AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
January 08, 2009, 08:16:35 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 5356 Members
Latest Member: Gagabaksik
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: W32.Esbot.B 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: W32.Esbot.B  (Read 482 times)
TJ
Tech Team
Hero Member
********
Offline Offline

Posts: 136



View Profile
W32.Esbot.B
« on: August 17, 2005, 04:35:40 PM »

W32.Esbot.B is a worm that spreads by exploiting the Microsoft Windows Plug and Play Buffer Overflow Vulnerability

When W32.Esbot.B is executed, it performs the following actions:

   1. Creates the mutex "wpa", so that only one copy of the worm runs on the compromised computer:

   2. Copies itself as %System%\wpa.exe.

      Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

   3. Runs itself as a service:

      Service Name: wpa
      Display Name: Windows Product Activation
      Path to executable: %System%\wpa.exe

   4. Injects itself to explorer.exe.

   5. Modifies the value:

      "EnableDCOM" = "N"

      in the registry subkey:

      HKEY_LOCAL_MACHINE\Software\Microsoft\Ole

      to disable DCOM.

   6. Adds the value:

      "restrictanonymous" = "1"

      to the registry subkey:

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa

      to restrict anonymous access to network shares.

   7. Creates the following read only file:

      %Windir%\debug\dcpromo.log

      Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.

   8. Connects to an IRC server on the ypgw.wallloan.com domain on TCP port 18067 to listen for IRC commands.

   9. IRC commands allow the attacker to perform the following actions:

          * Download and execute files
          * List, stop, and start processes and threads
          * Launch Denial of Service (DoS) attacks
          * Find files on local hard disks
          * Scans for computers and attempts to exploit the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS05-039). If successful, the worm sends shell code to the remote machine.
Logged
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: W32.Esbot.B « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!