English
Deutsch
Francais
Español
Italian
Home
Virus Info
TR/Vundo.HY
Search
Home
Support
Solutions
Products
Downloads
Virus Info
Statistics
Phishing Worldmap
VDF History
Virus Science
Submit Sample
Security News
Viruses In the Wild
Company
Press
Partners
Newsletter
TR/Vundo.HY - Trojan
In alte limbi
Scurta descriere
Descriere completa
Statistici
How would you rate this information?
Worthless
Excellent
Nume:
TR/Vundo.HY
Descoperit pe data de:
13/06/2008
Tip:
Troian
ITW:
Nu
Numar infectii raportate:
Scazut spre mediu
Potential de raspandire:
Scazut
Potential de distrugere:
Mediu
Fisier static:
Da
Marime:
321.536 Bytes
MD5:
985c2011d7971e33d9ace5892a51f28b
Versiune IVDF:
7.00.04.187
General
Metoda de raspandire:
• Nu are rutina proprie de raspandire
Alias:
• Sophos: Troj/FakeAle-CB
• Eset: a variant of Win32/Adware.Virtumonde application
Sistem de operare:
• Windows 95
• Windows 98
• Windows 98 SE
• Windows NT
• Windows ME
• Windows 2000
• Windows XP
• Windows 2003
Efecte secundare:
• Descarca un fisier malware
• Creeaza fisiere
• Modificari in registri
Fisiere
Sunt create fisierele:
– Fisiere inofensive:
• C:\
%directorul de activare malware%
\rt.ini
• C:\
%directorul de activare malware%
\rt.ini2
Incearca sa descarce un fisier:
– Adresa este urmatoarea:
• http://62.4.83.203/antispy/**********
Fisierul este stocat pe hard disc la:
%TEMPDIR%
\
%sir de 8 caractere aleatoare%
.dll Analiza ulterioara a relevat ca si acest fisier este malware. Detectat ca: TR/Monder.XO
Registrii sistemului
Urmatoarea cheie este adaugata in registri pentru a rula procesul la repornirea sistemului:
– [HKCR\CLSID\{2C72B974-315C-439C-B13E-FB0E062D6B1C}\InprocServer32]
• @="
%directorul de activare malware%
\
%dll malware%
"
• "ThreadingModel"="Both"
Inregistreaza un browser helper object (BHO) prin adaugarea urmatoarei chei in registri:
– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\
• {2C72B974-315C-439C-B13E-FB0E062D6B1C}]
Detaliile fisierului
Limbaj de programare:
Limbaj de programare folosit: C (compilat cu Microsoft Visual C++).
Pentru o descriere scurta click
aici
.
Descriere introdusa de Thomas Wegele la Thu, 19 Jun 2008 14:54 (GMT+1)
Descriere actualizata de Thomas Wegele la Thu, 19 Jun 2008 15:17 (GMT+1)
»
About Malware
»
About Phishing
»
Viruses In the Wild
« back
Print this page
Worm/Mytob.U
Worm/Netsky.J
Worm/Mytob.AT
Worm/Mytob.AD
Worm/Klez.E
HEUR/PDF.Obfuscated
SPR/mIRC.Gen
TR/Crypt.UPKM.Gen
JS/Dldr.Agent.cex
TR/Dldr.Tiny.bqw
Get comfortable up to the minute info from Avira as
Detects and removes the following malware and its variants:
Worm/Sober.J
Worm/Sober.P
Worm/Sober.Y
W32/Stanit.A
Worm/NetSky.AA
Worm/NetSky.B.1
Worm/NetSky.C
Worm/Netsky.D.Dam
Worm/NetSky.P
Worm/NetSky.X
Worm/Mytob.IN.2
Worm/Mytob.KS
TR/Spy.Banker.AATZ
TR/Spy.Banker.AATZ.1
TR/Spy.Banker.AATZ.2
TR/Spy.Banker.AATZ.3
Download here
Click
here
to get the panel...
© 2008 Avira GmbH
Copyright
Privacy
Sitemap
Feedback
Imprint
FAQ
Contact