a worm - tel.xls.exe

上一篇 / 下一篇  2006-10-31 02:19:43 / 天氣: 晴朗 / 心情: 高興 / 個人分類:Security

File name: tel.xls.exe
Size: 48.0 KB (49,152 bytes)
Checksum: d88f7c6c15585404c30c92a11c429c36 (MD5)
Packer: None
Written in: Visual Basic 6
Virus detected as:
  • KAV: Trojan.Win32.VB.atg
  • Duba: -
  • Rising: -
  • KV: -
Details:
    File System Change(s):
  1. After execution,the file replicates itself to:
    • %System%\SocksA.exe
    • %System%\algsrv.exe
    • %System%\FileKan.exe

      PS: %System% is an environment variable.This represent the System32 folder in Windows NT/2000/XP/Server 2003 (eg. C:\Windows\System32 )

  2. It also replicates itsef to all fixed drives and renamed as tel.xls.exe
  3. Create autorun.inf to all fixed drives
  4. After replicating the files,it executes explorer.exe with parameter %SystemDrive%,Windows Explorer will be shown

    Registry Change(s):
  1. Create the following values to HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    • "ASocksrv" = "SocksA.exe"
    • "BSserver" = "FileKan.exe"
  2. Modify the value "CheckedValue" in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL

Removal Procedure:
  1. Press Ctrl + Alt + Del to execute Windows Task Manager,terminate the following processes:
    • SocksA.exe
    • algsrv.exe
    • FileKan.exe
  2. Delete the autorun.inf files
  3. Delete the tel.xls.exe files
  4. Delete the following files:
    • %System%\SocksA.exe
    • %System%\algsrv.exe
    • %System%\FileKan.exe

      PS: %System% is an environment variable.This represent the System32 folder in Windows NT/2000/XP/Server 2003 (eg. C:\Windows\System32 )
Comment: In fact,this is a worm
Write-up by: Krazaf/tkabc

TAG: Security

 

評分:0

我來說兩句

顯示全部

:loveliness: :handshake :victory: :funk: :time: :kiss: :call: :hug: :lol :'( :Q :L ;P :$ :P :o :@ :D :( :)

日曆

« 2012-04-20  
1234567
891011121314
15161718192021
22232425262728
2930     

數據統計

  • 訪問量: 6590
  • 日誌數: 21
  • 文件數: 3
  • 建立時間: 2006-08-20
  • 更新時間: 2007-01-22

RSS訂閱

Open Toolbar