Help - Search - Members - Calendar
Full Version: PE386 system32:lzx32.sys Rootkit Hijack - 81.177.15.226
B.I.S.S. Forums > Malware Research Forum > Malware IP Research Section
Moore
========================================

Remember - dont try this at home !

Don't be stupid and run this on your real system , I am testing this in a virtual PC.

SSM [ free version ] did not block the alternate data stream service being added and the rootkit will totally bypass your firewall once it has loaded , if it gets the chance.

The files dropped into the system in this hijack will be different for each new visit to the server.

-------------------------------------------------------------------------


Well this one was interesting.. total firewall bypass and nothing I used [ blacklight , gmer , etc ] could detect the lzx32.sys rootkit first time around except for SSM [ free] , which just popped up to say the service was just added. It did not block it though , even after denying the service the second time around.

p386 - C:\Windows\system32:lzx32.sys -
display name - Win23 lzx files loader


So I clicked on allow service in SSM to see what happened next.. biggrin.gif

In round 2 I denied it and was able to detect it with a few different things.

Processguard option to block driver/service is not available in the free version so that was useless. Well it could have blocked everything via execution protection to begin with but where's the fun in that. tongue.gif

PG free was set to prevent modification of files to limit the severity of the hijack though , no hijack files had access to physical memory.






----------------------------------------------------------------------------------------------------

I did allow the infection of the system to a degree, allowing many Outpost 4.0 [ out soon ! cool.gif ] Anti-leak prompts of a few associated malware files to access DNS API requests before the rootkit could even load up... after that though ..

http://www.symantec.com/security_response/...-99&tabid=2

QUOTE
7: Alters the correct functioning of the following system modules used for network communications to bypass firewalls and to perform network packet manipulations :

tcpip.sys
wanarp.ss
ndis.sys


--
------------------------------------------------------------------------
---------------------------------

August 6th : round 1 -

---------------------------------

Started here -> zdfttygzjm.biz - 81.177.15.226

http://whois.domaintools.com/zdfttygzjm.biz

Domain Name: ZDFTTYGZJM.BIZ
Domain ID: D13755256-BIZ
Sponsoring Registrar: ESTDOMAINS INC
Sponsoring Registrar IANA ID: 832
Domain Status: clientTransferProhibited
Registrant ID: DI_3197285
Registrant Name: Luke Clark
Registrant Organization: N/A
Registrant Address1: West 1000 North
Registrant City: Rexburg
Registrant State/Province: Idaho
Registrant Postal Code: 83440
Registrant Country: United States
Registrant Country Code: US
Registrant Phone Number: +001.2083501141
Registrant Email: zdfttygzjm.mail.ru
Name Server: NS1.ZDFTTYGZJM.BIZ
Name Server: NS2.ZDFTTYGZJM.BIZ
Created by Registrar: ESTDOMAINS INC
Last Updated by Registrar: ESTDOMAINS INC
Domain Registration Date: Mon Jun 19 20:28:21 GMT 2006
Domain Expiration Date: Mon Jun 18 23:59:59 GMT 2007
Domain Last Updated Date: Wed Jul 26 11:48:59 GMT 2006

--


zhmbscwdgk.biz = [ 81.177.15.226 ]
Domain Name: ZHMBSCWDGK.BIZ
Domain ID: D13770072-BIZ
Sponsoring Registrar: ESTDOMAINS INC
Sponsoring Registrar IANA ID: 832
Domain Status: clientTransferProhibited
Registrant ID: DI_3206151
Registrant Name: Bill Passmore
Registrant Organization: N/A
Registrant Address1: Oak Creek Drive
Registrant City: Austin
Registrant State/Province: Texas
Registrant Postal Code: 78727
Registrant Country: United States
Registrant Country Code: US
Registrant Phone Number: 001.5122445985
Registrant Email: zhmbscwdgk@mail.ru
Name Server: NS1.ZDFTTYGZJM.BIZ
Name Server: NS2.ZDFTTYGZJM.BIZ
Created by Registrar: ESTDOMAINS INC
Last Updated by Registrar: ESTDOMAINS INC
Domain Registration Date: Mon Jun 19 20: 28: 21 GMT 2006
Domain Expiration Date: Mon Jun 18 23: 59: 59 GMT 2007
Domain Last Updated Date: Wed Jul 26 11: 48: 59 GMT 2006


========================================

- Full IP / Domain log -

========================================

There's some really weird places these guys wanted to visit .. blink.gif

CODE
http://zdfttygzjm.biz/dl/adv596.php
http://zdfttygzjm.biz/dl/xpladv596.wmf
http://zdfttygzjm.biz/dl/fillmemadv596.htm
http://zdfttygzjm.biz/dl/loaderadv596.jar
http://zdfttygzjm.biz/dl/java.jar
http://zdfttygzjm.biz/dl/loaderadv596_4.exe
http://zdfttygzjm.biz/dl/loaderadv596_2.exe
http://zdfttygzjm.biz/dl/fillmemadv596.htm
http://zdfttygzjm.biz/dl/fillmemadv596.htm
http://zdfttygzjm.biz/dl/fillmemadv596.htm
http://zdfttygzjm.biz/dl/fillmemadv596.htm
http://zdfttygzjm.biz/dl/fillmemadv596.htm
http://zdfttygzjm.biz/dl/fillmemadv596.htm
http://zdfttygzjm.biz/dl/fillmemadv596.htm
http://zdfttygzjm.biz/dl/bag.htm
http://zdfttygzjm.biz/dl/loaderadv596_3.exe
http://zdfttygzjm.biz/dl/cheat.php?adv=adv596
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qigzwt.php?adv=adv596
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qlgmvcyid
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qigzwt.php?adv=adv596
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qlgmvcyid
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qlgmvcyid
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qlgmvcyid
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qlgmvcyid
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qlgmvcyid
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qlgmvcyid
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qlgmvcyid
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/nzkqatdwi
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qlgmvcyid
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/nzkqatdwi
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qlgmvcyid
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/nzkqatdwi
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/nzkqatdwi
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/nzkqatdwi
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/nzkqatdwi
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/nzkqatdwi
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lpokhrbxq.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/nzkqatdwi
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/nzkqatdwi
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lpokhrbxq.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/nzkqatdwi
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lpokhrbxq.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lpokhrbxq.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lpokhrbxq.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lpokhrbxq.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lpokhrbxq.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lpokhrbxq.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/ypourx
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lpokhrbxq.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lpokhrbxq.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uzbhebyhnx.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uzbhebyhnx.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uzbhebyhnx.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uzbhebyhnx.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uzbhebyhnx.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uzbhebyhnx.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uzbhebyhnx.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uzbhebyhnx.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uzbhebyhnx.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uzbhebyhnx.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/vvlebhq
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/vvlebhq
http://ftp.icq.com/pub/ICQ_Win95_98_NT4/ICQ_5/icq5_setup.exe
http://www.google.com/search?hl=en&q=love%2Bprocessor
http://www.cooking.com/products/shprodde.asp?SKU=456000
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/vvlebhq
http://www.google.com/search?hl=en&q=politic%2Bpolitic%2Blaser
http://www.plastic.com/article.html;sid=04/08/26/05363198
http://208.66.194.14/banner/index.php
http://208.66.194.14/banner/index.php
http://www.google.com/search?hl=en&q=news%2Blove
http://www.zdaily.com/
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/vvlebhq
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/vvlebhq
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/vvlebhq
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/vvlebhq
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/vvlebhq
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/vvlebhq
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/vvlebhq
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/emsyio.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/emsyio.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/emsyio.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/emsyio.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/emsyio.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/emsyio.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/emsyio.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/emsyio.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/emsyio.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/emsyio.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uvkdwt.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uvkdwt.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/wodjczjtzs.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/wodjczjtzs.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/mqcie.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/mqcie.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/hybhext
http://zhmbscwdgk.biz/uniq.php
http://208.66.194.14/banner/index.php
http://www.google.com/search?hl=en&q=soft%2Benter%2Bprocessor
http://www.elecdesign.com/Articles/ArticleID/6972/6972.html
http://208.66.194.14/banner/index.php
http://www.google.com/search?hl=en&q=stuff%2Bgames
http://www.ebaumsworld.com/
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lldnxgd.php?exp=3&adv=adv596&code1=LRL0&code2=3505
http://zhmbscwdgk.biz/uniq.php
http://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lldnxgd.php?exp=2&adv=adv596&code1=LRL0&code2=3505
http://www.google.com/search?hl=en&q=disk%2Benter%2Bprocessor
http://pearpc.sourceforge.net/getstart.html
http://www.google.com/search?hl=en&q=free
http://www.free-counters.co.uk/
http://208.66.194.14/banner/index.php
http://www.google.com/search?hl=en&q=data%2Bdisk%2Bprocessor
http://72.14.203.104/search?q=cache:x00NsjJIbtUJ:www.macnn.com/news.php%2Bdata%2Bdisk%2Bprocessor&hl=en&ct=clnk&cd=10
http://www.google.com/search?hl=en&q=enter
http://www.enter.net/
http://208.66.194.14/banner/index.php
http://www.google.com/search?hl=en&q=crack
http://crackspider.net/
http://www.google.com/search?hl=en&q=download
http://www.download.com/
http://208.66.194.14/banner/index.php
http://www.google.com/search?hl=en&q=games
http://www.ferryhalim.com/orisinal/
http://www.google.com/search?hl=en&q=news
http://www.cbsnews.com/
http://208.66.194.14/banner/index.php
http://www.google.com/search?hl=en&q=games%2Bprocessor%2Bdownload
http://www.indt.org.br/maemo/
http://www.google.com/search?hl=en&q=book
http://www.abebooks.com/
http://208.66.194.14/banner/index.php
http://www.google.com/search?hl=en&q=enter%2Bbook%2Bsoft
http://www.rfbdnj.org/victorsoft.html
http://www.google.com/search?hl=en&q=download
http://www.real.com/realone/
http://208.66.194.14/banner/index.php
http://www.google.com/search?hl=en&q=free%2Bpolitic%2Blaser
http://www.pcmag.com/article2/0%2C4149%2C1205082%2C00.asp
http://www.google.com/search?hl=en&q=download
http://www.real.com/
http://208.66.194.14/banner/index.php
http://www.google.com/search?hl=en&q=soft%2Bgames
http://www.baysoftgames.com/
http://www.google.com/search?hl=en&q=soft%2Bfree%2Bdisk
http://www.loycn.com/
http://208.66.194.14/banner/index.php
http://moneycentral.msn.com/inc/news/providerredir.asp?feed=FT&Date=20060804&ID=5923453
http://www.google.com/search?hl=en&q=laser%2Blaser%2Bpolitic




================================

:: Outpost DNS Cache Log ::

================================

Only logs DNS lookups / host names not direct IP connections ..

6/08/2006 3:09:32 PM zdfttygzjm.biz 81.177.15.226
6/08/2006 3:45:16 PM google.com 64.233.187.99, 72.14.207.99, 64.233.167.99
6/08/2006 3:45:17 PM ftp.icq.com 152.163.212.245
6/08/2006 3:45:35 PM www.cooking.com 64.94.104.152, 64.94.104.24
6/08/2006 3:45:46 PM maila.microsoft.com 131.107.1.7, 131.107.1.6
6/08/2006 3:46:07 PM www.plastic.com 64.81.27.93
6/08/2006 3:46:20 PM www.zdaily.com 216.92.125.14
6/08/2006 3:53:03 PM zhmbscwdgk.biz 81.177.15.226
6/08/2006 3:56:34 PM www.elecdesign.com 66.133.124.78
6/08/2006 3:56:39 PM www.ebaumsworld.com 8.2.119.110, 209.0.146.20, 4.78.57.55, 8.2.118.111
6/08/2006 4:06:42 PM pearpc.sourceforge.net 66.35.250.209
6/08/2006 4:06:44 PM www.free-counters.co.uk 66.98.153.103, 66.98.153.102
6/08/2006 4:17:05 PM www.enter.net 216.193.128.46
6/08/2006 4:17:16 PM crackspider.net 81.211.111.185
6/08/2006 4:27:19 PM www.download.com 216.239.122.225
6/08/2006 4:27:27 PM www.ferryhalim.com 72.29.80.39
6/08/2006 4:37:37 PM www.cbsnews.com 170.20.0.24, 170.20.0.25
6/08/2006 4:38:01 PM www.indt.org.br 72.3.139.221
6/08/2006 4:48:15 PM www.abebooks.com 125.252.195.50
6/08/2006 4:48:29 PM www.rfbdnj.org 209.123.244.71
6/08/2006 4:58:40 PM www.real.com 66.203.115.26
6/08/2006 4:59:04 PM www.pcmag.com 63.87.252.186
6/08/2006 5:09:47 PM www.baysoftgames.com 68.142.205.137
6/08/2006 5:20:00 PM www.loycn.com 84.19.186.219
6/08/2006 5:28:36 PM moneycentral.msn.com 65.54.150.19
6/08/2006 5:44:11 PM www.lasersedgecd.com 207.217.96.37, 207.217.96.38, 207.217.96.39, 207.217.96.40, 207.217.96.41, 207.217.96.42, 207.217.96.43, 207.217.96.44, 207.217.96.45, 207.217.96.28, 207.217.96.29, 207.217.96.30, 207.217.96.31, 207.217.96.32, 207.217.96.33, 207.217.96.34, 207.217.96.35, 207.217.96.36
6/08/2006 5:52:34 PM www.intel.com 203.206.163.5, 203.206.163.8
6/08/2006 5:52:51 PM hubcap.clemson.edu 130.127.28.32
6/08/2006 6:03:08 PM www.x-ways.net 212.227.190.78
6/08/2006 6:03:21 PM www.bath.ac.uk 138.38.32.5
6/08/2006 6:13:30 PM www.volition.com 199.106.67.180
6/08/2006 6:13:46 PM laser.narr.as 213.114.223.201


================================================























Lots of this kind of stuff :














---

Onto round 2 ->

---
Moore
Here we go again rolleyes.gif laugh.gif

----------------------------------------------------


2nd run through of the site zdfttygzjm.biz :


----------------------------------------------------

Problems at iframecash.biz?

QUOTE
The operations of the iframecash.biz gang has been covered in our blog before. Basically, they've been buying traffic from anybody who's been willing to sell it to them - then they use exploits to take over innocent surfer's computers and install trojans and spyware on them.

Now, the good news is that at least for the present, their main site www.iframecash.biz is offline. Hopefully it stays that way.


http://www.f-secure.com/weblog/archives/ar...6.html#00000900


--------------------------------------------------------------------------------------------------


81.177.15.226 [no reverse DNS set]
10 Results for 81.177.15.226 (Dkgate.biz)

1. dkgate.biz
2. iframecash.biz
3. zabywjwzlr.biz
4. zbzppbwqmm.biz
5. zchxsikpgz.biz
6. zdfttygzjm.biz
7. zetbvdpbjh.biz
8. zfwrzemtha.biz
9. zgeghrlgro.biz
10. zhmbscwdgk.biz


http://whois.domaintools.com/iframecash.biz

-------------------------

Started testing here with the server IP - http ://81.177.15.226/

This gets you an .exe file called bl4ck.com dropped straight into the system through the temporary internet files folder , showing up in taskmanager and also a new notepad dropped along with it.

http ://dkgate.biz/notepad.exe

Their web page displays the message = pwn3d !

biggrin.gif cheeky buggers

-------------------------

Just messing around with the server below looking for other things , get a page displayed showing they are running Fedora:

http ://zhmbscwdgk.biz/
http ://zhmbscwdgk.biz/dl/
http ://zhmbscwdgk.biz/dl/adv596.php
http ://zhmbscwdgk.biz/icons/apache_pb2.gif
http ://zhmbscwdgk.biz/icons/powered_by_fedora.png

-------------------------


Ok now the hijack starts here from the top - Many of the urls were repeatedly hit , for the sake of keeping this log small I'll just include each url only once. Virtually all of the files downloaded are .exe files , including the htm/txt files.

http ://zdfttygzjm.biz/dl/adv596.php
http ://zdfttygzjm.biz/dl/xpladv596.wmf
http ://zdfttygzjm.biz/dl/loaderadv596.jar
http ://zdfttygzjm.biz/dl/fillmemadv596.htm
http ://zdfttygzjm.biz/dl/java.jar
http ://zdfttygzjm.biz/dl/loaderadv596_4.exe
http ://zdfttygzjm.biz/dl/fillmemadv596.htm
http ://zdfttygzjm.biz/dl/loaderadv596_2.exe
http ://zdfttygzjm.biz/dl/fillmemadv596.htm
http ://zdfttygzjm.biz/dl/bag.htm
http ://zdfttygzjm.biz/dl/loaderadv596_3.exe
http ://zdfttygzjm.biz/dl/cheat.php?adv=adv596
http ://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qigzwt.php?adv=adv596
http ://zdfttygzjm.biz/progs_traff/plxmwpzsyr/qlgmvcyid
http ://zdfttygzjm.biz/progs_traff/plxmwpzsyr/nzkqatdwi
http ://zdfttygzjm.biz/progs_traff/plxmwpzsyr/lpokhrbxq.php
http ://zdfttygzjm.biz/progs_traff/plxmwpzsyr/ypourx
http ://81.95.147.107/cgi-bin/cert.cgi
http ://81.95.147.107/cgi-bin/options.cgi?user_id=1127901772791119679271&version_id=723471888291&passphrase=fkjvhsdvlksdhvlsd
http ://zdfttygzjm.biz/progs_traff/plxmwpzsyr/uzbhebyhnx.php
http ://zdfttygzjm.biz/progs_traff/plxmwpzsyr/emsyio.php
http ://zdfttygzjm.biz/progs_traff/plxmwpzsyr/vvlebhq
http ://zdfttygzjm.biz/progs_traff/plxmwpzsyr/wodjczjtzs.php
http ://zdfttygzjm.biz/progs_traff/plxmwpzsyr/mqcie.php
http ://zdfttygzjm.biz/progs_traff/plxmwpzsyr/hybhext

http ://zhmbscwdgk.biz/uniq.php

http ://v5.windowsupdate.microsoft.com/v5consumer/QyehIhd.inc
http ://v5.windowsupdate.microsoft.com/windowsupdate/v6/default.aspx?404;http://v5.windowsupdate.microsoft.com:80/v5consumer/QyehIhd.inc

http ://87.249.38.126/asg234/g124.php?v=35&u=kent-7&t=l&p=21265&g=09B33A3D293A4F41AB68DBBD4B5AAF60&w=WXP%20Service%20Pack%201
http ://87.249.38.126/update/s.dat?v=35

The hijack is now fully loaded and this url just repeats over and over :

http ://81.95.147.107/cgi-bin/options.cgi?user_id=1127901772791119679271&version_id=723471888291&passphrase=fkjvhsdvlksdhvlsd


-------------------------


xpladv596.wmf file loads , then this : :
























The second time I used SSM to stop the service , although it still shows as added anyway.. first goes the XP ICF firewall .. Then in comes the rootkit.



--

--------------------------------------------------

Succesful detection of the pe386 lzx32.sys : service :

--------------------------------------------------

1 - Gmer beta detection - detected rootkit / ads / all the hidden registry keys used

2 - Blacklight beta detection - detected hidden service

3 - boot to safe mode - check ntbtlog - shows did not load driver lzx32.sys


This time Blacklight and new Gmer beta detected the rootkit no problems:



















-------------------------------------------------------------------------------------------------

C:\Windows\temp\18467.tmp

references

p386 - C:\Windows\system32:lzx32.sys -
display name - Win23 lzx files loader


More Links ::
http://www.sophos.com/security/analyses/trojrusdrpa.html
http://www.symantec.com/security_response/...-070513-1305-99
http://www.bleepingcomputer.com/startups/l....sys-15548.html
http://secubox.aldria.com/topic-post1212.html
http://www.f-secure.com/v-descs/mailbot_az.shtml
http://www.offensivecomputing.net/?q=node/227

--------------------------

! - copying/removing alternate data streams - f-secure

QUOTE
Removing a hidden data stream, especially one attached to a Windows system directory, is quite tricky.

Since the rootkit is also active in Safe Mode, the easiest solution is to reboot to Windows Recovery Console and write out the data stream from there.

You can do this by copying a suitable file on top of the stream ("copy c:\windows\SomeNonExecutableFile c:\windows\system32:18467"). The copy operation won't succeed, but it will clear out the stream.




QUOTE
--

CWSandbox Analysis report for file: 0e6eb631f6d0db70790b1b1246eab1ea.exe

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 1 (c:\temp\0e6eb631f6d0db70790b1b1246eab1ea.exe MD5: [0e6eb631f6d0db70790b1b1246eab1ea], PID 120, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


==============================================================================
DLL-Handling
==============================================================================
Loaded DLL - DLL: (c:\temp\0e6eb631f6d0db70790b1b1246eab1ea.exe)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\user32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\oleaut32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MSVCRT.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\OLE32.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\comctl32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\wsock32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Secur32.dll)
Loaded DLL - DLL: (advapi32.dll)
Loaded DLL - DLL: (ntdll.dll)
Loaded DLL - DLL: (USER32.dll)

==============================================================================
Filesystem Changes
==============================================================================
Open File: \\.\PIPE\svcctl (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)

==============================================================================
Process Management
==============================================================================
Enum Processes

Open Process - Filename (C:\WINDOWS\Explorer.EXE) CommandLine: () Target PID: (1712) As User: () Creation Flags: ()

==============================================================================
Service Management
==============================================================================
Open Service Manager - Name: (SCM) Start Type: ()
Create Service - Name: (pe386) Display Name: (Win23 lzx files loader) File Name: (C:\WINDOWS\System32:lzx32.sys) Control: () Start Type: (SERVICE_SYSTEM_START)
Start Service - Name: (pe386) Display Name: () File Name: () Control: () Start Type: ()

==============================================================================
System Info
==============================================================================
Get System Directory

==============================================================================
Threads
==============================================================================
Create Remote Thread - Target PID (1712) Thread ID ($0510) Thread ID ($00BA0100) Parameter Address ($00123456) Creation Flags (CREATE_SUSPENDED)

==============================================================================
Virtual Memory
==============================================================================
VM Allocate - Target: (1712) Address: ($00BA0000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE) Allocation Type: (MEM_COMMIT,MEM_RESERVE)
VM Allocate - Target: (1712) Address: ($00BD0000) Size: (65536) Protect: (PAGE_READWRITE) Allocation Type: (MEM_RESERVE)
VM Allocate - Target: (1712) Address: ($00BDE000) Size: (8192) Protect: (PAGE_READWRITE) Allocation Type: (MEM_COMMIT)
VM Protect - Target: (1712) Address: ($00BA0000) Size: (4096) Protect: (PAGE_READWRITE) Allocation Type: ()
VM Protect - Target: (1712) Address: ($00BA0000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE) Allocation Type: ()
VM Protect - Target: (1712) Address: ($00BA0000) Size: (4096) Protect: (PAGE_READWRITE) Allocation Type: ()
VM Protect - Target: (1712) Address: ($00BDE000) Size: (4096) Protect: (PAGE_READWRITE,PAGE_GUARD) Allocation Type: ()
VM Write - Target: (1712) Address: ($00BA0000) Size: (256) Protect: () Allocation Type: ()
VM Write - Target: (1712) Address: ($00BA0100) Size: (2306) Protect: () Allocation Type: ()

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 2 (services.exe MD5: [], PID 536, User: SYSTEM)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


==============================================================================
Service Management
==============================================================================
Load Driver - Name: (\Registry\Machine\System\CurrentControlSet\Services\pe386) File Name: ()

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 3 (C:\WINDOWS\Explorer.EXE MD5: [a82b28bfc2e4455fe43022a498c0ef0a], PID 1712, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


==============================================================================
DLL-Handling
==============================================================================
Loaded DLL - DLL: (C:\WINDOWS\Explorer.EXE)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\msvcrt.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\USER32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\SHLWAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\SHELL32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ole32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\OLEAUT32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\BROWSEUI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\SHDOCVW.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\UxTheme.dll)
Loaded DLL - DLL: (C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1612_x-ww_7c379b08\)
Loaded DLL - DLL: (C:\WINDOWS\system32\comctl32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\appHelp.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\CLBCATQ.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\COMRes.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\VERSION.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\cscui.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\CSCDLL.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\themeui.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Secur32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\MSIMG32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\USERENV.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\NETAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\SAMLIB.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\LINKINFO.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntshrui.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\SETUPAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\urlmon.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\NETSHELL.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\credui.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WINSTA.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\webcheck.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\stobject.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\BatMeter.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\POWRPROF.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WTSAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\msi.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WININET.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\CRYPT32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MSASN1.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\printui.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WINSPOOL.DRV)
Loaded DLL - DLL: (C:\WINDOWS\System32\ACTIVEDS.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\adsldpc.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\CFGMGR32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MPR.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WINMM.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\browselc.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\drprov.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntlanman.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\NETUI0.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\NETUI1.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\NETRAP.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\davclnt.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\hgfs1.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DUSER.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\MSGINA.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ODBC32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\comdlg32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\odbcint.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\shdoclc.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\SXS.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\wsock32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (comctl32.dll)
Loaded DLL - DLL: (RASAPI32.DLL)
Loaded DLL - DLL: (RTUTILS.DLL)
Loaded DLL - DLL: (SHELL32.dll)
Loaded DLL - DLL: (netapi32.dll)
Loaded DLL - DLL: (WININET.dll)

==============================================================================
Filesystem Changes
==============================================================================
Find File: C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
Find File: C:\WINDOWS\System32\Ras\*.pbk
Find File: C:\Documents and Settings\Administrator\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
Open File: \\.\PIPE\svcctl (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: \\.\PIPE\lsarpc (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: c:\autoexec.bat (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Get File Attributes: C:\analysis\cwsandbox.exe Flags: (SECURITY_ANONYMOUS)
Get File Attributes: c:\autoexec.bat Flags: (SECURITY_ANONYMOUS)

==============================================================================
Mutex Changes
==============================================================================
Creates Mutex: RasPbFile

==============================================================================
Service Management
==============================================================================
Open Service Manager - Name: (SCM) Start Type: ()
Open Service - Name: (RASMAN) Start Type: ()

==============================================================================
System Info
==============================================================================
Get System Directory
Get Computer Name
Get System Time

==============================================================================
User Management
==============================================================================
Impersonate User - Domain: () User: (Administrator) Host: () Handle: (2380)

==============================================================================
Window
==============================================================================
Enum Windows

==============================================================================
Winsock
==============================================================================


Report generated at 8/8/2006 3:10:40 PM with CWSandbox Version Beta 1.80
This analysis was created by the CWSandbox Copyright © 2006 Carsten Willems
Copyright © 1996-2006 Sunbelt Software. All rights reserved.


===============================================


Taskmgn.exe : 87.249.38.126 = [ NOLAZ-pc-38-126.unnet.ru ]






QUOTE
Troj/Manager-A is a backdoor Trojan.

The Trojan listens for backdoor commands on a random port number.

Troj/Manager-A copies itself to the Windows system folder as TASKMGN.EXE and sets the following registry entry to run itself on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows Task Manager = "C:\windows\system32\taskmgn.exe"

Troj/Manager-A also creates registry entries in the following location:
HKCU\Software\Microsoft\DMSDOS\









What was funny was when both the main downloader files crashed one after the other :






-------------------------
--------------------------------------------------------
-------------------------

http:// * /progs_traff/plxmwpzsyr/emsyio.php

emsyio.exe

: [NORMAN SANDBOX] contains a security risk - W32/Downloader (Signature:W32/Agent.AGKM)
[ General information ]
* File might be compressed.
* Decompressing FSG.
* File length: 14720 bytes.
* MD5 hash: 0f216f13d2a8a73f2bdde8120fb20c18.

[ Changes to filesystem ]
* Creates file C:\WINDOWS\SYSTEM32\vdrv]EW[.exe.

[ Network services ]
* Opens URL: hxxp ://download.jupitersatellites.biz/*/ppiigg.exe.

[ Security issues ]
* Starting downloaded file - potential security problem.

[ Signature Scanning ]
* C:\WINDOWS\SYSTEM32\vdrv]EW[.exe (4096 bytes) : no signature detection.

File downloaded from hxxp ://download.jupitersatellites.biz/*/ppiigg.exe. -
recognized as type HTML


------------------------------------------------------------------------------------------

rpcc.exe






QUOTE
Troj/Spammit-E
http://www.sophos.com/security/analyses/trojspammite.html

Trojan
Summary
Name Troj/Spammit-E
Type Trojan

Affected operating systems Windows

Side effects Uses its own emailing engine
Downloads code from the internet
Reduces system security
Installs itself in the Registry

Aliases SpamTool.Win32.Agent.h

Description
Troj/Spammit-E is an email spamming Trojan for the Windows platform.

Troj/Spammit-E includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Spammit-E copies itself to <System>\rpcc.exe.

The following registry entry is created to run rpcc.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
rpcc
rpcc.exe

Troj/Spammit-E also attempts to send commands to circumvent the Windows Firewall to allow the Trojan to spam.

The following registry entry is also set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WinOpts
Id
<number>




QUOTE
@echo off
:Repeat
del "c:\bgcg.exe">nul
ping 0.0.0.0>nul
if exist "c:\bgcg.exe" goto Repeat
del "%0"


---------------------------------------------------------

ewido anti-spyware - Scan Report

---------------------------------------------------------

--------------------

:: Program Files Folder ::

--------------------


programfiles\blwyt.exe -> Not-A-Virus.Hoax.Win32.Renos.dc
programfiles\yywrtguo.exe -> Not-A-Virus.Hoax.Win32.Renos.dc


-------------

:: C:\ drive ::

-------------

jupid.exe -> Downloader.Small.ctf
tkma.exe -> Downloader.Small.ctf
xncwuv.exe -> Downloader.Small.ctf
aqwddxp.exe -> Not-A-Virus.Hoax.Win32.Renos.bw
pqwi.exe -> Not-A-Virus.Hoax.Win32.Renos.bw
blwyt.exe -> Not-A-Virus.Hoax.Win32.Renos.dc
nmywiek.exe -> Not-A-Virus.Hoax.Win32.Renos.dc

iiybmc.exe -> Proxy.Agent.km
ygciibyd.exe -> Proxy.Agent.km
fvfirqh.exe -> Trojan.ProcKill.DJ
ivxoaho.exe -> Trojan.ProcKill.DJ
qvse.exe -> Trojan.ProcKill.DJ
rlsnidwy.exe -> Trojan.ProcKill.DJ
dgmot.exe -> Trojan.ProcKill.DJ
yyanqgiv.exe -> Trojan.ProcKill.DJ
lpmebhh.exe -> Trojan.ProcKill.DJ

dbuodhxv.exe -> Trojan.Sinowal.ae
maieflob.exe -> Trojan.Sinowal.ae

-------------

:: Temporary Internet Files ::

-------------

java.jar/NewURLClassLoader.class -> Not-A-Virus.Exploit.ByteVerify
java.jar/NewSecurityClassLoader.class -> Not-A-Virus.Exploit.ByteVerify
java.jar/GetAccess.class -> Downloader.OpenConnection.aj
java.jar/Installer.class -> Downloader.OpenConnection.aj

hybhext.txt -> Downloader.Small.ctf
xpladv596.wmf -> Exploit.MS05-053-WMF

bag.htm -> Not-A-Virus.Exploit.JS.CVE20051790.j

nzkqatdw.exe -> Not-A-Virus.Hoax.Win32.Renos.bw
nzkqatdwi.txt -> Not-A-Virus.Hoax.Win32.Renos.bw
vvlebhq.txt -> Not-A-Virus.Hoax.Win32.Renos.dc
emsyio.htm -> Proxy.Agent.km
wodjczjtzs.htm -> Trojan.ProcKill.DJ
qlgmvcyid.txt -> Trojan.Sinowal.ae


--------------
:: System 32 :
--------------

dlh9jkdq2.exe -> Downloader.Tibs.gc
dlh9jkdq5.exe -> Downloader.Small.dgk
dlh9jkdq6.exe -> Downloader.Small.dht
dlh9jkdq7.exe -> Downloader.Small.dht


::Report end::

-------------
Moore
===============================================

connecting out to here every 30-60 seconds -

81.95.147.107 [reverse DNS - ip-147-107.rbnnetwork.com]


Domain Name: RBNNETWORK.COM
Registrar: ENOM, INC.
Whois Server: whois.enom.com
Referral URL: http://www.enom.com
Name Server: NS1.INFOBOX.ORG
Name Server: NS2.INFOBOX.ORG
Status: ACTIVE
Updated Date: 07-jun-2006
Creation Date: 06-jun-2006
Expiration Date: 06-jun-2007

inetnum: 81.95.144.0 - 81.95.147.255
netname: RBNET
descr: Russian Business Network
admin-c: RBNR-ORG
tech-c: RBNR-ORG
mnt-by: RBN-MNT
status: ASSIGNED PA
country: RU
remarks: INFRA-AW
changed: noc@rbnnetwork.com 20060620
source: RIPE

HTTP - 80 HTTP/1.1 200 OK
Date: Mon, 07 Aug 2006 23:06:44 GMT
Server: Apache/2.0.55 (Unix) mod_ssl/2.0.55 OpenSSL/0.9.7e-p1 mod_perl/2.0.2 Perl/v5.8.7
Last-Modified: Mon, 13 Feb 2006 06:29:52 GMT
ETag: "398003-4-34d09800"
Accept-Ranges: bytes
Content-Length: 4
Connection: close
Content-Type: text/html


==============================================
==============================================

QUOTE
Problems at iframecash.biz?

The operations of the iframecash.biz gang has been covered in our blog before. Basically, they've been buying traffic from anybody who's been willing to sell it to them - then they use exploits to take over innocent surfer's computers and install trojans and spyware on them.

Now, the good news is that at least for the present, their main site www.iframecash.biz is offline. Hopefully it stays that way.

http://www.f-secure.com/weblog/archives/ar...6.html#00000900


Definitely not offline , just using a different domain name :

81.177.15.226 [no reverse DNS set]
10 Results for 81.177.15.226 (Dkgate.biz)
1. dkgate.biz
2. iframecash.biz
3. zabywjwzlr.biz
4. zbzppbwqmm.biz
5. zchxsikpgz.biz
6. zdfttygzjm.biz
7. zetbvdpbjh.biz
8. zfwrzemtha.biz
9. zgeghrlgro.biz
10. zhmbscwdgk.biz

http://whois.domaintools.com/dkgate.biz

QUOTE
Domain Name: DKGATE.BIZ
Domain ID: D13747371-BIZ
Sponsoring Registrar: TLDS INC.
Sponsoring Registrar IANA ID: 320
Domain Status: clientTransferProhibited
Registrant ID: 6580705-SRSPLUS
Registrant Name: Ivan Soto
Registrant Organization: Private person
Registrant Address1: Paulison Avenue
Registrant City: Passaic
Registrant State/Province: NJ
Registrant Postal Code: 07055
Registrant Country: United States
Registrant Country Code: US
Registrant Phone Number: +1.9738828080
Registrant Email:
Administrative Contact ID: 6580706-SRSPLUS
Administrative Contact Name: Ivan Soto
Administrative Contact Organization: Private person
Administrative Contact Address1: Paulison Avenue
Administrative Contact City: Passaic
Administrative Contact State/Province: NJ
Administrative Contact Postal Code: 07055
Administrative Contact Country: United States
Administrative Contact Country Code: US
Administrative Contact Phone Number: +1.9738828080
Administrative Contact Email:
Billing Contact ID: 6580706-SRSPLUS
Billing Contact Name: Ivan Soto
Billing Contact Organization: Private person
Billing Contact Address1: Paulison Avenue
Billing Contact City: Passaic
Billing Contact State/Province: NJ
Billing Contact Postal Code: 07055
Billing Contact Country: United States
Billing Contact Country Code: US
Billing Contact Phone Number: +1.9738828080
Billing Contact Email:
Technical Contact ID: 6580707-SRSPLUS
Technical Contact Name: Ivan Soto
Technical Contact Organization: Private person
Technical Contact Address1: Paulison Avenue
Technical Contact City: Passaic
Technical Contact State/Province: NJ
Technical Contact Postal Code: 07055
Technical Contact Country: United States
Technical Contact Country Code: US
Technical Contact Phone Number: +1.9738828080
Technical Contact Email:
Name Server: NS1.DKGATE.BIZ
Name Server: NS2.DKGATE.BIZ
Created by Registrar: TLDS INC.
Last Updated by Registrar: TLDS INC.
Domain Registration Date: Mon Jun 19 04:35:27 GMT 2006
Domain Expiration Date: Mon Jun 18 23:59:59 GMT 2007
Domain Last Updated Date: Wed Jun 21 08:31:21 GMT 2006

>>>> Whois database was last updated on: Mon Aug 07 22:58:38 GMT 2006 <<<<


http://whois.domaintools.com/iframecash.biz

QUOTE
Website Title: iframeCASH.biz
Record Type: Domain Name

Meta Description: Partnership program. We buy iframe traffic. $61/1000 unique installs or it's up to 15$ per 1000 unique visitors. Weekly payments. Payment by Fethard, Webmoney, E-Gold, Wire

Meta Keywords: traffic purchase iframe trafic traff traf adult webmaster partnership affiliate program afiliate exploit fethard fet webmoney wm i-frame money dollars purchase traffic trade buy toolbar dialer homepage unique visitors $ installs refferal system referral


Domain Name: IFRAMECASH.BIZ
Domain ID: D10183589-BIZ
Sponsoring Registrar: DIRECT INFORMATION PVT LTD DBA PUBLICDOMAINREGISTRY.COM
Sponsoring Registrar IANA ID: 303
Domain Status: clientTransferProhibited
Registrant ID: DI_1876530
Registrant Name: Ezhi Brozkevitsh1
Registrant Organization: Hober Aus1
Registrant Address1: Al. Armii Ludowej 24
Registrant City: Warszawa
Registrant State/Province: Warazawa
Registrant Postal Code: 00-609
Registrant Country: Poland
Registrant Country Code: PL
Registrant Phone Number: +22.5798400
Registrant Email: webmaster@iframecash.biz
Administrative Contact ID: DI_1876530
Administrative Contact Name: Ezhi Brozkevitsh1
Administrative Contact Organization: Hober Aus1
Administrative Contact Address1: Al. Armii Ludowej 24
Administrative Contact City: Warszawa
Administrative Contact State/Province: Warazawa
Administrative Contact Postal Code: 00-609
Administrative Contact Country: Poland
Administrative Contact Country Code: PL
Administrative Contact Phone Number: +22.5798400
Billing Contact ID: DI_1876530
Billing Contact Name: Ezhi Brozkevitsh1
Billing Contact Organization: Hober Aus1
Billing Contact Address1: Al. Armii Ludowej 24
Billing Contact City: Warszawa
Billing Contact State/Province: Warazawa
Billing Contact Postal Code: 00-609
Billing Contact Country: Poland
Billing Contact Country Code: PL
Billing Contact Phone Number: +22.5798400
Email: webmaster@iframecash.biz
Technical Contact ID: DI_1876530
Technical Contact Name: Ezhi Brozkevitsh1
Technical Contact Organization: Hober Aus1
Technical Contact Address1: Al. Armii Ludowej 24
Technical Contact City: Warszawa
Technical Contact State/Province: Warazawa
Technical Contact Postal Code: 00-609
Technical Contact Country: Poland
Technical Contact Country Code: PL
Technical Contact Phone Number: +22.5798400
Technical Contact Email:
Name Server: NS1.IFRAMECASH.BIZ
Name Server: NS2.IFRAMECASH.BIZ
Created by Registrar: DIRECT INFORMATION PVT LTD DBA PUBLICDOMAINREGISTRY.COM
Last Updated by Registrar: DIRECT INFORMATION PVT LTD DBA PUBLICDOMAINREGISTRY.COM
Domain Registration Date: Thu Jun 23 16:12:36 GMT 2005
Domain Expiration Date: Fri Jun 22 23:59:59 GMT 2007
Domain Last Updated Date: Fri Jul 28 06:49:26 GMT 2006


ZABYWJWZLR.BIZ

QUOTE
Domain Name: ZABYWJWZLR.BIZ
Domain ID: D13747367-BIZ
Sponsoring Registrar: TLDS INC.
Sponsoring Registrar IANA ID: 320
Domain Status: clientTransferProhibited
Registrant ID: 6580702-SRSPLUS
Registrant Name: Greg Roa
Registrant Organization: Private person
Registrant Address1: Zion rd Cleves
Registrant City: Cleves
Registrant State/Province: OH
Registrant Postal Code: 45002
Registrant Country: United States
Registrant Country Code: US
Registrant Phone Number: +1.5134676554
Registrant Email:
Administrative Contact ID: 6580703-SRSPLUS
Administrative Contact Name: Greg Roa
Administrative Contact Organization: Private person
Administrative Contact Address1: Zion rd Cleves
Administrative Contact City: Cleves
Administrative Contact State/Province: OH
Administrative Contact Postal Code: 45002
Administrative Contact Country: United States
Administrative Contact Country Code: US
Administrative Contact Phone Number: +1.5134676554
Administrative Contact Email:
Billing Contact ID: 6580703-SRSPLUS
Billing Contact Name: Greg Roa
Billing Contact Organization: Private person
Billing Contact Address1: Zion rd Cleves
Billing Contact City: Cleves
Billing Contact State/Province: OH
Billing Contact Postal Code: 45002
Billing Contact Country: United States
Billing Contact Country Code: US
Billing Contact Phone Number: +1.5134676554
Billing Contact Email:
Technical Contact ID: 6580704-SRSPLUS
Technical Contact Name: Greg Roa
Technical Contact Organization: Private person
Technical Contact Address1: Zion rd Cleves
Technical Contact City: Cleves
Technical Contact State/Province: OH
Technical Contact Postal Code: 45002
Technical Contact Country: United States
Technical Contact Country Code: US
Technical Contact Phone Number: +1.5134676554
Technical Contact Email:
Name Server: NS1.ZABYWJWZLR.BIZ
Name Server: NS2.ZABYWJWZLR.BIZ
Created by Registrar: TLDS INC.
Last Updated by Registrar: TLDS INC.
Domain Registration Date: Mon Jun 19 04:34:55 GMT 2006
Domain Expiration Date: Mon Jun 18 23:59:59 GMT 2007
Domain Last Updated Date: Wed Jun 21 08:32:00 GMT 2006



ZHMBSCWDGK.BIZ

QUOTE
Domain Name: ZHMBSCWDGK.BIZ
Domain ID: D13770072-BIZ
Sponsoring Registrar: ESTDOMAINS INC
Sponsoring Registrar IANA ID: 832
Domain Status: clientTransferProhibited
Registrant ID: DI_3206151
Registrant Name: Bill Passmore
Registrant Organization: N/A
Registrant Address1: Oak Creek Drive
Registrant City: Austin
Registrant State/Province: Texas
Registrant Postal Code: 78727
Registrant Country: United States
Registrant Country Code: US
Registrant Phone Number: +001.5122445985
Registrant Email:
Administrative Contact ID: DI_3206151
Administrative Contact Name: Bill Passmore
Administrative Contact Organization: N/A
Administrative Contact Address1: Oak Creek Drive
Administrative Contact City: Austin
Administrative Contact State/Province: Texas
Administrative Contact Postal Code: 78727
Administrative Contact Country: United States
Administrative Contact Country Code: US
Administrative Contact Phone Number: +001.5122445985
Administrative Contact Email:
Billing Contact ID: DI_3206151
Billing Contact Name: Bill Passmore
Billing Contact Organization: N/A
Billing Contact Address1: Oak Creek Drive
Billing Contact City: Austin
Billing Contact State/Province: Texas
Billing Contact Postal Code: 78727
Billing Contact Country: United States
Billing Contact Country Code: US
Billing Contact Phone Number: +001.5122445985
Billing Contact Email:
Technical Contact ID: DI_3206151
Technical Contact Name: Bill Passmore
Technical Contact Organization: N/A
Technical Contact Address1: Oak Creek Drive
Technical Contact City: Austin
Technical Contact State/Province: Texas
Technical Contact Postal Code: 78727
Technical Contact Country: United States
Technical Contact Country Code: US
Technical Contact Phone Number: +001.5122445985
Technical Contact Email:
Name Server: NS1.ZHMBSCWDGK.BIZ
Name Server: NS2.ZHMBSCWDGK.BIZ
Created by Registrar: ESTDOMAINS INC
Last Updated by Registrar: ESTDOMAINS INC
Domain Registration Date: Wed Jun 21 07:49:59 GMT 2006
Domain Expiration Date: Wed Jun 20 23:59:59 GMT 2007
Domain Last Updated Date: Wed Jul 26 11:49:00 GMT 2006
Moore
:: NOD32 ::

bag[1].htm JS/Exploit.CVE-2005-1790.J trojan
qlgmvcyid[1].txt Win32/PSW.Sinowal trojan
nzkqatdwi[1].txt Win32/Adware.SpySheriff
lpokhrbxq[1].htm Win32/Spy.Agent.NBO trojan
yxqella.exe Win32/Spy.Agent.NBO trojan
xthtjls.exe Win32/TrojanClicker.Costrat.G trojan
xncwuv.exe Win32/TrojanDownloader.Small.CTF
utllnhqa.exe Win32/PSW.Sinowal trojan
ssekmwgh.exe Win32/TrojanProxy.Daemonize trojan
pqwi.exe Win32/Adware.SpySheriff application
pndyqkm.exe Win32/Adware.SpySheriff application
tkma.exe Win32/TrojanDownloader.Small.CTF
ollxys.exe Win32/Spy.Agent.NBO trojan
nnhtjdq.exe Win32/TrojanClicker.Costrat.G trojan
iiybmc.exe Win32/TrojanProxy.Daemonize trojan
dbuodhxv.exe Win32/PSW.Sinowal trojan



\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Virustotal


xpladv596_1_.wmf
qlgmvcyid.exe
loaderadv596_4_1_.exe
ypourx.exe
uvkdwt.exe
uzbhebyhnx_1_.htm
lpokhrbxq_1_.htm
aqwddxp.exe

====================================================================

STATUS: FINISHED

Complete scanning result of "xpladv596_1_.wmf", received in VirusTotal at 08.08.2006, 05:18:02 (CET).

Antivirus Version Update Result
AntiVir 6.35.1.0 08.07.2006 EXP/MS06-001.WMF
Authentium 4.93.8 08.08.2006 contains the exploit named CVE-2005-4560
Avast 4.7.844.0 08.04.2006 MS06-001 WMF Exploit
AVG 386 08.07.2006 Downloader.Agent.13.AI
BitDefender 7.2 08.08.2006 Exploit.Win32.WMF-PFV
CAT-QuickHeal 8.00 08.07.2006 WMF.Exploit
ClamAV devel-20060426 08.08.2006 Exploit.WMF.A
DrWeb 4.33 08.08.2006 Exploit.MS05-053
eTrust-InoculateIT 23.72.89 08.08.2006 Win32/Worfo.Variant!Trojan
eTrust-Vet 12.6.2328 08.07.2006 Win32/Worfo
Ewido 4.0 08.07.2006 Exploit.MS05-053-WMF
Fortinet 2.77.0.0 08.08.2006 suspicious
F-Prot 3.16f 08.06.2006 Contains the exploit named CVE-2005-4560
F-Prot4 4.2.1.29 08.06.2006 CVE-2005-4560
Ikarus 0.2.65.0 08.07.2006 Exploit.IMG-WMF
Kaspersky 4.0.2.24 08.08.2006 Trojan-Downloader.Win32.Agent.acd
McAfee 4823 08.07.2006 Exploit-WMF
Microsoft 1.1508 08.04.2006 Exploit:Win32/Wmfap
NOD32v2 1.1696 08.07.2006 a variant of Win32/Exploit.WMF
Norman 5.90.23 08.07.2006 W32/Exploit.Gen
Panda 9.0.0.4 08.07.2006 Exploit/Metafile
Sophos 4.08.0 08.07.2006 Troj/DownLdr-NO
Symantec 8.0 08.08.2006 Downloader
TheHacker 5.9.8.187 08.07.2006 Exploit/WMF
UNA 1.83 08.07.2006 Exploit.WMF.Agent
VBA32 3.11.0 08.07.2006 Exploit.WMF
VirusBuster 4.3.7:9 08.07.2006 Exploit.WMF-PFV.Gen.1


Aditional Information
File size: 16036 bytes
MD5: 338411fe5f203486aa1a5b526d11f75e
SHA1: 97c18b0577d89e7c041c00688ad970082f66c63d


=============================================================================

Complete scanning result of "qlgmvcyid.exe", received in VirusTotal at 08.08.2006, 04:35:43 (CET).

Antivirus Version Update Result
AntiVir 6.35.1.0 08.07.2006 TR/PSW.Sinowal.AE.92
Authentium 4.93.8 08.08.2006 no virus found
Avast 4.7.844.0 08.04.2006 Win32:Trojano-P
AVG 386 08.07.2006 PSW.Generic2.DPY
BitDefender 7.2 08.08.2006 Trojan.PWS.Sinowal.AH
CAT-QuickHeal 8.00 08.07.2006 TrojanPSW.Sinowal.ae
ClamAV devel-20060426 08.08.2006 Trojan.Spy.Sinowal-40
DrWeb 4.33 08.08.2006 Trojan.PWS.Snap
eTrust-InoculateIT 23.72.89 08.08.2006 Win32/Anserin.FBO!Trojan
eTrust-Vet 12.6.2328 08.07.2006 Win32/Anserin!generic
Ewido 4.0 08.07.2006 Trojan.Sinowal.ae
Fortinet 2.77.0.0 08.08.2006 W32/Sinowal.AE!tr.pws!011
F-Prot 3.16f 08.06.2006 no virus found
F-Prot4 4.2.1.29 08.06.2006 no virus found
Ikarus 0.2.65.0 08.07.2006 no virus found
Kaspersky 4.0.2.24 08.08.2006 Trojan-PSW.Win32.Sinowal.ae
McAfee 4823 08.07.2006 no virus found
Microsoft 1.1508 08.04.2006 no virus found
NOD32v2 1.1696 08.07.2006 Win32/PSW.Sinowal
Norman 5.90.23 08.07.2006 W32/Sinowal.NY
Panda 9.0.0.4 08.07.2006 Trj/Sinowal.BW
Sophos 4.08.0 08.07.2006 no virus found
Symantec 8.0 08.08.2006 no virus found
TheHacker 5.9.8.187 08.07.2006 no virus found
UNA 1.83 08.07.2006 Trojan.PSW.Win32.Sinowal
VBA32 3.11.0 08.07.2006 Trojan-PSW.Win32.Sinowal.ae
VirusBuster 4.3.7:9 08.07.2006 Trojan.DR.Sinowal.Gen.8


Aditional Information
File size: 72704 bytes
MD5: b4de7a89d6322b544fa2d79f4d0c245d
SHA1: 9dcb472a5c5bda72721961e51877deab5559eed4
packers: UPX


===================================================================


STATUS: FINISHED

Complete scanning result of "loaderadv596_4_1_.exe", received in VirusTotal at 08.08.2006, 04:39:25 (CET).

Antivirus Version Update Result
AntiVir 6.35.1.0 08.07.2006 TR/Crypt.F.Gen
Authentium 4.93.8 08.08.2006 Possibly a new variant of W32/Downloader-Sml-based!Maximus
Avast 4.7.844.0 08.04.2006 no virus found
AVG 386 08.07.2006 no virus found
BitDefender 7.2 08.08.2006 Win32.FpuJunk.2
CAT-QuickHeal 8.00 08.07.2006 no virus found
ClamAV devel-20060426 08.08.2006 no virus found
DrWeb 4.33 08.08.2006 Trojan.DownLoader.9899
eTrust-InoculateIT 23.72.89 08.08.2006 no virus found
eTrust-Vet 12.6.2328 08.07.2006 Win32/Vxidl!generic
Ewido 4.0 08.07.2006 Downloader.Tibs.hh
Fortinet 2.77.0.0 08.08.2006 no virus found
F-Prot 3.16f 08.06.2006 Possibly a new variant of W32/Downloader-Sml-based!Maximus
F-Prot4 4.2.1.29 08.06.2006 W32/Downloader-Sml-based!Maximus
Ikarus 0.2.65.0 08.07.2006 no virus found
Kaspersky 4.0.2.24 08.08.2006 Trojan-Downloader.Win32.Tibs.hh
McAfee 4823 08.07.2006 no virus found
Microsoft 1.1508 08.04.2006 no virus found
NOD32v2 1.1696 08.07.2006 no virus found
Norman 5.90.23 08.07.2006 no virus found
Panda 9.0.0.4 08.07.2006 Suspicious file
Sophos 4.08.0 08.07.2006 no virus found
Symantec 8.0 08.08.2006 Bloodhound.Tibs
TheHacker 5.9.8.187 08.07.2006 no virus found
UNA 1.83 08.07.2006 no virus found
VBA32 3.11.0 08.07.2006 Trojan-Downloader.Win32.Tibs.hh
VirusBuster 4.3.7:9 08.07.2006 no virus found


Aditional Information
File size: 8648 bytes
MD5: fcca34392d90dc162c77e1af93748b98
SHA1: 2b06a627f001fd1c660f7df029254c257d2302b2

=======================================================================


STATUS: SCANNING
File "loaderadv596_2_1_.exe" received on 08.08.2006 at 05:03:47 (CET)

Antivirus Version Update Result
AntiVir 6.35.1.0 08.07.2006 TR/Crypt.F.Gen
Authentium 4.93.8 08.08.2006 Possibly a new variant of W32/Downloader-Sml-based!Maximus
Avast 4.7.844.0 08.04.2006 no virus found
AVG 386 08.07.2006 no virus found
BitDefender 7.2 08.08.2006 Win32.FpuJunk.2
CAT-QuickHeal 8.00 08.07.2006 no virus found
ClamAV devel-20060426 08.08.2006 no virus found
DrWeb 4.33 08.08.2006 Trojan.DownLoader.9899
eTrust-InoculateIT 23.72.89 08.08.2006 no virus found
eTrust-Vet 12.6.2328 08.07.2006 Win32/Vxidl!generic
Ewido 4.0 08.07.2006 Downloader.Tibs.hh
Fortinet 2.77.0.0 08.08.2006 no virus found
F-Prot 3.16f 08.06.2006 Possibly a new variant of W32/Downloader-Sml-based!Maximus
F-Prot4 4.2.1.29 08.06.2006 W32/Downloader-Sml-based!Maximus
Ikarus 0.2.65.0 08.07.2006 no virus found
Kaspersky 4.0.2.24 08.08.2006 Trojan-Downloader.Win32.Tibs.hh
McAfee 4823 08.07.2006 no virus found
Microsoft 1.1508 08.04.2006 no virus found


Aditional Information
File size: 8676 bytes
MD5: 1b8b09124ef14b9beca9e13c8b162bf1
SHA1: 79518076b3d0196898a8b58d90c0f9b025644554


===============================================================================

STATUS: FINISHED

Complete scanning result of "ypourx.exe", received in VirusTotal at 08.08.2006, 04:44:53 (CET).

Antivirus Version Update Result
AntiVir 6.35.1.0 08.07.2006 TR/Click.Costrat.G
Authentium 4.93.8 08.08.2006 no virus found
Avast 4.7.844.0 08.04.2006 no virus found
AVG 386 08.07.2006 no virus found
BitDefender 7.2 08.08.2006 no virus found
CAT-QuickHeal 8.00 08.07.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 08.08.2006 no virus found
DrWeb 4.33 08.08.2006 Trojan.Spambot
eTrust-InoculateIT 23.72.89 08.08.2006 no virus found
eTrust-Vet 12.6.2328 08.07.2006 no virus found
Ewido 4.0 08.07.2006 Hijacker.Costrat.g
Fortinet 2.77.0.0 08.08.2006 suspicious
F-Prot 3.16f 08.06.2006 no virus found
F-Prot4 4.2.1.29 08.06.2006 no virus found
Ikarus 0.2.65.0 08.07.2006 no virus found
Kaspersky 4.0.2.24 08.08.2006 Trojan-Clicker.Win32.Costrat.g
McAfee 4823 08.07.2006 no virus found
Microsoft 1.1508 08.04.2006 no virus found
NOD32v2 1.1696 08.07.2006 Win32/TrojanClicker.Costrat.G
Norman 5.90.23 08.07.2006 no virus found
Panda 9.0.0.4 08.07.2006 Suspicious file
Sophos 4.08.0 08.07.2006 no virus found
Symantec 8.0 08.08.2006 no virus found
TheHacker 5.9.8.187 08.07.2006 no virus found
UNA 1.83 08.07.2006 TrojanClicker.Win32.Costrat
VBA32 3.11.0 08.07.2006 Trojan.Spambot
VirusBuster 4.3.7:9 08.07.2006 no virus found


Aditional Information
File size: 70656 bytes
MD5: 0e6eb631f6d0db70790b1b1246eab1ea
SHA1: c1ceac900333adc3b9251d340d4bc06b11eadccb


======================================================================


STATUS: FINISHEDComplete scanning result of "uvkdwt.exe", received in VirusTotal at 08.08.2006, 04:50:11 (CET).

Antivirus Version Update Result
AntiVir 6.35.1.0 08.07.2006 no virus found
Authentium 4.93.8 08.08.2006 no virus found
Avast 4.7.844.0 08.04.2006 no virus found
AVG 386 08.07.2006 no virus found
BitDefender 7.2 08.08.2006 no virus found
CAT-QuickHeal 8.00 08.07.2006 no virus found
ClamAV devel-20060426 08.08.2006 no virus found
DrWeb 4.33 08.08.2006 no virus found
eTrust-InoculateIT 23.72.89 08.08.2006 no virus found
eTrust-Vet 12.6.2328 08.07.2006 Win32/Suspect
Ewido 4.0 08.07.2006 no virus found
Fortinet 2.77.0.0 08.08.2006 no virus found
F-Prot 3.16f 08.06.2006 no virus found
F-Prot4 4.2.1.29 08.06.2006 no virus found
Ikarus 0.2.65.0 08.07.2006 no virus found
Kaspersky 4.0.2.24 08.08.2006 no virus found
McAfee 4823 08.07.2006 New Malware.am
Microsoft 1.1508 08.04.2006 no virus found
NOD32v2 1.1696 08.07.2006 probably unknown NewHeur_PE virus
Norman 5.90.23 08.07.2006 no virus found
Panda 9.0.0.4 08.07.2006 Trj/Agent.CBM
Sophos 4.08.0 08.07.2006 no virus found
Symantec 8.0 08.08.2006 no virus found
TheHacker 5.9.8.187 08.07.2006 no virus found
UNA 1.83 08.07.2006 no virus found
VBA32 3.11.0 08.07.2006 no virus found
VirusBuster 4.3.7:9 08.07.2006 no virus found


Aditional Information
File size: 23552 bytes
MD5: 5e8bfa962140cbb30d17a086f3d3dfed
SHA1: b89fcfcb6b3231c697c1fb4b0ab85411cd8ddc6a

=========================================================================

STATUS: FINISHEDComplete scanning result of "uzbhebyhnx_1_.htm",
received in VirusTotal at 08.08.2006, 04:53:33 (CET).

Antivirus Version Update Result
AntiVir 6.35.1.0 08.07.2006 no virus found
Authentium 4.93.8 08.08.2006 HTML/AdClicker.A@adw
Avast 4.7.844.0 08.04.2006 no virus found
AVG 386 08.07.2006 SpySheriff
BitDefender 7.2 08.08.2006 Trojan.SpySheriff.C
CAT-QuickHeal 8.00 08.07.2006 no virus found
ClamAV devel-20060426 08.08.2006 Adware.Atris-1
DrWeb 4.33 08.08.2006 no virus found
eTrust-InoculateIT 23.72.89 08.08.2006 HTML/Startpage.TH!Trojan
eTrust-Vet 12.6.2328 08.07.2006 HTML/Startpage.TH
Ewido 4.0 08.07.2006 no virus found
Fortinet 2.77.0.0 08.08.2006 W32/Harnig.A!tr
F-Prot 3.16f 08.06.2006 HTML/AdClicker.A@adw
F-Prot4 4.2.1.29 08.06.2006 HTML/AdClicker.A
Ikarus 0.2.65.0 08.07.2006 Trojan.Win32.Harnig.A
Kaspersky 4.0.2.24 08.08.2006 Trojan.Win32.Harnig.a
McAfee 4823 08.07.2006 StartPage-IH
Microsoft 1.1508 08.04.2006 no virus found
NOD32v2 1.1696 08.07.2006 Win32/Hoax.Renos
Norman 5.90.23 08.07.2006 HTML/Renos
Panda 9.0.0.4 08.07.2006 no virus found
Sophos 4.08.0 08.07.2006 no virus found
Symantec 8.0 08.08.2006 no virus found
TheHacker 5.9.8.187 08.07.2006 Trojan/StartPage-htm
UNA 1.83 08.07.2006 no virus found
VBA32 3.11.0 08.07.2006 Trojan.HTML.SpySheriff#1
VirusBuster 4.3.7:9 08.07.2006 no virus found


Aditional Information
File size: 3024 bytes
MD5: b139b6e4a1a8e20b25c0d5d4ec2f1382
SHA1: 4d831c4efe7712649cb1e170c9a03d66a09935d4


======================================================================


STATUS: FINISHED

Complete scanning result of "lpokhrbxq_1_.htm", received in VirusTotal at 08.08.2006, 05:10:17 (CET).

Antivirus Version Update Result
AntiVir 6.35.1.0 08.07.2006 HEUR/Crypted.E
Authentium 4.93.8 08.08.2006 Possibly a new variant of W32/SecRisk-ProcessPatcher-Sml-based!Maximus
Avast 4.7.844.0 08.04.2006 no virus found
AVG 386 08.07.2006 no virus found
BitDefender 7.2 08.08.2006 BehavesLike:Win32.ExplorerHijack
CAT-QuickHeal 8.00 08.07.2006 no virus found
ClamAV devel-20060426 08.08.2006 no virus found
DrWeb 4.33 08.08.2006 no virus found
eTrust-InoculateIT 23.72.89 08.08.2006 no virus found
eTrust-Vet 12.6.2328 08.07.2006 no virus found
Ewido 4.0 08.07.2006 no virus found
Fortinet 2.77.0.0 08.08.2006 suspicious
F-Prot 3.16f 08.06.2006 Possibly a new variant of W32/SecRisk-ProcessPatcher-Sml-based!Maximus
F-Prot4 4.2.1.29 08.06.2006 W32/SecRisk-ProcessPatcher-Sml-based!Maximus
Ikarus 0.2.65.0 08.07.2006 no virus found
Kaspersky 4.0.2.24 08.08.2006 no virus found
McAfee 4823 08.07.2006 no virus found
Microsoft 1.1508 08.04.2006 no virus found
NOD32v2 1.1696 08.07.2006 no virus found
Norman 5.90.23 08.07.2006 no virus found
Panda 9.0.0.4 08.07.2006 Suspicious file
Sophos 4.08.0 08.07.2006 no virus found
Symantec 8.0 08.08.2006 no virus found
TheHacker 5.9.8.187 08.07.2006 no virus found
UNA 1.83 08.07.2006 no virus found
VBA32 3.11.0 08.07.2006 suspected of Downloader.Small.165
VirusBuster 4.3.7:9 08.07.2006 no virus found


Aditional Information
File size: 9216 bytes
MD5: e96fa245396580989af45d74e41f5131
SHA1: 86201365324c308d1752223916effff1eaf03a22
packers: UPX
packers: UPX


============================================================


STATUS: FINISHED

Complete scanning result of "aqwddxp.exe", received in VirusTotal at 08.08.2006, 07:20:20 (CET).

Antivirus Version Update Result
AntiVir 6.35.1.0 08.07.2006 ADSPY/Hoax.Renos.AG
Authentium 4.93.8 08.08.2006 W32/FakeAlert.BN
Avast 4.7.844.0 08.04.2006 Win32:Hoaxalarm-V
AVG 386 08.07.2006 Generic.SUZ
BitDefender 7.2 08.08.2006 Trojan.Dwnldr.BON
CAT-QuickHeal 8.00 08.07.2006 Hoax.Renos.cn (Not a Virus)
ClamAV devel-20060426 08.08.2006 Trojan.Fakealert-2
DrWeb 4.33 08.08.2006 Trojan.Fakealert
eTrust-InoculateIT 23.72.89 08.08.2006 Win32/Oneraw.32768!Trojan
eTrust-Vet 12.6.2328 08.07.2006 Win32/Oneraw.AY
Ewido 4.0 08.07.2006 Not-A-Virus.Hoax.Win32.Renos.bw
Fortinet 2.77.0.0 08.08.2006 Misc/SpySheriff
F-Prot 3.16f 08.06.2006 security risk named W32/FakeAlert.BN
F-Prot4 4.2.1.29 08.06.2006 W32/FakeAlert.BN
Ikarus 0.2.65.0 08.07.2006 Trojan.Fakealert
Kaspersky 4.0.2.24 08.08.2006 not-virus:Hoax.Win32.Renos.cn
McAfee 4823 08.07.2006 Downloader-AFH
Microsoft 1.1508 08.04.2006 SpySheriff (threat-c)
NOD32v2 1.1696 08.07.2006 Win32/Adware.SpySheriff
Norman 5.90.23 08.07.2006 W32/Renos.EK
Panda 9.0.0.4 08.07.2006 Adware/SpySheriff
Sophos 4.08.0 08.07.2006 Troj/DwnLdr-BON
Symantec 8.0 08.08.2006 no virus found
TheHacker 5.9.8.187 08.07.2006 Aplicacion/Renos.cn
UNA 1.83 08.07.2006 Hoax.Win32.Renos
VBA32 3.11.0 08.07.2006 Trojan.Fakealert
VirusBuster 4.3.7:9 08.07.2006 Trojan.Renos.AH


Aditional Information
File size: 32768 bytes
MD5: ce302aad98fb79e168e36dbe70484c3b
SHA1: 9530f4000f9d4b7f0f83a2152e189a9d5532003a


-----------------------------------------------------------------------------
Moore
QUOTE
CWSandbox Analysis report for file: ce302aad98fb79e168e36dbe70484c3b.exe

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 1 (c:\temp\ce302aad98fb79e168e36dbe70484c3b.exe MD5: [ce302aad98fb79e168e36dbe70484c3b], PID 652, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


====================================================
COM
====================================================
COM Create Instance: %SystemRoot%\system32\SHELL32.dll, ProgID: (), Interface ID: ({F490EB00-1240-11D1-9888-006097DEACF9})

====================================================
DLL-Handling
====================================================
Loaded DLL - DLL: (c:\temp\ce302aad98fb79e168e36dbe70484c3b.exe)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\USER32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WSOCK32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\msvcrt.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ole32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\SHELL32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\SHLWAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\COMCTL32.dll)
Loaded DLL - DLL: (C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1612_x-ww_7c379b08\)
Loaded DLL - DLL: (C:\WINDOWS\system32\oleaut32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Secur32.dll)
Loaded DLL - DLL: (.\UxTheme.dll)
Loaded DLL - DLL: (SHELL32.dll)
Loaded DLL - DLL: (ole32.dll)
====================================================
Filesystem Changes
====================================================
Copy File: c:\temp\ce302aad98fb79e168e36dbe70484c3b.exe to C:\winstall.exe
Create File: C:\Program Files\SpySheriff\base.avd
Create File: C:\Program Files\SpySheriff\base001.avd
Create File: C:\Program Files\SpySheriff\base002.avd
Create File: C:\Program Files\SpySheriff\found.wav
Create File: C:\Program Files\SpySheriff\heur000.dll
Create File: C:\Program Files\SpySheriff\heur001.dll
Create File: C:\Program Files\SpySheriff\heur002.dll
Create File: C:\Program Files\SpySheriff\heur003.dll
Create File: C:\Program Files\SpySheriff\notfound.wav
Create File: C:\Program Files\SpySheriff\removed.wav
Create File: C:\Program Files\SpySheriff\SpySheriff.exe
Create File: C:\Program Files\SpySheriff\Uninstall.exe
Create File: C:\Program Files\SpySheriff\SpySheriff.dvm
Open File: \\.\PIPE\lsarpc (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: \\.\PIPE\ntsvcs (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Create/Open File: C:\Program Files\SpySheriff\SpySheriff.exe (OPEN_ALWAYS), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Create/Open File: C:\Documents and Settings\Administrator\Application Data\Install.dat (OPEN_ALWAYS), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Get File Attributes: C:\WINDOWS\Registration Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:\WINDOWS\ Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:\Documents and Settings\Administrator\Application Data\desktop.ini Flags: (SECURITY_ANONYMOUS)

====================================================
INI Files
====================================================
Read from INI file: C:\Documents and Settings\Administrator\Application Data\desktop.ini [DeleteOnCopy] Owner =
Read from INI file: C:\Documents and Settings\Administrator\Application Data\desktop.ini [.ShellClassInfo] LocalizedResourceName =

====================================================
Registry Changes
====================================================
Create or Open:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders -
HKEY_CURRENT_USER\SOFTWARE\Install -
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop -
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer -
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General -
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Desktop\General -


Registry Changes:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ "Windows installer" = (C:\winstall.exe)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\ "NoChangingWallpaper" = ([REG_DWORD, value: 00000000])
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\ "NoComponents" = ([REG_DWORD, value: 00000000])
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\ "NoAddingComponents" = ([REG_DWORD, value: 00000000])
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\ "NoDeletingComponents" = ([REG_DWORD, value: 00000000])
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\ "NoEditingComponents" = ([REG_DWORD, value: 00000000])
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\ "NoHTMLWallPaper" = ([REG_DWORD, value: 00000000])
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ "NoActiveDesktop" = ([REG_DWORD, value: 00000000])
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ "ClassicShell" = ([REG_DWORD, value: 00000000])
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ "ForceActiveDesktopOn" = ([REG_DWORD, value: 00000001])
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ "Wallpaper" = ()
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\ "WallpaperStyle" = (2)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\ "TileWallpaper" = (0)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\ "ComponentsPositioned" = ([REG_DWORD, value: 00000002])
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\ "WallpaperFileTime" = ([REG_BINARY, size: 8 bytes])
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\ "WallpaperLocalFileTime" = ([REG_BINARY, size: 8 bytes])
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\ "WallpaperFileTime" = ([REG_BINARY, size: 8 bytes])
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\ "WallpaperLocalFileTime" = ([REG_BINARY, size: 8 bytes])


Registry Reads:
Software\Microsoft\Windows\CurrentVersion\ThemeManager\ "Compositing"
Control Panel\Desktop\ "LameButtonText"
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ "AppData"
HKEY_CURRENT_USER\SOFTWARE\Install\ "Version"


Registry Enums:

====================================================
System Info
====================================================
Get System Directory
Get Windows Directory

====================================================
Window
====================================================
Find Window - Class Name () Window Name (Windows Security Alert)
Find Window - Class Name () Window Name (Create rule for CE302AAD98FB79E168E36DBE70484C3B.EXE)
Find Window - Class Name () Window Name (Hidden Process Requests Network Access)
Find Window - Class Name () Window Name (Warning: Components Have Changed)
Find Window - Class Name () Window Name (PermissionDlg)

====================================================
Winsock
====================================================

Report generated at 8/8/2006 4:29:58 PM with CWSandbox Version Beta 1.80
This analysis was created by the CWSandbox Copyright © 2006 Carsten Willems
Copyright © 1996-2006 Sunbelt Software. All rights reserved.


==

QUOTE
CWSandbox Analysis report for file: 338411fe5f203486aa1a5b526d11f75e.exe

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 1 (c:\temp\338411fe5f203486aa1a5b526d11f75e.exe MD5: [338411fe5f203486aa1a5b526d11f75e], PID 652, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

NtVdmControl

====================================================
DLL-Handling
====================================================
Loaded DLL - DLL: (C:\WINDOWS\system32\ntvdm.exe)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\USER32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\oleaut32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MSVCRT.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\OLE32.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\comctl32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\wsock32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\Secur32.dll)
Loaded DLL - DLL: (WINMM.DLL)
Loaded DLL - DLL: (NTVDMD.DLL)
Loaded DLL - DLL: (Userenv.dll)
Loaded DLL - DLL: (.\UxTheme.dll)

====================================================
Filesystem Changes
====================================================
Find File: C:\MSDOS.SYS
Find File: C:\IO.SYS
Delete File: C:\WINDOWS\TEMP\scs5.tmp
Delete File: C:\WINDOWS\TEMP\scs6.tmp
Open File: \DosDevices\A: (), (FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: \DosDevices\B: (), (FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\System32\ntio.sys (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\System32\ntdos.sys (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_WRITE_ATTRIBUTES), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\CONFIG.NT (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\TEMP\SCS5.TMP (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_WRITE_ATTRIBUTES), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\HIMEM.SYS (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_WRITE_ATTRIBUTES), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\HIMEM.SYS (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\COUNTRY.SYS (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_WRITE_ATTRIBUTES), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: \DosDevices\C: (), (FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_READ_A
TTRIBUTES), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\COMMAND.COM (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_WRITE_ATTRIBUTES), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\COMMAND.COM (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32 (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\AUTOEXEC.NT (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\TEMP\SCS6.TMP (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_WRITE_ATTRIBUTES), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\MSCDEXNT.EXE (), (FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\MSCDEXNT.EXE (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\REDIR.??? (), (FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\REDIR.EXE (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\DOSX.??? (), (FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM32\DOSX.EXE (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\SYSTEM.INI (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_WRITE_ATTRIBUTES), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: c:\TEMP\338411~1.EXE (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_DELETE,SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Create/Open File: C:\WINDOWS\TEMP\scs5.tmp (OPEN_ALWAYS), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (FILE_ATTRIBUTE_TEMPORARY,SECURITY_ANONYMOUS)
Create/Open File: C:\WINDOWS\TEMP\scs6.tmp (OPEN_ALWAYS), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (FILE_ATTRIBUTE_TEMPORARY,SECURITY_ANONYMOUS)
Get File Attributes: C:\WINDOWS\_default.pif Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:\WINDOWS\SYSTEM32\SYSTEM.INI Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:\SYSTEM.INI Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:\WINDOWS\SYSTEM.INI Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:\WINDOWS\SYSTEM32\KRNL386.EXE Flags: (SECURITY_ANONYMOUS)

====================================================
Registry Changes
====================================================
Create or Open:


Registry Changes:


Registry Reads:
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\ "Identifier"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WOW\ "RomFontPointers"
\REGISTRY\MACHINE\HARDWARE\DESCRIPTION\SYSTEM\ "Configuration Data"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers\ "VDD"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup\ "BootDir"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\ "RootDrive"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Software\Microsoft\Windows\CurrentVersion\ThemeManager\ "Compositing"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Control Panel\Desktop\ "LameButtonText"


Registry Enums:


====================================================
System Info
====================================================
Get System Directory
Get Windows Directory
Get System Time

====================================================
Window
====================================================
Find Window - Class Name (ConsoleWindowClass) Window Name (ntvdm-28c.2ac.320002)

Report generated at 8/8/2006 4:34:38 PM with CWSandbox Version Beta 1.80
This analysis was created by the CWSandbox Copyright © 2006 Carsten Willems
Copyright © 1996-2006 Sunbelt Software. All rights reserved.


==


QUOTE
CWSandbox Analysis report for file: 0f216f13d2a8a73f2bdde8120fb20c18.exe

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 1 (c:\temp\0f216f13d2a8a73f2bdde8120fb20c18.exe MD5: [0f216f13d2a8a73f2bdde8120fb20c18], PID 652, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


==============================================================================
DLL-Handling
==============================================================================
Loaded DLL - DLL: (c:\temp\0f216f13d2a8a73f2bdde8120fb20c18.exe)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\user32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\oleaut32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MSVCRT.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\OLE32.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\comctl32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\wsock32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Secur32.dll)
Loaded DLL - DLL: (KERNEL32.dll)
Loaded DLL - DLL: (USER32.dll)
Loaded DLL - DLL: (ADVAPI32.dll)
Loaded DLL - DLL: (MSVCRT.dll)
Loaded DLL - DLL: (comctl32.dll)
Loaded DLL - DLL: (WININET.dll)
Loaded DLL - DLL: (WS2_32.dll)
Loaded DLL - DLL: (RASAPI32.DLL)
Loaded DLL - DLL: (RTUTILS.DLL)
Loaded DLL - DLL: (SHELL32.dll)
Loaded DLL - DLL: (netapi32.dll)

==============================================================================
Filesystem Changes
==============================================================================
Find File: C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
Find File: C:\WINDOWS\System32\Ras\*.pbk
Find File: C:\Documents and Settings\Administrator\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
Find File: vdrvNQ[M.exe
Find File: TheMatrixHasYou.exe
Create File: C:\WINDOWS\System32\vdrvNQ[M.exe
Create File: C:\WINDOWS\System32\TheMatrixHasYou.exe
Open File: \\.\PIPE\svcctl (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: \\.\PIPE\lsarpc (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: c:\autoexec.bat (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: \SystemRoot\AppPatch\sysmain.sdb (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: \SystemRoot\AppPatch\systest.sdb (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE,FILE_ADD_SUBDIR
ECTORY,FILE_APPEND_DATA,FILE_CREATE_PIPE_INSTANCE,FILE_WRITE_EA,FILE_WRITE_ATTRIB
UTES), (), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\System32\vdrvNQ[M.exe (), (FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\System32\TheMatrixHasYou.exe (), (FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Create/Open File: \Device\RasAcd (OPEN_ALWAYS), (FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_
ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE), (SHARE_READ,SHARE_WRITE), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Get File Attributes: c:\autoexec.bat Flags: (SECURITY_ANONYMOUS)

==============================================================================
Mutex Changes
==============================================================================
Creates Mutex: RasPbFile
Creates Mutex: ZonesCounterMutex
Creates Mutex: ZonesCacheCounterMutex

==============================================================================
Registry Changes
==============================================================================
Create or Open:


Registry Changes:


Registry Reads:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ "DisableImprovedZoneCheck"


Registry Enums:
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\ -


==============================================================================
Process Management
==============================================================================
Creates Process - Filename () CommandLine: (C:\WINDOWS\System32\vdrvNQ[M.exe) Target PID: (212) As User: () Creation Flags: (DETACHED_PROCESS)
Creates Process - Filename (C:\WINDOWS\System32\TheMatrixHasYou.exe) CommandLine: (/k c:\temp\0f216f13d2a8a73f2bdde8120fb20c18.exe) Target PID: (288) As User: () Creation Flags: (DETACHED_PROCESS)

==============================================================================
Service Management
==============================================================================
Open Service Manager - Name: (SCM) Start Type: ()
Open Service - Name: (RASMAN) Start Type: ()

==============================================================================
System Info
==============================================================================
Get System Directory
Get Computer Name

==============================================================================
User Management
==============================================================================
Impersonate User - Domain: () User: (Administrator) Host: () Handle: (1416)
Get User Name


==============================================================================
Winsock
==============================================================================


@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 2 (services.exe MD5: [], PID 536, User: SYSTEM)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 3 (C:\WINDOWS\System32\vdrvNQ[M.exe MD5: [c05c5f92e4a86c99c6996de040a31b6d], PID 212, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


==============================================================================
DLL-Handling
==============================================================================
Loaded DLL - DLL: (C:\WINDOWS\System32\vdrvNQ[M.exe)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\user32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\oleaut32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MSVCRT.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\OLE32.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\comctl32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\wsock32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Secur32.dll)
Loaded DLL - DLL: (KERNEL32.dll)
Loaded DLL - DLL: (USER32.dll)
Loaded DLL - DLL: (ADVAPI32.dll)
Loaded DLL - DLL: (MSVCRT.dll)
Loaded DLL - DLL: (comctl32.dll)
Loaded DLL - DLL: (WININET.dll)
Loaded DLL - DLL: (WS2_32.dll)

==============================================================================
Filesystem Changes
==============================================================================
Copy File: c:\windows\system32\vdrvnq[m.exe to C:\WINDOWS\System32\truetype.exe
Find File: truetype.exe
Find File: TheMatrixHasYou.exe
Create File: C:\WINDOWS\System32\TheMatrixHasYou.exe
Delete File: C:\WINDOWS\System32\truetype.exe
Open File: \SystemRoot\AppPatch\sysmain.sdb (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: \SystemRoot\AppPatch\systest.sdb (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE,FILE_ADD_SUBDIR
ECTORY,FILE_APPEND_DATA,FILE_CREATE_PIPE_INSTANCE,FILE_WRITE_EA,FILE_WRITE_ATTRIB
UTES), (), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\System32\truetype.exe (), (FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\System32\TheMatrixHasYou.exe (), (FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)

==============================================================================
Registry Changes
==============================================================================
Create or Open:
HKEY_LOCAL_MACHINE\Software\Microsoft\ -


Registry Changes:
HKEY_LOCAL_MACHINE\Software\Microsoft\\ "ATI_VER" = ([REG_DWORD, value: 44D8F956])


Registry Reads:


Registry Enums:


==============================================================================
Process Management
==============================================================================
Creates Process - Filename () CommandLine: (C:\WINDOWS\System32\truetype.exe) Target PID: (200) As User: () Creation Flags: (DETACHED_PROCESS)
Creates Process - Filename (C:\WINDOWS\System32\TheMatrixHasYou.exe) CommandLine: (/k c:\windows\system32\vdrvnq[m.exe) Target PID: (460) As User: () Creation Flags: (DETACHED_PROCESS)

==============================================================================
System Info
==============================================================================
Get System Directory

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 4 (C:\WINDOWS\System32\TheMatrixHasYou.exe /k c:\temp\0f216f13d2a8a73f2bdde8120fb20c18.exe MD5: [], PID 288, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


==============================================================================
DLL-Handling
==============================================================================
Loaded DLL - DLL: (C:\WINDOWS\System32\TheMatrixHasYou.exe)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\user32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\oleaut32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MSVCRT.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\OLE32.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\comctl32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\wsock32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Secur32.dll)
Loaded DLL - DLL: (KERNEL32.dll)
Loaded DLL - DLL: (USER32.dll)

==============================================================================
Filesystem Changes
==============================================================================
Delete File: c:\temp\0f216f13d2a8a73f2bdde8120fb20c18.exe
Open File: c:\temp\0f216f13d2a8a73f2bdde8120fb20c18.exe (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 5 (C:\WINDOWS\System32\truetype.exe MD5: [c05c5f92e4a86c99c6996de040a31b6d], PID 200, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


==============================================================================
DLL-Handling
==============================================================================
Loaded DLL - DLL: (C:\WINDOWS\System32\truetype.exe)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\user32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\oleaut32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MSVCRT.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\OLE32.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\comctl32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\wsock32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Secur32.dll)
Loaded DLL - DLL: (KERNEL32.dll)
Loaded DLL - DLL: (USER32.dll)
Loaded DLL - DLL: (ADVAPI32.dll)
Loaded DLL - DLL: (MSVCRT.dll)
Loaded DLL - DLL: (comctl32.dll)
Loaded DLL - DLL: (WININET.dll)
Loaded DLL - DLL: (WS2_32.dll)
Loaded DLL - DLL: (ICMP.DLL)
Loaded DLL - DLL: (RASAPI32.DLL)
Loaded DLL - DLL: (RTUTILS.DLL)
Loaded DLL - DLL: (SHELL32.dll)
Loaded DLL - DLL: (netapi32.dll)

==============================================================================
Filesystem Changes
==============================================================================
Find File: C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
Find File: C:\WINDOWS\System32\Ras\*.pbk
Find File: C:\Documents and Settings\Administrator\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
Find File: dxvwlvpo.exe
Create File: C:\WINDOWS\System32\win.ini.t00
Create File: C:\WINDOWS\System32\dxvwlvpo.exe
Open File: \\.\PIPE\svcctl (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: \\.\PIPE\lsarpc (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: c:\autoexec.bat (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: \SystemRoot\AppPatch\sysmain.sdb (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: \SystemRoot\AppPatch\systest.sdb (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING), (FILE_ANY_ACCESS,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE,FILE_ADD_SUBDIR
ECTORY,FILE_APPEND_DATA,FILE_CREATE_PIPE_INSTANCE,FILE_WRITE_EA,FILE_WRITE_ATTRIB
UTES), (), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\System32\dxvwlvpo.exe (), (FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Create/Open File: \Device\RasAcd (OPEN_ALWAYS), (FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_
ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE), (SHARE_READ,SHARE_WRITE), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Get File Attributes: C:\WINDOWS\System32\win.ini.t00 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: c:\autoexec.bat Flags: (SECURITY_ANONYMOUS)

==============================================================================
Mutex Changes
==============================================================================
Creates Mutex: 4457319-QdmJgU
Creates Mutex: RasPbFile
Creates Mutex: ZonesCounterMutex
Creates Mutex: ZonesCacheCounterMutex

==============================================================================
Registry Changes
==============================================================================
Create or Open:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices -
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run -
HKEY_LOCAL_MACHINE\Software\Microsoft\ -


Registry Changes:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ "truetype" = (C:\WINDOWS\System32\truetype.exe)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ "truetype" = (C:\WINDOWS\System32\truetype.exe)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ "truetype" = (C:\WINDOWS\System32\truetype.exe)


Registry Reads:
HKEY_LOCAL_MACHINE\Software\Microsoft\\ "ATI_VER"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ "DisableImprovedZoneCheck"


Registry Enums:
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\ -


==============================================================================
Process Management
==============================================================================
Creates Process - Filename () CommandLine: (C:\WINDOWS\System32\dxvwlvpo.exe) Target PID: (896) As User: () Creation Flags: (DETACHED_PROCESS)

==============================================================================
Service Management
==============================================================================
Open Service Manager - Name: (SCM) Start Type: ()
Open Service - Name: (RASMAN) Start Type: ()

==============================================================================
System Info
==============================================================================
Get System Directory
Get Computer Name

==============================================================================
User Management
==============================================================================
Impersonate User - Domain: () User: (Administrator) Host: () Handle: (500)
Get User Name


==============================================================================
Winsock
==============================================================================

Opening Listening TCP Connection - Local Port: 43633 - Connection Established: 0 - Socket: 756

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 6 (C:\WINDOWS\System32\TheMatrixHasYou.exe /k c:\windows\system32\vdrvnq[m.exe MD5: [], PID 460, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


==============================================================================
DLL-Handling
==============================================================================
Loaded DLL - DLL: (C:\WINDOWS\System32\TheMatrixHasYou.exe)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\user32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\oleaut32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MSVCRT.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\OLE32.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\comctl32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\wsock32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Secur32.dll)
Loaded DLL - DLL: (KERNEL32.dll)
Loaded DLL - DLL: (USER32.dll)

==============================================================================
Filesystem Changes
==============================================================================
Delete File: c:\windows\system32\vdrvnq[m.exe
Open File: c:\windows\system32\vdrvnq[m.exe (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 7 (C:\WINDOWS\System32\dxvwlvpo.exe MD5: [3bbb65107d22226f6dfd9c762522d7ff], PID 896, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


==============================================================================
COM
==============================================================================
COM Create Instance: C:\WINDOWS\System32\hnetcfg.dll, ProgID: (HNetCfg.HNetShare.1), Interface ID: ({C08956B7-1CD3-11D1-B1C5-00805FC1270E})
COM Create Instance: C:\WINDOWS\System32\hnetcfg.dll, ProgID: (), Interface ID: ({85D18B6C-3032-11D4-9348-00C04F8EEB71})
COM Create Instance: C:\WINDOWS\System32\wbem\wbemprox.dll, ProgID: (), Interface ID: ({DC12A687-737F-11CF-884D-00AA004B2E24})
COM Create Instance: C:\WINDOWS\System32\wbem\wbemprox.dll, ProgID: (), Interface ID: ({00000000-0000-0000-C000-000000000046})
COM Create Instance: , ProgID: (), Interface ID: ({C08956A2-1CD3-11D1-B1C5-00805FC1270E})
COM Create Instance: , ProgID: (), Interface ID: ({00000149-0000-0000-C000-000000000046})
COM Get Class Object: C:\WINDOWS\System32\wbem\wbemsvc.dll, Interface ID: ({D5F569D0-593B-101A-B569-08002B2DBF7A})

==============================================================================
DLL-Handling
==============================================================================
Loaded DLL - DLL: (C:\WINDOWS\System32\dxvwlvpo.exe)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ole32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\USER32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\OLEAUT32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MSVCRT.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\comctl32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\wsock32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Secur32.dll)
Loaded DLL - DLL: (KERNEL32.DLL)
Loaded DLL - DLL: (ADVAPI32.dll)
Loaded DLL - DLL: (ole32.dll)
Loaded DLL - DLL: (OLEAUT32.dll)
Loaded DLL - DLL: (USER32.dll)
Loaded DLL - DLL: (WS2_32.dll)
Loaded DLL - DLL: (.\UxTheme.dll)
Loaded DLL - DLL: (comctl32.dll)
Loaded DLL - DLL: (RASAPI32.DLL)
Loaded DLL - DLL: (OLE32)
Loaded DLL - DLL: (rpcrt4.dll)

==============================================================================
Filesystem Changes
==============================================================================
Find File: C:\WINDOWS
Find File: C:\WINDOWS\system32
Find File: C:\WINDOWS\system32\WBEM
Find File: C:\WINDOWS\system32\WBEM\Logs
Create File: C:\WINDOWS\System32\drivers\etc\hosts
Open File: C:\WINDOWS\System32\drivers\etc\hosts (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: C:\Documents and Settings\Administrator\Application Data\Microsoft\2238.dat (OPEN_EXISTING), (FILE_ANY_ACCESS), (), (SECURITY_ANONYMOUS)
Open File: \\.\PIPE\lsarpc (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: \\.\PIPE\svcctl (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Create/Open File: \Device\Tcp (OPEN_ALWAYS), (FILE_ANY_ACCESS), (SHARE_READ,SHARE_WRITE), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Get File Attributes: C:\WINDOWS\Registration Flags: (SECURITY_ANONYMOUS)

==============================================================================
Mutex Changes
==============================================================================
Creates Mutex: hs5pdllv42238
Creates Mutex: RasPbFile

==============================================================================
Registry Changes
==============================================================================
Create or Open:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run -
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C1CD3D7-86AC-4068-93BC-A02304BB2238}\InProcServer32 -
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM -
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM -


Registry Changes:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ "Explorer 2238" = (C:\WINDOWS\System32\dxvwlvpo.exe)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C1CD3D7-86AC-4068-93BC-A02304BB2238}\InProcServer32\ "" = (C:\WINDOWS\System32\dxvwlvpo.exe)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C1CD3D7-86AC-4068-93BC-A02304BB2238}\InProcServer32\ "ThreadingModel" = (Apartment)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\ "{2C1CD3D7-86AC-4068-93BC-A02304BB2238}" = (DCOM Server 2238)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ "DCOM Server 2238" = ({2C1CD3D7-86AC-4068-93BC-A02304BB2238})


Registry Reads:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C1CD3D7-86AC-4068-93BC-A02304BB2238}\InProcServer32\ ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ "AppData"
Software\Microsoft\Windows\CurrentVersion\ThemeManager\ "Compositing"
Control Panel\Desktop\ "LameButtonText"
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\ "Logging Directory"
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\ "Logging"
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\ "Log File Max Size"
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\ "Repository Directory"
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\TRANSPORTS\Network Transport Modules\ "Stack Order"
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\TRANSPORTS\Network Transport Modules\{F7CE2E13-8C90-11D1-9E7B-00C04FC324A8}\ "Independent"
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\ "EnablePrivateObjectHeap"
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\ "EnableObjectValidation"


Registry Enums:


==============================================================================
Service Management
==============================================================================
Open Service Manager - Name: (SCM) Start Type: ()
Open Service - Name: (SharedAccess) Start Type: ()

==============================================================================
System Info
==============================================================================
Get System Directory
Get Computer Name
Get System Time

==============================================================================
Window
==============================================================================
Enum Windows

==============================================================================
Winsock
==============================================================================

Opening Listening TCP Connection - Local Port: 43633 - Connection Established: 0 - Socket: 512

Report generated at 8/8/2006 4:54:29 PM with CWSandbox Version Beta 1.80
This analysis was created by the CWSandbox Copyright © 2006 Carsten Willems
Copyright © 1996-2006 Sunbelt Software. All rights reserved.


.


==
Moore
-----------------------------------------------------
- Round 3 -
-----------------------------------------------------

Loaded up the full version of Processguard & SSM instead of using the free versions of PG & SSM that I used in the previous runs above and went back again.

This time Processguard had no problems blocking the lzx32.sys file which gets dropped into the system32 folder along with various other hijack files distributed throughout the whole system.



The files are mainly dropped into windows / cdrive / system32 and temporary internet files folder. The hosts file is modified to block the majority of antivirus sites and registry run keys and internet explorer start page are hijacked , among other things.

No this isnt a update for Lavasoft's Ad-aware..

Kfmvqgl.exe - http ://download.lavasoftupdate.com/traff/piglett.exe - C:\KFMVQGL.EXE



Hardly a surprise that estdomains are involved , seems all the worst malware comes from them , netcat hosting and Atrivotech/Intercage over the last few years since obviously no one in charge really cares what runs on their networks.

QUOTE
download.lavasoftupdate.com = [ 85.255.114.149 ]
Registration Service Provided By: ESTDOMAINS
Contact: 1.3027224217
Website: http ://www.estdomains.com
Domain Name: LAVASOFTUPDATE.COM
Registrant:
Deloitte corp.
Andrzej Zborowski andrzboro@yahoo.com

Kielbasniza 16
Wroclaw
50127
PL
Tel. 48.223799110
Creation Date: 02-Jun-2005
Expiration Date: 02-Jun-2007
Domain servers in listed order:
ns1.lavasoftupdate.com
ns2.lavasoftupdate.com

Administrative Contact:
Deloitte corp.
Andrzej Zborowski andrzboro@yahoo.com
Kielbasniza 16
Wroclaw
50127
PL
Tel. 48.223799110
Status: ACTIVE


----------------------------------------------------------------------------------------


Why this kind of attack against people is not illegal or worried about by any of the authorities out there I have no idea.. blink.gif


QUOTE
--------------------------------------------------------------------------------

Apache/2.0.53 (Fedora) Server at zdfttygzjm.biz Port 80

------------------------------------------------------------------------------


















































































---------------

:: HTTPLog ::

---------------

CODE
http ://zdfttygzjm.biz/dl/adv596.php - C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
http ://zdfttygzjm.biz/dl/xpladv596.wmf - C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
http ://zdfttygzjm.biz/dl/loaderadv596_1.exe - C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE

Internet Explorer - http ://zdfttygzjm.biz/dl/java.jar - C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Internet Explorer - http ://zdfttygzjm.biz/dl/bag.htm -C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Internet Explorer - http ://zdfttygzjm.biz/dl/Parser.class - C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Internet Explorer - http://zdfttygzjm.biz/dl/Parser.class - C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Internet Explorer - http ://zdfttygzjm.biz/dl/loaderadv596_2.exe - C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Internet Explorer - http ://zdfttygzjm.biz/progs_traff/mygmf/upxdngdji - C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE

Pyiyj.exe - http ://inthehoom/trial.php?rest=0&ver=16182540&a=00000001 - C:\PYIYJ.EXE

A.exe - http ://zdfttygzjm.biz/progs_traff/mygmf/sfvbyroxdk.php - C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\A.EXE

Dtdftcu.exe - http://81.95.147.107/cgi-bin/cert.cgi - C:\DTDFTCU.EXE

A.exe - http ://zdfttygzjm.biz/progs_traff/mygmf/gxjpify- C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\A.EXE

Dtdftcu.exe - http ://81.95.147.107/cgi-bin/options.cgi?u...id=723471888291&passphrase=fkjvhsdvlksdhvlsd - C:\DTDFTCU.EXE

A.exe - http ://zdfttygzjm.biz/progs_traff/mygmf/fgrbhunt.php - C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\A.EXE

A.exe - http ://zdfttygzjm.biz/progs_traff/mygmf/nedfpv[/url] - C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\A.EXE

Dtdftcu.exe - http ://81.95.147.107/cgi-bin/options.cgi?u...id=723471888291&passphrase=fkjvhsdvlksdhvlsd - C:\DTDFTCU.EXE

A.exe - http ://zdfttygzjm.biz/progs_traff/mygmf/bwcjf.php - C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\A.EXE

Dtdftcu.exe - http://81.95.147.107/cgi-bin/options.cgi?u...id=723471888291&passphrase=fkjvhsdvlksdhvlsd - C:\DTDFTCU.EXE

Kfmvqgl.exe - http://download.lavasoftupdate.com/traff/piglett.exe - C:\KFMVQGL.EXE

A.exe - http ://zdfttygzjm.biz/progs_traff/mygmf/gtwcmjf.php - C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\A.EXE

A.exe - http ://zdfttygzjm.biz/progs_traff/mygmf/dqcifpmib.php[/url] - C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\A.EXE

A.exe - http ://zdfttygzjm.biz/progs_traff/mygmf/ulxdjtcjsy.php - C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\A.EXE

A.exe - http ://zdfttygzjm.biz/progs_traff/mygmf/yikdagw - C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\A.EXE

Mgcg.exe - http ://zhmbscwdgk.biz/uniq.php - C:\MGCG.EXE

A.exe - http ://zdfttygzjm.biz/progs_traff/mygmf/ne...&code2=9135[/url]    - C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\A.EXE



Then A.exe became a casualty laugh.gif ...


-------------------------------------------------------------------------------

-----------------------------
SYSTEM
-----------------------------

lzx32.sys
pigglett.exe
popspig
thematrixhasyou.exe
vdrvvar^.exe

-----------------------------
WINDOWS
-----------------------------

msdef4.exe
services.exe

-----------------------------
C:\
-----------------------------

dtdftcu.exe
hnqakqj.exe
isksxj.exe
mgcg.exe
pyiyj.exe
secure32.html
ubwq.exe
uniq
vacwey.exe
winstall.exe
wrrislv.exe

-----------------------------

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html

O4 - HKLM\..\RunServices: [pigglett] c:\windows\system32\pigglett.exe
O4 - HKCU\..\Run: [RPCser32g4] C:\WINDOWS\SYSTEM32\SERVICES.EXE

-----------------------------

Scanned files results- [ both Jotti and virustotal were overloaded so used the kaspersky online scan and sunbelt sandbox ]

=============
:: Files ::
=============

isksxj.exe drops the lzx32.sys file

Kasperky online scanner:

isksxj.exe - infected by Trojan-Clicker.Win32.Costrat.k
lzx32.sys - infected by Trojan-Clicker.Win32.Costrat.j

:: Virustotal ::

isksxj.exe

QUOTE
STATUS: FINISHED
Complete scanning result of "isksxj.exe",
received in VirusTotal at 08.14.2006, 16:54:49 (CET).

Antivirus Version Update Result
AntiVir 6.35.1.0 08.14.2006 TR/Agent.TW.1
Authentium 4.93.8 08.13.2006 no virus found
Avast 4.7.844.0 08.14.2006 no virus found
AVG 386 08.14.2006 Clicker.CQU
BitDefender 7.2 08.14.2006 Trojan.Agent.TW
CAT-QuickHeal 8.00 08.14.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 08.14.2006 no virus found
DrWeb 4.33 08.14.2006 Trojan.Spambot
eTrust-InoculateIT 23.72.94 08.14.2006 no virus found
eTrust-Vet 30.3.3019 08.14.2006 no virus found
Ewido 4.0 08.13.2006 no virus found
Fortinet 2.77.0.0 08.13.2006 suspicious
F-Prot 3.16f 08.13.2006 no virus found
F-Prot4 4.2.1.29 08.13.2006 no virus found
Ikarus 0.2.65.0 08.14.2006 no virus found
Kaspersky 4.0.2.24 08.14.2006 Trojan-Clicker.Win32.Costrat.k
McAfee 4828 08.13.2006 no virus found
Microsoft 1.1560 08.14.2006 no virus found
NOD32v2 1.1705 08.14.2006 probably unknown NewHeur_PE virus
Norman 5.90.23 08.14.2006 no virus found
Panda 9.0.0.4 08.14.2006 no virus found
Sophos 4.08.0 08.14.2006 no virus found
Symantec 8.0 08.14.2006 no virus found
TheHacker 5.9.8.192 08.14.2006 no virus found
UNA 1.83 08.11.2006 no virus found
VBA32 3.11.0 08.13.2006 no virus found

Aditional Information
File size: 73216 bytes
MD5: 444a499c5413999a8a21f6d4c4e5608b
SHA1: 46f5cd4e1cf912e37339eac5157288e7f5bf64cd
packers: embedded



lzx32.sys

QUOTE
STATUS: FINISHED
Complete scanning result of "lzx32.sys",
received in VirusTotal at 08.14.2006, 18:27:24 (CET).

Antivirus Version Update Result
AntiVir 6.35.1.0 08.14.2006 no virus found
Authentium 4.93.8 08.14.2006 no virus found
Avast 4.7.844.0 08.14.2006 no virus found
AVG 386 08.14.2006 no virus found
BitDefender 7.2 08.14.2006 no virus found
CAT-QuickHeal 8.00 08.14.2006 no virus found
ClamAV devel-20060426 08.14.2006 no virus found
DrWeb 4.33 08.14.2006 Trojan.Spambot
eTrust-InoculateIT 23.72.94 08.14.2006 no virus found
eTrust-Vet 30.3.3019 08.14.2006 no virus found
Ewido 4.0 08.14.2006 no virus found
Fortinet 2.77.0.0 08.13.2006 suspicious
F-Prot 3.16f 08.14.2006 no virus found
F-Prot4 4.2.1.29 08.14.2006 no virus found
Ikarus 0.2.65.0 08.14.2006 no virus found
Kaspersky 4.0.2.24 08.14.2006 Trojan-Clicker.Win32.Costrat.j
McAfee 4829 08.14.2006 no virus found
Microsoft 1.1560 08.14.2006 no virus found
NOD32v2 1.1706 08.14.2006 no virus found
Norman 5.90.23 08.14.2006 no virus found
Panda 9.0.0.4 08.14.2006 no virus found
Sophos 4.08.0 08.14.2006 no virus found
Symantec 8.0 08.14.2006 no virus found
TheHacker 5.9.8.192 08.14.2006 no virus found
UNA 1.83 08.11.2006 no virus found
VBA32 3.11.0 08.13.2006 no virus found
VirusBuster 4.3.7:9 08.14.2006 no virus found

File Size: 68120 bytes
MD5: b948ddcc9d665f3cf668f65bb4deb4d9
SHA1: 287c789473b516ce3b49e643ba382707274ab09a



====

Scanned file: gxjpify[1].txt - Infected
gxjpify.txt - infected by Trojan-Clicker.Win32.Costrat.k

Still waiting for sandbox report

====

Scanned file: a.exe - Infected
a.exe - infected by Trojan-Downloader.Win32.Small.dib

==

Scanned file: vacwey.exe - Infected
vacwey.exe - infected by Trojan-PSW.Win32.Sinowal.ao

==

Scanned file: fgrbhunt[1].htm - Infected
fgrbhunt[1].htm - infected by Trojan.Win32.Harnig.a

==

Scanned file: fillmemadv596[1].htm - Infected
fillmemadv596[1].htm - infected by Exploit.JS.CVE-2005-1790.j

==

Scanned file: iqpiflhe[1].txt - Infected
iqpiflhe[1].txt - infected by not-virus:Hoax.Win32.Renos.cn

==

Scanned file: java[1].jar - Infected

java[1].jar/META-INF/MANIFEST.MF - OK
java[1].jar/GetAccess.class - infected by Trojan-Downloader.Java.OpenConnection.aj
java[1].jar/Installer.class - infected by Trojan-Downloader.Java.OpenConnection.aj
java[1].jar/NewSecurityClassLoader.class - OK
java[1].jar/NewURLClassLoader.class - OK

==

Scanned file: loaderadv596_2[1].exe - Infected
loaderadv596_2[1].exe - infected by Trojan-Downloader.Win32.Small.dib

==

mgcg.exe - infected by Trojan-Downloader.Win32.Small.ctf
msdef4.exe - infected by Backdoor.Win32.Prexot.b
pyiyj.exe - infected by not-virus:Hoax.Win32.Renos.cn
secure32.html - infected by Trojan.Win32.Harnig.a
services.exe - infected by Backdoor.Win32.Prexot.b
TheMatrixHasYou.exe - infected by Trojan-Proxy.Win32.Small.bo
ubwq.exe - infected by Backdoor.Win32.Prexot.b
upxdngdji[1].txt - infected by Trojan-PSW.Win32.Sinowal.ao
vacwey.exe - infected by Trojan-PSW.Win32.Sinowal.ao
winstall.exe - infected by not-virus:Hoax.Win32.Renos.cn


==============================================

undetected by kaspersky online scanner :

dtdftcu.exe
hnqakqj.exe
loaderadv596.jar
pigglett.exe
sfvbyroxdk.htm
vdrvVAR^.exe
wrrislv.exe


==============================================

vdrvVAR^.exe results


Norman Sandbox:

QUOTE
vdrvVAR^.exe : [SANDBOX] contains a security risk - W32/Malware (Signature: NO_VIRUS)
[ General information ]
* File might be compressed.
* Decompressing FSG.
* File length: 14864 bytes.
* MD5 hash: 016fab21854de4881f261a5b2e55fdb7.

[ Changes to filesystem ]
* Deletes file C:\WINDOWS\SYSTEM32\pigglett.exe.
* Creates file C:\WINDOWS\SYSTEM32\pigglett.exe.

[ Changes to registry ]
* Sets value "ATI_VER"="Cs7?" in key "HKLM\Software\Microsoft".
* Creates value "pigglett"="c:\windows\system32\pigglett.exe" in key
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
* Creates value "pigglett"="c:\windows\system32\pigglett.exe" in key
"HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices".
* Creates value "pigglett"="c:\windows\system32\pigglett.exe" in key
"HKCU\Software\Microsoft\Windows\CurrentVersion\Run".

[ Network services ]
* Opens URL: http:///pukaka/access.php.

[ Security issues ]
* Possible backdoor functionality [UNKNOWN] port 5899.

[ Process/window information ]
* Creates a mutex 4457319-QdmJgU.
* Will automatically restart after boot (I'll be back...).

[ Signature Scanning ]
* C:\WINDOWS\SYSTEM32\pigglett.exe (14864 bytes) : no signature detection.


Sunbelt/CWS Sandbox:

QUOTE
CWSandbox Analysis report for file: 016fab21854de4881f261a5b2e55fdb7.exe

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 1 (c:\temp\016fab21854de4881f261a5b2e55fdb7.exe MD5:
[016fab21854de4881f261a5b2e55fdb7], PID 652, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


==============================================================================
DLL-Handling
==============================================================================
Loaded DLL - DLL: (c:\temp\016fab21854de4881f261a5b2e55fdb7.exe)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\user32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\oleaut32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MSVCRT.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\OLE32.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\comctl32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\wsock32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Secur32.dll)
Loaded DLL - DLL: (KERNEL32.dll)
Loaded DLL - DLL: (USER32.dll)
Loaded DLL - DLL: (ADVAPI32.dll)
Loaded DLL - DLL: (MSVCRT.dll)
Loaded DLL - DLL: (comctl32.dll)
Loaded DLL - DLL: (WININET.dll)
Loaded DLL - DLL: (WS2_32.dll)

==============================================================================
Filesystem Changes
==============================================================================
Copy File: c:\temp\016fab21854de4881f261a5b2e55fdb7.exe to
C:\WINDOWS\System32\pigglett.exe
Find File: pigglett.exe
Delete File: C:\WINDOWS\System32\pigglett.exe
Open File: \SystemRoot\AppPatch\sysmain.sdb (OPEN_EXISTING),
(FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES), (SHARE_READ),
(FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: \SystemRoot\AppPatch\systest.sdb (OPEN_EXISTING),
(FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES), (SHARE_READ),
(FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING),
(FILE_ANY_ACCESS,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE,FILE_ADD_SUBDIR
ECTORY,FILE_APPEND_DATA,FILE_CREATE_PIPE_INSTANCE,FILE_WRITE_EA,FILE_WRITE_ATTRIB
UTES),
(), (FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Open File: C:\WINDOWS\System32\pigglett.exe (),
(FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY),
(SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)

==============================================================================
Registry Changes
==============================================================================
Create or Open:
HKEY_LOCAL_MACHINE\Software\Microsoft\ -


Registry Changes:
HKEY_LOCAL_MACHINE\Software\Microsoft\\ "ATI_VER" = ([REG_DWORD, value: 44E0891C])


Registry Reads:


Registry Enums:


==============================================================================
Process Management
==============================================================================
Creates Process - Filename () CommandLine: (C:\WINDOWS\System32\pigglett.exe)
Target PID: (1664) As User: () Creation Flags: (DETACHED_PROCESS)

==============================================================================
System Info
==============================================================================
Get System Directory

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 2 (C:\WINDOWS\System32\pigglett.exe MD5:
[016fab21854de4881f261a5b2e55fdb7], PID 1664, User: Administrator)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


==============================================================================
DLL-Handling
==============================================================================
Loaded DLL - DLL: (C:\WINDOWS\System32\pigglett.exe)
Loaded DLL - DLL: (C:\WINDOWS\System32\ntdll.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\kernel32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\user32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\GDI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\ADVAPI32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\RPCRT4.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\oleaut32.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\MSVCRT.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\OLE32.DLL)
Loaded DLL - DLL: (C:\WINDOWS\system32\comctl32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\wsock32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2_32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\WS2HELP.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Wship6.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\iphlpapi.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\pstorec.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\ATL.DLL)
Loaded DLL - DLL: (C:\WINDOWS\System32\mswsock.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\DNSAPI.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\winrnr.dll)
Loaded DLL - DLL: (C:\WINDOWS\system32\WLDAP32.dll)
Loaded DLL - DLL: (C:\WINDOWS\System32\Secur32.dll)
Loaded DLL - DLL: (KERNEL32.dll)
Loaded DLL - DLL: (USER32.dll)
Loaded DLL - DLL: (ADVAPI32.dll)
Loaded DLL - DLL: (MSVCRT.dll)
Loaded DLL - DLL: (comctl32.dll)
Loaded DLL - DLL: (WININET.dll)
Loaded DLL - DLL: (WS2_32.dll)
Loaded DLL - DLL: (ICMP.DLL)
Loaded DLL - DLL: (RASAPI32.DLL)
Loaded DLL - DLL: (RTUTILS.DLL)
Loaded DLL - DLL: (SHELL32.dll)
Loaded DLL - DLL: (netapi32.dll)

==============================================================================
Filesystem Changes
==============================================================================
Find File: C:\Documents and Settings\All Users\Application
Data\Microsoft\Network\Connections\Pbk\*.pbk
Find File: C:\WINDOWS\System32\Ras\*.pbk
Find File: C:\Documents and Settings\Administrator\Application
Data\Microsoft\Network\Connections\Pbk\*.pbk
Create File: C:\WINDOWS\System32\popspig
Open File: \\.\PIPE\svcctl (OPEN_EXISTING), (FILE_ANY_ACCESS),
(SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: \\.\PIPE\lsarpc (OPEN_EXISTING), (FILE_ANY_ACCESS),
(SHARE_READ,SHARE_WRITE), (SECURITY_ANONYMOUS)
Open File: c:\autoexec.bat (OPEN_EXISTING), (FILE_ANY_ACCESS), (SHARE_READ),
(FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS)
Get File Attributes: C:\WINDOWS\System32\popspig Flags: (SECURITY_ANONYMOUS)
Get File Attributes: c:\autoexec.bat Flags: (SECURITY_ANONYMOUS)

==============================================================================
Mutex Changes
==============================================================================
Creates Mutex: 4457319-QdmJgU
Creates Mutex: RasPbFile

==============================================================================
Registry Changes
==============================================================================
Create or Open:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices -
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run -
HKEY_LOCAL_MACHINE\Software\Microsoft\ -


Registry Changes:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
"pigglett" = (c:\windows\system32\pigglett.exe)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ "pigglett" =
(c:\windows\system32\pigglett.exe)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ "pigglett" =
(c:\windows\system32\pigglett.exe)


Registry Reads:
HKEY_LOCAL_MACHINE\Software\Microsoft\\ "ATI_VER"


Registry Enums:


==============================================================================
Service Management
==============================================================================
Open Service Manager - Name: (SCM) Start Type: ()
Open Service - Name: (RASMAN) Start Type: ()

==============================================================================
System Info
==============================================================================
Get System Directory
Get Computer Name

==============================================================================
User Management
==============================================================================
Impersonate User - Domain: () User: (Administrator) Host: () Handle: (532)

==============================================================================
Winsock
==============================================================================

Opening Listening TCP Connection - Local Port: 43633 - Connection Established: 0 -
Socket: 744

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Processes 3 (services.exe MD5: [], PID 536, User: SYSTEM)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@


Report generated at 8/14/2006 10:33:52 AM with CWSandbox Version Beta 1.80
This analysis was created by the CWSandbox Copyright © 2006 Carsten Willems
Copyright © 1996-2006 Sunbelt Software. All rights reserved.



==============

Added to system32/drivers/etc/hosts

:: Hosts file blocks ::

==============

Adding these to the hosts file prevents the infected user from being able to download anti-virus updates , visit any of the following sites for help , or to scan their computers with online virus scanners:

127.0.0.1 avp.com
127.0.0.1 ca.com
127.0.0.1 customer.symantec.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 download.mcafee.com
127.0.0.1 downloads-eu1.kaspersky-labs.com
127.0.0.1 downloads-us1.kaspersky-labs.com
127.0.0.1 downloads1.kaspersky-labs.com
127.0.0.1 downloads2.kaspersky-labs.com
127.0.0.1 downloads3.kaspersky-labs.com
127.0.0.1 downloads4.kaspersky-labs.com
127.0.0.1 f-secure.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 kaspersky.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 mast.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 microsoft.com
127.0.0.1 my-etrust.com
127.0.0.1 nai.com
127.0.0.1 networkassociates.com
127.0.0.1 oxyd.fr
127.0.0.1 pandasoftware.com
127.0.0.1 rads.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 sophos.com
127.0.0.1 symantec.com
127.0.0.1 t35.com
127.0.0.1 t35.net
127.0.0.1 trendmicro.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 viruslist.com
127.0.0.1 virustotal.com
127.0.0.1 www.avp.com
127.0.0.1 www.ca.com
127.0.0.1 www.f-secure.com
127.0.0.1 www.grisoft.com
127.0.0.1 www.kaspersky.com
127.0.0.1 www.mcafee.com
127.0.0.1 www.microsoft.com
127.0.0.1 www.my-etrust.com
127.0.0.1 www.nai.com
127.0.0.1 www.networkassociates.com
127.0.0.1 www.oxyd.fr
127.0.0.1 www.pandasoftware.com
127.0.0.1 www.sophos.com
127.0.0.1 www.symantec.com
127.0.0.1 www.t35.com
127.0.0.1 www.t35.net
127.0.0.1 www.trendmicro.com
127.0.0.1 www.viruslist.com
127.0.0.1 www.virustotal.com


=============================================
Moore
Found another file scan in my spam box ..

Norman Scanner Engine 5.90. 7
Sandbox 05.90, dated 11/06-2006

Your message ID (for later reference): 20060814-972


services.exe : [SANDBOX] contains a security risk - W32/Malware (Signature: NO_VIRUS)
[ General information ]

* File might be compressed.
* Decompressing Petite[2].
* Creating several executable files on hard-drive.
* File length: 39457 bytes.
* MD5 hash: bc8cfe0d6b5498eb08bb3191b1184bc9.

[ Changes to filesystem ]
* Creates file C:\WINDOWS\services.exe.
* Creates file C:\WINDOWS\msdef4.exe.
* Deletes file C:\WINDOWS\mstempf.exe.
* Creates file C:\WINDOWS\mstempf.exe.

[ Changes to registry ]
* Sets value "Msrewfdarh4"="?" in key "HKCU\Software\Microsoft\Internet
Explorer".
* Creates value "RPCser32g4"="C:\WINDOWS\services.exe" in key
"HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
* Sets value "Start"="" in key
"HKLM\System\CurrentControlSet\Services\SharedAccess".
* Sets value "IEPgfsgdc4"="" in key "HKCU\Software\Microsoft\Internet Explorer".
* Sets value "EnableFirewall"="" in key
"HKLM\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy".
* Sets value "EnableFirewall"="" in key
"HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy".
* Sets value "DisableRegistryTools"="" in key
"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies".
* Sets value "DisableRegistryTools"="" in key
"HKLM\Software\Microsoft\Windows\CurrentVersion\policies".

[ Network services ]
* Looks for an Internet connection.
* Connects to "11proc.com" on port 80 (TCP).
* Connects to "101.0.168.1" on port 445 (IP).
* Connects to "101.0.168.2" on port 445 (IP).
* Connects to "49mag.com" on port 80 (TCP).
* Connects to "101.0.168.3" on port 445 (IP).
* Connects to "101.0.168.4" on port 445 (IP).
* Connects to "101.0.168.2" on port 20044 (TCP).
* Connects to "101.0.168.1" on port 20044 (TCP).
* Connects to "101.0.168.5" on port 445 (IP).
* Connects to "101.0.168.3" on port 20044 (TCP).
* Connects to "101.0.168.6" on port 445 (IP).
* Connects to "101.0.168.4" on port 20044 (TCP).
* Connects to "101.0.168.7" on port 445 (IP).
* Connects to "101.0.168.5" on port 20044 (TCP).
* Connects to "101.0.168.8" on port 445 (IP).
* Connects to "101.0.168.6" on port 20044 (TCP).
* Connects to "101.0.168.9" on port 445 (IP).
* Connects to "101.0.168.10" on port 445 (IP).
* Connects to "101.0.168.8" on port 20044 (TCP).
* Connects to "101.0.168.7" on port 20044 (TCP).
* Connects to "101.0.168.11" on port 445 (IP).
* Connects to "101.0.168.9" on port 20044 (TCP).
* Connects to "101.0.168.12" on port 445 (IP).
* Connects to "101.0.168.10" on port 20044 (TCP).
* Connects to "101.0.168.13" on port 445 (IP).
* Connects to "101.0.168.11" on port 20044 (TCP).
* Connects to "101.0.168.14" on port 445 (IP).
* Connects to "101.0.168.15" on port 445 (IP).
* Connects to "101.0.168.13" on port 20044 (TCP).
* Connects to "101.0.168.16" on port 445 (IP).
* Connects to "101.0.168.14" on port 20044 (TCP).
* Connects to "101.0.168.17" on port 445 (IP).
* Connects to "101.0.168.15" on port 20044 (TCP).
* Connects to "101.0.168.12" on port 20044 (TCP).
* Connects to "101.0.168.18" on port 445 (IP).
* Connects to "101.0.168.16" on port 20044 (TCP).
* Connects to "101.0.168.19" on port 445 (IP).
* Connects to "101.0.168.17" on port 20044 (TCP).
* Connects to "101.0.168.20" on port 445 (IP).
* Connects to "101.0.168.18" on port 20044 (TCP).

[ Security issues ]
* Possible backdoor functionality [UNKNOWN] port 10006.
* Exploits MS04-011 vulnerability.

[ Process/window information ]
* Creates a mutex agfdfgsasdfdawqkw.
* Will automatically restart after boot (I'll be back...).

[ Signature Scanning ]
* C:\WINDOWS\services.exe (39457 bytes) : no signature detection.
* C:\WINDOWS\msdef4.exe (39457 bytes) : no signature detection.


Received 14.Aug 2006 at 20.30 - processed 15.Aug 2006 at 23.38.



49mag.com = [ 66.185.126.50 ]

Domain Name : 49mag.com
: :Registrant: :
Name : don mazza
Email : Don-mazza@hotmail.com
Address : 1111 E Cabrillo Blvd
Zipcode : 93111
Nation : US
Tel : 9822867217
Fax :
: :Administrative Contact: :
Name : don mazza
Email : Don-mazza@hotmail.com
Address : 1111 E Cabrillo Blvd
Zipcode : 93111
Nation : US
Tel : 9822867217
Fax :
: :Technical Contact: :
Name : don mazza
Email : Don-mazza@hotmail.com
Address : 1111 E Cabrillo Blvd
Zipcode : 93111
Nation : US
Tel : 9822867217
Fax :
: :Name Servers: :
dns1.49mag.com
dns2.49mag.com
dns111.49mag.com
dns112.49mag.com
: :Dates & Status: :
Created Date 2006-05-29 16: 04: 38 EDT
Updated Date 2006-05-29 16: 04: 38 EDT
Valid Date 2007-05-29 16: 04: 38 EDT
Status ACTIVE



11proc.com = [ 66.185.126.50 ]

Domain Name : 11proc.com
: :Registrant: :
Name : don mazza
Email : Don-mazza@hotmail.com
Address : 1111 E Cabrillo Blvd
Zipcode : 93111
Nation : US
Tel : 9822867217
Fax :
: :Administrative Contact: :
Name : don mazza
Email : Don-mazza@hotmail.com
Address : 1111 E Cabrillo Blvd
Zipcode : 93111
Nation : US
Tel : 9822867217
Fax :
: :Technical Contact: :
Name : don mazza
Email : Don-mazza@hotmail.com
Address : 1111 E Cabrillo Blvd
Zipcode : 93111
Nation : US
Tel : 9822867217
Fax :
: :Name Servers: :
dns1.11proc.com
dns2.11proc.com
: :Dates & Status: :
Created Date 2006-05-29 16: 02: 14 EDT
Updated Date 2006-05-29 16: 02: 14 EDT
Valid Date 2007-05-29 16: 02: 14 EDT
Status ACTIVE



66.185.126.50 - IP hosts 5 Total Domains ...

Domain Name
1 11METODO.COM.
2 11PROC.COM.
3 49MAG.COM.
4 HACHAPURI.NET.
5 YOMOEDOMKA.COM.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.