Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Jan 8th, 2009, 12:54pm
   Mischel Internet Security Forum
   Malware
   Trojans
(Moderators: Helena, Gavin_Coe, Magnus)
   Sober.B, Wincap.B and Duster.B
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Sober.B, Wincap.B and Duster.B  (Read 384 times)
Ian
Stole All the Forum Stars
********



Good things come to those who wait ...

   


Posts: 2913
Sober.B, Wincap.B and Duster.B
« on: Jan 5th, 2004, 7:53pm »
Quote Quote  Modify Modify

Just before Christmas - sorry it's late - but no doubt there's a joke available, along the lines of 'you'd better B good...'. You have my permission to groan.

Sober.B is a worm that spreads via e-mail in a message written in English or German. This worm sends itself out to all the addresses it finds using its own SMTP engine and validates itself on the mail servers from which it sends itself out under the name 'MailerVB.de'.
 
When Sober.B has infected a computer, it creates two copies of itself, which stay resident in memory. This worm checks if both copies are running, and if one of the processes has terminated, or if one of the files has been deleted, the other copy will regenerate it.  
 
Duster.B is a virus with the characteristics of a worm that spreads through the P2P file sharing program KaZaA and across network shares. It does this following the routines below:
 
Through KaZaA
Duster.B looks for the default shared folder of this file sharing program. If this folder is not shared, it modifies an entry in  the Windows Registry in order to share it. Then, it infects all the PE files it finds in the shared folder by adding its code to the beginning of them. When other users access these files remotely, they will download the files infected by Duster.B, thinking that they are useful computer programs, images, etc. However, when they run the downloaded file, their computers will also be infected by Duster.B.
 
Across network shares.
Duster.B checks if the infected computer belongs to a network and if it is, it tries to copy the file DUST.EXE to all the network computers and creates a file called AUTOEXEC.BAT on each one. The aim of this file is to run the virus every time the computer is started.
 
Duster.B connects to the IP address 208.178.231.190, which belongs to an IRC server, through port 6667. After it has done this, it waits for control commands like download and run files.
 
Wincap.B is a Trojan that contains a list of web addresses belonging to online financial entities, among others. When the user accesses any of these websites, this malicious code tries to capture the passwords used and saves them in a file that it will compress and send to a hacker via e-mail.
« Last Edit: Jan 5th, 2004, 7:53pm by Ian » IP Logged

... but crap arrives pretty much straight away.
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register