Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

W32/Spybot-R

Thread Tools
 
Search this Thread
 
Old 14 October 2003, 03:49 PM
  #1  
DJ Dunk
Moderator
Support Scoobynet!
Thread Starter
iTrader: (5)
 
DJ Dunk's Avatar
 
Join Date: Nov 2001
Location: Not all those who wander are lost
Posts: 17,863
Received 0 Likes on 0 Posts
Exclamation

W32/Spybot-R is a P2P worm that spreads via the KaZaA file sharing network.
Upon execution, W32/Spybot-R displays the fake error message
"Runtime Error", "Unable to locate Smartinstl32.dll. Re-installing the application may fix the problem".

The worm creates the folder <system>\kazaabackupfiles and copies itself there using several different filenames, including:

Battlefield_1942.Keygen.FDX.ShareReactor.exe
C&C.Generals-keygen.exe
cs-keygen.exe
dev-nfs.exe
eatop605kg.exe
Freelancer Keygen.exe
hv-Max5-kg.exe
Opera601key.exe
PowerDVD XP v4.0 Keygen.exe
QuickTime 6 Pro keygen.exe
Sonic Foundry ACID Pro 4.0 Keygen(1).exe
VMware 320 keygen (1).exe
Windows XP Professional Keygen by CaFo.exe

To enable sharing of these files the registry entry HKCU\Software\Kazaa\LocalContent\Dir0 is updated to point to this location.

In order to be run automatically on system startup the worm copies itself to explorer64.exe in the Windows system folder and adds the following registry entries which point to this file:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run \Microsof Explorer(64)
HKCU\Software\Microsoft\Windows\CurrentVersion\Run Once\Microsof Explorer(64)

W32/Spybot-R has an IRC backdoor component which has keylogging and backdoor capibilities. The worm connects to an IRC server announcing the infection and allows a malicious user remote access to the computer.
Old 14 October 2003, 04:05 PM
  #2  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Pretty sure we - McAfee - get this one Genericaly description here
Old 14 October 2003, 04:10 PM
  #3  
DJ Dunk
Moderator
Support Scoobynet!
Thread Starter
iTrader: (5)
 
DJ Dunk's Avatar
 
Join Date: Nov 2001
Location: Not all those who wander are lost
Posts: 17,863
Received 0 Likes on 0 Posts
Post

I saw the old one a few months back, I assumed this was a new variant ?

[Edited by DJ Dunk - 10/14/2003 4:11:00 PM]
Old 14 October 2003, 05:40 PM
  #4  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

"This family of worms is expanding extremely rapidly (89 variants currently) and new variants are constantly being covered by our generic detection. For up-to-date protection from the latest variants you need to use the latest DATs."
Old 14 October 2003, 06:41 PM
  #5  
DJ Dunk
Moderator
Support Scoobynet!
Thread Starter
iTrader: (5)
 
DJ Dunk's Avatar
 
Join Date: Nov 2001
Location: Not all those who wander are lost
Posts: 17,863
Received 0 Likes on 0 Posts
Thumbs up

Cheers Jack




All times are GMT +1. The time now is 01:11 PM.