|
|
The Computer Guys Miami to Fort Lauderdale Since 1994 - Thank You!
|
|
|
|
|
We Build the Best & Repair the Rest! © |
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
Top 10 malware reported to Sophos in September 2003
This section is for technical experts who want to know more.W32/Gibe-F is a worm which spreads by emailing itself via its own SMTP
engine to addresses extracted from various sources on the victim's drives
(e.g. MBX and DBX files). The worm also spreads using the KaZaA peer-to-peer
shared folders, via IRC channels and will copy itself to the Startup folder
of mapped W32/Gibe-F will attempt to get a user to enter email account details by displaying a fake error dialog box with fields for entering user name, password, email address and server names. If the worm is run with a filename which starts with a P,Q,U or I (regardless of the case) the W32/Gibe-F displays the message "Microsoft Internet Update Pack "This will install Microsoft Security Update. Do you wish to continue?" and may also pretend to be an installation package by displaying an "Searching for installed components ..." If W32/Gibe-F detects the installation of a debugger active in memory it displays the message "Try to pull my legs?".
The worm copies itself to the Windows folder as a randomly-named lowercase executable (e.g. jlfsm.exe) and adds an entry to the registry at HKLM\Software\Microsoft\Windows\CurrentVersion\Run to run itself on system restart. The worm also changes the entries in the registry at: HKCR\exefile\shell\open\command so that it is run before EXE, COM, PIF, BAT, SCR files and to display a
false error message (e.g. "Error occurred Memory access violation in module
kernel32 at
The worm sets several entries in the registry to signify installation, confirm KaZaA infection and to prevent REGEDIT.EXE from running. W32/Gibe-F may also create a file called SWEN1.DAT in the Windows folder containing a list of several IP addresses and domain names which may be NNTP servers. W32/Gibe-F may attempt to exploit a vulnerability in Microsoft's software which allows automatic execution of attachments while viewing an email message. Microsoft issued a patch which reportedly fixes this vulnerability in 2001. The patch is available from www.microsoft.com/technet/security/bulletin/MS01-027.asp. (This patch fixes a number of vulnerabilities in Microsoft's software, including the one exploited by this worm.) Emails constructed by the worm have the following characteristics: From: may be the bona fide victim's name or may be randomly constructed from the following unknown and bulletin (e.g. MS Support Department <random>@support.microsoft.com) To: randomly constructed from the following User Subject line: randomly constructed from the following Corp. Message text: randomly constructed from the following MS the attached file (EXE, COM, PIF, BAT, SCR or ZIP) may have a randomly generated name or may be randomly chosen from the following PATCH Alternatively, W32/Gibe-F may attempt to mimic a mail delivery failure message. The subject line and message text will then be constructed from the following Message follows: W32/Gibe-F copies itself to the KaZaA shared folder and to the Windows folder with various EXE or ZIP filenames randomly contructed from the following(e.g "WINZIP UPLOAD.EXE"): Virus Generator W32/Gibe-F attempts to terminate various processes related to anti-virus or security software (e.g. sweep95, zonealarm and blackice).
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
Copyright © 1998 The Computer Guys |
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||