 | PandaLabs has informed about lots of a worm variants, which affects many PCs around the world, and leave them defenceless since one of the functions of Bagle is to deactivate the firewall and antvirus. |
Full Name: Worm.W32/Bagle.GX@MM Type: E-mail worm. Plataform: [W32] Portable Executables .EXE, .SCR, .DLL de Windows de 32 bits: 95, 98, Me, NT, 2000, XP y 2003. Compressed size (bytes): 94126 Alias: WORM_BAGLE.GX by Trend Micro), W32/Bagle.fb!pwdzip by McAfee y W32.Beagle.FG@mm by por Symantec.
In it first execution, it creates the following files in the system:
hidn.exe (copy of itself)
m_hook.sys (rootkit component)
error.gif (element without importance)
temp.zip (copy of itself)
It generates a key in the register to restart its operations together with Windows:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]"drv_st_key" = "%UserProfile%\Application Data\hidn\hidn.exe"
Other entries are generated to support its operations:
[HKEY_CURRENT_USER\Software\FirstRuxzx]"FirstRun" = "1"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\m_hook]
[HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_M_HOOK]
It diminishes the stability to the start system through the elimination of the following register:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot]
Note: %UserProfile% equals to C:\Documents and Settings\[user's name] for Windows 2000/XP/NT.
| It shuts up the different process belonging to antiviral and firewall utilities and it also starts its hiding process in its rootkit component:
|
wuauserv Aavmker4 ABVPN2K ADBLOCK.DLL ADFirewall AFWMCL AntiyFirewall ARP.DLL aswTdi avast! Antivirus avast! Mail Scanner avast! Web Scanner AVEService AVExch32Service AvFlt Avg7Alrt Avg7Core AvgCore AvgFsh AVGFwSrv AVIRAMailService AVIRAService awhost32 backweb client-4476822 BackWeb Client - 7681197 backweb client-4476822 Bdfndisf bdftdif bdss BlackICE BsFileSpy ccSetMgr ccSetMgr.exe CONTENT.DLL ewido security suite control ewido security suite driver ewido security suite guard F-Prot Antivirus Update Monitor F-Secure Gatekeeper Handler Starter firewall FSFW FSMA FTPFILT. DLL DLL HTTPFILT.DLL KAVMonitorService KAVSvc McAfeeFramework McShield McTaskManager mcupdmgr.exe NDIS_RD Network Associates Log Service nipsvc Norman Type-R Norman ZANDA Norton AntiVirus Server nvcoas Personal Firewall POP3FILT.DLL PREVSRV ravmon8 SECRET.DLL SharedAccess SweepNet SWEEPSRV.SYS Symantec AntiVirus Client Symantec Core LC tmtdi tm_cfw Vba32ECM Vba32ifs VisNetic AntiVirus Plug-in vrfwsvc vsmon xcommWith
Its Simple Mail Transfer Protocol, it resends itself to all e-mail addresses found in the extensions with the following extensions:
wab txt msg htm shtm stm xml dbx mbx mdx cfg asp php pl wsh adb tbb sht jsp
It avoids be resent to e-mail addresses with the following strings:
rating@ f-secur news feste gold-certs@ help@ info@ nobody@ noone@ kasp admin icrosoft sopho winzip abuse panda cafee spam pgp
Through the TCP25 port, the Bagle.GX will try to establish connection with SMTP servers to send messages, for example:
smtp.google.com
Read more...
|