Pages

Showing posts with label Worm Internet. Show all posts
Showing posts with label Worm Internet. Show all posts

Tuesday, November 17, 2009

Virus Sasser - Worm


The first version of worm struck on April 30, 2004. The worm’s three modified versions have followed it since then, known as Sasser.B, Sasser.C and Sasser.D. The companies affected by the worm included the Agence France-Presse (AFP), Delta Air Lines, Nordic insurance company If and their Finnish owners Sampo Bank.

Another worm to exploit a Windows flaw, 'Sasser' led to several computers crashing and rebooting themselves.

Sunday, November 8, 2009

Storm worm - Botnet Worm

Another big Trojan attack was Storm worm that hit computers worldwide in January 2007. The Storm worm originally posed as breaking news of bad weather hitting Europe. Over time, the worm was also seen in emails with the following subjects: personal greetings, reports that Saddam Hussein is still alive, reports that Fidel Castro is dead, sexy women, YouTube, and even blogs.

Users who fell for it unknowingly became a part of a botnet. A botnet serves as an army of commandeered computers, which are later used by attackers without their owners' knowledge.

Friday, November 6, 2009

W32/Autorun.worm.gen - Virus Generic Worm

This detection is for a worm that attempts to copy itself to the root of any accessible disk volumes.
Additionally it attempts to place an Autorun.inf file on the root of the volume so that it is executed the next time the volume is mounted.

Aliases
Worm.Win32.AutoRun.dve (Kaspersky)
Worm/Autorun.dve (AntiVir)

Characteristics


This detection is for a worm.
It attempts to spread to removable drives by creating an autorun.inf file, which will run the worm automatically, if a systems which use the removable drive are set to Autorun.

Win32/Conficker.A - Worm Conficker

Win32/Conficker.A is a worm that spreads by exploiting a vulnerability in Server Service . The file is run-time compressed using UPX .

Installation
When executed, the worm copies itself in the %system% folder using the following name:
%variable%.dll
A string with variable content is used instead of %variable% .

The library %variable%.dll is loaded and injected into the following process:
services.exe

The worm registers itself as a system service using the following filename:
netsvcs

Wednesday, November 4, 2009

Win32/Zafi.B - Email Worm

Win32/Zafi.B (Other names: W32.Erkez.B) is a worm spreading via e-mail and P2P networks. It runs on Windows 95 and higher versions. Its size is 12800 bytes compressed by the FSG utility. After its decompression its size is 49 kB.

Note: In following text a symbolic inscription %windir% is used instead of the name of directory in which Windows operating system is installed. Of course, this may differ from installation to installation. The subdirectory System or System32 placed in %windir% has a name %system%.

The worm arrives in an e-mail message with randomly selected subject line and body from the pre-defined subject lines and bodies specified in the worm code. The text in the subject line might be for example:

eIngyen SMS!

And the message body:

Win32/NetSky.Q - Worm Internet

Win32/NetSky.Q is an internet worm spreading via e-mail messages, P2P networks or shared network drives. Use ESET NOD32 Antivirus to protect your computer

Note: In following text a symbolic inscription %windir% is used instead of the name of directory in which Windows operating system is installed. Of course, this may differ from installation to installation. The subdirectory System or System32 placed in %windir% has a name %system%

The worm is in an executable that is nearly 29 kiobytes long. Upon execution it copies itself into the %windir% directory using the name "FVProtect.exe".
It also creates a file called "userconfig9x.dll", that is 26 kB long. This dynamic library file is then executed.

In order to be run every time the Windows starts, the worm creates Registry entry called "Norton Antivirus AV" in the following key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

The new entry contains the path to "FVProtect.exe".