<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" title="XSL Formatting" href="virus.xsl" media="all"?>
<rss version="2.0"><channel>
		<title>	<![CDATA[Anchiva latest virus list]]></title>
		<image>
			<title><![CDATA[Anchiva virus information]]></title>
			<link>http://www.anchiva.com/virus </link>
			<url>http://www.anchiva.com/images/en/logo.jpg </url>
		</image>
		<description><![CDATA[Anchiva latest virus list]]></description>
		<link>http://www.anchiva.com/virus/</link>
		<language>en-us,en;q=0.5</language>
		<generator>WWW.ANCHIVA.COM</generator>
		<copyright><![CDATA[Copyright&copy; 2005-2009 Anchiva Systems, Inc. All rights reserved worldwide.]]></copyright>		
		
		<item>
			<title><![CDATA[Virus Name: Worm/Bot.651B@net]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/Bot.651B@net</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/Bot.651B@net</guid>
			<pubDate>2012-5-18 17:05:09</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a worm, it will be downloaded by a user when visiting malicious websites, dropped by other malwares or spreaded by USB flash disk and msn. This worm will connect to the server of hacker and receive commands.</p><br /><br /><strong>Technical_details</strong><br /><p>The worm will copy itself, and create service for it:</p>
<ul>
    <li>%TEMP%\{random name}.exe</li>
</ul>
<p>Copy itself to all root directory, and create config files, the worm will be runned when user click the disk:</p>
<ul>
    <li>{all root directorys}\_recycling49.exe</li>
    <li>{all root directorys}\autorun.inf</li>
    <li>{all root directorys}\autorun.bat</li>
    <li>{all root directorys}\autorun.vbs</li>
</ul>
<p>Add registry:</p>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vuauxlfelk]
    <ul>
        <li>&quot;Type&quot;=0x00000110</li>
        <li>&quot;Start&quot;=0x00000002</li>
        <li>&quot;ErrorControl&quot;=0x00000000</li>
        <li>&quot;ImagePath&quot;=&quot;%TEMP%\{random name1}.exe -svc&quot;</li>
        <li>&quot;DisplayName&quot;=&quot;bzyktpisqh&quot;</li>
        <li>&quot;ObjectName&quot;=&quot;LocalSystem&quot;</li>
    </ul>
    </li>
    <li>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vuauxlfelk\Security]
    <ul>
        <li>&quot;Security&quot;=01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00</li>
    </ul>
    </li>
    <li>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vuauxlfelk\Enum]
    <ul>
        <li>&quot;0&quot;=&quot;Root\LEGACY_VUAUXLFELK\0000&quot;</li>
        <li>&quot;Count&quot;=0x00000001</li>
        <li>&quot;NextInstance&quot;=0x00000001</li>
    </ul>
    </li>
    <li>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer]
    <ul>
        <li>&quot;{name1 got from the information of disk}&quot;={hexadecimal number got from the local time}</li>
        <li>&quot;{name2 got from the information of disk}&quot;=0x00000001</li>
    </ul>
    </li>
</ul>
<p>Visit the website(Failure):</p>
<ul>
    <li>http://network.e****d.com/webyx/iLog.php?dl=5.6&amp;log=Loader: 506^EXP</li>
</ul>
<p>Connect to the remote web server(Failure):</p>
<ul>
    <li>{random name2}.ive****edya.com/webyx/remote.php?</li>
    <li>{random name2}.ivep****edya.com/webyx/remote.php?</li>
    <li>{random name2}.ipr****tya.com/webyx/remote.php?</li>
    <li>{random name2}.emn****ying.com/webyx/remote.php?</li>
    <li>{random name2}.emn****rked.com/webyx/remote.php?</li>
</ul>
<p>Receive commands:</p>
<ul>
    <li>reset - terminate process of the worm and config it</li>
    <li>use - start the worm</li>
    <li>useasuser - start the worm with administrator</li>
    <li>sleep - suspend process of the worm</li>
    <li>dl - download malwares from the web server</li>
    <li>visit - visit directory of the worm</li>
    <li>setasnew - delete registry of the worm</li>
    <li>update - update the worm</li>
</ul>
<p>And this worm will spread to all friends by msn</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Inject.81FF]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Inject.81FF</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Inject.81FF</guid>
			<pubDate>2012-5-18 17:05:05</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>It's the Trojan,which disables Task Manager, Registry Editor, and Folder Options.<br />
It connects to specified websites to send and receive information.<br />
It can encrypt the user all the files, and then extort money from the user.<br />
&nbsp;</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution,it copies itself into the affected system:</p>
<ul>
    <li>%Application Data%\{random}\{random}.exe</li>
    <li>%System%\{random}.exe</li>
</ul>
<p>It adds the following registry entries to enable its automatic execution at every system startup:</p>
<ul>
    <li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {random}= &quot;%User Profile%\Application Data\{random}\{random}.exe&quot;<br />
It modifies the following registry entries:</p>
<ul>
    <li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&nbsp;&nbsp;&nbsp;</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Userinit = &quot;%System%\userinit.exe,%System%\{random}.exe,&quot;<br />
This Trojan creates the following registry entries to disable Task Manager, Registry Tools and Folder Options:</p>
<ul>
    <li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Debugger= &quot;P9KDMF.EXE&quot;</p>
<ul>
    <li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Debugger = &quot;P9KDMF.EXE&quot;</p>
<ul>
    <li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Debugger= &quot;P9KDMF.EXE&quot;</p>
<ul>
    <li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;DisableRegistryTools&quot;=dword:00000001</p>
<ul>
    <li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;DisableRegedit&quot;=dword:00000001<br />
It connects to the following website to send and receive information:</p>
<ul>
    <li>http://hor{blocked}rum.com/a.php</li>
    <li>http://spa{blocked}eb.com/a.php</li>
    <li>http://q{blocked}cc.com/a.php</li>
    <li>http://ho{blocked}o.com/a.php</li>
    <li>http://sp{blocked}w.com/a.php</li>
    <li>http://q{blocked}a.com/a.php</li>
</ul>
<p>Receive hacker commands:</p>
<ul>
    <li>IMAGES&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Display picture</li>
    <li>EXECUTE&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Execute files&nbsp;&nbsp;&nbsp;</li>
    <li>LOAD&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Download and Execute</li>
    <li>GEO&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Sleep</li>
    <li>LOCK&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Lock all the files</li>
    <li>UNLOCK&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Unlock all the files</li>
    <li>URLS&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Modify url</li>
    <li>KILL&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Uninstall itself</li>
    <li>UPGRADE&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Update itself</li>
    <li>UPGRADEURL&nbsp;&nbsp;&nbsp; Update connect url and download file</li>
</ul>
<p>From the above instructions,i think it will encrypt the user all the document, and then extort money from the user.</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Worm/Ngrbot.FA1E@net]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/Ngrbot.FA1E@net</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/Ngrbot.FA1E@net</guid>
			<pubDate>2012-5-18 17:04:39</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a worm, it may be downloaded by a user when visting malicious websites or it could be released by other malware.<br />
It connects remote website and receives harmful hacker commands.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution,it copies itself into the affected system:</p>
<ul>
    <li>%Application Data%\{the HDD serial number}.exe</li>
</ul>
<p>It creates the following registry entry to enable its automatic run at every system startup:</p>
<ul>
    <li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {the HDD serial number}.exe=&quot;%Application Data%\{the HDD serial number}.exe&quot;</p>
<ul>
    <li>HKEY_USERS\S-1-5-21-1606980848-1677128483-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {the HDD serial number}.exe=&quot;%Application Data%\{the HDD serial number}.exe&quot;<br />
It can connect the following web to collects the user's IP address and country of origin:</p>
<ul>
    <li>http://api.wipmania.com/</li>
</ul>
<p>Connect following IRC server:</p>
<ul>
    <li>ng.ma{blocked}lone.com</li>
    <li>ng.th{blocked}aby.com</li>
    <li>ng.li{blocked}sez11.com</li>
    <li>ng.co{blocked}oan.com</li>
</ul>
<p>Receive hacker commands:</p>
<ul>
    <li>dl&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Downloads and executes</li>
    <li>up&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Update it</li>
    <li>die&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; kill it</li>
    <li>rm&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Uninstall itself</li>
    <li>m&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Enable/disable all commands</li>
    <li>vs&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Visit specified website</li>
    <li>v&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Send bot's Version</li>
    <li>rc&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; reconnect IRC server</li>
    <li>j&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Join channel</li>
    <li>p&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Part channel&nbsp;&nbsp;&nbsp;</li>
    <li>s&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; sort</li>
    <li>us&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Unsort</li>
    <li>mod&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Enable/disable modules that use hooks</li>
    <li>stats&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Retrieves statistics</li>
    <li>logins&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Retrieves all grabbed logins information</li>
    <li>http.set&nbsp;&nbsp;&nbsp; Set the message for facebook spreading</li>
    <li>http.int&nbsp;&nbsp;&nbsp; Set the number of Facebook messages</li>
    <li>http.inj&nbsp;&nbsp;&nbsp; HTTP inject</li>
    <li>mod&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; module on/offmsn.set</li>
    <li>msn.ini&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Set the number of MSN</li>
    <li>msn.set&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Set message to spread via MSN messages</li>
    <li>mdns&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Block access to specified Domain/IP&nbsp;&nbsp;&nbsp;</li>
    <li>ssyn&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; SYN attack</li>
    <li>udp&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; UDP attack</li>
</ul>
<p>It prevents users from accessing a URL that contains the following string:</p>
<ul>
    <li>webroot.</li>
    <li>fortinet.</li>
    <li>virusbuster.nprotect.</li>
    <li>gdatasoftware.</li>
    <li>virus.</li>
    <li>precisesecurity.</li>
    <li>lavasoft.</li>
    <li>heck.tc</li>
    <li>emsisoft.</li>
    <li>onlinemalwarescanner.</li>
    <li>onecare.live.</li>
    <li>f-secure.</li>
    <li>bullguard.</li>
    <li>clamav.</li>
    <li>pandasecurity.</li>
    <li>sophos.</li>
    <li>malwarebytes.</li>
    <li>sunbeltsoftware.</li>
    <li>norton.</li>
    <li>norman.</li>
    <li>mcafee.</li>
    <li>symantec</li>
    <li>comodo.</li>
    <li>avast.</li>
    <li>avira.</li>
    <li>avg.</li>
    <li>bitdefender.</li>
    <li>eset.</li>
    <li>kaspersky.</li>
    <li>trendmicro.</li>
    <li>iseclab.</li>
    <li>virscan.</li>
    <li>garyshood.</li>
    <li>viruschief.</li>
    <li>jotti.</li>
    <li>threatexpert.</li>
    <li>novirusthanks.</li>
    <li>virustotal.</li>
</ul>
<p>Visit our website contains the following string, it will collects the user's password</p>
<ul>
    <li>*paypal.*/webscr?cmd=_login-submit*</li>
    <li>*google.*/*ServiceLoginAuth*</li>
    <li>*aol.*/*login.psp*</li>
    <li>*screenname.aol.*/login.psp*</li>
    <li>*bigstring.*/*index.php*</li>
    <li>*fastmail.*/mail/*</li>
    <li>*gmx.*/*FormLogin*</li>
    <li>*login.live.*/*post.srf*</li>
    <li>*login.yahoo.*/*login*</li>
    <li>*facebook.*/login.php*</li>
    <li>*hackforums.*/member.php</li>
    <li>*steampowered*/login*</li>
    <li>*dyndns*/account*</li>
    <li>*runescape*/*weblogin*</li>
    <li>*.moneybookers.*/*login.pl</li>
    <li>*.alertpay.*/*login.aspx</li>
    <li>*twitter.com/sessions</li>
    <li>*secure.logmein.*/*logincheck*</li>
    <li>*officebanking.cl/*login.asp*</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Keyloger.7EB0!drop]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Keyloger.7EB0!drop</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Keyloger.7EB0!drop</guid>
			<pubDate>2012-5-11 14:52:27</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is trojan, it may be downloaded by a user when visiting malicious websites or dropped by other malwares. It will record the buttons of keyboard and send the information to the hacker.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution, a message box will apears:</p>
<ul>
    <li><img alt="" width="369" height="116" src="/virus/upload/image/alter.bmp" /></li>
</ul>
<p>Release a config file:</p>
<ul>
    <li>%SYSTEM32%\setkl.sys</li>
</ul>
<p>Release and execute a BAT file:</p>
<ul>
    <li>C:\tmp.bat</li>
</ul>
<p>Copy itself to:</p>
<ul>
    <li>%SYSTEM32%\kl.exe</li>
</ul>
<p>Add registry to set it executing with starting up of system:</p>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <ul>
        <li>ccv=&quot;%SYSTEM32%\kl.exe&quot;</li>
    </ul>
    </li>
</ul>
<p>This trojan will record the buttons of keyboard, login the email:</p>
<ul>
    <li>username:ma***535@gmail.com</li>
    <li>password:0142***3313</li>
</ul>
<p>Send the record of information to the email of hacker:</p>
<ul>
    <li>be.hza***000@gmail.com</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Virtum.A36C]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Virtum.A36C</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Virtum.A36C</guid>
			<pubDate>2012-4-27 15:22:22</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a spyware.It arrives in the affected system as dropped or downloaded file by other malware or unsuspecting users.<br />
It steals account information of following online games:AskTao, DragonNest, XCB.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution, it creates following files:</p>
<ul>
    <li>%CommonProgramFiles%\whh{random number}.ocx &nbsp;detected as Spyware/WOW.B732 by Anchiva</li>
    <li>%CommonProgramFiles%\{random}.dll detected as Trojan/Generic.F1F4 by Anchiva</li>
    <li>%System32%\whhfd008.ocx detected as Trojan/Virtum.A36C by Anchiva</li>
</ul>
<div>The spyware also creates following registry entries:</div>
<ul>
    <li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\CONTROL\KEYBOARD LAYOUTS\E0200804</li>
</ul>
<div style="margin-left: 40px; ">IME FILE = whhfd008.ocx</div>
<div style="margin-left: 40px; ">Layout Text = US</div>
<div style="margin-left: 40px; ">Layout File = kbdus.dll</div>
<div>It steals account information of following online games:</div>
<ul>
    <li>AskTao</li>
    <li>DragonNest</li>
    <li>XCB</li>
</ul>
<div>It sends account information to hacker via following urls:</div>
<ul>
    <li>http://113.107.95.81:801/fen{block}01/lin.asp</li>
    <li>http://113.107.95.81:801/fe{block}bao.asp</li>
    <li>http://113.107.95.81:801/fen{block}ny.asp</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Heur.8E95]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Heur.8E95</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Heur.8E95</guid>
			<pubDate>2012-4-23 10:30:01</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>It is a trojan,it will steal onlinegame&lt;Dungeon Fighter&gt; user's password,and send to the remote sites.<br />
It may be in the user visit a malicious sites cheated to download and execution.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution,it copy itself to the followinig path:</p>
<ul>
    <li>C:\WINDOWS\system32\t91.mod</li>
</ul>
<p>Modify the following registry key:</p>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;SFCDisable&quot;=dword:ffffff9d<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;SFCScan&quot;=dword:00000000<br />
Find the following process and try to closed</p>
<ul>
    <li>DNF.exe</li>
    <li>DNFchina.exe</li>
    <li>QQlogin.exe</li>
</ul>
<p>Create following configuration file:</p>
<ul>
    <li>C:\WINDOWS\system32\t910080ttt86t950065.t91</li>
</ul>
<p>Drops following files from itself.</p>
<ul>
    <li>C:\WINDOWS\system32\dlsp.dll&nbsp;&nbsp;&nbsp; Detected as &quot;Spyware/OnLineGames.565A!pws&quot; by ANCHIVA</li>
    <li>C:\WINDOWS\system32\0ILX.dll&nbsp;&nbsp;&nbsp; Detected as &quot;Trojan/Packed.59EF&quot; by ANCHIVA</li>
</ul>
<p>The &quot;dlsp.dll&quot; file is added to the Service Provider Interface(SIP) for monitor the network.<br />
It modifies the following system file:</p>
<ul>
    <li>C:\WINDOWS\system32\rasapi32.dll&nbsp;&nbsp;&nbsp; Detected as &quot;Trojan/Patched.48D0&quot; by ANCHIVA</li>
</ul>
<p>The modified file will load &quot;0ILX.dll&quot; file,so every time the game starts,&quot;0ILX.dll&quot; will be loading.The &quot;0ILX.dll&quot;file mian purpose is steal onlinegame&lt;Dungeon Fighter&gt; user's password and send to the specified site.<br />
The &quot;0ILX.dll&quot; files also be download following file and execution.</p>
<ul>
    <li>http://c3905{BLOCKED}7d84.3322.org:7043/1.jpg</li>
</ul>
<p>Modifies the original &quot;hosts&quot; file,and writing the following strings to the file:</p>
<ul>
    <li>60.***.217.243&nbsp; 7a57a{BLOCKED}894a0e.3322.org</li>
</ul>
<p>At last,it will download the other malicious software from following websize and save it as &quot;t910.exe&quot;</p>
<ul>
    <li>121.***.113.77:368/1.exe&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Detected as&quot;Trojan/Injepe.C768!dldr&quot; by ANCHIVA</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Worm/Ngrbot.9A71@net]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/Ngrbot.9A71@net</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/Ngrbot.9A71@net</guid>
			<pubDate>2012-5-4 15:15:48</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a worm, it may be downloaded by a user when visting malicious websites or spreaded by FaceBook and MSN. It will connect to the IRC server and receive hacker commands.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon executing, this worm will inject the process of explorer.exe, write the Boot Sector, to prevent being killed, and it will start with explorer.exe.<br />
Copy itself to:</p>
<ul>
    <li>%APPDATA%\{The name got form serial number of hard disk drives}.exe</li>
</ul>
<p>Add registry:</p>
<ul>
    <li>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ul>
        <li>&quot;{The name got form serial number of hard disk drives}&quot;=&quot;%APPDATA%\{The name got form serial number of hard disk drives}.exe&quot;</li>
    </ul>
    </li>
</ul>
<p>It will visit the website to get the information of&nbsp; ip address and area:</p>
<ul>
    <li>http://api.wipmania.com/</li>
</ul>
<p>Visit the IRC of hacker:</p>
<ul>
    <li>ng.best****sever.biz</li>
    <li>ng.xm****verx.info</li>
    <li>ng.ido****ies.com</li>
    <li>ng.furi****zzle.info</li>
    <li>ng.stud****center-org.com</li>
</ul>
<p>Receive hacker commands:</p>
<ul>
    <li>dl -
    <ul>
        <li>&nbsp;&nbsp;&nbsp;&nbsp; Connect to the specified server:
        <ul>
            <li>146.185.246.133</li>
        </ul>
        </li>
        <li>&nbsp;&nbsp;&nbsp;&nbsp; Download and execute files:
        <ul>
            <li>&nbsp;&nbsp;&nbsp;&nbsp; %APPDATA%\{number1}.exe(Indentified by anchiva as:Trojan/Jorik.0733)</li>
            <li>&nbsp;&nbsp;&nbsp;&nbsp; %APPDATA%\{number2}.exe(Indentified by anchiva as:Trojan/Injector.1D15!drop)</li>
            <li>&nbsp;&nbsp;&nbsp;&nbsp; %APPDATA%\{number3}.exe(Indentified by anchiva as:Trojan/Yakes.6AD7)</li>
        </ul>
        </li>
    </ul>
    </li>
    <li>v - Send the customer name, its version and the filepath to hacker</li>
    <li>rc - Reconnect&nbsp;&nbsp;</li>
    <li>die - Disconnect from the IRC server and does not reconnect until its system reboots</li>
    <li>rm - Remove itself</li>
    <li>s&nbsp;&nbsp; - Join the channel for its country</li>
    <li>us - Part the channel for its country</li>
    <li>stats - Retrieves statistics for spreading and/or login grabbing</li>
    <li>logins - Retrieves all grabbed and cached logins and prints them to channel or PM.Can also be used to clear login cache.</li>
    <li>msn.set - Set the message that will be used for MSN spreading</li>
    <li>msn.int - Set the number of MSN messages in a conversation before one is changed with your spreading message</li>
    <li>http.set - Set the message that will be used for FaceBook spreading</li>
    <li>http.int - Set the number of Facebook messages in a conversation before one is changed with your spreading message</li>
    <li>up - Updates its file</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/Tepfer.BE08!pws]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Tepfer.BE08!pws</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Tepfer.BE08!pws</guid>
			<pubDate>2012-4-23 10:29:51</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a spyware.It maybe downloaded or dropped by other malwares or unsuspecting users.<br />
It steals account information from following FTP softwares and web browsers:Firefox, FireFTP, LeechFTP, WinFTP, FTPGetter, ALFTP, IE, DeluxeFTP, Chrome, FreshFTP, GoFTP, 3D-FTP, Robo-FTP.It also downloads and executes other malwares.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution, it creates following registry entry as an infection marker:</p>
<ul>
    <li>HKLM\Software\WinRAR</li>
</ul>
<div style="margin-left: 40px; ">HWID = {random GUID}</div>
<div>By looking into the saved account information of following FTP softwares and web browsers, the spyware collects accounts, passwords and corresponding urls:</div>
<ul>
    <li>Firefox</li>
    <li>FireFTP</li>
    <li>LeechFTP</li>
    <li>WinFTP</li>
    <li>FTPGetter</li>
    <li>ALFTP</li>
    <li>IE</li>
    <li>DeluxeFTP</li>
    <li>Chrome</li>
    <li>FreshFTP</li>
    <li>GoFTP</li>
    <li>3D-FTP</li>
    <li>Robo-FTP</li>
</ul>
<div>It sends the stealed information to hacker via following urls, also downloads and executes other malwares:</div>
<ul>
    <li>http://www.alberghi.com:8080/po{block}e.php</li>
    <li>http://buyandsmile.atomclick.co:8080{block}te.php</li>
    <li>http://licitatiiblog.ro/jzVvvc3{block}uo.exe - detected as Spyware/Zbot.DEAD by Anchiva</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/KillAV.F23B]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/KillAV.F23B</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/KillAV.F23B</guid>
			<pubDate>2012-4-17 10:36:30</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>It is a trojan,it will terminate user's Security software,it attemps to infected user's removable disk.<br />
It will download other malicous software in order to achieve the purpose of further control the victim computer.</p><br /><br /><strong>Technical_details</strong><br /><p>Once launched,it coye itself to following path:</p>
<ul>
    <li>C:\Program Files\Common Files\rgdltecq\nhoifz.pif</li>
</ul>
<p>It extracts files from its body and saves them in the system as:</p>
<ul>
    <li>C:\\WINDOWS\\system32\\622421.DLL&nbsp;&nbsp; Detected by ANCHIVA as &quot;Trojan/KillAV.12A3&quot;</li>
</ul>
<p>(In fact the name is random number)<br />
The dll file download configuration from the following website:</p>
<ul>
    <li><a href="http://c.shi{BLOCK}bian.com/s.gif">http://c.shi{BLOCK}bian.com/s.gif</a></li>
</ul>
<p>It to decrypt the configuration file, it will download other malicious software from the following URL:</p>
<ul>
    <li><a href="http://blog.51cto.com/attachment/201204/4594{BLOCK}138005.rar">http://blog.51cto.com/attachment/201204/4594{BLOCK}138005.rar</a>&nbsp;&nbsp;&nbsp; Detected by ANCHIVA as &quot;Spyware/OnLineGames.80C9!pws&quot;</li>
</ul>
<p>The DLL file dorp following driver file:</p>
<ul>
    <li>C:\WINDOWS\system\XeWz.url&nbsp;&nbsp;&nbsp;&nbsp; Detected by ANCHIVA as &quot;Trojan/KillAV.1199&quot;</li>
</ul>
<p>And registered the following system services:</p>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\autb]</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;Type&quot;=dword:00000001<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;Start&quot;=dword:00000003<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;ErrorControl&quot;=dword:00000000<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;ImagePath&quot;=\??\C:\WINDOWS\system\XeWz.url<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;DisplayName&quot;=&quot;autb&quot;<br />
The Trojan horse in order to run automatically when the computer reboot, it create registered items as follows:</p>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;360se&quot;=&quot;C:\Program Files\Common Files\rgdltecq\nhoifz.pif&quot;</p>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&quot;WebCheck&quot;=&quot;{E6FB5E20-DE35-11CF-9C87-00AA005127ED}&quot;</p>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32]</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; @=&quot;C:\\WINDOWS\\system32\\622421.DLL&quot; <br />
It will terminate the following process:</p>
<ul>
    <li>ekrn.exe</li>
    <li>360safe.exe</li>
    <li>egui.exe</li>
    <li>nod32krn.exe</li>
    <li>RSTray.exe</li>
    <li>avgnt.exe</li>
    <li>avnotify.exe</li>
    <li>avguard.exe</li>
    <li>guardgui.exe</li>
    <li>avwebgrd.exe</li>
    <li>kudiskmon.EXE</li>
    <li>beikearpsvc.EXE</li>
    <li>mcshield.exe</li>
    <li>RavMonD.EXE</li>
    <li>kpopserver.exe</li>
    <li>KVMonXP.EXE</li>
    <li>QQPCTray.EXE</li>
    <li>Twister.EXE</li>
    <li>avp.EXE</li>
    <li>KANSvr.EXE</li>
</ul>
<p>In face contanin many anti-spware software,Fox example:HijackThisTrojanDetectorIceSword etc.<br />
It will through the infection removable disk spread itself.</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Yoshi.68E5]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Yoshi.68E5</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Yoshi.68E5</guid>
			<pubDate>2012-4-17 10:36:34</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a trojan, it may be downloaded by a user when visting malicious websites or dropped by other malwares. It will modify the default setting of browser and visit the web sites of hacker.</p><br /><br /><strong>Technical_details</strong><br /><p>This trojan will modify the registry to set the proxy server of Internet Explorer:</p>
<ul>
    <li>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    <ul>
        <li>&quot;AutoConfigUrl&quot;=&quot;http://vid****ame.portal****dastrohsbc.org&quot;</li>
        <li>&quot;ProxyHttp1.1&quot;=0x00000001</li>
        <li>&quot;EnableHttp1.1&quot;=0x00000001</li>
    </ul>
    </li>
    <li>[HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel]
    <ul>
        <li>&quot;Connection Settings&quot;=0x00000001</li>
    </ul>
    </li>
</ul>
<p>And it will terminate the process of firefox.exe, modify the setting file to set firefox.exe launch with proxy.<br />
Visit the website of hacker:</p>
<ul>
    <li>www.10****agen-biel.ch/media/system/css/style/notify.php</li>
</ul>
<p>Search the address list of email and send it to hacker:</p>
<ul>
    <li>www.di****na.org/dipa/logs/files/Archive.php</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Kryptik.88B2]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Kryptik.88B2</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Kryptik.88B2</guid>
			<pubDate>2012-4-13 10:08:12</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a dropper.It arrives in the affected system as dropped or downloaded file by other malwares or unsuspecting users.<br />
It drops other malware, removes Temporary Internet files and Cookies, accesses malicious urls, monitors internet connection and restarts system.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution, it creates following file:</p>
<ul>
    <li>%SYSTEM32%\{random}.dll - detected as Trojan/Kryptik.45F3 by Anchiva</li>
</ul>
<div>The trojan removes all files in following folders:</div>
<ul>
    <li>C:\Documents and Settings\Administrator\Cookies</li>
    <li>C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files</li>
</ul>
<div>It also creates following registry entires, so new GUI processes will load the dropped component automatically:</div>
<ul>
    <li>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows &nbsp;</li>
</ul>
<div style="margin-left: 40px; ">AppInit_DLLs = %SYSTEM32%\{random}.dll</div>
<div style="margin-left: 40px; ">LoadAppInit_DLLs = 1</div>
<div>It sends computer information to remote hacker via following url:</div>
<ul>
    <li>clickjoinseo.com/phpbb/get.php?id={Product Id}&amp;key={random}&amp;av=0&amp;vm=1&amp;al=0&amp;p={random}&amp;os={OS Version}&amp;z={random}&amp;hash={hash value of computer name}</li>
</ul>
<div>The trojan mointors internet connection, causing webpages display incorrectly sometimes.</div>
<div>The trojan restarts the system when it arrives.</div><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/Ddox.DCF9]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Ddox.DCF9</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/Ddox.DCF9</guid>
			<pubDate>2012-4-17 10:36:52</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a trojan, it may be released by other malware or downloaded by trojan downloader. This program will update the client of XtremeRAT.</p><br /><br /><strong>Technical_details</strong><br /><p>This torjan will inject to the processes of svchost.exe and explorer.exe<br />
Copy itself to:</p>
<ul>
    <li>%SYSTEM32%\Windows5.0\Taskmg.exe</li>
</ul>
<p>Release files:</p>
<ul>
    <li>%APPDATA%\Microsoft\Windows\uQTEXD.cfg</li>
    <li>%APPDATA%\Microsoft\Windows\uQTEXD.dat</li>
</ul>
<p>Delete registry:</p>
<ul>
    <li>[HKEY_CURRENT_USER\SOFTWARE\XtremeRAT]</li>
</ul>
<p>Add registry:</p>
<ul>
    <li>[HKEY_CURRENT_USER\SOFTWARE\uQTEXD\]
    <ul>
        <li>&quot;ServerStarted&quot;=&quot;(localtime)&quot;</li>
        <li>&quot;InstalledServer&quot;=&quot;%SYSTEM32%\Windows5.0\Taskmg.exe&quot;</li>
    </ul>
    </li>
    <li>[HKEY_CURRENT_USERSOFTWARE\FakeMessage\]
    <ul>
        <li>&quot;FakeMessage&quot;=&quot;OK&quot;</li>
    </ul>
    </li>
    <li>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\]
    <ul>
        <li>&quot;Antivirus&quot;=&quot;%SYSTEM32%\Windows5.0\Taskmg.exe&quot;</li>
    </ul>
    </li>
    <li>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\]
    <ul>
        <li>&quot;Antivirus&quot;=&quot;%SYSTEM32%\Windows5.0\Taskmg.exe&quot;</li>
    </ul>
    </li>
    <li>[HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{5F3D0Y86-3B3O-R5Q4-52HI-PW6BO4Q266N6}\]
    <ul>
        <li>&quot;StubPath&quot;=&quot;%SYSTEM32%\Windows5.0\Taskmg.exe&quot;</li>
    </ul>
    </li>
    <li>[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{5F3D0Y86-3B3O-R5Q4-52HI-PW6BO4Q266N6}\]
    <ul>
        <li>&quot;StubPath&quot;=&quot;%SYSTEM32%\Windows5.0\Taskmg.exe&quot;</li>
    </ul>
    </li>
    <li>[HKEY_CURRENT_USER\SOFTWARE\(processID)\]
    <ul>
        <li>&quot;Mutex&quot;=&quot;uQTEXD&quot;</li>
    </ul>
    </li>
</ul>
<p>Visit the website of hacker:</p>
<ul>
    <li>URL= http://djamel.hopto.org:92/1234567890.functions</li>
</ul>
<p>Download file to update the client of XtremeRAT：</p>
<ul>
    <li>%APPDATA%\Microsoft\Windows\uQTEXD.xtr</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/ServStart.B0BE]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/ServStart.B0BE</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/ServStart.B0BE</guid>
			<pubDate>2012-4-13 10:08:50</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>It is a Trojan horse,it disguised as a picture file trick users into clicking.In order to self-start it register a system service.<br />
The trojan connect to a remote hacker sites,execution hackers insttuctions,Ex:DDOS attacks,download other malicious program.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution,it will copy itself to following directory and delete itself.</p>
<ul>
    <li>C:\Documents and Settings\UserData.exe</li>
</ul>
<p>Then,restart copy file,it register a system service and creates the following registry entries:</p>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Nationalahy]</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;Type&quot;=dword:00000010<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;Start&quot;=dword:00000002<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;ErrorControl&quot;=dword:00000000<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;ImagePath&quot;=&quot;C:\Documents and Settings\UserData.exe&quot;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;DisplayName&quot;=&quot;Nationalyyq Instruments Domain Service&quot;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;ObjectName&quot;=&quot;LocalSystem&quot;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;Description&quot;=&quot;Providesnnb a domain server for NI security.&quot;</p>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NATIONALAHY\0000]</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;Service&quot;=&quot;Nationalahy&quot;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;Legacy&quot;=dword:00000001<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;ConfigFlags&quot;=dword:00000000<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;Class&quot;=&quot;LegacyDriver&quot;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;ClassGUID&quot;=&quot;{8ECC055D-047F-11D1-A537-0000F8753ED1}&quot;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;DeviceDesc&quot;=&quot;Nationalyyq Instruments Domain Service&quot;<br />
<br />
It may inject itself to the following process:</p>
<ul>
    <li>iexplore.exe</li>
</ul>
<p>The trojan wil send users information to following websize:</p>
<ul>
    <li>tj{BLOCK}.3322.org:123</li>
</ul>
<p>Receive instructions,it will execution following operation:</p>
<ul>
    <li>Execution files</li>
    <li>Update itself</li>
    <li>Download and execution files</li>
    <li>Shut down the computer</li>
    <li>Simulation browser requests</li>
    <li>Delete itself</li>
    <li>User IE browse the web</li>
    <li>Send data</li>
    <li>receive date</li>
    <li>DDOS attack</li>
</ul>
<p>&nbsp;</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Worm/Autorun.D595!dldr]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Worm/Autorun.D595!dldr</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Worm/Autorun.D595!dldr</guid>
			<pubDate>2012-4-13 10:03:36</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a worm.It arrives in the affected system via removable drives or dropped by other malwares.<br />
It downloads, drops and executes other malwares, also infects mobile disk.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution, it creates following files:</p>
<ul>
    <li>%COMMONPROGRAMFILES%\rgdltecq\ngoifz.pif - copy itself</li>
    <li>%SYSTEM32%\{random number}.dll - detected as Trojan/Geral.31D1!dldr by Anchiva</li>
</ul>
<div>It also sets all folders in root directory of mobile disk to hidden, and creates executable files with same name as those folders, the newly created files are actually copies of the malware.When user try to access those folders, the worm will infect the system.</div>
<div>The worm creates following registry entries to make IE automatic load the dropped component:</div>
<ul>
    <li>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad</li>
</ul>
<p style="margin-left: 40px; ">WebCheck = {E6FB5E20-DE35-11CF-9C87-00AA005127ED}</p>
<ul>
    <li>HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32</li>
</ul>
<p style="margin-left: 40px; ">{default} = %SYSTEM32%\{random number}.dll</p>
<div>It downloads malware via following url:</div>
<ul>
    <li>http://b.shidaihuabian.com/{block}f - expired</li>
</ul>
<div>The worm try to escape from following AV software:</div>
<ul>
    <li>ESET Nod32</li>
    <li>360</li>
    <li>QQ PCManager</li>
    <li>AntiVir Guard</li>
    <li>Kaspersky</li>
    <li>rising</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Backdoor/Trustezeb.8D4F]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Backdoor/Trustezeb.8D4F</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Backdoor/Trustezeb.8D4F</guid>
			<pubDate>2012-3-26 11:20:22</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>It is backdoor, it Destruction of &nbsp;security software Trusteer Rapport,and impersonates it to tricked user<br />
It opens a back door on the compromised computer,to accept some of the hackers instruction.</p>
<p>&nbsp;</p><br /><br /><strong>Technical_details</strong><br /><p>&nbsp;Upon execution,it copy itself to following directory and delete itself.</p>
<ul>
    <li>%System%\[RANDOM].exe</li>
    <li>%Temp%\[RANDOM].exe</li>
</ul>
<div>&nbsp;</div>
<div>It also createfollowing files:</div>
<ul>
    <li>%ProgramFiles%\Trusteer Rapport\Stop Rapport.lnk</li>
    <li>%ProgramFiles%\Trusteer Rapport\Rapport Console.lnk</li>
    <li>%ProgramFiles%\Trusteer Rapport\Start Rapport.lnk</li>
</ul>
<div>&nbsp;</div>
<div>It dorp following:</div>
<ul>
    <li>%ProgramFiles%\Trusteer\Rapport\bin\RapportService.exe</li>
    <li>%System%\RPService.exe</li>
</ul>
<div>In fact,they are used as fake security software Trusteer Rapport</div>
<div>&nbsp;</div>
<div>It then creates the following registry entries:&nbsp;</div>
<ul>
    <li>[HKEY_CLASSES_ROOT\.eze]</li>
</ul>
<div>&nbsp; &nbsp; &nbsp; &nbsp; @=&quot;MyEze.1&quot;</div>
<ul>
    <li>[HKEY_CLASSES_ROOT\MyEze.1\shell\open\command]</li>
</ul>
<div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;@=&quot;%SystemRoot%\system32\RPService.exe %0 %1 %2&quot;</div>
<ul>
    <li>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]</li>
</ul>
<div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&quot;D07946C952&quot;=&quot;%Temp%\[RANDOM].exe,&quot;</div>
<div>&nbsp;</div>
<div>It then modified the following registry entries:</div>
<ul>
    <li>[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]</li>
</ul>
<div>&nbsp; &nbsp; &nbsp; &nbsp; &quot;load&quot;=&quot;%Temp%\[RANDOM].exe,&quot;</div>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]</li>
</ul>
<div>&nbsp; &nbsp; &nbsp; &nbsp; &quot;Userinit&quot;=&quot;C:\\WINDOWS\\system32\\userinit.exe,%System%\[RANDOM].exe,&quot;</div>
<div>&nbsp;</div>
<div>It will delete the following file:</div>
<ul>
    <li>%System%\drivers\RaportKELL.sys</li>
</ul>
<div>&nbsp;</div>
<div>The backdoor will send user information to following websizes:</div>
<div>
<ul>
    <li>http://sk{BLOCK}ni.com/home/credit.php</li>
    <li>http://ma{BLOCK}ns.com/maps.php</li>
    <li>http://ri{BLOCK}pe.com/world.php</li>
    <li>http://ru{BLOCK}mo.com/manage/user.phps</li>
</ul>
</div>
<div>&nbsp;</div>
<div>And receive the following hacker instructions:</div>
<ul>
    <li>LOAD:<span class="Apple-tab-span" style="white-space:pre">		</span>Download and execute files</li>
    <li>EXECUTE:<span class="Apple-tab-span" style="white-space:pre">	</span>Execute files</li>
    <li>URLS:<span class="Apple-tab-span" style="white-space:pre">		</span>Specified website to download file</li>
    <li>KILL:<span class="Apple-tab-span" style="white-space:pre">		</span>kill itself</li>
    <li>UPGRADE:<span class="Apple-tab-span" style="white-space:pre">	</span>UPGRADE itself<span class="Apple-tab-span" style="white-space:pre">	</span></li>
    <li>X:<span class="Apple-tab-span" style="white-space:pre">		</span>Sleep</li>
</ul>
<p>&nbsp;</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/Frethoq.0F20]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Frethoq.0F20</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/Frethoq.0F20</guid>
			<pubDate>2012-3-26 11:20:26</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a spyware.It maybe dropped or downloaded by other malwares and unsuspecting users.<br />
It steals account information of World Of Warcraft.</p><br /><br /><strong>Technical_details</strong><br /><p>&nbsp;Upon execution, it creates following files:</p>
<ul>
    <li>%TEMP%\{random number}.dat - detected as Spyware/Frethoq.A95A by anchiva</li>
    <li>%SYSTEM32%\ksuser.dll - detected as Spyware/Frethoq.A95A by anchiva</li>
    <li>%SYSTEM32%\midimap.dll - detected as Spyware/Frethoq.A95A by anchiva</li>
    <li>%SYSTEM32%\msimg32.dll - detected as Spyware/Frethoq.A95A by anchiva</li>
    <li>%SYSTEM32%\sysapp{random}.dll - detected as Spyware/Frethoq.A95A by anchiva</li>
</ul>
<div>The spyware removes Cryptographic Services, may try to destory the password protection mechanism of World Of Warcraft.</div>
<div>It 360 AV software is running, it would terminate the process.</div>
<div>It steals account information of World Of Warcraft.</div><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Trojan/SysHijack.75A7!drop]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Trojan/SysHijack.75A7!drop</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Trojan/SysHijack.75A7!drop</guid>
			<pubDate>2012-3-26 11:21:11</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a trojan, it may be downloaded by a user when visting malicious web sites or dropped by other malwares. It will drop a backdoor program, this backdoor will connect to the server of hacker.</p><br /><br /><strong>Technical_details</strong><br /><p>It will drop files like:</p>
<ul>
    <li>c:\t.bat</li>
    <li>c:\tt.inf</li>
    <li>c:\windows\system32\winhelp32.exe(Indentified by anchiva as Backdoor/PoisonIvy.09C0)</li>
</ul>
<p>Run c:\t.bat, add the registry to create the service for winhelp32.exe:</p>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinHelp64]
    <ul>
        <li>&quot;Type&quot;=0x00000010</li>
        <li>&quot;Start&quot;=0x00000002</li>
        <li>&quot;ErrorControl&quot;=0x00000000</li>
        <li>&quot;ImagePath&quot;=&quot;c:\windows\system32\winhelp32.exe</li>
        <li>&quot;DisplayName&quot;=&quot;Windows Internet Service&quot;</li>
        <li>&quot;ObjectName&quot;=&quot;LocalSystem&quot;</li>
        <li>&quot;Description&quot;=&quot;提供对 Internet 信息服务管理的支持。&quot;</li>
    </ul>
    </li>
    <li>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinHelp64\Enum]
    <ul>
        <li>&quot;0&quot;=&quot;Root\LEGACY_WINHELP64\0000&quot;</li>
        <li>&quot;Count&quot;=0x00000001</li>
        <li>&quot;NextInstance&quot;=0x00000001</li>
    </ul>
    </li>
</ul>
<p>The service will connect to the server of hacker:</p>
<ul>
    <li>a.9**k.com:6060(74.126.178.24:6060)</li>
</ul>
<p>Send the information of system to the hacker, receive commands to download a malware or clean the trace of the trojan.</p><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/OnLineGames.FB07!pws]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/OnLineGames.FB07!pws</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/OnLineGames.FB07!pws</guid>
			<pubDate>2012-3-26 11:22:05</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>It is a spyware,it will steal onlinegame &lt;Vindictus&gt; user's password,and send to the hacker remote sites.<br />
This spyware may be in the user visit malicious sites to deceive download and Execution.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution it copy itslef to following directory,then execution copy file and delete the original file.</p>
<ul>
    <li>%temp%\Help360hero.exe</li>
</ul>
<p>It attemps to closed following process:</p>
<ul>
    <li>HeroesLauncher.exe</li>
    <li>HEroes.exe</li>
</ul>
<p>Then,it through check the registry and file traversal to find the game directory,it drop following file to the directory.</p>
<ul>
    <li>&lt;Game directory&gt;\hero.dll&nbsp; Detected as &ldquo;Spyware/OnLineGames.1992!pws&rdquo; by ANCHIVA</li>
</ul>
<p><br />
The &quot;hero.dll&quot; will steal password information and save the following file in the game directory.</p>
<ul>
    <li>&lt;Game directory&gt;\info.cy</li>
</ul>
<p>The following is the content of &quot;info.cy&quot; file:</p>
<ul>
    <li>[LQCYC]</li>
</ul>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; id = &lt;User account&gt;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; mm = &lt;User password&gt;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; place = &lt;Area Code&gt;<br />
<br />
It will send that to following sites:</p>
<ul>
    <li>58.***.35.110</li>
</ul>
<p><br />
then it modify the game the default &quot;nmconew.dll&quot;,erevy time the game will start loading &quot;nmconew DLL.&quot;,the modification of he &quot;nmconew.dll&quot; will attempt to laod &quot;hero.dll&quot;,so each time the game is running, the account will be stolen.<br />
<br />
Finally it create following&nbsp; empty file,it used for infection success marks.</p>
<ul>
    <li>%Systemroot%\System32\lq0223.Fe</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Backdoor/Xyligan.9865]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Backdoor/Xyligan.9865</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Backdoor/Xyligan.9865</guid>
			<pubDate>2012-3-26 11:22:08</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a backdoor program, it may be downloaded by a user when visting malicious web sites or dropped by other malwares. This program will connect to the server of hacker.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon executing, it will copy itself to the system directory and create a service:</p>
<ul>
    <li>%SYSTEM32%\{random name}.exe</li>
</ul>
<p>Add the registry:</p>
<ul>
    <li>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    <ul>
        <li>&quot;%SYSTEM32%\{random name}.exe&quot;=&quot;%SYSTEM32%\ffntdq.exe:*:Enabled:Microsoft (R) Internetal IExplore&quot;</li>
    </ul>
    </li>
    <li>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rcmdsvc]
    <ul>
        <li>&quot;Type&quot;=0x00000010</li>
        <li>&quot;Start&quot;=0x00000002</li>
        <li>&quot;ErrorControl&quot;=0x00000000</li>
        <li>&quot;ImagePath&quot;=&quot;%SYSTEM32%\{random name}.exe&quot;</li>
        <li>&quot;DisplayName&quot;=&quot;Remote Command Service&quot;</li>
        <li>&quot;ObjectName&quot;=&quot;LocalSystem&quot;</li>
        <li>&quot;Description&quot;=&quot;Windows Resource Kit&quot;</li>
    </ul>
    </li>
</ul>
<p>Connect to the server of hacker:</p>
<ul>
    <li>121.163.177.95(Failure)</li>
</ul>
<p>Receive commands to do something like:</p>
<ul>
    <li>Download and execute the pernicious file:
    <ul>
        <li>%TEMP%\cvbdfgj.exe</li>
    </ul>
    </li>
    <li>Send the information of system</li>
    <li>File management</li>
    <li>Monitoring desktop</li>
</ul><br /><br />]]></description>
		</item>
		
		<item>
			<title><![CDATA[Virus Name: Spyware/OnLineGames.2446]]></title>
			<link>http://www.anchiva.com/virus/view.asp?vanme=Spyware/OnLineGames.2446</link>
			<author>WWW.ANCHIVA.COM</author>
			<guid>http://www.anchiva.com/virus/view.asp?vanme=Spyware/OnLineGames.2446</guid>
			<pubDate>2012-3-26 11:22:14</pubDate>
			<description><![CDATA[<strong>Overview</strong><br /><p>This is a trojan.It may be downloaded or dropped by other malwares and unsuspecting users.<br />
It steals account information of following online games:DNF, MapleStory, FIFA Online2, World of Warcraft, PMang BoardGame, RayCity.</p><br /><br /><strong>Technical_details</strong><br /><p>Upon execution, it creates following file:</p>
<ul>
    <li>%SYSTEMROOT%\Tasks\{random}.dat - detected as Trojan/Heur.1D11 by Anchiva</li>
</ul>
<div>The trojan terminates processes of following antivirus software:</div>
<ul>
    <li>NaverVaccine</li>
    <li>ALYac</li>
    <li>V3Lite</li>
</ul>
<div>It steals account information of following online games:</div>
<ul>
    <li>DNF</li>
    <li>MapleStory</li>
    <li>FIFA Online2</li>
    <li>World of Warcraft</li>
    <li>PMang BoardGame</li>
    <li>RayCity</li>
</ul>
<div>The trojan sends account informaiton to following email address:</div>
<ul>
    <li>{blokc}rackserver@rambler.ru</li>
</ul><br /><br />]]></description>
		</item>
		
	</channel>
</rss>
