<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" title="XSL Formatting" href="virus.xsl" media="all"?>
<rss version="2.0"><channel>
		<title>	<![CDATA[Anchiva latest virus list]]></title>
		<image>
			<title><![CDATA[Anchiva virus information]]></title>
			<link>http://www.anchiva.com/virus </link>
			<url>http://www.anchiva.com/images/en/logo.jpg </url>
		</image>
		<description><![CDATA[Anchiva latest virus list]]></description>
		<link>http://www.anchiva.com/virus/</link>
		<language>en-us,en;q=0.5</language>
		<generator>WWW.ANCHIVA.COM</generator>
		<copyright><![CDATA[Copyright&copy; 2005-2009 Anchiva Systems, Inc. All rights reserved worldwide.]]></copyright>		
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Ransom.AE49]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Ransom.AE49</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Ransom.AE49</guid>
			<pubDate>2010-3-10 9:57:51</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>&nbsp;&nbsp; This Trojan arrives in the affected system as dropped or downloaded file by other malwares or unsuspecting users.<br />
&nbsp;&nbsp; Upon execution,it modifies the following registry entry to enable its automatic execution and disables Task Manager.It searches for anti-virus processes,sends the information of the affected machine to remote host,pops the warning that levys a ransom on user.</p><br /><br /><strong>Technical_details</strong><br /><p>It terminates itself once found the folllowing processes in the affected system.</p>
<ul>
    <li>gcasServ.exe&nbsp;</li>
    <li>SpybotSD.exe&nbsp;</li>
    <li>Ad-Aware.exe</li>
    <li>sunasServ.exe</li>
    <li>spysweeper.exe</li>
    <li>PPActiveDetection.exe</li>
    <li>msscli.exe</li>
    <li>Tmas.exe</li>
    <li>swdoctor.exe</li>
    <li>spycatcher.exe</li>
    <li>avp.exe</li>
    <li>ekrn.exe</li>
    <li>avguard.exe</li>
    <li>dwengine.exe</li>
</ul>
<p>It modifies the following registry entry to enable its automatic execution at system reboot:<br />
&nbsp;&nbsp;&nbsp;&nbsp; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&nbsp;</p>
<ul>
    <li>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Userinit = &quot;%System%\userinit.exe, %CurrentPath%\Currentname.exe,&quot;</li>
</ul>
<p>It creates the following registry entry to disable Task Manager<br />
&nbsp;&nbsp; HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Policies\System</p>
<ul>
    <li>&nbsp;&nbsp;&nbsp;&nbsp; DisableTaskMgr = 00000001</li>
</ul>
<p>&nbsp;HKEY_USERS\S-1-5-21-1275210071-299502267-725345543-1003\Software\Microsoft\Windows\Currentversion\Policies\System</p>
<ul>
    <li>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; DisableTaskMgr = 00000001</li>
</ul>
<p>It connects to following address to send the information of the affected host.</p>
<ul>
    <li>http://94.102.51.150/preinstall?r=21&amp;id={ID}&amp;a=0&amp;checksum=Number</li>
</ul>
<p>It pops the warning that levy a ransom on user.</p>
<p><img alt="" style="width: 614px; height: 465px" src="/virus/upload/image/shenc/2010-03-09.jpg" /></p>
<p>main points：</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; It requirs the user to pay for online-porn-vedio-service,and it declares: Any fail to pay or knowing attempt to defraud will damage your computer and information.</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/OnLineGames.2B17]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/OnLineGames.2B17</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/OnLineGames.2B17</guid>
			<pubDate>2010-3-8 16:03:53</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This spyware is Anchiva's detection for a certain DLL file that is dropped by Spyware/Onlinegames variant.<br />
It is also launched by infected system DLL in the infected system,then steals the user login info and sends them to a remote user via HTTPpost.</p><br /><br /><strong>Technical_details</strong><br /><p>This spyware is Anchiva's detection for a certain DLL file that is dropped by Spyware/Onlinegames variant.<br />
It is also launched by infected system DLL(mostly&nbsp;is dsound.dll) in the infected system.<br />
It can reads the game directory(&quot;user\uicommon.ini&quot;) to get configuration info and steals JXSJ's login-info and then sends them to a remote user via HTTP post.</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Encrypt.21DD]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Encrypt.21DD</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Encrypt.21DD</guid>
			<pubDate>2010-3-5 13:51:58</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This malware arrives as a dropped file of another malware. It can also be downloaded by user by visting malicious websites.<br />
It downloads other malware into the affected system and execute it.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution,It randomly traverse the following URL list to download a malware and save it as %system32%\{random string}.exe(It also detected as Trojan/Encrypt.21DD by ANCHIVA) and execute it.</p>
<ul>
    <li>http://www.52{BLOCKED}.cn/sports/image.jpg</li>
    <li>http://www.52{BLOCKED}.cn/news/image.jpg</li>
    <li>http://www.52{BLOCKED}.cn/files/image.jpg</li>
    <li>http://www.52{BLOCKED}.cn/nba//image.jpg</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Worm/IRCBot.B045@net]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/IRCBot.B045@net</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/IRCBot.B045@net</guid>
			<pubDate>2010-3-4 13:33:02</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>&nbsp;This worm mainly propagates via removalbe drives,it may also be downloaded by other malwares or unsuspecting users.<br />
&nbsp;It opens random TCP ports to connect to an Internet Relay Chat (IRC) server and joins an IRC channel. Once connected, it acts as a backdoor that allows a remote malicious user to issue commands locally on an affected machine to perform some tasks.&nbsp;<br />
&nbsp;It also infects removable drives and hard disk drives.</p><br /><br /><strong>Technical_details</strong><br /><p>&nbsp;It injects dll to iexplorer.exe,and copies itself as follow name:<br />
&nbsp; %ProgramFiles%\Internet Explorer\svchost.exe<br />
&nbsp; <br />
&nbsp;It creates the following registry entries to enable its automatic execution at system reboot:<br />
&nbsp;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&nbsp;&quot;system32.exe&quot;=&quot;%USERPROFILE%\Application Data\Microsoft\system32.exe&quot;<br />
&nbsp;<br />
&nbsp;It also drops &quot;Autorun.inf&quot; and a copy of itself to the removable drive and hard disk drives.<br />
&nbsp;<br />
&nbsp;It opens random TCP ports to connect to an Internet Relay Chat (IRC) server and joins an IRC channel. Once connected, it acts as a backdoor that allows a remote malicious user to issue commands locally on an affected machine to perform some tasks.&nbsp;<br />
&nbsp;</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Refroso.298E]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Refroso.298E</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Refroso.298E</guid>
			<pubDate>2010-3-3 13:58:29</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This Trojan arrives in the affected system as a dropped or downloaded file by other malwares or unsuspecting users.</p>
<p>It copies itself into the system and registers itself in the Windows startup.</p>
<p>It makes contact with the resident Internet connection by opening a pre-specified TCP port. This action enables backdoor access to a remote hacker.</p>
<p>In addition to opening a backdoor, it also is a keylogger,it monitors user's input-information and saves them,then sends the sensitive infomation to the attacker via http post.</p><br /><br /><strong>Technical_details</strong><br /><p>This Trojan arrives in the affected system as a dropped or downloaded file by other malwares or unsuspecting users.</p>
<p>Upon execution,It drops following files:</p>
<ul>
    <li>%AppData%\addons.dat&nbsp; - backdoor files</li>
    <li>%Program Files%\Bifrost\logg.dat - keylogger files</li>
    <li>%Program Files%\Bifrost\server.exe - copy of itself</li>
</ul>
<p>It creates follow registry entry to enable its automatic run:</p>
<ul>
    <li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}&nbsp;
    <ul>
        <li>stubpath=%Program Files%\Bifrost\server.exe s</li>
    </ul>
    </li>
</ul>
<p>It also creates follow registry entries related to backdoor and keylogger:</p>
<ul>
    <li>HKEY_CURRENT_USER\Software\Bifrost
    <ul>
        <li>klg=&quot;hex:01,&quot;</li>
    </ul>
    </li>
    <li>HKEY_CURRENT_USER\Software\Bifrost&nbsp;
    <ul>
        <li>plg1=&quot;hex:ea,44,dc,02,a3,27,{...},3a,d8,5a,8f,41,&quot;</li>
    </ul>
    </li>
    <li>HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost&nbsp;
    <ul>
        <li>nck=&quot;hex:ed,1b,e6,27,b9,28,d6,32,74,c3,cd,74,fa,93,5b,67, &quot;</li>
    </ul>
    </li>
    <li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo&nbsp;
    <ul>
        <li>&quot;&quot;=&quot;&quot;</li>
    </ul>
    </li>
    <li>HKEY_USERS\S-1-5-21-1390067357-1935655697-839522115-1003\Software\Bifrost&nbsp;
    <ul>
        <li>klg=&quot;hex:01,&quot;</li>
    </ul>
    </li>
    <li>HKEY_USERS\S-1-5-21-1390067357-1935655697-839522115-1003\Software\Bifrost&nbsp;
    <ul>
        <li>plg1=&quot;hex:ea,44,dc,02,a3,27,{...},3a,d8,5a,8f,41,&quot;</li>
    </ul>
    </li>
</ul>
<p>It makes contact with the resident Internet connection by opening a pre-specified TCP port. This action enables backdoor access to a remote hacker. <br />
In addition to opening a backdoor, it also is a keylogger,it monitors user's input-information and saves them,then sends the sensitive infomationto the attacker via follow address.</p>
<ul>
    <li>moooon15.no-ip.biz:{pre-specified TCP port}</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Vilsel.E0A2!drop]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Vilsel.E0A2!drop</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Vilsel.E0A2!drop</guid>
			<pubDate>2010-3-2 16:23:02</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;This Trojan arrives in the affected system as dropped or downloaded file by other malwares or unsuspecting users.<br />
&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;Upon execution,it copys the system file %system%\sfc_os.dll to %systemroot%\my_sfc_os.dll,and invokes fcFileException function(unnamed API at oridinal 5) to disable WFP(Windows File Protection).Then renames the system file %system%\comres.dll as %system%\hunsa4.dll,drops a new file %Windows%\comres.dll which to enable this malicious dll component can automatic run at every system reboot.It also&nbsp;kills the process qq.exe.<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The new comres.dll steals some onlinegames-relative account,password and other sensitive information,then it sends the gained information to special Email&nbsp;address&nbsp;via specified links.It also downloads other file.</p><br /><br /><strong>Technical_details</strong><br /><p>It copys the system file %system%\sfc_os.dll to %systemroot%\my_sfc_os.dll,and invokes fcFileException function(unnamed API at oridinal 5) to disable WFP(Windows File Protection).Then renames the system file %system%\comres.dll as %system%\hunsa4.dll,deletes the file %System%\dllcache\comres.dll,drops a new file %Windows%\comres.dll.</p>
<ul>
    <li>&nbsp; %System%\hunsa4.dll&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; --the original comres.dll&nbsp;</li>
    <li>&nbsp; %Windows%\comres.dll&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; --detected by Anchiva as Spyware/OnLineGames.AABC</li>
    <li>&nbsp; %Windows%\my_sfc_os.dll&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; --the copy of sfc_os.dll</li>
    <li>&nbsp; %System%\dllcache\comres.dll&nbsp;&nbsp; --deleted&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</li>
    <li>&nbsp; %Windows%\hpig_WS2.dat&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; --used to save the Configuration Information&nbsp;&nbsp;&nbsp;</li>
</ul>
<p>The malicious dll steals the following onlinegames-relative account,password and other sensitive information:</p>
<ul>
    <li>qq.exe</li>
    <li>asdegame.exe</li>
    <li>glworld.exe</li>
    <li>QQLogin.exe</li>
</ul>
<p>The malicious dll sends the gained information to special Email via the following links.</p>
<ul>
    <li>http://fw98.com/2010/qq/mail.asp?tomail=hehe@163.com&amp;mailbody=</li>
    <li>http://fw98.com/2010/lz/mail.asp?tomail=hehe@163.com&amp;mailbody=</li>
    <li>http://fw98.com/2010/bf/mail.asp?tomail=hehe@163.com&amp;mailbody=</li>
    <li>http://fw98.com/2010/dnf/mail.asp?tomail=hehe@163.com&amp;mailbody=</li>
    <li>http://www.xxx.com/qq070809/mail.asp?tomail=xxx@163.com&amp;mailbody=</li>
</ul>
<p>The malicious dll connects to following address to download files.<br />
&nbsp;&nbsp;&nbsp;&nbsp; jy74.cn/t2/houmen/rows.exe<br />
when this writting ,the said addresses are already unavailable.</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Exploit/MSOLE2.Maldrp.BB87]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Exploit/MSOLE2.Maldrp.BB87</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Exploit/MSOLE2.Maldrp.BB87</guid>
			<pubDate>2010-3-1 15:12:27</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This exploit drops a malware onto the affected system. It is usually delivered via email attachments, as a component of targeted attacks. When unsuspecting user opens such mal-crafted documents, sensitive information maybe in danger of loss. It is also possible to install certain backdoors, and being controlled by the remote attacker.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution, it leverages certain vulnerabilities of Microsoft Office to execute arbitrary code, usually download or drop other malware.</p>
<ul>
    <li>%TEMP%/svchost.exe - Detected by Anchiva as <strong>Trojan/Buzus.1AE8</strong></li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/Zbot.220B]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Zbot.220B</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Zbot.220B</guid>
			<pubDate>2010-2-25 13:30:57</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; This Spyware arrives in the affected system as dropped or downloaded file by other malwares or unsuspecting users,or junk email's attachment.<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; It drops a copy of itself in the Windows system folder and creates a folder with attributes set to System and Hidden to prevent users from discovering and removing its components. It modifies a registry entry to enable its automatic execution at every system reboot. It also injects itself into processes as part of its memory residency routine.This Spyware attempts to access a Web site to download file.It maybe steal sensitive online banking information.</p><br /><br /><strong>Technical_details</strong><br /><p>It checks for the following processes which are related to Outpost Personal Firewall and ZoneLabs Firewall Client:</p>
<ul>
    <li>outpost.exe</li>
    <li>zlclient.exe</li>
</ul>
<p>It creates a copy of itself into %System%\sdra64.exe and add some garbage at the end of it in order to have a different md5 hash thus trying to avoid av detection.</p>
<ul>
    <li>&nbsp;&nbsp;&nbsp; %System%\sdra64.exe</li>
</ul>
<p>It will then create the following folder and files with attributes set to System and Hidden to prevent users from discovering and removing its components:</p>
<ul>
    <li>%System%\lowsec&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -folder</li>
    <li>%System%\lowsec\local.ds</li>
    <li>%System%\lowsec\user.ds&nbsp; - used to save the gathered information</li>
</ul>
<p>It hooks API NtQueryDirectoryFile function to hide the files given above.<br />
It trys to inject itself into the all processes as part of its memory residency routine except for csrss.exe processe.<br />
It modifies the following registry entry to enable its automatic execution at system reboot:<br />
&nbsp;&nbsp;&nbsp;&nbsp; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&nbsp;</p>
<ul>
    <li>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Userinit = &quot;%System%\userinit.exe, %System%\sdra64.exe,&quot;</li>
</ul>
<p>It also creates the following registry entry as part of its installation routine:<br />
&nbsp;&nbsp;&nbsp;&nbsp; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network&nbsp;</p>
<ul>
    <li>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; UID = &quot;{Computer name}_{Random numbers}&quot;</li>
</ul>
<p>It also creates the following registry entry to disable Windows Firewall:<br />
&nbsp;&nbsp;&nbsp; HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile&nbsp;</p>
<ul>
    <li>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; EnableFirewall = &quot;0&quot;</li>
</ul>
<p>It connects to following address to download files.<br />
&nbsp;&nbsp;&nbsp;&nbsp; http://symyho3393245.cn/tmp.dat<br />
when this writting ,the said addresses are already unavailable.</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/FakeAV.33D9!packed]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/FakeAV.33D9!packed</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/FakeAV.33D9!packed</guid>
			<pubDate>2010-2-22 15:17:31</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>&nbsp;This trojan arrives in the affected system as downloaded file by other malwares or unsuspecting users.It may also be distributes by Email as attachment.<br />
&nbsp;It downloads other malwares to the affected system.</p><br /><br /><strong>Technical_details</strong><br /><p>&nbsp;Upon execution,It downloads malwares via follow urls and launch them.<br />
&nbsp;http://95.143.192.38/pr/pic/main.exe <br />
&nbsp; http://195.88.190.44/pr/pic/main.exe <br />
&nbsp; http://195.88.190.44/pr/pic/fixer_sdgareh_b.exe <br />
&nbsp; http://95.143.192.38/pr/pic/fixer_sdgareh_b.exe</p>
<p>&nbsp; The downloaded malwares were always fake Antivirus.</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/HTML.IFrame.51C6]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/HTML.IFrame.51C6</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/HTML.IFrame.51C6</guid>
			<pubDate>2010-2-21 14:07:04</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This trojan is a variant of the Trojan/HTML.IFrame family. It is hosted by malicious site, and usualy be delivered to the affected system as componet of drive-by-download attack. A hidden iframe is embedded in the malicious file, which leads to a bunch of other malicious scripts, further downloads other malware.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution, it first checks if certain security related softwares have been installed, and loads malicious script or redirects to blank page accordingly. This check lists are as follows:</p>
<ul>
    <li>res://C:\\Program%20Files\\360\\360Safe\\360hotfix.exe/GIF/172</li>
    <li>res://D:\\program%20files\\360safe\\360hotfix.exe/GIF/172</li>
    <li>res://C:\\program%20files\\360safe\\360hotfix.exe/GIF/172</li>
    <li>res://D:\\Program%20Files\\360\\360Safe\\360hotfix.exe/GIF/172</li>
    <li>res://e:\\Program%20Files\\360\\360Safe\\360hotfix.exe/GIF/172</li>
    <li>res://f:\\Program%20Files\\360\\360Safe\\360hotfix.exe/GIF/172</li>
    <li>res://C:\\Program%20Files\\Rising\\Rav\\rssafety.exe/PNG/123</li>
    <li>res://D:\\Program%20Files\\Rising\\Rav\\rssafety.exe/PNG/123</li>
    <li>res://e:\\Program%20Files\\Rising\\Rav\\rssafety.exe/PNG/123</li>
    <li>res://f:\\Program%20Files\\Rising\\Rav\\rssafety.exe/PNG/123</li>
    <li>res://C:\\program%20files\\360safe\\360Safe.exe/GIF/172</li>
    <li>res://D:\\program%20files\\360safe\\360Safe.exe/GIF/172</li>
    <li>res://E:\\program%20files\\360safe\\360Safe.exe/GIF/172</li>
    <li>res://F:\\program%20files\\360safe\\360Safe.exe/GIF/172</li>
    <li>res://C:\\program%20files\\360\\360safe\\360Safe.exe/GIF/172</li>
    <li>res://D:\\program%20files\\360\\360safe\\360Safe.exe/GIF/172</li>
    <li>res://E:\\program%20files\\360\\360safe\\360Safe.exe/GIF/172</li>
    <li>res://F:\\program%20files\\360\\360safe\\360Safe.exe/GIF/172</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/StartPage.776D!drop]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/StartPage.776D!drop</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/StartPage.776D!drop</guid>
			<pubDate>2010-2-23 14:59:31</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This malware arrives in the affected system as dropped or downloaded file by other malwares or unsuspecting users.<br />
Upon execution,it drops a script file and launch it,then drops lots of Website url linkings to the Favorites Folder, and modifies the start page through replacing &quot;Internet Explorer&quot; in desktop and Quick Launch.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution，it drops following script file and launch it via cscript.exe:</p>
<ul>
    <li>c:\y2.jse - detected by anchiva as Trojan/StartPage.1D43</li>
</ul>
<p>The script file drops lots of Website url linkings to the Favorites folder:</p>
<ul>
    <li>C:\Documents and Settings\User Name\Favorites\绿色下载站.url</li>
    <li>C:\Documents and Settings\User Name\Favorites\三只涨停黑马股票推荐.url</li>
    <li>C:\Documents and Settings\User Name\Favorites\淘宝特卖.url&nbsp;&nbsp;</li>
    <li>C:\Documents and Settings\User Name\Favorites\网络赚钱宝典.url</li>
    <li>C:\Documents and Settings\User Name\Favorites\最实用的减肥丰胸方法大全.url</li>
    <li>C:\Documents and Settings\User Name\Favorites\链接\绿色下载站.url</li>
    <li>C:\Documents and Settings\User Name\Favorites\链接\三只涨停黑马股票推荐.url</li>
    <li>C:\Documents and Settings\User Name\Favorites\链接\淘宝特卖.url&nbsp;&nbsp;</li>
    <li>C:\Documents and Settings\User Name\Favorites\链接\网络赚钱宝典.url</li>
    <li>C:\Documents and Settings\User Name\Favorites\链接\最实用的减肥丰胸方法大全.url</li>
</ul>
<p>also drops following files:</p>
<ul>
    <li>C:\Documents and Settings\User Name\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.ywk -replacing &quot;Internet Explorer&quot; in Quick Launch</li>
    <li>C:\Documents and Settings\User Name\桌面\Internet Explorer.ywk -replacing &quot;Internet Explorer&quot; in Desktop</li>
    <li>C:\Documents and Settings\User Name\桌面\淘宝特卖.ywk</li>
    <li>C:\Documents and Settings\User Name\[开始]菜单\程序\启动\y2.jse - copy of itself</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/ACVE.3FBC!dldr]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/ACVE.3FBC!dldr</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/ACVE.3FBC!dldr</guid>
			<pubDate>2010-2-12 9:11:02</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>&nbsp;This trojan arrives in the affected system as downloaded file by other malwares or unsuspecting users.<br />
&nbsp;It drops components to system,closes processes of Antivirus,and downloads other malwares.</p><br /><br /><strong>Technical_details</strong><br /><p>&nbsp;It drops follow components to system:<br />
&nbsp;%windir%/jiocs.dll--detected by Anchiva as Backdoor/Inject.72E5<br />
&nbsp;%temp%/78767551--detected by Anchiva as Rootkit/Agent.4F6E<br />
&nbsp;%temp%/{random}.dll--detected by Anchiva as Spyware/RunMalware.633F<br />
&nbsp;<br />
&nbsp;It download malware list via http://www.l63.ln.cn/1128.txt as follow name.<br />
&nbsp;%windir%\sadfasdf.jpg<br />
&nbsp;<br />
&nbsp;It get malware URL from the list,continue with downloading and runing the malware.<br />
&nbsp;<br />
&nbsp;It close follow processes of Antivirus:<br />
&nbsp;safeboxTray.exe<br />
&nbsp;360tray.exe<br />
&nbsp;psapi.dll<br />
&nbsp;kavstart.exe<br />
&nbsp;kissvc.exe<br />
&nbsp;kmailmon.exe<br />
&nbsp;kpfw32.exe<br />
&nbsp;kpfwsvc.exe<br />
&nbsp;kwatch.exe<br />
&nbsp;ccenter.exe<br />
&nbsp;ras.exe<br />
&nbsp;rstray.exe<br />
&nbsp;rsagent.exe<br />
&nbsp;ravtask.exe<br />
&nbsp;ravstub.exe<br />
&nbsp;ravmon.exe<br />
&nbsp;ravmond.exe<br />
&nbsp;avp.exe<br />
&nbsp;360safebox.exe<br />
&nbsp;360Safe.exe<br />
&nbsp;rfwmain.exe<br />
&nbsp;rfwstub.exe<br />
&nbsp;rfwsrv.exe</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/HTML.IFrame.F06E]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/HTML.IFrame.F06E</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/HTML.IFrame.F06E</guid>
			<pubDate>2010-2-11 14:06:06</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This trojan is a variant of the family Trojan/HTML.IFrame. It is a component of drive-by-download attack toolkits, mostly hosted by malicious site. When unsuspecting user visits certain infected web page, other malwares will be downloaded without user consent, leading to further system compromise.</p><br /><br /><strong>Technical_details</strong><br /><p>It contains a bunch of hidden iframes, pointing to other remote malicious JavaScripts, which usually leverage certain vulnerabilities of operating system or 3rd party software components to execute arbitrary code. It first check where the visitor comes from via the refer, and load other malicious script accordingly. Those malicious urls are blocked by Anchiva's Malicious Site as well.</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Worm/IRCBot.E2D3@net]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/IRCBot.E2D3@net</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/IRCBot.E2D3@net</guid>
			<pubDate>2010-2-10 13:55:32</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This worm may be dropped by other malware. It may arrive via network shares. It may be downloaded unknowingly by a user when visiting malicious web sites.</p>
<p>It opens random TCP ports to connect to an Internet Relay Chat (IRC) server and joins an IRC channel. Once connected, it acts as a backdoor that allows a remote malicious user to issue commands locally on an affected machine to perform some tasks such as DDOS.</p><br /><br /><strong>Technical_details</strong><br /><p>It opens random TCP ports to connect to an Internet Relay Chat (IRC) server:</p>
<ul>
    <li>irc.bifferent.net</li>
</ul>
<p>Port:6667<br />
Channel:#starttrouble<br />
Nick:Acolyte_{random letter}</p>
<p>Once connected, it acts as a backdoor that allows a remote malicious user to issue commands locally on an affected machine.The commands listed following:</p>
<ul>
    <li>!UPTIME</li>
    <li>!RECONNECT</li>
    <li>!OPEN</li>
    <li>!DELETE</li>
    <li>!RAW</li>
    <li>!DDOSICMP</li>
    <li>!DDOSUDP</li>
    <li>!DDOSSYN</li>
    <li>!DDOSSTOP</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Downloader.F743]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Downloader.F743</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Downloader.F743</guid>
			<pubDate>2010-2-9 14:39:17</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This malware arrives as a dropped file of another malware. It can also be downloaded by user by visting malicious websites.<br />
It downloads other malwares into the affected system and then runs them.&nbsp;</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution,It downloads&nbsp;two malwares from&nbsp;following urls&nbsp;and save it as &quot;c:\1.exe&quot; and .Then launch them.</p>
<ul>
    <li>195.88.190.36/pr/pic/fixer_sdgareh_b.exe(%windows%/Temp/_ex-68.exe) detect as Trojan/FakeAv.3403</li>
    <li>83.133.122.160/pr/pic/fixer_sdgareh_b.exe(%windows%/Temp/_ex-68.exe) detect as Trojan/FakeAv.3403</li>
    <li>195.88.190.36/pr/pic/sys.exe(%windows%/Temp/_ex-08.exe) detect as Trojan/Downloader.F743</li>
    <li>83.133.122.160/pr/pic/sys.exe(%windows%/Temp/_ex-08.exe) detect as Trojan/Downloader.F743</li>
</ul>
<p>&nbsp;</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Exploit/JS.CVE-2010-0249.7684]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Exploit/JS.CVE-2010-0249.7684</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Exploit/JS.CVE-2010-0249.7684</guid>
			<pubDate>2010-2-8 14:16:23</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This exploit leverages certain vulnerabilities of Internet Explorer to execute arbitrary remote code. It is usually hosted by malicious site, delivered by drive-by-download attacks. When unsuspecting user visits such infected web page, other malware will be downloaded and leading to further system compromise.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution, it takes advantage of an Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 to execute arbitrary remote code, usually download other malware.</p>
<ul>
    <li><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx">MS10-002</a></li>
    <li><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0249">CVE-2010-0249</a></li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Backdoor/Robobot.8E53]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Backdoor/Robobot.8E53</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Backdoor/Robobot.8E53</guid>
			<pubDate>2010-2-5 14:29:55</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>&nbsp;&nbsp; This backdoor arrives in the affected system as E-mail attachment,it may also be downloaded by other malwares or unsuspecting users.<br />
&nbsp; &nbsp;Upon execution,it closes system service,downloads other malware,get remote instructions to control local computer.<br />
&nbsp; &nbsp;It also sends malicious E-mail.</p><br /><br /><strong>Technical_details</strong><br /><p>&nbsp;&nbsp;&nbsp;It copies itself as name of %windir%\System\csrss.exe<br />
&nbsp; &nbsp;<br />
&nbsp; &nbsp;It creates the following registry entries to enable its automatic execution at system reboot:<br />
&nbsp;&nbsp;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&nbsp;&nbsp;&quot;system32.exe&quot;=&quot;%USERPROFILE%\Application Data\Microsoft\system32.exe&quot;<br />
&nbsp;&nbsp;<br />
&nbsp;&nbsp;It closes systems security service,and creates follow registry to enable its access to internet.<br />
&nbsp;&nbsp; HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List<br />
&nbsp;&nbsp; C:\WINDOWS\System\csrss.exe=&quot;%windir%\System\csrss.exe:*:Enabled:Microsoft Update&quot;&nbsp;<br />
&nbsp;&nbsp; <br />
&nbsp;&nbsp; It downloads other malware via follow URL:<br />
&nbsp;&nbsp; http://upseek.org/u/upd_0003.exe<br />
&nbsp;&nbsp; <br />
&nbsp;&nbsp; It connects to one of follow IRC servers,and gets instructions to control local computer.<br />
&nbsp;&nbsp;ad.fonarez.com:1021<br />
&nbsp;&nbsp;ad.dartonfire.com:1088<br />
&nbsp;&nbsp;php.gondatme.com:5190&nbsp;&nbsp; <br />
&nbsp;&nbsp;<br />
&nbsp;&nbsp;It get download URL from IRC backdoor,and downloads E-mail content,and then sends to specified receivers.</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Worm/SPYBOT.2440@mm]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/SPYBOT.2440@mm</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/SPYBOT.2440@mm</guid>
			<pubDate>2010-2-3 18:50:55</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This worm arrives as attachment to email messages spammed by another malware or a malicious user,it also Propagates via peer-to-peer networks. It drops copies of itself in all removable drives. It drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.It drops other malicious component to system directory and creates registry key(s) as part of its installation routine.<br />
It drops copies of itself in folders used in peer-to-peer networks. It uses attractive file names for its dropped copies. It sends junk email and uses the copy of itself as attachment and induce user to open it.</p><br /><br /><strong>Technical_details</strong><br /><p>This worm arrives as attachment to email messages spammed by another malware or a malicious user.The content of email has some different forms.We get one of them and place a&nbsp;snapshot of these emails here,take a look:</p>
<p><img alt="" style="width: 656px; height: 464px" src="http://www.eshidai520.com/spamer.jpg" /></p>
<p>it harvests email adresses from file using the following extention in the affected system:</p>
<ul>
    <li>&nbsp;txt</li>
    <li>&nbsp;htm</li>
    <li>&nbsp;xml</li>
    <li>&nbsp;php</li>
    <li>&nbsp;asp</li>
    <li>&nbsp;dbx</li>
    <li>&nbsp;log</li>
    <li>&nbsp;nfo</li>
    <li>&nbsp;lst</li>
    <li>&nbsp;rtf</li>
    <li>&nbsp;xml</li>
    <li>&nbsp;wpd</li>
    <li>&nbsp;wps</li>
    <li>&nbsp;xls</li>
    <li>&nbsp;doc</li>
    <li>&nbsp;wab</li>
</ul>
<p>and it dont send the email to the address with following strings:</p>
<ul>
    <li>berkeley</li>
    <li>mit.e</li>
    <li>ibm.com</li>
    <li>debian</li>
    <li>kernel</li>
    <li>linux</li>
    <li>usenet</li>
    <li>rfc-ed</li>
    <li>sendmail</li>
    <li>arin.</li>
    <li>sun.com</li>
    <li>isi.e</li>
    <li>isc.o</li>
    <li>secur</li>
    <li>acketst</li>
    <li>apache</li>
    <li>tanford.e</li>
    <li>utgers.ed</li>
    <li>mozilla</li>
    <li>firefox</li>
    <li>redhat</li>
    <li>sourceforge</li>
    <li>slashdot</li>
    <li>samba</li>
    <li>cisco</li>
    <li>syman</li>
    <li>panda</li>
    <li>avira</li>
    <li>f-secure</li>
    <li>ERS\flp</li>
    <li>sopho</li>
    <li>www.ca.com</li>
    <li>ahnlab</li>
    <li>novirusthanks</li>
    <li>prevx</li>
    <li>drweb</li>
    <li>bitdefender</li>
    <li>clamav</li>
    <li>eset.com</li>
    <li>ikarus</li>
    <li>mcafee</li>
    <li>kaspersky</li>
    <li>virusbuster</li>
    <li>badware</li>
    <li>immunityinc.com</li>
    <li>avg.comsysinternals</li>
    <li>borlan</li>
    <li>inpris</li>
    <li>lavasoft</li>
    <li>jgsoft</li>
    <li>ghisler.com</li>
    <li>wireshark</li>
    <li>winpcap</li>
    <li>acdnet.com</li>
    <li>acdsystems.com</li>
    <li>acd-group</li>
    <li>bpsoft.com</li>
    <li>2\DRI</li>
    <li>buyrar.com</li>
    <li>bluewin.ch</li>
    <li>quebecor.com</li>
    <li>alcatel-lucent.com</li>
    <li>ssh.com</li>
    <li>winamp</li>
    <li>nullsoft.org</li>
    <li>example</li>
    <li>mydomai</li>
    <li>nodomai</li>
    <li>ruslis</li>
    <li>virus</li>
    <li>messagelabs</li>
    <li>honeynet</li>
    <li>honeypot</li>
    <li>security</li>
    <li>idefense</li>
    <li>qualys</li>
    <li>samples</li>
    <li>postmaster</li>
    <li>webmaster</li>
    <li>noone</li>
    <li>nobody</li>
    <li>nothing</li>
    <li>anyone</li>
    <li>someone</li>
    <li>rating</li>
    <li>contact</li>
    <li>somebody</li>
    <li>privacy</li>
    <li>service</li>
    <li>submit</li>
    <li>sales</li>
    <li>gold-certs</li>
    <li>the.bat</li>
    <li>admin</li>
    <li>icrosoft</li>
    <li>support</li>
    <li>ntivi</li>
    <li>linux</li>
    <li>listserv</li>
    <li>certific</li>
    <li>security</li>
    <li>ot\Syst</li>
    <li>secur</li>
    <li>abuse</li>
</ul>
<p>and the email address of the sender also can be the following:</p>
<ul>
    <li>e-cards@hallmark.com</li>
    <li>invitations@twitter.com</li>
    <li>invitations@hi5.com</li>
    <li>order-update@amazon.com</li>
    <li>resume-thanks@google.com</li>
</ul>
<p>and the subject of the email may like following:<br />
&nbsp;</p>
<ul>
    <li>You have received A Hallmark E-Card!</li>
    <li>Your friend invited you to twitter!</li>
    <li>Jessica would like to be your friend on hi5!</li>
    <li>Shipping update for your Amazon.com order 254-71546325-658732</li>
    <li>Thank you from Google!</li>
</ul>
<p>and the email message may be like any of following:<br />
&nbsp;</p>
<p>There's something special about that E-Card feeling. We invite you to make a friend's day and send one.<br />
Hope to see you soon,Your friends at Hallmark.</p>
<p>be your friend on hi5!&nbsp; I set up a hi5 profile and I want to add you as a friend so we can share pictures and start building our network. <br />
First see your invitation card I attached! Once you join, you will have a chance to create a profile, share pictures, and find friends.</p>
<p>Shipping update for your Amazon.com order 254-78546325-658742.Please check the attachment and confirm your shipping details.</p>
<p>selected and others that may be a fit. Should there be a suitable match, we will be sure to get in touch with you. Click on the attached file to review your submitted application.Have fun and thanks again for applying to Google!</p>
<p>and the file name of the attachment may be like following:</p>
<ul>
    <li>Postcard</li>
    <li>Invitation Card</li>
    <li>Shipping documents</li>
    <li>CV-20100120-112</li>
</ul>
<p>This worm creates the following folders:</p>
<p>C:\Documents and Settings\{username}\Application Data\SystemProc <br />
It drops the following copy of itself:</p>
<ul>
    <li>%System%\GoogleUpdate.exe</li>
</ul>
<p>It drops the following file:</p>
<ul>
    <li>%System%\stacsv.exe - it detected by anchiva as:Worm/SPYBOT.2440@mm</li>
    <li>%Windows%\bootstat.ocx -none malicious file where save the keypress and the name running processes</li>
    <li>C:\Documents and Settings\{username}\Application Data\SystemProc\lsass.exe - also detected as Worm/SPYBOT.2440@mm</li>
</ul>
<p>It adds the following keys as part of its installation routine:</p>
<ul>
    <li>HKEY_CURRENT_USER\Software\Microsoft\Google1</li>
    <li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4207UWF4-IXEP-UTPF-2TDE-6606643L1T10}</li>
    <li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Google1</li>
</ul>
<p>This worm creates the following registry entries to enable its automatic execution at every system startup:<br />
&nbsp;</p>
<p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run<br />
Sun Java Updater = &quot;%System%\stacsv.exe&quot;</p>
<p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run<br />
Google Update = &quot;%System%\GoogleUpdate.exe&quot;</p>
<p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run<br />
Sun Java Updater = &quot;%System%\stacsv.exe&quot;</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4207UWF4-IXEP-UTPF-2TDE-6606643L1T10}<br />
StubPath = &quot;%System%\stacsv.exe&quot;</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run<br />
RTHDBPL = &quot;C:\Documents and Settings\{username}\Application Data\SystemProc\lsass.exe&quot;</p>
<p>This worm drops copies of itself in the following peer-to-peer shared folders:<br />
&nbsp;</p>
<ul>
    <li>C:\program files\bearshare\shared\</li>
    <li>C:\program files\edonkey2000\incoming\</li>
    <li>C:\program files\emule\incoming\</li>
    <li>C:\program files\grokster\my grokster\</li>
    <li>C:\program files\icq\shared folder\</li>
    <li>C:\program files\kazaa lite k++\my shared folder\</li>
    <li>C:\program files\kazaa lite\my shared folder\</li>
    <li>C:\program files\kazaa\my shared folder\</li>
    <li>C:\program files\limewire\shared\</li>
    <li>C:\program files\morpheus\my shared folder\</li>
    <li>C:\program files\tesla\files\</li>
    <li>C:\program files\winmx\shared\</li>
</ul>
<p>It uses the following file names for its dropped copies:</p>
<ul>
    <li>AOL Instant Messenger (AIM) Hacker.exe</li>
    <li>AOL Password Cracker.exe</li>
    <li>Brutus FTP Cracker.exe</li>
    <li>Counter-Strike KeyGen.exe</li>
    <li>DCOM Exploit.exe</li>
    <li>DivX 5.0 Pro KeyGen.exe</li>
    <li>FTP Cracker.exe</li>
    <li>Half-Life 2 Downloader.exe</li>
    <li>Hotmail Cracker.exe</li>
    <li>Hotmail Hacker.exe</li>
    <li>ICQ Hacker.exe</li>
    <li>IP Nuker.exe</li>
    <li>Keylogger.exe</li>
    <li>L0pht 4.0 Windows Password Cracker.exe</li>
    <li>Microsoft Visual Basic KeyGen.exe</li>
    <li>Microsoft Visual C++ KeyGen.exe</li>
    <li>Microsoft Visual Studio KeyGen.exe</li>
    <li>MSN Password Cracker.exe</li>
    <li>NetBIOS Cracker.exe</li>
    <li>NetBIOS Hacker.exe</li>
    <li>Norton Anti-Virus 2005 Enterprise Crack.exe</li>
    <li>Password Cracker.exe</li>
    <li>sdbot with NetBIOS Spread.exe</li>
    <li>Sub7 2.3 Private.exe</li>
    <li>UT 2003 KeyGen.exe</li>
    <li>Website Hacker.exe</li>
    <li>Windows 2003 Advanced Server KeyGen.exe</li>
    <li>Windows Password Cracker.exe</li>
</ul>
<p>This worm drops copies of itself in all removable drives,and the content of the said AUTORUN.inf file like following strings:<br />
[autorun]<br />
open=RECYCLER\S-1-6-21-2434476521-1645641927-702000330-1542\redmond.exe<br />
icon=%SystemRoot%\system32\SHELL32.dll,4<br />
action=Open folder to view files<br />
shell\open=Open<br />
shell\open\command=RECYCLER\S-1-6-21-2434476521-1645641927-702000330-1542\redmond.exe<br />
shell\open\default=1</p>
<p>&nbsp;</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Qakbot.F73C]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Qakbot.F73C</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Qakbot.F73C</guid>
			<pubDate>2010-2-4 13:59:07</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>&nbsp;&nbsp;&nbsp; This Trojan arrives in the affected system as dropped or downloaded file by other malwares or unsuspecting users.It may also arrive via infected removable drives.<br />
&nbsp;&nbsp;&nbsp;&nbsp; Upon execution,This Trojan creates a folder named &quot;Microsoft Common&quot; and copys itself into it,and spreads itself with autorun.inf file via removable drives.In addition,it injects its code into processes svchost.exe and explorer.exe.Then the infected process explorer.exe will delete itself,and the infected process svchost.exe will connect to remote host,post sensitive information, acquire commands which will lead to complete the relevant operations.</p><br /><br /><strong>Technical_details</strong><br /><p>Unpon execution,This Trojan creates a folder named &quot;Microsoft Common&quot; and copys itself into it:</p>
<ul>
    <li>&nbsp;&nbsp; %Program File%\Microsoft Common\svchost.exe</li>
</ul>
<p>It creates the following registry entry to enable its automatic run at every system startup:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe&nbsp;&nbsp;</p>
<ul>
    <li>&nbsp; Debugger = %Program File%\Microsoft Common\svchost.exe</li>
</ul>
<p>If a new removable drive is connected to an infected system, the malware will create a copy of itself to removable drives along with an autostart.inf which may lead to automatic execution of the dropped file upon the disk's access.</p>
<p>It injects its code into processes svchost.exe.Then the infected process svchost.exe will connect to remote host,post sensitive information(OS ProductId),acquire commands which will lead to complete the relevant operations.<br />
The command such as：</p>
<ul>
    <li>[number]|OS-ProductId.[options].[parameter]</li>
</ul>
<p>number:<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; It may be index of the OS-ProductId or affected machine&nbsp;<br />
options:<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; d:download and launch file,[parameter] is the download address&nbsp;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; w:Wait,[parameter] is the time for wait&nbsp;&nbsp;<br />
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;x:download and launch file,[parameter] is the download address</p>
<p>when this writting ,it will connect to following address to download and launch malicious file<br />
&nbsp;&nbsp; http://109.{block}.115.34/ee/ltr1.exe&nbsp;&nbsp;&nbsp;--- detect as Spyware/Zbot.4615 by Anchiva</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Worm/Warezov.580A@mm]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/Warezov.580A@mm</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/Warezov.580A@mm</guid>
			<pubDate>2010-2-3 11:26:32</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This&nbsp;worm may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.</p>
<p>It drops some files in the Windows system folder and it will create some registry entries to enable its automatic execution at every system startup.</p>
<p>It captures lots of user's sensitive information and send them to a appointed URL.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution it will drop the following files:</p>
<ul>
    <li>%system32%\msswmsjt.exe - copy of itself</li>
    <li>%system32%\cdfvmydo.exe - detected by anchiva as Worm/Warezov.492C@mm</li>
    <li>%system32%\e1.dll - detected by anchiva as Worm/Warezov.6A9A@mm</li>
    <li>%system32%\msyunv4_.dll - detected by anchiva as Worm/Warezov.F862@mm</li>
    <li>%system32%\ntmsdisp.dll - detected by anchiva as Worm/Warezov.AFE1@mm</li>
</ul>
<p>It creates or modifies the following registry entry so that it runs every time Windows starts:</p>
<ul>
    <li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    <ul>
        <li>msswmsjt=&quot;%system32%\msswmsjt.exe&quot;</li>
    </ul>
    </li>
    <li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    <ul>
        <li>AppInit_DLLs=&quot; ntmsdisp.dll e1.dll&quot;</li>
    </ul>
    </li>
</ul>
<p>It terminates certain services related to the following Firewall:</p>
<ul>
    <li>ZoneAlarm</li>
    <li>Sygate Personal Firewall</li>
    <li>SharedAccess</li>
    <li>Symantec Internet Security</li>
    <li>Agnitum Outpost Firewall</li>
    <li>McAfee Personal Firewall</li>
    <li>kerio winroute firewall</li>
</ul>
<p>It injects e1.dll into following process to terminates related service.</p>
<ul>
    <li>tbmon</li>
    <li>spiderml</li>
    <li>autodown</li>
    <li>mcupdate</li>
    <li>nod32krn</li>
    <li>wuauclt1</li>
    <li>upgrader</li>
    <li>avgupsvc</li>
    <li>drwebupw</li>
    <li>explorer</li>
    <li>avginet</li>
    <li>wupdmgr</li>
    <li>wuauclt</li>
    <li>kavsv</li>
    <li>kav</li>
</ul>
<p>It downloads and executes unknown malware from the following website:</p>
<ul>
    <li>post{blocked}rds-3.com/bt1308.exe</li>
</ul>
<p>It captures lots of user's sensitive information and send them to a appointed URL.</p>
<ul>
    <li>postcards-3.com</li>
</ul><br /><br />]]></description>
		</item>
		
	</channel>
</rss>