AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 03, 2008, 04:37:45 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4765 Members
Latest Member: hunteryazmin
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: PWSteal.Drorar 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: PWSteal.Drorar  (Read 592 times)
TJ
Tech Team
Hero Member
********
Offline Offline

Posts: 136



View Profile
PWSteal.Drorar
« on: September 19, 2005, 11:42:12 PM »

PWSteal.Drorar is a Trojan horse that attempts to steal system information and log keystrokes. It sends the gathered information to predetermined URLs.

When PWSteal.Drorar is executed, it performs the following actions:

   1. Creates a Microsoft Word document named mssvr.doc and opens it.

   2. Copies itself as following:

          * %ProgramFiles%\Common Files\system\ado\mssrv.exe
          * %ProgramFiles%\Common Files\system\svchost.exe

            Note: %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.

   3. Creates the following service so that it executes every time Windows starts:

      Name: MSDCSRV32
      ImagePath: %Program Files%\Common Files\system\ado\mssrv.exe
      DisplayName: Network Distributed Transaction Coordinator for Workstation

   4. Creates the following files:

          * %Windir%\WindowsUpdate.dat
          * %Windir%\sclureg32a.dll
          * %Windir%\winsock_32a.dll

            Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.

   5. Adds the value:

      "PathName" = "%Windir%\winsock_32a.dll"

      to the registry subkey:

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\
      FCMAIL_TCPIPDOG

   6. Logs key strokes and gathers system information from the compromised computer.

   7. Writes the gathered information to the following files:

          * %Windir%\Setup32set.ini
          * %Windir%\SetupRe.dat

   8. Sends the gathered information to the following URLs as HTTP POST data:

          * [http://]www.stone122.com/[REMOVED]/DoUp.php
          * [http://]www2.stone122.com/[REMOVED]/DoUp.php
          * [http://]www.stone199.com/[REMOVED]/DoUp.php


REMOVAL INSTRUCTIONS
See: http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.drorar.html


To delete the value from the registry
   1. Click Start > Run.
   2. Type regedit
   3. Click OK.
   4. Navigate to the subkey:

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\
      FCMAIL_TCPIPDOG

   5. In the right pane, delete the value:

      "PathName" = "%Windir%\winsock_32a.dll"

   6. Exit the Registry Editor.
Logged
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: PWSteal.Drorar « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!