
RULAUNCH
RTVSCN95
RTVSCAN
RSHELL
RRGUARD
RESCUE32
RESCUE
REGEDT32
REGEDIT
REGED
REALMON
RCSYNC
RB32
RAY
RAV8WIN32ENG
RAV7WIN
RAV7
RAPAPP
QSERVER
QCONSOLE
PVIEW95
PUSSY
PURGE
PSPF
PROTECTX
PROPORT
PROGRAMAUDITOR
PROCEXPLORERV1.0
PROCESSMONITOR
PROCDUMP
PRMVR
PRMT
PRIZESURFER
PPVSTOP
PPTBC
PPINUPDT
POWERSCAN
PORTMONITOR
PORTDETECTIVE
POPSCAN
POPROXY
POP3TRAP
PLATIN
PINGSCAN
PGMONITR
PFWADMIN
PF2
PERSWF
PERSFW
PERISCOPE
PENIS
PDSETUP
PCSCAN
PCIP10117_0
PCFWALLICON
PCDSETUP
PCCWIN98
PCCWIN97
PCCNTMON
PCCIOMON
PCC2K_76_1436
PCC2002S902
PAVW
PAVSCHED
PAVPROXY
PAVCL
PATCH
PANIXK
PADMIN
OUTPOSTPROINSTALL
OUTPOSTINSTALL
OTFIX
OSTRONET
OPTIMIZE
ONSRVR
OLLYDBG
NWTOOL16
NWSERVICE
NWINST4
NVSVC32
NVC95
NVARCH16
NUI
NTXconfig
NTVDM
NTRTSCAN
NT
NSUPDATE
NSTASK32
NSSYS32
NSCHED32
NPSSVC
NPSCHECK
NPROTECT
NPFMESSENGER
NPF40_TW_98_NT_ME_2K
NOTSTART
NORTON_INTERNET_SECU_3.0_407
NORMIST
NOD32
NMAIN
NISUM
NISSERV
NETUTILS
NETSTAT
NETSPYHUNTER-1.2
NETSCANPRO
NETMON
NETINFO
NETD32
NETARMOR
NEOWATCHLOG
NEOMONITOR
NDD32
NCINST4
NC2000
NAVWNT
NAVW32
NAVSTUB
NAVNT
NAVLU32
NAVENGNAVEX15.NAVLU32
NAVDX
NAVAPW32
NAVAPSVC
NAVAP.NAVAPSVC
AUTO-PROTECT.NAV80TRY
NAV
OUTPOST
NUPGRADE
N32SCANW
MWATCH
MU0311AD
MSVXD
MSSYS
MSSMMC32
MSMSGRI32
MSMGT
MSLAUGH
MSINFO32
MSIEXEC16
MSDOS
MSDM
MSCONFIG
MSCMAN
MSCCN32
MSCACHE
MSBLAST
MSBB
MSAPP
MRFLUX
MPFTRAY
MPFSERVICE
MPFAGENT
MOSTAT
MOOLIVE
MONITOR
MMOD
MINILOG
MGUI
MGHTML
MGAVRTE
MGAVRTCL
MFWENG3.02D30
MFW2EN
MFIN32
MD
MCVSSHLD
MCVSRTE
MCTOOL
MCSHIELD
MCMNHDLR
MCAGENT
MAPISVC32
LUSPT
LUINIT
LUCOMSERVER
LUAU
LSETUP
LORDPE
LOOKOUT
LOCKDOWN2000
LOCKDOWN
LOCALNET
LOADER
LNETINFO
LDSCAN
LDPROMENU
LDPRO
LDNETMON
LAUNCHER
KILLPROCESSSETUP161
KERNEL32
KERIO-WRP-421-EN-WIN
KERIO-WRL-421-EN-WIN
KERIO-PF-213-EN-WIN
KEENVALUE
KAZZA
KAVPF
KAVPERS40ENG
KAVLITE40ENG
JEDI
JDBGMRG
JAMMER
ISTSVC
MCUPDATE
LUALL
ISRV95
ISASS
IRIS
IPARMOR
IOMON98
INTREN
INTDEL
INIT
INFWIN
INFUS
INETLNFO
IFW2000
IFACE
IEXPLORER
IEDRIVER
IEDLL
IDLE
ICSUPPNT
ICMON
ICLOADNT
ICLOAD95
IBMAVSP
IBMASN
IAMSTATS
IAMSERV
IAMAPP
HXIUL
HXDL
HWPE
HTPATCH
HTLOG
HOTPATCH
HOTACTIO
HBSRV
HBINST
HACKTRACERSETUP
GUARDDOG
GUARD
GMT
GENERICS
GBPOLL
GBMENU
GATOR
FSMB32
FSMA32
FSM32
FSGK32
FSAV95
FSAV530WTBYB
FSAV530STBYB
FSAV32
FSAV
FSAA
FRW
FPROT
FP-WIN_TRIAL
FP-WIN
FNRB32
FLOWPROTECTOR
FIREWALL
FINDVIRU
FIH32
FCH32
FAST
FAMEH32
F-STOPW
F-PROT95
F-PROT
F-AGNT95
EXPLORE
EXPERT
EXE.AVXW
EXANTIVIRUS-CNET
EVPN
ETRUSTCIPE
ETHEREAL
ESPWATCH
ESCANV95
ICSUPP95
ESCANHNT
ESCANH95
ESAFE
ENT
EMSW
EFPEADM
ECENGINE
DVP95_0
DVP95
DSSAGENT
DRWEBUPW
DRWEB32
DRWATSON
DPPS2
DPFSETUP
DPF
DOORS
DLLREG
DLLCACHE
DIVX
DEPUTY
DEFWATCH
DEFSCANGUI
DEFALERT
DCOMX
DATEMANAGER
Claw95
CWNTDWMO
CWNB181
CV
CTRL
CPFNT206
CPF9X206
CPD
CONNECTIONMONITOR
CMON016
CMGRDIAN
CMESYS
CMD32
CLICK
CLEANPC
CLEANER3
CLEANER
CLEAN
CFINET32
CFINET
CFIADMIN
CFGWIZ
CFD
CDP
CCPXYSVC
CCEVTMGR
CCAPP
BVT
BUNDLE
BS120
BRASIL
BPC
BORG2
BOOTWARN
BOOTCONF
BLSS
BLACKICE
BLACKD
BISP
BIPCPEVALSETUP
BIPCP
BIDSERVER
BIDEF
BELT
BEAGLE
BD_PROFESSIONAL
BARGAINS
BACKWEB
CLAW95CF
CFIAUDIT
AVXMONITORNT
AVXMONITOR9X
AVWUPSRV
AVWUPD
AVWINNT
AVWIN95
AVSYNMGR
AVSCHED32
AVPTC32
AVPM
AVPDOS32
AVPCC
AVP32
AVP
AVNT
AVLTMAIN
AVKWCTl9
AVKSERVICE
AVKSERV
AVKPOP
AVGW
AVGUARD
AVGSERV9
AVGSERV
AVGNT
AVGCTRL
AVGCC32
AVE32
AVCONSOL
AU
ATWATCH
ATRO55EN
ATGUARD
ATCON
ARR
APVXDWIN
APLICA32
APIMONITOR
ANTS
ANTIVIRUS
ANTI-TROJAN
AMON9X
ALOGSERV
ALEVIR
ALERTSVC
AGENTW
AGENTSVR
ADVXDWIN
ADAWARE
AVXQUAR
ACKWIN32
AVWUPD32
AVPUPD
AUTOUPDATE
AUTOTRACE
AUTODOWN
AUPDATE
ATUPDATER

W32/Agobot-QA may also be used to terminate the following services on 
remote computers:
Themes
srservice
wuauserv
WZCSVC
winmgmt
WebClient
W32Time
uploadmgr
TrkWks
TermService
TapiSrv
stisvc
SSDPSRV
Spooler
ShellHWDetection
SENS
seclogon
Schedule
SamSs
RpcSs
RasMan
ProtectedStorage
PolicyAgent
PlugPlay
Nla
Netman
Messenger
MDM
LmHosts
lanmanworkstation
lanmanserver
helpsvc
FastUserSwitchingCompatibility
EventSystem
Eventlog
ERSvc
Dnscache
dmserver
Dhcp
CryptSvc
Browser
AudioSrv
Ati HotKey Poller

W32/Agobot-QA may search for shared folders on the internet with weak 
passwords and copy itself into them.

A text file named HOSTS in C:\\drivers\etc\ may be 
created or overwritten with a list of anti-virus and other 
security-related websites, each bound to the IP loopback address of 
127.0.0.1 which would effectively prevent access to these sites. For 
example:
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com

W32/Agobot-QA can sniff HTTP, ICMP, FTP and IRC network traffic and 
steal data from them.

The following vulnerabilities can also be exploited to aid propagation 
on unpatched systems and manipulate registry keys:

Remote Procedure Call (RPC) vulnerability
Distributed Component Object Model (DCOM) vulnerability
RPC Locator vulnerability
IIS5/WEBDAV Buffer Overflow vulnerability

For more information about these Windows vulnerabilities, please refer 
to the following Microsoft Security Bulletins:

Microsoft Security Bulletin MS03-001
Microsoft Security Bulletin MS03-007
Microsoft Security Bulletin MS03-039

W32/Agobot-QA can also polymorph on installation in order to evade 
detection and share / delete the admin$, ipc$ etc drives.

It can also test the available bandwidth by attempting to GET or POST 
data to the following websites:
yahoo.co.jp
www.nifty.com
www.d1asia.com
www.st.lib.keio.ac.jp
www.lib.nthu.edu.tw
www.above.net
www.level3.com
nitro.ucsc.edu
www.burst.net
www.cogentco.com
www.rit.edu
www.nocster.com
www.verio.com
www.stanford.edu
www.xo.net
de.yahoo.com
www.belwue.de
www.switch.ch
www.1und1.de
verio.fr
www.utwente.nl
www.schlund.net

W32/Agobot-QA can also be used to initiate denial-of-service (DoS) and 
distributed denial-of-service (DDoS) synflood/httpflood/fraggle/smurf 
attacks against remote systems.

This worm can steal the Windows Product ID and keys from several 
computer applications or games including:
AOL Instant Messenger
Battlefield 1942
Battlefield 1942: Secret Weapons Of WWII
Battlefield 1942: The Road To Rome
Battlefield 1942: Vietnam
Black and White
Call of Duty
Command and Conquer: Generals
Command and Conquer: Generals: Zero Hour
Command and Conquer: Red Alert2
Command and Conquer: Tiberian Sun
Counter-Strike
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden and Dangerous 2
Industry Giant 2
IGI2: Covert Strike
James Bond 007: Nightfire
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
NHL 2002
NHL 2003
Need For Speed: Hot Pursuit 2
Need For Speed: Underground
Neverwinter Nights
Ravenshield
Shogun Total War - Warlord Edition
Soldiers Of Anarchy
Soldier of Fortune II - Double Helix
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004
Windows Messenger

W32/Agobot-QA will delete all files named "sound*.*".





W32/Agobot-LI

Aliases
Gaobot, Nortonbot, Phatbot, Polybot.

Type
Win32 worm

Detection
At the time of writing, Sophos has received just one report of this worm 
from the wild.

Description
W32/Agobot-LI is an IRC backdoor Trojan and network worm which 
establishes an IRC channel to a remote server in order to grant an 
intruder access to the compromised computer.

This worm will move itself into the Windows System32 folder under the 
filename SCVHOST.EXE and may create the following registry entries so 
that it can execute automatically on system restart:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
scvhost = scvhost.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
scvhost = scvhost.exe

This worm may also attempt to glean email addresses from the Windows 
Address Book and send itself to these email addresses using its own SMTP 
engine with itself included as an executable attachment.

W32/Agobot-LI may attempt to terminate anti-virus and other 
security-related processes, in addition to other viruses, worms or 
Trojans.
For example:

_AVPM
_AVPCC
_AVP32
ZONEALARM
ZONALM2601
ZATUTOR
ZAPSETUP3001
ZAPRO
XPF202EN
WYVERNWORKSFIREWALL
WUPDT
WUPDATER
WSBGATE
WRCTRL
WRADMIN
WNT
WNAD
WKUFIND
WINUPDATE
WINTSK32
WINSTART001
WINSTART
WINSSK32
WINSERVN
WINRECON
WINPPR32
WINNET
WINMAIN
WINLOGIN
WININITX
WININIT
WININETD
WINDOWS
WINDOW
WINACTIVE
WIN32US
WIN32
WIN-BUGSFIX
WIMMUN32
WHOSWATCHINGME
WGFE95
WFINDV32
WEBTRAP
WEBSCANX
WEBDAV
WATCHDOG
W9X
W32DSM89
VSWINPERSE
VSWINNTSE
VSWIN9XE
VSSTAT
VSMON
VSMAIN
VSISETUP
VSHWIN32
VSECOMR
VSCHED
VSCENU6.02D30
VSCAN40
VPTRAY
VPFW30S
VPC42
VPC32
VNPC3000
VNLAN300
VIRUSMDPERSONALFIREWALL
VIR-HELP
VFSETUP
VETTRAY
VET95
VET32
VCSETUP
VBWINNTW
VBWIN9X
VBUST
VBCONS
VBCMSERV
UTPOST
UPGRAD
UPDAT
UNDOBOOT
TVTMD
TVMD
TSADBOT
TROJANTRAP3
TRJSETUP
TRJSCAN
TRICKLER
TRACERT
TITANINXP
TITANIN
TGBOB
TFAK5
TFAK
TEEKIDS
TDS2-NT
TDS2-98
TDS-3
TCM
TCA
TC
TBSCAN
TAUMON
TASKMON
TASKMO
TASKMG
SYSUPD
SYSTEM32
SYSTEM
SYSEDIT
SYMTRAY
SYMPROXYSVC
SWEEPNET.SWEEPSRV.SYS.SWNETSUP
SWEEP95
SVSHOST
SVCHOSTS
SVCHOSTC
SVC
SUPPORTER5
SUPPORT
SUPFTRL
STCLOADER
START
ST2
SSGRATE
SS3EDIT
SRNG
SREXE
SPYXX
SPOOLSV32
SPOOLCV
SPOLER
SPHINX
SPF
SPERM
SOFI
SOAP
SMSS32
SMS
SMC
SHOWBEHIND
SHN
UPDATE
SHELLSPYINSTALL
SH
SGSSFW32
SFC
SETUP_FLOWPROTECTOR_US
SETUPVAMEEVAL
SERVLCES
SERVLCE
SERVICE
SERV95
SD
SCVHOST
SCRSVR
SCRSCAN
SCANPM
SCAN95
SCAN32
SCAM32
SC
SBSERV
SAVENOW
SAVE
SAHAGENT
SAFEWEB
RUXDLL32
RUNDLL16
RUNDLL
RUN32DLL
RULAUNCH
RTVSCN95
RTVSCAN
RSHELL
RRGUARD
RESCUE32
RESCUE
REGEDT32
REGEDIT
REGED
REALMON
RCSYNC
RB32
RAY
RAV8WIN32ENG
RAV7WIN
RAV7
RAPAPP
QSERVER
QCONSOLE
PVIEW95
PUSSY
PURGE
PSPF
PROTECTX
PROPORT
PROGRAMAUDITOR
PROCEXPLORERV1.0
PROCESSMONITOR
PROCDUMP
PRMVR
PRMT
PRIZESURFER
PPVSTOP
PPTBC
PPINUPDT
POWERSCAN
PORTMONITOR
PORTDETECTIVE
POPSCAN
POPROXY
POP3TRAP
PLATIN
PINGSCAN
PGMONITR
PFWADMIN
PF2
PERSWF
PERSFW
PERISCOPE
PENIS
PDSETUP
PCSCAN
PCFWALLICON
PCDSETUP
PCCWIN98
PCCWIN97
PCCNTMON
PCCIOMON
PAVW
PAVSCHED
PAVPROXY
PAVCL
PATCH
PANIXK
PADMIN
OUTPOSTPROINSTALL
OUTPOSTINSTALL
OTFIX
OSTRONET
OPTIMIZE
ONSRVR
OLLYDBG
NWTOOL16
NWSERVICE
NWINST4
NVSVC32
NVC95
NVARCH16
NUI
NTXconfig
NTVDM
NTRTSCAN
NT
NSUPDATE
NSTASK32
NSSYS32
NSCHED32
NPSSVC
NPSCHECK
NPROTECT
NPFMESSENGER
NPF40_TW_98_NT_ME_2K
NOTSTART
NORTON_INTERNET_SECU_3.0_407
NORMIST
NOD32
NMAIN
NISUM
NISSERV
NETUTILS
NETSTAT
NETSPYHUNTER-1.2
NETSCANPRO
NETMON
NETINFO
NETD32
NETARMOR
NEOWATCHLOG
NEOMONITOR
NDD32
NCINST4
NAVWNT
NAVW32
NAVSTUB
NAVNT
NAVLU32
NAVENGNAVEX15.NAVLU32
NAVDX
NAVAPW32
NAVAPSVC
NAVAP.NAVAPSVC
AUTO-PROTECT.NAV80TRY
NAV
OUTPOST
NUPGRADE
N32SCANW
MWATCH
MU0311AD
MSVXD
MSSYS
MSSMMC32
MSMSGRI32
MSMGT
MSLAUGH
MSINFO32
MSIEXEC16
MSDOS
MSDM
MSCONFIG
MSCMAN
MSCCN32
MSCACHE
MSBLAST
MSBB
MSAPP
MRFLUX
MPFTRAY
MPFSERVICE
MPFAGENT
MOSTAT
MOOLIVE
MONITOR
MMOD
MINILOG
MGUI
MGHTML
MGAVRTE
MGAVRTCL
MFWENG3.02D30
MFW2EN
MFIN32
MD
MCVSSHLD
MCVSRTE
MCTOOL
MCSHIELD
MCMNHDLR
MCAGENT
MAPISVC32
LUSPT
LUINIT
LUCOMSERVER
LUAU
LSETUP
LORDPE
LOOKOUT
LOCKDOWN2000
LOCKDOWN
LOCALNET
LOADER
LNETINFO
LDSCAN
LDPROMENU
LDPRO
LDNETMON
LAUNCHER
KILLPROCESSSETUP161
KERNEL32
KERIO-WRP-421-EN-WIN
KERIO-WRL-421-EN-WIN
KERIO-PF-213-EN-WIN
KEENVALUE
KAZZA
KAVPF
KAVPERS40ENG
KAVLITE40ENG
JEDI
JDBGMRG
JAMMER
ISTSVC
MCUPDATE
LUALL
ISRV95
ISASS
IRIS
IPARMOR
IOMON98
INTREN
INTDEL
INIT
INFWIN
INFUS
INETLNFO
IFW2000
IFACE
IEXPLORER
IEDRIVER
IEDLL
IDLE
ICSUPPNT
ICMON
ICLOADNT
ICLOAD95
IBMAVSP
IBMASN
IAMSTATS
IAMSERV
IAMAPP
HXIUL
HXDL
HWPE
HTPATCH
HTLOG
HOTPATCH
HOTACTIO
HBSRV
HBINST
HACKTRACERSETUP
GUARDDOG
GUARD
GMT
GENERICS
GBPOLL
GBMENU
GATOR
FSMB32
FSMA32
FSM32
FSGK32
FSAV95
FSAV530WTBYB
FSAV530STBYB
FSAV32
FSAV
FSAA
FRW
FPROT
FP-WIN_TRIAL
FP-WIN
FNRB32
FLOWPROTECTOR
FIREWALL
FINDVIRU
FIH32
FCH32
FAST
FAMEH32
F-STOPW
F-PROT95
F-PROT
F-AGNT95
EXPLORE
EXPERT
EXE.AVXW
EXANTIVIRUS-CNET
EVPN
ETRUSTCIPE
ETHEREAL
ESPWATCH
ESCANV95
ICSUPP95
ESCANHNT
ESCANH95
ESAFE
ENT
EMSW
EFPEADM
ECENGINE
DVP95_0
DVP95
DSSAGENT
DRWEBUPW
DRWEB32
DRWATSON
DPPS2
DPFSETUP
DPF
DOORS
DLLREG
DLLCACHE
DIVX
DEPUTY
DEFWATCH
DEFSCANGUI
DEFALERT
DCOMX
DATEMANAGER
Claw95
CWNTDWMO
CWNB181
CV
CTRL
CPFNT206
CPF9X206
CPD
CONNECTIONMONITOR
CMON016
CMGRDIAN
CMESYS
CMD32
CLICK
CLEANPC
CLEANER3
CLEANER
CLEAN
CFINET32
CFINET
CFIADMIN
CFGWIZ
CFD
CDP
CCPXYSVC
CCEVTMGR
CCAPP
BVT
BUNDLE
BS120
BRASIL
BPC
BORG2
BOOTWARN
BOOTCONF
BLSS
BLACKICE
BLACKD
BISP
BIPCPEVALSETUP
BIPCP
BIDSERVER
BIDEF
BELT
BEAGLE
BD_PROFESSIONAL
BARGAINS
BACKWEB
CLAW95CF
CFIAUDIT
AVXMONITORNT
AVXMONITOR9X
AVWUPSRV
AVWUPD
AVWINNT
AVWIN95
AVSYNMGR
AVSCHED32
AVPTC32
AVPM
AVPDOS32
AVPCC
AVP32
AVP
AVNT
AVLTMAIN
AVKWCTl9
AVKSERVICE
AVKSERV
AVKPOP
AVGW
AVGUARD
AVGSERV9
AVGSERV
AVGNT
AVGCTRL
AVGCC32
AVE32
AVCONSOL
AU
ATWATCH
ATRO55EN
ATGUARD
ATCON
ARR
APVXDWIN
APLICA32
APIMONITOR
ANTS
ANTIVIRUS
ANTI-TROJAN
AMON9X
ALOGSERV
ALEVIR
ALERTSVC
AGENTW
AGENTSVR
ADVXDWIN
ADAWARE
AVXQUAR
ACKWIN32
AVWUPD32
AVPUPD
AUTOUPDATE
AUTOTRACE
AUTODOWN
AUPDATE
ATUPDATER

W32/Agobot-LI may also be used to terminate the following processes on 
remote computers:

Themes
srservice
wuauserv
WZCSVC
winmgmt
WebClient
W32Time
uploadmgr
TrkWks
TermService
TapiSrv
stisvc
SSDPSRV
Spooler
ShellHWDetection
SENS
seclogon
Schedule
SamSs
RpcSs
RasMan
ProtectedStorage
PolicyAgent
PlugPlay
Nla
Netman
Messenger
MDM
LmHosts
lanmanworkstation
lanmanserver
helpsvc
FastUserSwitchingCompatibility
EventSystem
Eventlog
ERSvc
Dnscache
dmserver
Dhcp
CryptSvc
Browser
AudioSrv
Ati HotKey Poller

This worm may search for shared folders on the internet with weak 
passwords and copy itself into them.

A text file named HOSTS may also be dropped into 
C:\\drivers\etc\ which may contain a list of 
anti-virus and other security-related websites each bound to the IP 
loopback address of 127.0.0.1 which would effectively prevent access to 
these sites. For example:

127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com

W32/Agobot-LI can sniff HTTP, VULN, ICMP, FTP and IRC network traffic 
and steal data from them.

The following vulnerabilities can also be exploited to aid propagation 
on unpatched systems and manipulate registry keys:

Remote Procedure Call (RPC) vulnerability.
Distributed Component Object Model (DCOM) vulnerability.
RPC Locator vulnerability.
IIS5/WEBDAV Buffer Overflow vulnerability.

For more information about these Windows vulnerabilities, please refer 
to the following Microsoft Security Bulletins:

Microsoft Security Bulletin MS03-001
Microsoft Security Bulletin MS03-007
Microsoft Security Bulletin MS03-039.

W32/Agobot-LI can also polymorph on installation in order to evade 
detection and share / delete the admin$, ipc$ etc drives.

It can also test the available bandwidth by attempting to GET or POST 
data to the following websites:

'yahoo.co.jp'
'www.nifty.com'
'www.d1asia.com'
'www.st.lib.keio.ac.jp'
'www.lib.nthu.edu.tw'
'www.above.net'
'www.level3.com'
'nitro.ucsc.edu'
'www.burst.net'
'www.cogentco.com'
'www.rit.edu'
'www.nocster.com'
'www.verio.com'
'www.stanford.edu'
'www.xo.net'
'de.yahoo.com'
'www.belwue.de'
'www.switch.ch'
'www.1und1.de'
'verio.fr'
'www.utwente.nl'
'www.schlund.net'

W32/Agobot-LI can also be used to initiate denial-of-service (DoS) and 
distributed denial-of-service (DDoS) synflood / httpflood / fraggle / 
smurf etc attacks against remote systems.

This worm can steal the Windows Product ID and keys from several 
computer applications or games including:

AOL Instant Messenger
Battlefield 1942
Battlefield 1942: Secret Weapons Of WWII
Battlefield 1942: The Road To Rome
Battlefield 1942: Vietnam
Black and White
Call of Duty
Command and Conquer: Generals
Command and Conquer: Generals: Zero Hour
Command and Conquer: Red Alert2
Command and Conquer: Tiberian Sun
Counter-Strike
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden and Dangerous 2
Industry Giant 2
IGI2: Covert Strike
James Bond 007: Nightfire
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
NHL 2002
NHL 2003
Need For Speed: Hot Pursuit 2
Need For Speed: Underground
Neverwinter Nights
Ravenshield
Shogun Total War - Warlord Edition
Soldiers Of Anarchy
Soldier of Fortune II - Double Helix
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004
Windows Messenger

W32/Agobot-LI may delete all files named 'sound*.*'.





W32/Agobot-JO

Aliases
WORM_AGOBOT.JO, W32.Gaobot.AFJ, Backdoor.Agobot.gen

Type
Win32 worm

Detection
At the time of writing, Sophos has received just one report of this worm 
from the wild.

Description
W32/Agobot-JO is a network worm with IRC and password stealing 
capabilities allowing complete remote control of the infected computer. 
The worm attempts to copy itself to the Windows system32 folder as 
soundcontrl.exe and sets the following registry keys to auto-start on 
user logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
soundcontrl = soundcontrl.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
soundcontrl = soundcontrl.exe

W32/Agobot-JO attempts to delete registry entries and files associated 
with other worms. The worm then modifies the HOSTS file to redirect 
AntiVirus and security related addresses to 127.0.0.1 thereby preventing 
access to these sites.





W32/Agobot-JI

Aliases
Gaobot, Nortonbot, Phatbot, Polybot.

Type
Win32 worm

Detection
At the time of writing, Sophos has received just one report of this worm 
from the wild.

Description
W32/Agobot-JI is an IRC backdoor Trojan and network worm which 
establishes an IRC channel to a remote server in order to grant an 
intruder access to the compromised computer.

This worm will move itself into the Windows System32 folder under the 
filename CSRSS32.EXE and may create the following registry entries so 
that it can execute automatically on system restart:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
System Log Event = csrss32.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
System Log Event = csrss32.exe

This worm may also attempt to glean email addresses from the Windows 
Address Book and send itself to these email addresses using its own SMTP 
engine with itself included as an executable attachment.

W32/Agobot-JI may attempt to terminate anti-virus and other 
security-related processes, in addition to other viruses, worms or 
Trojans. For example:

_AVPM
_AVPCC
_AVP32
ZONEALARM
ZONALM2601
ZATUTOR
ZAPSETUP3001
ZAPRO
XPF202EN
WYVERNWORKSFIREWALL
WUPDT
WUPDATER
WSBGATE
WRCTRL
WRADMIN
WNT
WNAD
WKUFIND
WINUPDATE
WINTSK32
WINSTART001
WINSTART
WINSSK32
WINSERVN
WINRECON
WINPPR32
WINNET
WINMAIN
WINLOGIN
WININITX
WININIT
WININETD
WINDOWS
WINDOW
WINACTIVE
WIN32US
WIN32
WIN-BUGSFIX
WIMMUN32
WHOSWATCHINGME
WGFE95
WFINDV32
WEBTRAP
WEBSCANX
WEBDAV
WATCHDOG
W9X
VSWINPERSE
VSWINNTSE
VSWIN9XE
VSSTAT
VSMON
VSMAIN
VSISETUP
VSHWIN32
VSECOMR
VSCHED
VSCENU6.02D30
VSCAN40
VPTRAY
VPFW30S
VPC42
VPC32
VNPC3000
VNLAN300
VIRUSMDPERSONALFIREWALL
VIR-HELP
VFSETUP
VETTRAY
VET95
W32DSM89
VET32
VCSETUP
VBWINNTW
VBWIN9X
VBUST
VBCONS
VBCMSERV
UTPOST
UPGRAD
UPDAT
UNDOBOOT
TVTMD
TVMD
TSADBOT
TROJANTRAP3
TRJSETUP
TRJSCAN
TRICKLER
TRACERT
TITANINXP
TITANIN
TGBOB
TFAK5
TFAK
TEEKIDS
TDS2-NT
TDS2-98
TDS-3
TCM
TCA
TC
TBSCAN
TAUMON
TASKMON
TASKMO
TASKMG
SYSUPD
SYSTEM32
SYSTEM
SYSEDIT
SYMTRAY
SYMPROXYSVC
SWEEPNET.SWEEPSRV.SYS.SWNETSUP
SWEEP95
SVSHOST
SVCHOSTS
SVCHOSTC
SVC
SUPPORTER5
SUPPORT
SUPFTRL
STCLOADER
START
ST2
SSGRATE
SS3EDIT
SRNG
SREXE
SPYXX
SPOOLSV32
SPOOLCV
SPOLER
SPHINX
SPF
SPERM
SOFI
SOAP
SMSS32
SMS
SMC
SHOWBEHIND
SHN
SHELLSPYINSTALL
SH
SGSSFW32
SFC
SETUP_FLOWPROTECTOR_US
UPDATE
SETUPVAMEEVAL
SERVLCES
SERVLCE
SERVICE
SERV95
SD
SCVHOST
SCRSVR
SCRSCAN
SCANPM
SCAN95
SCAN32
SCAM32
SC
SBSERV
SAVENOW
SAVE
SAHAGENT
SAFEWEB
RUXDLL32
RUNDLL16
RUNDLL
RUN32DLL
RULAUNCH
RTVSCN95
RTVSCAN
RSHELL
RRGUARD
RESCUE32
RESCUE
REGEDT32
REGEDIT
REGED
REALMON
RCSYNC
RB32
RAY
RAV8WIN32ENG
RAV7WIN
RAV7
RAPAPP
QSERVER
QCONSOLE
PVIEW95
PUSSY
PURGE
PSPF
PROTECTX
PROPORT
PROGRAMAUDITOR
PROCEXPLORERV1.0
PROCESSMONITOR
PROCDUMP
PRMVR
PRMT
PRIZESURFER
PPVSTOP
PPTBC
PPINUPDT
POWERSCAN
PORTMONITOR
PORTDETECTIVE
POPSCAN
POPROXY
POP3TRAP
PLATIN
PINGSCAN
PGMONITR
PFWADMIN
PF2
PERSWF
PERSFW
PERISCOPE
PENIS
PDSETUP
PCSCAN
PCFWALLICON
PCDSETUP
PCCWIN98
PCCWIN97
PCCNTMON
PCCIOMON
PAVW
PAVSCHED
PAVPROXY
PAVCL
PATCH
PANIXK
PADMIN
OUTPOSTPROINSTALL
OUTPOSTINSTALL
OTFIX
OSTRONET
OPTIMIZE
ONSRVR
NWTOOL16
NWSERVICE
NWINST4
NVSVC32
NVC95
NVARCH16
NUI
NTXconfig
NTVDM
NTRTSCAN
NT
NSUPDATE
NSTASK32
NSSYS32
NSCHED32
NPSSVC
NPSCHECK
NPROTECT
NPFMESSENGER
NPF40_TW_98_NT_ME_2K
NOTSTART
NORTON_INTERNET_SECU_3.0_407
NORMIST
NOD32M2
NOD32CC
NOD32
NMAIN
NISUM
NISSERV
NETUTILS
NETSTAT
NETSPYHUNTER-1.2
NETSCANPRO
NETMON
NETINFO
NETD32
NETARMOR
NEOWATCHLOG
NEOMONITOR
NDD32
NCINST4
NAVWNT
NAVW32
NAVSTUB
NAVNT
NAVLU32
NAVENGNAVEX15.NAVLU32
NAVDX
NAVAPW32
NAVAPSVC
NAVAP.NAVAPSVC
AUTO-PROTECT.NAV80TRY
NAV
N32SCANW
MWATCH
OLLYDBG
OUTPOST
NUPGRADE
MU0311AD
MSVXD
MSSYS
MSSMMC32
MSMSGRI32
MSMGT
MSLAUGH
MSINFO32
MSIEXEC16
MSDOS
MSDM
MSCONFIG
MSCMAN
MSCCN32
MSCACHE
MSBLAST
MSBB
MSAPP
MRFLUX
MPFTRAY
MPFSERVICE
MPFAGENT
MOSTAT
MOOLIVE
MONITOR
MMOD
MINILOG
MGUI
MGHTML
MGAVRTE
MGAVRTCL
MFWENG3.02D30
MFW2EN
MFIN32
MD
MCVSSHLD
MCVSRTE
MCTOOL
MCSHIELD
MCMNHDLR
MCAGENT
MAPISVC32
LUSPT
LUINIT
LUCOMSERVER
LUAU
LSETUP
LORDPE
LOOKOUT
LOCKDOWN2000
LOCKDOWN
LOCALNET
LNETINFO
LDSCAN
LDPROMENU
LDPRO
LDNETMON
LAUNCHER
KILLPROCESSSETUP161
KERNEL32
KERIO-WRP-421-EN-WIN
KERIO-WRL-421-EN-WIN
KERIO-PF-213-EN-WIN
KEENVALUE
KAZZA
KAVPF
KAVPERS40ENG
KAVLITE40ENG
JEDI
JDBGMRG
JAMMER
ISTSVC
ISRV95
LOADER
MCUPDATE
LUALL
ISASS
IRIS
IPARMOR
IOMON98
INTREN
INTDEL
INIT
INFWIN
INFUS
INETLNFO
IFW2000
IFACE
IEXPLORER
IEDRIVER
IEDLL
IDLE
ICSUPPNT
ICMON
ICLOADNT
ICLOAD95
IBMAVSP
IBMASN
IAMSTATS
IAMSERV
IAMAPP
HXIUL
HXDL
HWPE
HTPATCH
HTLOG
HOTPATCH
HOTACTIO
HBSRV
HBINST
HACKTRACERSETUP
GUARDDOG
GUARD
GMT
GENERICS
GBPOLL
GBMENU
GATOR
FSMB32
FSMA32
FSM32
FSGK32
FSAV95
FSAV530WTBYB
FSAV530STBYB
FSAV32
FSAV
FSAA
FRW
FPROT
FP-WIN_TRIAL
FP-WIN
FNRB32
FLOWPROTECTOR
FIREWALL
FINDVIRU
FIH32
FCH32
FAST
FAMEH32
F-STOPW
F-PROT95
F-PROT
F-AGNT95
EXPLORE
EXPERT
EXE.AVXW
EXANTIVIRUS-CNET
EVPN
ETRUSTCIPE
ETHEREAL
ESPWATCH
ESCANV95
ESCANHNT
ICSUPP95
ESCANH95
ESAFE
ENT
EMSW
EFPEADM
ECENGINE
DVP95_0
DVP95
DSSAGENT
DRWEBUPW
DRWEB32
DRWATSON
DPPS2
DPFSETUP
DPF
DOORS
DLLREG
DLLCACHE
DIVX
DEPUTY
DEFWATCH
DEFSCANGUI
DEFALERT
DCOMX
DATEMANAGER
Claw95
CWNTDWMO
CWNB181
CV
CTRL
CPFNT206
CPF9X206
CPD
CONNECTIONMONITOR
CMON016
CMGRDIAN
CMESYS
CMD32
CLICK
CLEANPC
CLEANER3
CLEANER
CLEAN
CFINET32
CFINET
CFIADMIN
CFGWIZ
CFD
CDP
CCPXYSVC
CCEVTMGR
CCAPP
BVT
BUNDLE
BS120
BRASIL
BPC
BORG2
BOOTWARN
BOOTCONF
BLSS
BLACKICE
BLACKD
BISP
BIPCPEVALSETUP
BIPCP
BIDSERVER
BIDEF
BELT
BEAGLE
BD_PROFESSIONAL
BARGAINS
BACKWEB
CLAW95CF
CFIAUDIT
AVXQUAR
AVXMONITORNT
AVXMONITOR9X
AVWUPSRV
AVWUPD
AVWINNT
AVWIN95
AVSYNMGR
AVSCHED32
AVPTC32
AVPM
AVPDOS32
AVPCC
AVP32
AVP
AVNT
AVLTMAIN
AVKWCTl9
AVKSERVICE
AVKSERV
AVKPOP
AVGW
AVGUARD
AVGSERV9
AVGSERV
AVGNT
AVGCTRL
AVGCC32
AVE32
AVCONSOL
AU
ATWATCH
ATRO55EN
ATGUARD
ATCON
ARR
APVXDWIN
APLICA32
APIMONITOR
ANTS
ANTIVIRUS
ANTI-TROJAN
AMON
AMON9X
ALOGSERV
ALEVIR
ALERTSVC
AGENTW
AGENTSVR
ADVXDWIN
ADAWARE
ACKWIN32
AVWUPD32
AVPUPD
AUTOUPDATE
AUTOTRACE
AUTODOWN
AUPDATE
ATUPDATER

This worm may search for shared folders on the internet with weak 
passwords and copy itself into them.

A text file named HOSTS may also be dropped into C:\\drivers\etc\ which 
may contain a list of anti-virus and other security-related websites 
each bound to the IP loopback address of 127.0.0.1 which would 
effectively prevent access to these sites.
For example:

127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com
127.0.0.1 www.grisoft.com

W32/Agobot-JI can sniff HTTP, VULN, ICMP, FTP and IRC network traffic 
and steal data from them.

The following vulnerabilities can also be exploited to aid propagation 
on unpatched systems and manipulate registry keys:

Remote Procedure Call (RPC) vulnerability.
Distributed Component Object Model (DCOM) vulnerability.
RPC Locator vulnerability.
IIS5/WEBDAV Buffer Overflow vulnerability.

For more information about these Windows vulnerabilities, please refer 
to the following Microsoft Security Bulletins:

Microsoft Security Bulletin MS03-001
Microsoft Security Bulletin MS03-007
Microsoft Security Bulletin MS03-039.

W32/Agobot-JI can also polymorph on installation in order to evade 
detection and share / delete the admin$, ipc$ etc drives.

It can also test the available bandwidth by attempting to GET or POST 
data to the following websites:

'www.ryan1918.net'
'www.ryan1918.org'
'www.ryan1918.com'
'yahoo.co.jp'
'www.nifty.com'
'www.d1asia.com'
'www.st.lib.keio.ac.jp'
'www.lib.nthu.edu.tw'
'www.above.net'
'www.level3.com'
'nitro.ucsc.edu'
'www.burst.net'
'www.cogentco.com'
'www.rit.edu'
'www.nocster.com'
'www.verio.com'
'www.stanford.edu'
'www.xo.net'
'de.yahoo.com'
'www.belwue.de'
'www.switch.ch'
'www.1und1.de'
'verio.fr'
'www.utwente.nl'
'www.schlund.net'

W32/Agobot-JI can also be used to initiate denial-of-service (DoS) and 
distributed denial-of-service (DDoS) synflood / httpflood / fraggle / 
smurf etc attacks against remote systems.

This worm can steal the Windows Product ID and keys from several 
computer applications or games including:

AOL Instant Messenger
Battlefield 1942
Battlefield 1942: Secret Weapons Of WWII
Battlefield 1942: The Road To Rome
Battlefield 1942: Vietnam
Black and White
Call of Duty
Chrome
Command and Conquer: Generals
Command and Conquer: Generals: Zero Hour
Command and Conquer: Red Alert2
Command and Conquer: Tiberian Sun
Counter-Strike
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden and Dangerous 2
Industry Giant 2
IGI2: Covert Strike
James Bond 007: Nightfire
Legends of Might and Magic
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
NHL 2002
NHL 2003
Need For Speed: Hot Pursuit 2
Need For Speed: Underground
Neverwinter Nights
Ravenshield
Shogun Total War - Warlord Edition
Soldiers Of Anarchy
Soldier of Fortune II - Double Helix
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004
Windows Messenger

W32/Agobot-JI will delete the files CSRSS.EXE and CSRSRV.DLL from the 
Windows System32 folder (if they exist) upon execution.





W32/Agobot-IJ

Aliases
Backdoor.Agobot.gen, W32/Gaobot.worm.gen.e, W32.HLLW.Gaobot.gen, 
WORM_AGOBOT.NO

Type
Win32 worm

Detection
At the time of writing, Sophos has received just one report of this worm 
from the wild.

Description
W32/Agobot-IJ is a member of the W32/Agobot family of network worms and 
backdoors for the Windows platform.

W32/Agobot-IJ allows a malicious user remote access to an infected 
computer via IRC. The worm creates a copy of itself named explore.exe in 
the Windows system folder.

In order to run automatically when Windows starts up W32/Agobot-IJ 
creates the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\10Base-T
=explore.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\10Base-T
=explore.exe.

W32/Agobot-IJ spreads to Windows computers with weak share passwords.

The worm attempts to terminate the following processes:

F-AGOBOT.EXE
HIJACKTHIS.EXE
_AVPM.EXE
_AVPCC.EXE
_AVP32.EXE
ZONEALARM.EXE
ZONALM2601.EXE
ZATUTOR.EXE
ZAPSETUP3001.EXE
ZAPRO.EXE
XPF202EN.EXE
WYVERNWORKSFIREWALL.EXE
WUPDT.EXE
WUPDATER.EXE
WSBGATE.EXE
WRCTRL.EXE
WRADMIN.EXE
WNT.EXE
WNAD.EXE
WKUFIND.EXE
WINUPDATE.EXE
WINTSK32.EXE
WINSTART001.EXE
WINSTART.EXE
WINSSK32.EXE
WINSERVN.EXE
WINRECON.EXE
WINPPR32.EXE
WINNET.EXE
WINMAIN.EXE
WINLOGIN.EXE
WININITX.EXE
WININIT.EXE
WININETD.EXE
WINDOWS.EXE
WINDOW.EXE
WINACTIVE.EXE
WIN32US.EXE
WIN32.EXE
WIN-BUGSFIX.EXE
WIMMUN32.EXE
WHOSWATCHINGME.EXE
WGFE95.EXE
WFINDV32.EXE
WEBTRAP.EXE
WEBSCANX.EXE
WEBDAV.EXE
WATCHDOG.EXE
W9X.EXE
W32DSM89.EXE
VSWINPERSE.EXE
VSWINNTSE.EXE
VSWIN9XE.EXE
VSSTAT.EXE
VSMON.EXE
VSMAIN.EXE
VSISETUP.EXE
VSHWIN32.EXE
VSECOMR.EXE
VSCHED.EXE
VSCENU6.02D30.EXE
VSCAN40.EXE
VPTRAY.EXE
VPFW30S.EXE
VPC42.EXE
VPC32.EXE
VNPC3000.EXE
VNLAN300.EXE
VIRUSMDPERSONALFIREWALL.EXE
VIR-HELP.EXE
VFSETUP.EXE
VETTRAY.EXE
VET95.EXE
VET32.EXE
VCSETUP.EXE
VBWINNTW.EXE
VBWIN9X.EXE
VBUST.EXE
VBCONS.EXE
VBCMSERV.EXE
UTPOST.EXE
UPGRAD.EXE
UPDAT.EXE
UNDOBOOT.EXE
TVTMD.EXE
TVMD.EXE
TSADBOT.EXE
TROJANTRAP3.EXE
TRJSETUP.EXE
TRJSCAN.EXE
TRICKLER.EXE
TRACERT.EXE
TITANINXP.EXE
TITANIN.EXE
TGBOB.EXE
TFAK5.EXE
TFAK.EXE
TEEKIDS.EXE
TDS2-NT.EXE
TDS2-98.EXE
TDS-3.EXE
TCM.EXE
TCA.EXE
TC.EXE
TBSCAN.EXE
TAUMON.EXE
TASKMON.EXE
TASKMO.EXE
TASKMG.EXE
SYSUPD.EXE
SYSTEM32.EXE
SYSTEM.EXE
SYSEDIT.EXE
SYMTRAY.EXE
SYMPROXYSVC.EXE
SWEEPNET.SWEEPSRV.SYS.SWNETSUP.EXE
SWEEP95.EXE
SVSHOST.EXE
SVCHOSTS.EXE
SVCHOSTC.EXE
SVC.EXE
SUPPORTER5.EXE
SUPPORT.EXE
SUPFTRL.EXE
STCLOADER.EXE
START.EXE
ST2.EXE
SSG_4104.EXE
SSGRATE.EXE
SS3EDIT.EXE
SRNG.EXE
SREXE.EXE
SPYXX.EXE
SPOOLSV32.EXE
SPOOLCV.EXE
SPOLER.EXE
SPHINX.EXE
SPF.EXE
SPERM.EXE
SOFI.EXE
SOAP.EXE
SMSS32.EXE
SMS.EXE
SMC.EXE
SHOWBEHIND.EXE
SHN.EXE
UPDATE.EXE
SHELLSPYINSTALL.EXE
SH.EXE
SGSSFW32.EXE
SFC.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SERVLCES.EXE
SERVLCE.EXE
SERVICE.EXE
SERV95.EXE
SD.EXE
SCVHOST.EXE
SCRSVR.EXE
SCRSCAN.EXE
SCANPM.EXE
SCAN95.EXE
SCAN32.EXE
SCAM32.EXE
SC.EXE
SBSERV.EXE
SAVENOW.EXE
SAVE.EXE
SAHAGENT.EXE
SAFEWEB.EXE
RUXDLL32.EXE
RUNDLL16.EXE
RUNDLL.EXE
RUN32DLL.EXE
RULAUNCH.EXE
RTVSCN95.EXE
RTVSCAN.EXE
RSHELL.EXE
RRGUARD.EXE
RESCUE32.EXE
RESCUE.EXE
REGEDT32.EXE
REGEDIT.EXE
REGED.EXE
REALMON.EXE
RCSYNC.EXE
RB32.EXE
RAY.EXE
RAV8WIN32ENG.EXE
RAV7WIN.EXE
RAV7.EXE
RAPAPP.EXE
QSERVER.EXE
QCONSOLE.EXE
PVIEW95.EXE
PUSSY.EXE
PURGE.EXE
PSPF.EXE
PROTECTX.EXE
PROPORT.EXE
PROGRAMAUDITOR.EXE
PROCEXPLORERV1.0.EXE
PROCESSMONITOR.EXE
PROCDUMP.EXE
PRMVR.EXE
PRMT.EXE
PRIZESURFER.EXE
PPVSTOP.EXE
PPTBC.EXE
PPINUPDT.EXE
POWERSCAN.EXE
PORTMONITOR.EXE
PORTDETECTIVE.EXE
POPSCAN.EXE
POPROXY.EXE
POP3TRAP.EXE
PLATIN.EXE
PINGSCAN.EXE
PGMONITR.EXE
PFWADMIN.EXE
PF2.EXE
PERSWF.EXE
PERSFW.EXE
PERISCOPE.EXE
PENIS.EXE
PDSETUP.EXE
PCSCAN.EXE
PCIP10117_0.EXE
PCFWALLICON.EXE
PCDSETUP.EXE
PCCWIN98.EXE
PCCWIN97.EXE
PCCNTMON.EXE
PCCIOMON.EXE
PCC2K_76_1436.EXE
PCC2002S902.EXE
PAVW.EXE
PAVSCHED.EXE
PAVPROXY.EXE
PAVCL.EXE
PATCH.EXE
PANIXK.EXE
PADMIN.EXE
OUTPOSTPROINSTALL.EXE
OUTPOSTINSTALL.EXE
OTFIX.EXE
OSTRONET.EXE
OPTIMIZE.EXE
ONSRVR.EXE
OLLYDBG.EXE
NWTOOL16.EXE
NWSERVICE.EXE
NWINST4.EXE
NVSVC32.EXE
NVC95.EXE
NVARCH16.EXE
NUI.EXE
NTXconfig.EXE
NTVDM.EXE
NTRTSCAN.EXE
NT.EXE
NSUPDATE.EXE
NSTASK32.EXE
NSSYS32.EXE
NSCHED32.EXE
NPSSVC.EXE
NPSCHECK.EXE
NPROTECT.EXE
NPFMESSENGER.EXE
NPF40_TW_98_NT_ME_2K.EXE
NOTSTART.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NORMIST.EXE
NOD32.EXE
NMAIN.EXE
NISUM.EXE
NISSERV.EXE
NETUTILS.EXE
NETSTAT.EXE
NETSPYHUNTER-1.2.EXE
NETSCANPRO.EXE
NETMON.EXE
NETINFO.EXE
NETD32.EXE
NETARMOR.EXE
NEOWATCHLOG.EXE
NEOMONITOR.EXE
NDD32.EXE
NCINST4.EXE
NC2000.EXE
NAVWNT.EXE
NAVW32.EXE
NAVSTUB.EXE
NAVNT.EXE
NAVLU32.EXE
NAVENGNAVEX15.NAVLU32.EXE
NAVDX.EXE
NAVAPW32.EXE
NAVAPSVC.EXE
NAVAP.NAVAPSVC.EXE
AUTO-PROTECT.NAV80TRY.EXE
NAV.EXE
OUTPOST.EXE
NUPGRADE.EXE
N32SCANW.EXE
MWATCH.EXE
MU0311AD.EXE
MSVXD.EXE
MSSYS.EXE
MSSMMC32.EXE
MSMSGRI32.EXE
MSMGT.EXE
MSLAUGH.EXE
MSINFO32.EXE
MSIEXEC16.EXE
MSDOS.EXE
MSDM.EXE
MSCONFIG.EXE
MSCMAN.EXE
MSCCN32.EXE
MSCACHE.EXE
MSBLAST.EXE
MSBB.EXE
MSAPP.EXE
MRFLUX.EXE
MPFTRAY.EXE
MPFSERVICE.EXE
MPFAGENT.EXE
MOSTAT.EXE
MOOLIVE.EXE
MONITOR.EXE
MMOD.EXE
MINILOG.EXE
MGUI.EXE
MGHTML.EXE
MGAVRTE.EXE
MGAVRTCL.EXE
MFWENG3.02D30.EXE
MFW2EN.EXE
MFIN32.EXE
MD.EXE
MCVSSHLD.EXE
MCVSRTE.EXE
MCTOOL.EXE
MCSHIELD.EXE
MCMNHDLR.EXE
MCAGENT.EXE
MAPISVC32.EXE
LUSPT.EXE
LUINIT.EXE
LUCOMSERVER.EXE
LUAU.EXE
LSETUP.EXE
LORDPE.EXE
LOOKOUT.EXE
LOCKDOWN2000.EXE
LOCKDOWN.EXE
LOCALNET.EXE
LOADER.EXE
LNETINFO.EXE
LDSCAN.EXE
LDPROMENU.EXE
LDPRO.EXE
LDNETMON.EXE
LAUNCHER.EXE
KILLPROCESSSETUP161.EXE
KERNEL32.EXE
KERIO-WRP-421-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-PF-213-EN-WIN.EXE
KEENVALUE.EXE
KAZZA.EXE
KAVPF.EXE
KAVPERS40ENG.EXE
KAVLITE40ENG.EXE
JEDI.EXE
JDBGMRG.EXE
JAMMER.EXE
ISTSVC.EXE
MCUPDATE.EXE
LUALL.EXE
ISRV95.EXE
ISASS.EXE
IRIS.EXE
IPARMOR.EXE
IOMON98.EXE
INTREN.EXE
INTDEL.EXE
INIT.EXE
INFWIN.EXE
INFUS.EXE
INETLNFO.EXE
IFW2000.EXE
IFACE.EXE
IEXPLORER.EXE
IEDRIVER.EXE
IEDLL.EXE
IDLE.EXE
ICSUPPNT.EXE
ICMON.EXE
ICLOADNT.EXE
ICLOAD95.EXE
IBMAVSP.EXE
IBMASN.EXE
IAMSTATS.EXE
IAMSERV.EXE
IAMAPP.EXE
HXIUL.EXE
HXDL.EXE
HWPE.EXE
HTPATCH.EXE
HTLOG.EXE
HOTPATCH.EXE
HOTACTIO.EXE
HBSRV.EXE
HBINST.EXE
HACKTRACERSETUP.EXE
GUARDDOG.EXE
GUARD.EXE
GMT.EXE
GENERICS.EXE
GBPOLL.EXE
GBMENU.EXE
GATOR.EXE
FSMB32.EXE
FSMA32.EXE
FSM32.EXE
FSGK32.EXE
FSAV95.EXE
FSAV530WTBYB.EXE
FSAV530STBYB.EXE
FSAV32.EXE
FSAV.EXE
FSAA.EXE
FRW.EXE
FPROT.EXE
FP-WIN_TRIAL.EXE
FP-WIN.EXE
FNRB32.EXE
FLOWPROTECTOR.EXE
FIREWALL.EXE
FINDVIRU.EXE
FIH32.EXE
FCH32.EXE
FAST.EXE
FAMEH32.EXE
F-STOPW.EXE
F-PROT95.EXE
F-PROT.EXE
F-AGNT95.EXE
EXPLORE.EXE
EXPERT.EXE
EXE.AVXW.EXE
EXANTIVIRUS-CNET.EXE
EVPN.EXE
ETRUSTCIPE.EXE
ETHEREAL.EXE
ESPWATCH.EXE
ESCANV95.EXE
ICSUPP95.EXE
ESCANHNT.EXE
ESCANH95.EXE
ESAFE.EXE
ENT.EXE
EMSW.EXE
EFPEADM.EXE
ECENGINE.EXE
DVP95_0.EXE
DVP95.EXE
DSSAGENT.EXE
DRWEBUPW.EXE
DRWEB32.EXE
DRWATSON.EXE
DPPS2.EXE
DPFSETUP.EXE
DPF.EXE
DOORS.EXE
DLLREG.EXE
DLLCACHE.EXE
DIVX.EXE
DEPUTY.EXE
DEFWATCH.EXE
DEFSCANGUI.EXE
DEFALERT.EXE
DCOMX.EXE
DATEMANAGER.EXE
Claw95.EXE
CWNTDWMO.EXE
CWNB181.EXE
CV.EXE
CTRL.EXE
CPFNT206.EXE
CPF9X206.EXE
CPD.EXE
CONNECTIONMONITOR.EXE
CMON016.EXE
CMGRDIAN.EXE
CMESYS.EXE
CMD32.EXE
CLICK.EXE
CLEANPC.EXE
CLEANER3.EXE
CLEANER.EXE
CLEAN.EXE
CFINET32.EXE
CFINET.EXE
CFIADMIN.EXE
CFGWIZ.EXE
CFD.EXE
CDP.EXE
CCPXYSVC.EXE
CCEVTMGR.EXE
CCAPP.EXE
BVT.EXE
BUNDLE.EXE
BS120.EXE
BRASIL.EXE
BPC.EXE
BORG2.EXE
BOOTWARN.EXE
BOOTCONF.EXE
BLSS.EXE
BLACKICE.EXE
BLACKD.EXE
BISP.EXE
BIPCPEVALSETUP.EXE
BIPCP.EXE
BIDSERVER.EXE
BIDEF.EXE
BELT.EXE
BEAGLE.EXE
BD_PROFESSIONAL.EXE
BARGAINS.EXE
BACKWEB.EXE
CLAW95CF.EXE
CFIAUDIT.EXE
AVXMONITORNT.EXE
AVXMONITOR9X.EXE
AVWUPSRV.EXE
AVWUPD.EXE
AVWINNT.EXE
AVWIN95.EXE
AVSYNMGR.EXE
AVSCHED32.EXE
AVPTC32.EXE
AVPM.EXE
AVPDOS32.EXE
AVPCC.EXE
AVP32.EXE
AVP.EXE
AVNT.EXE
AVLTMAIN.EXE
AVKWCTl9.EXE
AVKSERVICE.EXE
AVKSERV.EXE
AVKPOP.EXE
AVGW.EXE
AVGUARD.EXE
AVGSERV9.EXE
AVGSERV.EXE
AVGNT.EXE
AVGCTRL.EXE
AVGCC32.EXE
AVE32.EXE
AVCONSOL.EXE
AU.EXE
ATWATCH.EXE
ATRO55EN.EXE
ATGUARD.EXE
ATCON.EXE
ARR.EXE
APVXDWIN.EXE
APLICA32.EXE
APIMONITOR.EXE
ANTS.EXE
ANTIVIRUS.EXE
ANTI-TROJAN.EXE
AMON9X.EXE
ALOGSERV.EXE
ALEVIR.EXE
ALERTSVC.EXE
AGENTW.EXE
AGENTSVR.EXE
ADVXDWIN.EXE
ADAWARE.EXE
AVXQUAR.EXE
ACKWIN32.EXE
AVWUPD32.EXE
AVPUPD.EXE
AUTOUPDATE.EXE
AUTOTRACE.EXE
AUTODOWN.EXE
AUPDATE.EXE
ATUPDATER.EXE





Troj/StartPa-AE

Aliases
Trojan.WinREG.StartPage

Type
Trojan

Detection
At the time of writing, Sophos has received just one report of this 
Trojan from the wild.

Description
Troj/StartPa-AE changes browser settings for Microsoft Internet Explorer 
each time Windows is started.

Troj/StartPa-AE is simply a text file (typically named sysdll.reg) which 
can be used as an input to Regedit to set the following registry 
entries:

HKCU\Software\Microsoft\Internet Explorer\Main\Start Page
HKCU\Software\Microsoft\Internet Explorer\Main\HOMEOldSP
HKCU\Software\Microsoft\Internet Explorer\Main\Search Bar
HKCU\Software\Microsoft\Internet Explorer\Main\Search Page
HKCU\Software\Microsoft\Internet Explorer\Search\SearchAssistant
HKLM\Software\Microsoft\Internet Explorer\Main\Start Page
HKLM\Software\Microsoft\Internet Explorer\Main\HOMEOldSP
HKLM\Software\Microsoft\Internet Explorer\Main\Search Bar
HKLM\Software\Microsoft\Internet Explorer\Main\Search Page
HKLM\Software\Microsoft\Internet Explorer\Search\SearchAssistant

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
sys = "regedit -s sysdll.reg"

The last of these registry entries causes the registry to be updated 
using Troj/StartPa-AE each time Windows is started.

Troj/StartPa-AE may be installed on the computer by Troj/AdClick-AE.





Troj/Adtoda-A

Type
Trojan

Detection
At the time of writing, Sophos has received just one report of this 
Trojan from the wild.

Description
Troj/Adtoda-A is a backdoor Trojan.

When first run, Troj/Adtoda-A will display the following two messages:

"Setup was not able to continue the installation.
An illegal copy of Windows Operating System was detected on this 
computer. The computer informations is already collect and will be post 
as this computer name: (name of machine)"

"The operating system will not work properly before you get a permission 
after you complete the penalty! For any detail informations, Please 
contact the following link:
http:\\www.microsoft.com\~msproduct\~watch\~piracy10\secureID=OS_wiNver_532Fg32_ap12nt04A"

After the user clicks "OK" on both of these messages, Troj/Adtoda-A 
installs itself and activates the payload. This inverts the screen and 
freezes the machine so that is needs to be rebooted.

In order to run automatically when Windows starts up the Trojan creates 
the file C:\Windows\system\winupd32.exe and the shortcut
C:\Windows\Start Menu\Programs\StartUp\System Update Service.lnk 
pointing to it.

These files will cause the payload to be run again on system boot.

Troj/Adtoda-A also attempts to modify C:\boot.ini to prevent debugging.

 
--- MultiMail/Win32 v0.43
* Origin: Try Our Web Based QWK: DOCSPLACE.ORG (1:123/140)
SEEN-BY: 633/267 270
@PATH: 123/140 500 106/2000 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.