<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" title="XSL Formatting" href="virus.xsl" media="all"?>
<rss version="2.0"><channel>
		<title>	<![CDATA[Anchiva latest virus list]]></title>
		<image>
			<title><![CDATA[Anchiva virus information]]></title>
			<link>http://www.anchiva.com/virus</link>
			<url>http://www.anchiva.com/images/en/logo.jpg</url>
		</image>
		<description><![CDATA[Anchiva latest virus list]]></description>
		<link>http://www.anchiva.com/virus/</link>
		<language>en-us,en;q=0.5</language>
		<generator>WWW.ANCHIVA.COM</generator>
		<copyright><![CDATA[Copyright&copy; 2004-2008 Anchiva Systems, Inc. All rights reserved worldwide.]]></copyright>		
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Agent.C86E!dldr]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Agent.C86E!dldr</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Agent.C86E!dldr</guid>
			<pubDate>11/17/2008 7:47:08 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br />This trojan may be dropped by other malware or downloaded unknowingly by a user when visiting malicious Web sites.This trojan is a malware downloader that will download a text file that contain malicious urls which can be used by this trojan&nbsp;to download and execute other malware.<br /><br /><strong>Technical_details：</strong><br /><P>This trojan may be dropped by other malware or downloaded unknowingly by a user when visiting malicious Web sites.This trojan is a malware downloader that will download a text file that contain malicious urls which can be used by this trojan&nbsp;to download and execute other malware.</P>
<P><STRONG>Upon execution</STRONG></P>
<P><BR>&nbsp;This trojan donwload a text file from : http://www.oiuyt.net/ko.txt , and the content of the said text file that contain malicious urls like following:</P>
<BLOCKQUOTE dir=ltr style=MARGIN-RIGHT: 0px>
<P>[file]&nbsp;<BR>open=y<BR>url1=<BR>url2=http://61.160.210.45/new/new2.exe<BR>url3=http://61.160.210.45/new/new3.exe<BR>url4=http://61.160.210.45/new/new4.exe<BR>url5=http://61.160.210.45/new/new5.exe<BR>url6=http://61.160.210.46/new/new6.exe<BR>url7=http://61.160.210.46/new/new7.exe<BR>url8=http://61.160.210.46/new/new8.exe<BR>url9=http://61.160.210.46/new/new9.exe<BR>url10=http://61.160.210.46/new/new10.exe<BR>url11=http://61.160.210.43/new/new11.exe<BR>url12=http://61.160.210.43/new/new12.exe<BR>url13=http://61.160.210.43/new/new13.exe<BR>url14=http://61.160.210.43/new/new14.exe<BR>url15=http://61.160.210.43/new/new15.exe<BR>url16=http://61.160.210.43/new/new16.exe<BR>url17=http://61.160.210.43/new/new17.exe<BR>url18=http://61.160.210.44/new/new18.exe<BR>url19=http://61.160.210.44/new/new19.exe<BR>url20=http://61.160.210.44/new/new20.exe<BR>url21=http://61.160.210.42/new/new21.exe<BR>url22=http://61.160.210.42/new/new22.exe<BR>url23=http://61.160.210.42/new/new23.exe<BR>url24=http://61.160.210.42/new/new24.exe<BR>url25=http://61.160.210.42/new/new25.exe<BR>url26=http://61.160.210.42/new/new26.exe<BR>url27=http://61.160.210.42/new/new27.exe<BR>url28=http://61.160.210.42/new/new28.exe<BR>url29=http://61.160.210.41/new/new29.exe<BR>url30=http://61.160.210.41/new/new30.exe<BR>url31=http://61.160.210.41/new/new31.exe<BR>url32=http://61.160.210.41/new/new32.exe<BR>url33=http://61.160.210.41/new/new33.exe<BR>url34=<BR>url35=http://61.160.210.41/new/new35.exe<BR>url36=<BR>count=36&nbsp;&nbsp; </P></BLOCKQUOTE>
<P>and this trojan also drops a DLL component that exports funtions can be use to make downloaded malware run.</P>
<UL>
<LI>&quot;%user_profile%\temp\%s%x.x&quot; detected by anchiva as : Trojan/Runner.2015</LI></UL>
<P>&nbsp;</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Exploit/JS.MSIE.B3A3]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Exploit/JS.MSIE.B3A3</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Exploit/JS.MSIE.B3A3</guid>
			<pubDate>11/17/2008 7:47:03 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>This exploit is usually embedded in normal web page. It takes a vulnerability in Internet Explorer 6, which allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka &quot;the IFRAME vulnerability&quot; or the &quot;HTML Elements Vulnerability.&quot; Successfully exploit may lead to system compromise.</P>
<UL>
<LI><A href=http://www.microsoft.com/technet/security/Bulletin/MS04-040.mspx target=_blank>MS04-040</A> 
<LI><A href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1050 target=_blank>CVE-2004-1050</A> </LI></UL><br /><br /><strong>Technical_details：</strong><br /><P>Upon successfully exploit, it will download another malware and execute, this may further compromise the affected system:</P>
<UL>
<LI>http://t{blocked}.com/inst/go.gif</LI></UL>
<P>At the time of writing, the said url has been taken down.</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Worm/IRCBot.4847@net]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/IRCBot.4847@net</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/IRCBot.4847@net</guid>
			<pubDate>11/16/2008 9:37:33 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>This worm is part of a family of backdoors that connect to IRC.</P>
<P>It drops a copy of itself and some bat files to delete itself, creates some registry entries to enable its automatic execution at every system startup, and drops some files to removable drives in order to infect the system when user double click the drive. </P>
<P>It opens random TCP ports to connect to an Internet Relay Chat (IRC) server and joins an IRC channel. Once connected, it acts as a backdoor that allows a remote malicious user to issue commands locally on an affected system to download other malicious file.</P><br /><br /><strong>Technical_details：</strong><br /><P>Upon execution, it checks if it is in %SystemRoot%\System32 directory currently. If not, it copys itself to %SystemRoot%\System32 with a file name xxxxxx.exe, which &quot;xxxxxx&quot; stands for 6 random characters. To hide xxxxxx.exe, it modifies the time of xxxxxx.exe and makes it the same as the time of explorer.exe, and set its attributes as HIDDEN, SYSTEM and READONLY.</P>
<P>It compares the current user name with the following strings in order to check if it is running in a sandbox:</P>
<P>sandbox<BR>honey<BR>vmware<BR>currentuser<BR>nepenthes<BR>andy</P>
<P>It opens random TCP ports to connect to Internet Relay Chat (IRC) server and joins IRC channel.</P>
<P>sco.rs-forum.biz, rd.game-host.org<BR>Join the channel: #liquid</P>
<P>it probably accepts the following commands from the remote malicious user:</P>
<P>r.getfile<BR>dlnew<BR>r.update<BR>updat0r<BR>ddos.syn<BR>ddos.ack<BR>ddos.random<BR>ddos.supersyn<BR>login<BR>byefucker<BR>visit<BR>remove<BR>download<BR>update<BR>msn.msg<BR>msn.stop<BR>aim.msg<BR>aim.stop<BR>triton.msg<BR>triton.stop<BR>pstore<BR>pstore.search<BR>threads<BR>logout<BR>wonk.ack<BR>wonk.syn</P>
<P>It also checks if runing the following&nbsp; windows class related IM applications:</P>
<P>_Oscar_StatusNotify<BR>_Oscar_IconBtn<BR>Ate32Class<BR>CBClass<BR>WndAte32Class<BR>AIM_IMessage</P>
<P>It also uses the following table to crack the windows account:</P>
<P>user name:</P>
<P>oracle<BR>database<BR>default<BR>guest<BR>wwwadmin<BR>teacher<BR>student<BR>owner<BR>computer<BR>staff<BR>admin<BR>admins<BR>administrat<BR>administrateur<BR>administrador<BR>administrator</P>
<P>password:</P>
<P>intranet<BR>winpass<BR>blank<BR>office<BR>control<BR>nokia<BR>siemens<BR>compaq<BR>cisco<BR>orainstall<BR>sqlpassoainstall<BR>db1234<BR>databasepassword<BR>databasepass<BR>dbpassword<BR>dbpass<BR>access<BR>domainpassword<BR>domainpass<BR>domain<BR>hello<BR>bitch<BR>exchange<BR>backup<BR>technical<BR>loginpass<BR>login<BR>katie<BR>george<BR>chris<BR>brian<BR>susan<BR>peter<BR>win2000<BR>winnt<BR>winxp<BR>win2k<BR>win98<BR>windows<BR>oeminstall<BR>oemuser<BR>homeuser<BR>accounting<BR>accounts<BR>internet<BR>outlook<BR>qwerty<BR>server<BR>system<BR>changeme<BR>linux<BR>1234567890<BR>123456789<BR>12345678<BR>1234567<BR>123456<BR>12345<BR>pass1234<BR>passwd<BR>password<BR>password1</P>
<P><BR>Once found these applications, this worm&nbsp; may hijack them and probably sends some fake message to ask contact to view some malicious web sites.</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Worm/AutoRun.DEDF@net]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/AutoRun.DEDF@net</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/AutoRun.DEDF@net</guid>
			<pubDate>11/16/2008 9:37:19 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>Upon execution, it drops a driver to restore SSDT hooks that almost all antivirus sofwares used to anti virus and hijacks many security related tools, and tries to conncet to remote address.</P><br /><br /><strong>Technical_details：</strong><br /><P>Upon execution, it drops the following files:<BR>%SystemRoot\System32\drivers\beep.sys&nbsp; --&nbsp; detected as Spyware/Lmir.D933 by Anchiva</P>
<P>It tries to terminate the following processes:<BR>QQ.exe<BR>QQDoctor.exe<BR>QQDoctorMain.exe<BR>ntvdm.exe</P>
<P>It also tries to terminate the following processes and set the values of </P>
<P>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution </P>
<P>Options\xxxxxx\Debugger] to &quot;ntsd -d&quot; in order to hijack these programs (where xxxxxx stands for </P>
<P>the following programs):</P>
<P>RavMonD.exe<BR>Rav.exe<BR>avp.com<BR>avp.exe<BR>RavMon.exe<BR>AvastU3.exe<BR>ScanU3.exe<BR>AvU3Launcher.exe<BR>runiep.exe<BR>rfwmain.exe<BR>rfwsrv.exe<BR>KAVPF.exe<BR>KPFW32.exe<BR>nod32kui.exe<BR>nod32.exe<BR>Navapsvc.exe<BR>SelfUpdate.exe<BR>Navapw32.exe<BR>avconsol.exe<BR>webscanx.exe<BR>NPFMntor.exe<BR>vsstat.exe<BR>zjb.exe<BR>KPfwSvc.exe<BR>QQDoctorMain.exe<BR>RavTask.exe<BR>mmsk.exe<BR>WoptiClean.exe<BR>QQKav.exe<BR>EGHOST.exe<BR>QQDoctor.exe<BR>RegClean.exe<BR>FYFireWall.exe<BR>360Safe.exe<BR>iparmo.exe<BR>adam.exe<BR>IceSword.exe<BR>360rpt.exe<BR>360tray.exe<BR>AgentSvr.exe<BR>AppSvc32.exe<BR>autoruns.exe<BR>avgrssvc.exe<BR>AvMonitor.exe<BR>CCenter.exe<BR>ccSvcHst.exe<BR>FileDsty.exe<BR>FTCleanerShell.exe<BR>HijackThis.exe<BR>Iparmor.exe<BR>isPwdSvc.exe<BR>kabaload.exe<BR>KaScrScn.SCR<BR>KASMain.exe<BR>KASTask.exe<BR>AntiU.exe<BR>KAV32.exe<BR>KAVDX.exe<BR>KAVPFW.exe<BR>KAVSetup.exe<BR>KAVStart.exe<BR>KISLnchr.exe<BR>KMailMon.exe<BR>KMFilter.exe<BR>KPFW32X.exe<BR>KPFWSvc.exe<BR>KRegEx.exe<BR>KsLoader.exe<BR>KVCenter.kxp<BR>KvDetect.exe<BR>KvfwMcl.exe<BR>KVMonXP.kxp<BR>KVMonXP_1.kxp<BR>kvol.exe<BR>kvolself.exe<BR>KVScan.kxp<BR>KVSrvXP.exe<BR>KVStub.kxp<BR>kvupload.exe<BR>kvwsc.exe<BR>KvXP.kxp<BR>KvXP_1.kxp<BR>KWatch.exe<BR>KWatch9x.exe<BR>KWatchX.exe<BR>loaddll.exe<BR>MagicSet.exe<BR>PFW.exe<BR>mcconsol.exe<BR>mmqczj.exe<BR>nod32krn.exe<BR>PFWLiveUpdate.exe<BR>QHSET.exe<BR>RavStub.exe<BR>Ras.exe<BR>rfwcfg.exe<BR>RfwMain.exe<BR>RsAgent.exe<BR>Rsaupd.exe<BR>safelive.exe<BR>irsetup.exe<BR>scan32.exe<BR>shcfg32.exe<BR>SmartUp.exe<BR>SREng.EXE<BR>symlcsvc.exe<BR>SysSafe.exe<BR>TrojanDetector.exe<BR>Trojanwall.exe<BR>TrojDie.kxp<BR>regedit.exe<BR>UIHost.exe<BR>UmxAgent.exe<BR>UmxAttachment.exe<BR>UmxCfg.exe<BR>UmxFwHlp.exe<BR>UmxPol.exe<BR>UpLive.exe<BR>upiea.exe<BR>AST.exe<BR>ArSwp.exe<BR>USBCleaner.exe<BR>rstrui.exe<BR>KvReport.kxp<BR>QQSC.exe<BR>ghost.exe<BR>KRepair.com<BR>SREngPS.EXE<BR>XDelBox.exe<BR>kpfw32.exe<BR>kavstart.exe<BR>kwatch.exe<BR>kpfwsvc.exe<BR>kmailmon.exe<BR>kissvc.exe<BR>appdllman.exe<BR>~.exe<BR>sos.exe<BR>UFO.exe<BR>TNT.Exe<BR>niu.exe<BR>XP.exe<BR>Wsyscheck.exe<BR>TxoMoU.Exe<BR>AoYun.exe<BR>regedit32.exe<BR>auto.exe<BR>AutoRun.exe<BR>av.exe<BR>zxsweep.exe<BR>cross.exe<BR>Discovery.exe<BR>guangd.exe<BR>kernelwind32.exe<BR>logogo.exe<BR>NAVSetup.exe<BR>pagefile.exe<BR>pagefile.pif<BR>rfwProxy.exe<BR>SDGames.exe<BR>servet.exe<BR>360safebox.exe</P>
<P>It tries to stop the Beep service, and drops a new driver to replace the beep.sys in system and </P>
<P>creates the following registry entries in order to start this driver:<BR>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RESSDT]<BR>&quot;Type&quot;=dword:00000001 (SERVICE_KERNEL_DRIVER)<BR>&quot;Start&quot;=dword:00000003 (SERVICE_DEMAND_START)<BR>&quot;ErrorControl&quot;=dword:00000000 (SERVICE_ERROR_IGNORE)<BR>&quot;ImagePath&quot;=\??\C:\WINDOWS\System32\drivers\beep.sys<BR>&quot;DisplayName&quot;=RESSDT</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RESSDT\Security]<BR>&quot;Security&quot;=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\<BR>&nbsp; 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\<BR>&nbsp; 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\<BR>&nbsp; 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\<BR>&nbsp; 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\<BR>&nbsp; 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\<BR>&nbsp; 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RESSDT\Enum]<BR>&quot;0&quot;=Root\\LEGACY_RESSDT\\0000<BR>&quot;Count&quot;=dword:00000001<BR>&quot;NextInstance&quot;=dword:00000001</P>
<P>This driver calculates the addresses of NT services by reading the original data from </P>
<P>ntoskrnl.exe/ntkrnlpa.exe and restores them if they were modified. This will defeat the SSDT </P>
<P>hooks that almost all antivirus sofwares used to anti virus.</P>
<P>It disables the Windows Security Center, Windows Automatic Updates, Windows Help and Support, </P>
<P>Windows Error Reporting, Windows Firewall/Internet Connection Sharing (ICS), Write Protect for </P>
<P>disks, and Rising Antivirus by setting the value of the following registry entries:</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvc]<BR>&quot;Start&quot;=dword:00000004 (SERVICE_DISABLED)</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv]<BR>&quot;Start&quot;=dword:00000004 (SERVICE_DISABLED)</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc]<BR>&quot;Start&quot;=dword:00000004 (SERVICE_DISABLED)</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSPPSYS]<BR>&quot;Start&quot;=dword:00000004 (SERVICE_DISABLED)</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc]<BR>&quot;Start&quot;=dword:00000004 (SERVICE_DISABLED)</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]<BR>&quot;Start&quot;=dword:00000004 (SERVICE_DISABLED)</P>
<P>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting]<BR>&quot;DoReport&quot;=dword:00000000</P>
<P>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting]<BR>&quot;ShowUI&quot;=dword:00000000</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]<BR>&quot;Start&quot;=dword:00000004 (SERVICE_DISABLED)</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StorageDevicePolicies]<BR>&quot;WriteProtect&quot;=dword:00000000</P>
<P>It modifies the value of the following registry entries to hide files and turn on auto run of </P>
<P>disks:</P>
<P>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]<BR>&quot;ShowSuperHidden&quot;=dword:00000000</P>
<P>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\advanced\folder\hidden\sh</P>
<P>owall]<BR>&quot;CheckedValue&quot;=dword:00000001</P>
<P>[HKEY_USERS\S-1-5-21-725345543-1085031214-1801674531-1003</P>
<P>\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]<BR>&quot;Hidden&quot;=dword:00000002</P>
<P>SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer<BR>&quot;NoDriveTypeAutoRun&quot;=dword:00000091</P>
<P>It also tries to conncet to some remote address.</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/Goldun.35C9]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Goldun.35C9</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Goldun.35C9</guid>
			<pubDate>11/12/2008 8:38:42 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br />&nbsp;&nbsp;&nbsp;&nbsp; This malware arrives in the affected system as an attachment of some fake alert emails.<BR>&nbsp;&nbsp;&nbsp; Upon execution, it drops some malicious files ,steals user's sensitive information and sends to remote user.<br /><br /><strong>Technical_details：</strong><br /><P>&nbsp;&nbsp;&nbsp; This malware arrives in the affected system as an attachment of some fake alert emails.<BR>&nbsp;&nbsp;&nbsp; Upon execution, it drops some malicious files ,steals user's sensitive information and sends to remote user.</P>
<P>Once executed, it drops the following files in the affected system:<BR>%System%\gzipmod.dll&nbsp; -&nbsp; detected as Spyware/Goldun.FAEF by Anchiva<BR>%System%\vbagz.sys -&nbsp; detected as Rootkit/Goldun.9FF9 by Anchiva</P>
<P>It creates follow registry entry to enable its automatic run:</P>
<UL>
<LI>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gzipmod]<BR>&quot;DllName&quot;=gzipmod.dll<BR>&quot;Startup&quot;=gzipmod<BR>&quot;Impersonate&quot;=dword:00000001<BR>&quot;Asynchronous&quot;=dword:00000001<BR>&quot;MaxWait&quot;=dword:00000001<BR>&quot;adrn&quot;=[B7698B33D438DB063]</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vbagz]<BR>&quot;Type&quot;=dword:00000001 <BR>&quot;Start&quot;=dword:00000001 <BR>&quot;ErrorControl&quot;=dword:00000000 <BR>&quot;ImagePath&quot;=system32\vbagz.sys <BR>&quot;DisplayName&quot;=VBA PnP Driver </LI></UL>
<P>It also creates follow registry entries:</P>
<UL>
<LI>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List<BR>&quot;C:\WINDOWS\system32\rundll32.exe&quot;=C:\WINDOWS\system32\rundll32.exe:*:Enabled:rundll32</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vbagz.sys] <BR>@=&quot;Driver</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network]<BR>@=&quot;Driver</LI></UL>
<P>It send user's sensitive information via follow URL:</P>
<UL>
<LI>http://sergej-grienko.com/ie-bolt2/data.php?trackid=706172616D{blocked}</LI></UL><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Anomaly.82C7]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Anomaly.82C7</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Anomaly.82C7</guid>
			<pubDate>11/12/2008 8:38:28 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>The trojan is a malicious software that is used to accelerate a kind of games,such as Virtua Tennis 3.</P>
<P>It has some&nbsp;functions as follows:</P>
<UL dir=ltr 0px>
<LI>F5 - Serving in MAX power 
<LI>F6 - Get mass scores 
<LI>F7 - Freeze time 
<LI>F8 - Infinite Stamina 
<LI>F9 - LV up to max instantly 
<LI>F11 - Time's up</LI></UL><br /><br /><strong>Technical_details：</strong><br /><P>The trojan is a malicious software that is used to accelerate a kind of games,such as Virtua Tennis 3.</P>
<P>It has some&nbsp;functions as follows:</P>
<UL dir=ltr 0px>
<LI>F5 - Serving in MAX power 
<LI>F6 - Get mass scores 
<LI>F7 - Freeze time 
<LI>F8 - Infinite Stamina 
<LI>F9 - LV up to max instantly 
<LI>F11 - Time's up</LI></UL><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Agent.0A27]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Agent.0A27</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Agent.0A27</guid>
			<pubDate>11/11/2008 10:43:59 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>&nbsp; This trojan may arrive in the affected system as dropped or downloaded file by other malwares or unsuspecting users.<BR>&nbsp; Upon execution, It injects into system process,and connects to follow website.It may download other malware to execute.&nbsp;</P>
<UL>
<LI>&nbsp; http://www1.rixosspa.info/</LI></UL>
<P>&nbsp; However, as of this writing, the said URL is not available.<BR>&nbsp; <BR>&nbsp; It creates follow registry entry to set its privilege of accessing network:&nbsp; </P>
<UL>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]<BR>&quot;%system%\svchost.exe&quot;=%system%\svchost.exe:*:Enabled:svchost </LI></UL><br /><br /><strong>Technical_details：</strong><br /><P>&nbsp; This trojan may arrive in the affected system as dropped or downloaded file by other malwares or unsuspecting users.<BR>&nbsp; Upon execution, It injects into system process,and connects to follow website.It may download other malware to execute.&nbsp;</P>
<UL>
<LI>&nbsp; http://www1.rixosspa.info/</LI></UL>
<P>&nbsp; However, as of this writing, the said URL is not available.<BR>&nbsp; <BR>&nbsp; It creates follow registry entry to set its privilege of accessing network:&nbsp; </P>
<UL>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]<BR>&quot;%system%\svchost.exe&quot;=%system%\svchost.exe:*:Enabled:svchost </LI></UL><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Agent.A71C]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Agent.A71C</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Agent.A71C</guid>
			<pubDate>11/6/2008 11:45:44 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>This trojan may arrive the affected system as downloaded by other malware or unsuspect user. It drops its components into the system directory and inject its dropped dll into every running process, namely <EM>explorer.exe</EM>, to steal the victims online game information. It may further compromise the affected system.</P><br /><br /><strong>Technical_details：</strong><br /><P>Upon execution, it drops its components into the system directory:</P>
<UL>
<LI>%system%\9fd8db.sys - detected by RapidRx as <STRONG>Spyware/OnLineGames.6FF7</STRONG></LI>
<LI>%system%\E4814792.DLL - detected by RapidRx as <STRONG>Spyware/OnLineGames.1F53</STRONG></LI>
<LI>%system%\E4814792.cfg - trojan's config file</LI></UL>
<P>It creates the following registry entries to aim its injection routine and auto start after system restart:</P>
<UL>
<LI>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E4814792-EFA3-4C20-93D0-8B130A59F9A8}\InprocServer32]<BR>@=E4814792.dll</LI>
<LI>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E4814792-EFA3-4C20-93D0-8B130A59F9A8}\InprocServer32]<BR>&quot;ThreadingModel&quot;=Apartment</LI>
<LI>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<BR>&quot;{E4814792-EFA3-4C20-93D0-8B130A59F9A8}&quot;=&quot;&quot;</LI>
<LI>[HKEY_CLASSES_ROOT\CLSID\{E4814792-EFA3-4C20-93D0-8B130A59F9A8}\InprocServer32]<BR>@=E4814792.dll</LI>
<LI>[HKEY_CLASSES_ROOT\CLSID\{E4814792-EFA3-4C20-93D0-8B130A59F9A8}\InprocServer32]<BR>&quot;ThreadingModel&quot;=Apartment</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9fd8db]<BR>&quot;Type&quot;=dword:00000001</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9fd8db]<BR>&quot;Start&quot;=dword:00000003</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9fd8db]<BR>&quot;ErrorControl&quot;=dword:00000000</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9fd8db]<BR>&quot;ImagePath&quot;=hex(2):5c,3f,3f,5c,43,3a,5c,57,49,4e,44,4f,57,53,5c,53,79,73,74,65,6d,33,32,5c,39,66,64,38,64,62,2e,73,79,73,00,</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9fd8db]<BR>&quot;DisplayName&quot;=9fd8db</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9fd8db\Security]<BR>&quot;Security&quot;=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9fd8db\Enum]</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9fd8db\Enum]<BR>&quot;0&quot;=Root\\LEGACY_9FD8DB\\0000</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9fd8db\Enum]<BR>&quot;Count&quot;=dword:00000001</LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9fd8db\Enum]<BR>&quot;NextInstance&quot;=dword:00000001</LI></UL>
<P>Then it injects the said DLL, <EM>E4814792.dll</EM>, into every running process, specifically explorer.exe, and stay background to steal the victims online game information.</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/OnLineGames.E199!pws]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/OnLineGames.E199!pws</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/OnLineGames.E199!pws</guid>
			<pubDate>11/6/2008 1:00:18 AM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br />&nbsp; This Trojan arrives in the affected system as dropped or downloaded file by other malwares or unsuspecting users.<BR>&nbsp; Upon execution, It drops components to the system directory,injects dll compontent to every running process,and stays resident in backgound to steal the victim's infomation about online-games.<BR><br /><br /><strong>Technical_details：</strong><br /><P>&nbsp; This Trojan arrives in the affected system as dropped or downloaded file by other malwares or unsuspecting users.<BR>&nbsp; Upon execution, It drops components to the system directory,injects dll compontent to every running process,and stays resident in backgound to steal the victim's infomation about online-games.</P>
<P> <BR>Once executed, it drops the following files in the affected system:</P>
<UL>
<LI>%System%\19b5406.sys - Detected by Anchiva as Spyware/OnLineGames.6FF7</LI>
<LI>%System%\F65BDEC7.dll - Detected by Anchiva as Spyware/OnLineGames.1F53</LI>
<LI>%System%\F65BDEC7.cfg</LI></UL>
<P>It creates follow registry entry to enable its automatic run:</P>
<UL>
<LI>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F65BDEC7-4BF3-4512-840F-68B166B6D7AC}\InprocServer32]<BR>(Default) = &quot;F65BDEC7.dll&quot; <BR>ThreadingModel = &quot;Apartment&quot; <BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<BR>{F65BDEC7-4BF3-4512-840F-68B166B6D7AC} = &quot;&quot; </LI>
<LI>It also creates follow registry entries:<BR>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_19B5406\0000\Control]<BR>*NewlyCreated* = 0x00000000 <BR>ActiveService = &quot;19b5406&quot; </LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_19B5406\0000]<BR>Service = &quot;19b5406&quot; <BR>Legacy = 0x00000001 <BR>ConfigFlags = 0x00000000 <BR>Class = &quot;LegacyDriver&quot; <BR>ClassGUID = &quot;{8ECC055D-047F-11D1-A537-0000F8753ED1}&quot; <BR>DeviceDesc = &quot;19b5406&quot; </LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_19B5406]<BR>NextInstance = 0x00000001 </LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\19b5406\Enum]<BR>0 = &quot;Root\LEGACY_19B5406\0000&quot; <BR>Count = 0x00000001 <BR>NextInstance = 0x00000001 </LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\19b5406\Security]<BR>Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0 </LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\19b5406]<BR>Type = 0x00000001 <BR>Start = 0x00000003 <BR>ErrorControl = 0x00000000 <BR>ImagePath = &quot;%System%\19b5406.sys&quot; <BR>DisplayName = &quot;19b5406&quot; </LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_19B5406\0000\Control]<BR>*NewlyCreated* = 0x00000000 <BR>ActiveService = &quot;19b5406&quot; </LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_19B5406\0000]<BR>Service = &quot;19b5406&quot; <BR>Legacy = 0x00000001 <BR>ConfigFlags = 0x00000000 <BR>Class = &quot;LegacyDriver&quot; <BR>ClassGUID = &quot;{8ECC055D-047F-11D1-A537-0000F8753ED1}&quot; <BR>DeviceDesc = &quot;19b5406&quot; </LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_19B5406]<BR>NextInstance = 0x00000001 <BR>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\19b5406\Enum]<BR>0 = &quot;Root\LEGACY_19B5406\0000&quot; <BR>Count = 0x00000001 <BR>NextInstance = 0x00000001 </LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\19b5406\Security]<BR>Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0 </LI>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\19b5406]<BR>Type = 0x00000001 <BR>Start = 0x00000003 <BR>ErrorControl = 0x00000000 <BR>ImagePath = &quot;%System%\19b5406.sys&quot; <BR>DisplayName = &quot;19b5406&quot; </LI></UL>
<P>It sends the sensitive infomation to the attacker via follow http post:</P>
<UL>
<LI>http://121.12.168.127/zong10/lin.asp</LI></UL><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Backdoor/PcClient.EF2F]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Backdoor/PcClient.EF2F</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Backdoor/PcClient.EF2F</guid>
			<pubDate>11/6/2008 1:08:46 AM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>Upon execution, it drops some other files and starts a new service to do the malicious work. It also steals some sensitive information and sends them to remote malicious attacker.<BR></P><br /><br /><strong>Technical_details：</strong><br /><P>Upon execution, it drops the follwoing files:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>%SystemRoot%\System32\xxxxxx.dll<BR>%SystemRoot%\System32\xxxxxx.key<BR>%SystemRoot%\System32\drivers\xxxxxx.sys<BR>(where &quot;xxxxxx&quot; stands for 6 random characters, such as &quot;zdqgoj&quot; and &quot;ybmmhg&quot;)</P></BLOCKQUOTE>
<P>It creates the following registry entries in order to enable the driver to start automatically when system reboot:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\yirvudob]<BR>&quot;ImagePath&quot;=\??\C:\WINDOWS\System32\drivers\xxxxxx.sys<BR>&quot;DisplayName&quot;=yirvudob<BR>(&quot;xxxxxx&quot; stands for 6 random characters)</P></BLOCKQUOTE>
<P>It looks like the driver will hook some system service to help the xxxxxx.dll. But, in order to defeat the static disassembler, the header of this driver file has been modified. The SizeOfRawData of one section of this driver has been changed to very small (only 3 bytes), so the static disassembler can't read other data in this section, but the Windows loader can align the section automatically, thus no error will occurer. It appears that the driver was modified incorrect elsewhere, so it can't be loaded by Windows, and an event log &quot;The yirvudob service failed to start due to the following error: The specified driver is invalid. &quot; is added to the system. (A bug or by intention?)</P>
<P>The xxxxxx.dll are injected into many processes of the system and monitor system's activity. It then log these into xxxxxx.key file. The content of this file looks like the following:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>[2008-11-05 14:24:56] C:\WINDOWS\system32 C:\WINDOWS\Explorer.EXE<BR>ss<BR>[2008-11-05 14:25:08] Run C:\WINDOWS\Explorer.EXE<BR>notepad<BR>[2008-11-05 14:25:38] Run C:\WINDOWS\Explorer.EXE<BR>regedit</P></BLOCKQUOTE>
<P>It also steals some sensitive information and sends them to remote malicious attacker.</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/Goldun.E073]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Goldun.E073</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Goldun.E073</guid>
			<pubDate>11/6/2008 1:09:25 AM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>This malware arrives as a dropper file of another malware. It can also be downloaded by user by visting malicious websites.<BR>It belong to variants of Spyware/Goldun.<BR>It injects its dll component into running process such as rundll32.exe, and stay hidden in the background and may steal information related to Email and send the information to a remote malicious user.</P><br /><br /><strong>Technical_details：</strong><br /><P>Upon execution, it drops following files:</P>
<UL>
<LI>%system32%\gzipmod.dll 
<LI>%system32%\vbagz.sys 
<LI>%system32%\tremir.bin</LI></UL>
<P>It creates following registry entry to survive system restart:</P>
<UL>
<LI>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gzipmod<BR>DllName=gzipmod.dll<BR>Stratup=gzipmod<BR>adr9i=[0B748CF23E3D75D70] 
<LI>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List<BR>%system32%\rundll32.exe=%system32%\rundll32.exe:*:Enabled:rundll32 
<LI>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\vbagz<BR>DisplayName=VBA2 PnP Driver<BR>ImagePath=&quot;system32\vbagz.sys</LI></UL>
<P>It forbids following device drivers to visit:</P>
<UL>
<LI><A href=file://\\.\x86emul>\\.\x86emul</A> 
<LI><A href=file://\\.\syncm>\\.\syncm</A> 
<LI><A href=file://\\.\xprot>\\.\xprot</A> 
<LI><A href=file://\\.\netrp>\\.\netrp</A> 
<LI><A href=file://\\.\dwave>\\.\dwave</A> 
<LI><A href=file://\\.\vbagz>\\.\vbagz</A> 
<LI><A href=file://\\.\dprot>\\.\dprot</A> 
<LI><A href=file://\\.\klite>\\.\klite</A> 
<LI><A href=file://\\.\wlite>\\.\wlite</A> 
<LI><A href=file://\\.\pcixm>\\.\pcixm</A> 
<LI><A href=file://\\.\fprot>\\.\fprot</A> 
<LI><A href=file://\\.\vbugz>\\.\vbugz</A></LI></UL>
<P>It injects its dll component into running process such as rundll32.exe, and stay hidden in the background and may steal information related to Email and send the information to a remote malicious user.</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Worm/AutoRun.A7EA]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/AutoRun.A7EA</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/AutoRun.A7EA</guid>
			<pubDate>11/3/2008 10:18:06 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br />&nbsp; This worm arrives in the affected system as dropped or downloaded file by other malwares or unsuspecting users.It may also arrive via infected removable drives.<BR>&nbsp; Upon execution, It drops itself in victim's driver,and attempts to download malicious files to the local computer and execute them.&nbsp; <BR>&nbsp; It injects into the execution sequence of explorer.exe by being installed as its default debugger to auto start.<BR><br /><br /><strong>Technical_details：</strong><br /><P>&nbsp; This worm arrives in the affected system as dropped or downloaded file by other malwares or unsuspecting users.It may also arrive via infected removable drives.<BR>&nbsp; Upon execution, It drops itself in victim's driver,and attempts to download malicious files to the local computer and execute them.&nbsp;&nbsp;<BR>&nbsp; It injects into system process of svchost to hide itself.<BR>&nbsp; <BR>Once executed, it drops the following files in the affected system:<BR>%ProgramFiles%\Microsoft Common\wuauclt.exe&nbsp; copy of itself</P>
<P>It creates follow registry entry to enable its automatic run:</P>
<UL>
<LI>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]<BR>Debugger = &quot;%ProgramFiles%\Microsoft Common\wuauclt.exe&quot; </LI></UL>
<P>It also creates follow registry entries:</P>
<UL>
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AEC\0000]<BR>&quot;Service&quot;=aec<BR>&quot;Legacy&quot;=dword:00000001<BR>&quot;ConfigFlags&quot;=dword:00000000<BR>&quot;Class&quot;=LegacyDriver<BR>&quot;ClassGUID&quot;={8ECC055D-047F-11D1-A537-0000F8753ED1}<BR>&quot;DeviceDesc&quot;=Microsoft Kernel Acoustic Echo Canceller 
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AEC\0000\Control]<BR>&quot;*NewlyCreated*&quot;=dword:00000000<BR>&quot;ActiveService&quot;=aec 
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FASTFAT\0000\Control]<BR>&quot;ActiveService&quot;=Fastfat 
<LI>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aec\Enum]<BR>&quot;0&quot;=Root\\LEGACY_AEC\\0000<BR>&quot;Count&quot;=dword:00000001<BR>&quot;NextInstance&quot;=dword:00000001 
<LI>[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]<BR>&quot;Cookies&quot;=C:\\WINDOWS\\system32\\config\\systemprofile\\Cookies<BR>&quot;Cache&quot;=C:\\WINDOWS\\system32\\config\\systemprofile\\Local Settings\\Temporary Internet Files<BR>&quot;History&quot;=C:\\WINDOWS\\system32\\config\\systemprofile\\Local Settings\\History 
<LI>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B69F34DD-F0F9-42DC-9EDD-957187DA688D}\iexplore]<BR>&quot;Count&quot;=dword:00000013<BR>&quot;Time&quot;=hex:d8,07,0b,00,01,00,03,00,08,00,0b,00,04,00,03,01,</LI></UL>
<P>It gets malicious files download URLs form follow URL,and run the malicious files with administrative privileges.</P>
<UL>
<LI>http://aaszxt.ru/load4/ld.php?v=1&amp;rs={Harddisk Volume Serial Number}&amp;n=1&amp;uid=1</LI></UL>
<P>If exists removeable drives,it drops copies of itself in the drive root directory as system.exe.<BR>It also drops the file autorun.inf which contains commands that will execute the dropped copy of worm.<BR>The file autorun.inf contains the following commands:<BR>&nbsp;[autorun]<BR>&nbsp;open=system.exe<BR>&nbsp;shellexecute=system.exe<BR>&nbsp;shell\Explore\command=system.exe<BR>&nbsp;shell\Open\command=system.exe<BR>&nbsp;shell=Explore<BR>&nbsp;<BR>&nbsp;<BR></P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/ZBot.10EF]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/ZBot.10EF</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/ZBot.10EF</guid>
			<pubDate>11/2/2008 9:40:48 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>This spyware may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.<BR>Currently, according our Feed-back net monitor system ,we found this infection also is detected in email attachment.</P>
<P>And it's a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen pshots, downloads additional components, and provides a hacker with the remote access to the compromised system.</P><br /><br /><strong>Technical_details：</strong><br /><P>Upon exectuion,it drops some files into system directory:</P>
<UL>
<LI>%system32%\twext.exe&nbsp; - Detected by Anchiva RapidRx Labs as : Spyware/Zbot.4334 
<LI>%system32%\twain_32\local.ds (this file is zero size) 
<LI>%system32%\twain_32\user.ds&nbsp; (this file is zero size)</LI></UL>
<P>It mordiffies the following registry entry to enable its automatic execution in every system startup:</P>
<UL>
<LI>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit<BR>from<BR>C:\windows\system32\userinit.exe<BR>to<BR>C:\windows\system32\userinit.exe, c:\windows\system32\twext.exe</LI></UL>
<P>It terminates some computer firewall processes:<BR></P>
<UL>
<LI>&nbsp;1)outpost.exe 
<LI>&nbsp;2)zlcient.exe</LI></UL>
<P>And it's a banking trojan that steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system.It's a ba</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/Magania.6A7B]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Magania.6A7B</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Magania.6A7B</guid>
			<pubDate>10/30/2008 11:57:24 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>&nbsp;&nbsp;&nbsp;&nbsp; This spyware arrives in the affected system as a downloaded or dropped file by other malwares or unsuspecting users.</P>
<P>&nbsp;&nbsp;&nbsp;&nbsp; When executed it drops a copy of itself in the affected system. It also drops its active component which is detected by RapidRx as Spyware/OnLineGames.B5BB.</P>
<P>&nbsp;&nbsp;&nbsp;&nbsp; This spyware monitors the gaming habit of the affected user. It steals login credentials for popular online games and sends it to a remote user via HTTP post.</P><br /><br /><strong>Technical_details：</strong><br /><P>&nbsp;&nbsp;&nbsp;&nbsp; This spyware arrives in the affected system as a downloaded or dropped file by other malwares or unsuspecting users.</P>
<P>&nbsp;&nbsp;&nbsp;&nbsp; When executed, it drops the following files in the affected system:</P>
<UL>
<LI>%WINDOWS%\Help\F3C74E3FA248.dll - detected as Spyware/OnLineGames.B5BB 
<LI>%\WINDOWS%\Help\F3C74E3FA248.exe - copy of itself.</LI></UL>
<P>&nbsp;&nbsp;&nbsp;&nbsp; It then registers the active dll component as a class object as follows:</P>
<UL>
<LI>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1DBD6574-D6D0-4782-94C3-69619E719765}\InProcServer32 
<UL>
<LI>_Default = &quot;%WINDOWS%\HELP\F3C74E3FA248.dll&quot;</LI></UL></LI></UL>
<P>&nbsp;&nbsp;&nbsp;&nbsp; It then includes this object to the following registry to enable its automatic exucution upon startup:</P>
<UL>
<LI>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks 
<UL>
<LI>{1DBD6574-D6D0-4782-94C3-69619E719765} = &quot;&quot;</LI></UL></LI></UL>
<P>&nbsp;&nbsp;&nbsp;&nbsp; This spyware monitors the user's online gaming habit. It steal usernames and passwords of popular online games and sends it to a remote user via HTTP post.</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/OnlineGames.A71C]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/OnlineGames.A71C</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/OnlineGames.A71C</guid>
			<pubDate>10/30/2008 11:57:41 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P dir=ltr 0px>This&nbsp;spyware arrives in the affected system as a dropped or downloaded file by other malwares or unsuspecting users. </P>
<P dir=ltr 0px>Upon execution, this&nbsp;spyware drops&nbsp;some harmful file in the windows system folder.</P><br /><br /><strong>Technical_details：</strong><br /><P dir=ltr>This spyware&nbsp;arrives in the affected system as a dropped or downloaded file by other malwares or unsuspecting users. </P>
<P dir=ltr 0px>Upon execution, it deletes itself and drops two following files:</P>
<UL>
<LI 0px>&nbsp;%system%\DFEC5CB7.dll- detected as Spyware/OnLineGames.1F53
<LI 0px>%system%\9fd8db.sys - detected as Spyware/OnLineGames.6FF7</LI></UL>
<P 0px>It creates the following registry entries to survive system restart:</P>
<UL>
<LI 0px>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<UL>
<LI 0px>'{DFEC5CB7-E2AA-4B0A-BEB3-D140E59ED53A}'=&quot;&quot;</LI></UL>
<LI 0px>HKEY_CLASSES_ROOT\CLSID\{DFEC5CB7-E2AA-4B0A-BEB3-D140E59ED53A}\InProcServer32 
<UL>
<LI 0px>@='DFEC5CB7.dll'</LI></UL>
<LI 0px>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFEC5CB7-E2AA-4B0A-BEB3-D140E59ED53A}\InProcServer32 </LI>
<UL>
<LI 0px>@='DFEC5CB7.dll'</LI></UL></UL>
<P>After that, it injects the said DLL into every running process, stay resident to monitor the victim's activity and steal the affected user's online-game information. It may send the sensitive infomation to the attacker via http post.</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/ZBot.BF24]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/ZBot.BF24</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/ZBot.BF24</guid>
			<pubDate>10/30/2008 10:23:01 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>This malware arrives as a dropper file of another malware. It can also be downloaded by user by visting malicious websites.</P>
<P>It belong to variants of Spyware/Zbot.</P>
<P>It's a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system.<BR></P><br /><br /><strong>Technical_details：</strong><br /><P>Upon execution, it drops some copies of itself to certain directories:</P>
<UL>
<LI>%system32%\twain_32\local.ds</LI>
<LI>%system32%\twain_32\user.ds</LI>
<LI>%system32%\twxt.exe - detect as Spyware/Zbot.4CF1</LI></UL>
<P>It modifies the following registry entries to facilitate its auto start routine:<BR></P>
<UL>
<LI>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon<BR>From<BR>Userinit=%system32%\userinit.exe<BR>To<BR>Userinit=%system32%\userinit.exe,%system32%\twext.exe</LI></UL>
<P>It's a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system.</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/EncPk.638F]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/EncPk.638F</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/EncPk.638F</guid>
			<pubDate>10/30/2008 10:22:52 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>This is Anchiva's detection for programs packed with protection system typically used by malwares. Malwares in this family arrive in the affected system via email or by visiting compromised websites which download the malware into the system. When executed, the malware may perform routines that are hard to reverse such as the installation of rootkit programs that will hide the main malware. </P>
<P>Upon execution, it drops some malicious files and executes them. They hook many system services to hide themselves and steal user's information. It also delete itself and creates some registry entries to enable itself to autostart when system reboot. </P><br /><br /><strong>Technical_details：</strong><br /><P>This malware arrives in the affected system&nbsp;as an attachment of some fake alert emails, such as the following:</P>
<P><IMG src=http://www.anchiva.com/virus/upload/20081030222020446.JPG border=0></P>
<P>Unon execution, it drops the following files:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>%SystemRoot%\System32\gzipmod.dll&nbsp; -&nbsp; detected as Spyware/Goldun.FAEF by Anchiva<BR>%SystemRoot%\System32\vbagz.sys -&nbsp; detected as Rootkit/Goldun.9FF9 by Anchiva</P></BLOCKQUOTE>
<P>It trys to open the following devices to check if it is being run in a sandbox:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>\\.\x86emul<BR>\\.\emulx86<BR>\\.\ltppd<BR>\\.\itcoe<BR>\\.\dprot<BR>\\.\klite<BR>\\.\wlite<BR>\\.\fprot</P></BLOCKQUOTE>
<P>It creates the following named pipes and waits to be connected:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>\\.\pipe\ttfATE373<BR>\\.\pipe\ttfATE373msimn<BR>\\.\pipe\ttfATE373cmd1<BR>\\.\pipe\ttfATE373iexplore<BR>\\.\pipe\ttfATE373myie<BR>\\.\pipe\ttfATE373maxthon<BR>\\.\pipe\ttfATE373icq<BR>\\.\pipe\ttfATE373miranda<BR>\\.\pipe\ttfATE373mozilla<BR>\\.\pipe\ttfATE373thebat<BR>\\.\pipe\ttfATE373msn<BR>\\.\pipe\ttfATE373opera</P></BLOCKQUOTE>
<P>It creates the following registry entries in order to be loaded when system reboot:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MPRServices\TestService]<BR>&quot;DllName&quot;=gzipmod.dll<BR>&quot;EntryPoint&quot;=gzipmod<BR>&quot;StackSize&quot;=dword:00000000<BR>&quot;adrn&quot;=[B7698B33D438DB063]</P>
<P>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gzipmod]<BR>&quot;DllName&quot;=gzipmod.dll<BR>&quot;Startup&quot;=gzipmod<BR>&quot;Impersonate&quot;=dword:00000001<BR>&quot;Asynchronous&quot;=dword:00000001<BR>&quot;MaxWait&quot;=dword:00000001<BR>&quot;adrn&quot;=[B7698B33D438DB063]</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vbagz]<BR>&quot;Type&quot;=dword:00000001 <BR>&quot;Start&quot;=dword:00000001 <BR>&quot;ErrorControl&quot;=dword:00000000 <BR>&quot;ImagePath&quot;=system32\vbagz.sys <BR>&quot;DisplayName&quot;=VBA PnP Driver </P></BLOCKQUOTE>
<P>It adds the rundll32.exe to the following list to bypass the windows firewall:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List</P></BLOCKQUOTE>
<P>It creates the following registry entries in order to be loaded when system reboot in safe mode:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vbagz.sys] <BR>@=&quot;Driver</P>
<P>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network]<BR>@=&quot;Driver</P></BLOCKQUOTE>
<P>It hooks the following system services by inline hook and SSDT hook:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>NtQueryDirectoryFile<BR>NtCreateProcessEx<BR>NtCreateProcess<BR>NtProtectVirtualMemory<BR>NtWriteVirtualMemory<BR>IoGetCurrentProcess<BR>NtOpenProcess<BR>IoCreateFile<BR>NtOpenKey</P></BLOCKQUOTE>
<P>It hooks IoCreateFile service by inline hook and does the following malicious work:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>1. It clears the contents of .sxx files and .sol files when these files will be opened.<BR>2. It prevents the following files from being loaded:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>.vdb file&nbsp; ---&nbsp; Symantec AntiVirus virus definition file<BR>.cdb file&nbsp; ---&nbsp; The Cleaner Trojan definition file<BR>gmer.sys&nbsp;&nbsp; ---&nbsp; the driver of GMER, which is a famous anti-rootkit tool<BR>klif.sys&nbsp;&nbsp; ---&nbsp; Kaspersky AntiVirus file system filter driver<BR>.avz file&nbsp; ---&nbsp; AVZ Antiviral Toolkit malware definition file<BR>.avc file&nbsp; ---&nbsp; Kaspersky AntiVirus virus definition file<BR>avp.sys&nbsp;&nbsp;&nbsp; ---&nbsp; the driver of Kaspersky antivirus product</P></BLOCKQUOTE></BLOCKQUOTE>
<P>It hooks NtQueryDirectoryFile service by SSDT hook to hide themselves from user and many other antivirus and anti-rootk tools.</P>
<P>It steals user's sensitive information and sends them to remote malicious user.</P><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Kobcka.969C!dldr]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Kobcka.969C!dldr</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Kobcka.969C!dldr</guid>
			<pubDate>11/18/2008 7:27:09 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br />This trojan may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.<BR>Upon execution,it creates a forlder and drops a copy of itself into this created forlder and create some registry to enable <BR>its copy automatic execution at every system startup,it also injects thread into normal process.<br /><br /><strong>Technical_details：</strong><br /><P><STRONG>Installation</STRONG></P>
<P>This Trojan creates a folder and drops a copy of itself in created folder:</P>
<UL>
<LI>%Program Files%\Microsoft Common </LI></UL>
<P>(Note: %Program Files% is the default Program Files folder, usually C:\Program Files. )</P>
<UL>
<LI>%Program Files%\Microsoft Common\wuauclt.exe </LI></UL>
<P>It injects thread into the following&nbsp; process: </P>
<UL>
<LI>svchost.exe </LI></UL>
<P><STRONG>Autostart Techniques</STRONG></P>
<P>This Trojan creates the following registry entry to enable its automatic execution at every system startup: </P>
<UL>
<LI>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe</LI>
<UL>
<LI>Debugger = &quot;%Program Files%\Microsoft Common\wuauclt.exe</LI></UL></UL><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Worm/AutoRun.AAA2]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/AutoRun.AAA2</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/AutoRun.AAA2</guid>
			<pubDate>11/18/2008 7:26:59 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>This worm may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.This worm modiffy registry entry to enable its automatic execution at every system startup. </P>
<P>This worm drops copies of itself in all removable drives. It also drops an AUTORUN.INF file to automatically execute its dropped copies when the said drives are accessed. It also updates itself from certain website.</P><br /><br /><strong>Technical_details：</strong><br /><P><STRONG>Arrival, Installation and Autostart Technique</STRONG></P>
<P>This worm may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.</P>
<P>Upon execution, this worm drops the following component files:</P>
<UL>
<LI>%User_profile%\cftmonn.exe - copy of itself 
<LI>%Windows%\system32\drivers\spools.exe - copy of itself</LI></UL>
<P>It modiffies the following the following registry entries:</P>
<P><STRONG>from</STRONG></P>
<P>HKEY_CLASSES_ROOT\exefile\shell\open\command&nbsp;<BR>@=%1 %*&nbsp;</P>
<P><STRONG>to</STRONG></P>
<P>HKEY_CLASSES_ROOT\exefile\shell\open\command&nbsp;<BR>@=%User_Profile%\cftmon.exe %1&quot; %*&quot;</P>
<P><STRONG>from</STRONG></P>
<P>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule&nbsp;<BR>&nbsp;ImagePath=SystemRoot%\windows\svchost.exe -k netsvcs&quot;)<BR><STRONG>to</STRONG><BR>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule&nbsp;<BR>&nbsp;ImagePath=%c:\windows\system32\drivers\spools.exe)</P>
<P dir=ltr>It deletes following registry entries:</P>
<UL dir=ltr>
<LI>
<DIV>&nbsp;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run<BR>&nbsp;</DIV></LI></UL>
<P>The content of droped AUTORUN.INF is like following:</P>
<P>[autorun]</P>
<P>ShellExecute=autorun.exe</P>
<P>It also update itself from the following url,but when this report writting,the url is unavailable:</P>
<UL>
<LI>http://client{BLOCK}ster-hosting.com/?&amp;v=artisho1&amp;s=0<BR></LI></UL><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Pushdo.337A]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Pushdo.337A</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Pushdo.337A</guid>
			<pubDate>11/13/2008 9:10:43 PM</pubDate>
			<description><![CDATA[<strong>Overview：</strong><br /><P>Upon execution, this malware copys itself to the system directory, and creates a registry entry to enable itself to auto start when system reboot. It then creates a svchost.exe process and injects some code into it, and steals the serial number of Windows Operating System and sends it to the remote attackers.</P><br /><br /><strong>Technical_details：</strong><br /><P>Upon execution, it drops the following file:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>%SystemRoot%\System32\rs32net.exe&nbsp; --&nbsp; copy of itself</P></BLOCKQUOTE>
<P>It tries to open the following file, may be intend to check if it is running in a sandbox:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>\\.\Prot3</P></BLOCKQUOTE>
<P>It creates the following registry entry to enable itself to auto start when system reboot:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</P>
<UL>
<LI>&quot;rs32net&quot;=%SystemRoot%\System32\rs32net.exe</LI></UL></BLOCKQUOTE>
<P>This malware embedded another module, whose name is UMLoader.exe. (We can get this <BR>from the debug information in this module, which is &quot;d:\programs\siberia2\umloader\objfre_wxp_x86<BR>\i386\UMLoader.pdb&quot;.) It maybe to prevent itself from being detected by antivirus products, <BR>so does not drop this module, but make some fixes and run it directly in memory. </P>
<P>The UMLoader.exe uses the native apis which are exported by ntdll.dll to create a new process svchost.exe, and injects another module, whose name is Loader.exe in it. (We can get this from the debug information in this module, which is &quot;d:\programs\siberia2\loader\objfre_wxp_x86\i386\Loader.pdb&quot;.) It uses the same trick as above to do this. This module gets the encrypted serial number of Windows Operating System from the following registry entry:</P>
<BLOCKQUOTE dir=ltr 0px>
<P>HKEY_LOCAL_MACHINE\SYSTEM\WPA\SigningHash-XXXXXXXXXXXXXX\SigningHashData<BR>(Where 'X' standds for a character)</P></BLOCKQUOTE>
<P>It encrypts the encrypted serial number and sends it to the following malicious attackers:</P>
<UL dir=ltr 0px>
<LI>91.203.{blocked}:80 
<LI>216.195.{blocked}:80 
<LI>208.66.{blocked}:80 <BR></LI></UL><br /><br />]]></description>
		</item>
		
	</channel>
</rss>