<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoVirusThanks Blog &#187; inject</title>
	<atom:link href="http://blog.novirusthanks.org/tag/inject/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Wed, 01 Feb 2012 13:34:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Rootkit.Siberia2 + Rootkit.Cutwail.A &#8211; Analysis</title>
		<link>http://blog.novirusthanks.org/2008/11/rootkitcutwaila-rootkitsiberia2-analysis/</link>
		<comments>http://blog.novirusthanks.org/2008/11/rootkitcutwaila-rootkitsiberia2-analysis/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 18:04:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[ati5ssxx.sys]]></category>
		<category><![CDATA[BHO]]></category>
		<category><![CDATA[Cutwail.A]]></category>
		<category><![CDATA[DosDevices]]></category>
		<category><![CDATA[explorer.exe]]></category>
		<category><![CDATA[fastfat.sys]]></category>
		<category><![CDATA[Filt]]></category>
		<category><![CDATA[hooks]]></category>
		<category><![CDATA[iexplore.exe]]></category>
		<category><![CDATA[inject]]></category>
		<category><![CDATA[IRP]]></category>
		<category><![CDATA[kernel driver]]></category>
		<category><![CDATA[mailgrab]]></category>
		<category><![CDATA[NDIS.SYS]]></category>
		<category><![CDATA[ntfs.sys]]></category>
		<category><![CDATA[ntoskrnl.exe]]></category>
		<category><![CDATA[Prot3]]></category>
		<category><![CDATA[rooktit]]></category>
		<category><![CDATA[Rootkit.Siberia2]]></category>
		<category><![CDATA[SafeBoot]]></category>
		<category><![CDATA[services.exe]]></category>
		<category><![CDATA[siberia2]]></category>
		<category><![CDATA[Spam.Bot]]></category>
		<category><![CDATA[tcpsr.sys]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=289</guid>
		<description><![CDATA[Analysis Content: Rootkit.Siberia2 + Rootkit.Cutwail.A &#8211; Analysis Released: 20.11.2008 Author of Analysis: Robert Contact: robert@novirusthanks.org Website: http://novirusthanks.org Steve sent me another rootkit sample and here is the analysis : ) The file I received was named mtnjmcjubjjuyto.exe and below there is the report of the scan: Report Generated 20.11.2008 at 16.47.12 (GMT 1) Time for [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>Analysis Content: Rootkit.Siberia2 + Rootkit.Cutwail.A &#8211; Analysis<br />
Released: 20.11.2008<br />
Author of Analysis: Robert<br />
Contact: robert@novirusthanks.org<br />
Website: http://novirusthanks.org</p>
</blockquote>
<p>Steve sent me another rootkit sample and here is the analysis : )</p>
<p>The file I received was named <strong>mtnjmcjubjjuyto.exe</strong> and below there is the report of the scan:</p>
<blockquote><p>Report Generated 	20.11.2008 at 16.47.12 (GMT 1)<br />
Time for scan: 	22 seconds<br />
Filename: 	mtnjmcjubjjuyto.exe<br />
File size: 	9 KBF<br />
MD5 Hash: 	7499B7C5951B6A46689E5C387EFADC66<br />
SHA1 Hash: 	056FE023F0906C9C99E16674D6E673C39823BF84<br />
CRC32: 	1125039963<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">9</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan.Win32.Meredrop!IK</span><br />
Avira AntiVir 	<span style="color: red;">HEUR/Crypted</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: red;">Trojan horse Downloader.Generic_r.BT</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA <span style="color: red;"> Trojan-Downloader.Win32.Agent.apsz A</span><br />
IkarusT3 	<span style="color: red;">Trojan.Win32.Meredrop</span><br />
Kaspersky 	<span style="color: red;">Trojan-Downloader.Win32.Agent.apsz</span><br />
McAfee 	<span style="color: red;">Generic Dropper trojan</span><br />
NOD32 v3 	<span style="color: red;">probably a variant of Win32/Kryptik.BJ trojan</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus <span style="color: green;"> Nothing found!</span><br />
Sophos 	<span style="color: red;">Sus/Behav-273</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>After the execution of the above file, were created new files:</p>
<blockquote><p>C:\ebafud.exe<br />
C:\WINDOWS\system32\rs32net.exe</p>
</blockquote>
<p>And a new process was visible in Task Manager with the name of <strong>rs32net.exe</strong>.</p>
<p>Below there is the report of the scan:</p>
<blockquote><p>Report Generated 	20.11.2008 at 16.53.35 (GMT 1)<br />
Time for scan: 	29 seconds<br />
Filename: 	rs32net.exe<br />
File size: 	22 KB<br />
MD5 Hash: 	D3185511968F2F5A8A68FA9F67CCED2F<br />
SHA1 Hash: 	4254F0920877984724446BF6BCF0E764E27ADF07<br />
CRC32: 	1940657006<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">1</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: green;">Nothing found!</span><br />
Avira AntiVir 	<span style="color: red;">TR/Dropper.Gen</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA <span style="color: green;"> Nothing found!</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: green;">Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>New files were created after some seconds:</p>
<blockquote><p>C:\njkkjh.exe<br />
C:\nfgo.exe<br />
C:\duhtvwns.exe<br />
C:\WINDOWS\system32\jsne87fidgf.dll<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\winlogin.exe</p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 16.51.56 (GMT 1)<br />
Time for scan: 	26 seconds<br />
Filename: 	jsne87fidgf.dll<br />
File size: 	9 KB<br />
MD5 Hash: 	619BF3607989002B551E830ED151E8D9<br />
SHA1 Hash: 	C0776DD69B723793D477CD05A0C18236A319491D<br />
CRC32: 	3590387388<br />
Application Type:	Dinamyc Link Library (DLL) 32bit<br />
Packer detected:	Nothing found [Overlay] *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">3</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan-Clicker.Win32.Klik!IK</span><br />
Avira AntiVir 	<span style="color: red;">TR/Fakealert.HO</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: green;">Nothing found!</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: red;">Troj/Agent-IHC</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>We can see that this .DLL looks like a BHO (Browser Helper Objects) and it is <strong>injected</strong> into 2 processes:<br />
-<strong>IEXPLORE.EXE</strong><br />
-<strong>explorer.exe</strong></p>
<p>Below there is the report of the scan of <strong>winlogin.exe</strong>:</p>
<blockquote><p>Report Generated 	20.11.2008 at 17.00.37 (GMT 1)<br />
Time for scan: 	29 seconds<br />
Filename: 	winlogin.exe<br />
File size: 	14 KB<br />
MD5 Hash: 	FA14206DC72A8EC78B0D3E07F1DB8F73<br />
SHA1 Hash: 	1ABD0114E7AEFA3381B95BADCE96AE9294D0D7AF<br />
CRC32: 	4292284846<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found [Overlay] *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">5</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan-Clicker.Win32.Klik!IK</span><br />
Avira AntiVir 	<span style="color: red;">TR/Fakealert.HO</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: green;">Nothing found!</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: red;">Generic FakeAlert.d trojan</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: red;">Troj/Dloadr-CAD</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: red;">Win32 Shadow AutoStart Install</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>After, new files were created:</p>
<blockquote><p>C:\psqrhqn.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\bat9.tmp.bat<br />
C:\mfglmypk.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\BAT9TM~1.BAT<br />
C:\cvqkuk.exe<br />
C:\naxv.exe<br />
C:\WINDOWS\system32\fklame32.dll<br />
C:\cvqkuk.exe<br />
C:\nriljal.exe</p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 17.06.19 (GMT 1)<br />
Time for scan: 	23 seconds<br />
Filename: 	fklame32.dll<br />
File size: 	22 KB<br />
MD5 Hash: 	F049A08DD65E4AB04575B3667E56A408<br />
SHA1 Hash: 	1F0270794587CB51B514CFDA5B040C08CDD18212<br />
CRC32: 	733835836<br />
Application Type:	Dinamyc Link Library (DLL) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">9</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan.Win32.BHO.d!IK</span><br />
Avira AntiVir 	<span style="color: red;">TR/BHO.Gen</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: red;">Trojan.Generic.1134607</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: red;">Trojan.Win32.BHO.ibp A</span><br />
IkarusT3 	<span style="color: red;">Trojan.Win32.BHO.d</span><br />
Kaspersky 	<span style="color: red;">Trojan.Win32.BHO.ibp</span><br />
McAfee 	<span style="color: red;">Generic.dx trojan</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: red;">Mal/Emogen-G</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: red;">Trojan.Win32.BHO.ibp</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 17.11.00 (GMT 1)<br />
Time for scan: 	26 seconds<br />
Filename: 	naxv.exe<br />
File size: 	172 KB<br />
MD5 Hash: 	1EDB6B045A907E4F63EAFBCA43E8660E<br />
SHA1 Hash: 	E7B6CF6D1BC634F3F96D8EDA786F056B614EA6BC<br />
CRC32: 	1878180187<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">3</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: green;">Nothing found!</span><br />
Avira AntiVir 	<span style="color: green;">Nothing found!</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: red;">W32/FakeAlert.3!Maximus</span><br />
G DATA 	<span style="color: green;">Nothing found!</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: red;">a variant of Win32/Kryptik.BX trojan</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: red;">Suspicious</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: green;">Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>The file named fklame32.dll was <strong>injected</strong> in 2 processes:<br />
-<strong>IEXPLORE.EXE</strong><br />
-<strong>explorer.exe</strong></p>
<p>Another files were created:</p>
<blockquote><p>C:\DOCUME~1\user899\LOCALS~1\Temp\newbot.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\csrssc.exe  =&gt; Has attribute +H (Hidden)<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\loader.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\2029295898.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\2155777770.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\2165992458.exe<br />
C:\WINDOWS\system32\bdedabafadb.dll</p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 17.17.38 (GMT 1)<br />
Time for scan: 	27 seconds<br />
Filename: 	newbot.exe<br />
File size: 	71 KB<br />
MD5 Hash: 	29A9BDF7B39FFDC8AC8AE4EFEB540E35<br />
SHA1 Hash: 	681E92D08A374E8086303A9E453727BF609B283B<br />
CRC32: 	2651006629<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">2</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: green;">Nothing found!</span><br />
Avira AntiVir 	<span style="color: green;">Nothing found!</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: red;">Trojan.Win32.Inject.kdz A</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: red;">Trojan.Win32.Inject.kdz</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos <span style="color: green;"> Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>After, the file named <strong>bdedabafadb.dll</strong> was injected in <strong>explorer.exe</strong> and another file was created:</p>
<blockquote><p>C:\Documents and Settings\user899\Application Data\gadcom\gadcom.exe</p>
</blockquote>
<p>And was created also a new directory:</p>
<blockquote><p>C:\WINDOWS\tsd532</p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 17.26.58 (GMT 1)<br />
Time for scan: 	24 seconds<br />
Filename: 	gadcom.exe<br />
File size: 	55 KB<br />
MD5 Hash: 	3C4A94886E1A2C015CA9758E69A4A33B<br />
SHA1 Hash: 	6D86EB185C7DEC2E1FD7C4BD3291D5357CA2CA2B<br />
CRC32: 	1614352094<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">5</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Trojan.Win32.Matcash!IK</span><br />
Avira AntiVir 	<span style="color: green;">Nothing found!</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: green;">Nothing found!</span><br />
BitDefender 	<span style="color: green;">Nothing found!</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: red;">Trojan.Win32.Agent.aorq A</span><br />
IkarusT3 	<span style="color: red;">Trojan.Win32.Matcash</span><br />
Kaspersky 	<span style="color: red;">Heur.Trojan.Generic</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos <span style="color: green;"> Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: red;">Win32.Trojan-Downloader</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>And now 2 interesting files were created in <strong>C:\WINDOWS\system32\drivers\</strong>:</p>
<blockquote><p>C:\WINDOWS\system32\drivers\ati5ssxx.sys<br />
C:\WINDOWS\system32\drivers\tcpsr.sys</p>
</blockquote>
<blockquote><p>Report Generated 	20.11.2008 at 15.21.44 (GMT 1)<br />
Time for scan: 	24 seconds<br />
Filename: 	ati5ssxx.kdmp<br />
File size: 	32 KB<br />
MD5 Hash: 	F8D0B66BD259EBC5D1C9B4C347CC684B<br />
SHA1 Hash: 	CEB0ED5C79626383158E2396F248C0CA8A796A06<br />
CRC32: 	3826122122<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	<span style="color: red;">File is possible binded with malware</span><br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">8</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: red;">Rootkit.Win32.Protector!IK</span><br />
Avira AntiVir 	<span style="color: red;">RKIT/Protector.BC</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: red;">Trojan horse Rootkit-Agent.AV</span><br />
BitDefender 	<span style="color: red;">Trojan.Kobcka.FB</span><br />
ClamAV 	<span style="color: red;">Trojan.Rootkit.Protector-1</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: green;">Nothing found!</span><br />
IkarusT3 	<span style="color: red;">Rootkit.Win32.Protector</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman <span style="color: green;"> Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus <span style="color: green;"> Nothing found!</span><br />
Sophos 	<span style="color: green;">Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: red;">Rootkit.Siberia.Gen</span></p>
</blockquote>
<p>Below there are some interested strings extracted from the code:</p>
<blockquote><p>ntoskrnl.exe<br />
RSDS<br />
<strong>d:\programs\siberia2\protect\objfre_wxp_x86\i386\protect.pdb</strong><br />
services.exe<br />
<strong>d:\programs\siberia2\innerdrv\objfre_wxp_x86\i386\InnerDrv.pdb</strong></p>
<p>RtlAppendUnicodeStringToString<br />
wcslen<br />
memset<br />
ObfDereferenceObject<br />
strcmp<br />
PsLookupProcessByProcessId<br />
PsTerminateSystemThread<br />
KeDelayExecutionThread<br />
ZwClose<br />
PsCreateSystemThread<br />
wcsncpy<br />
ZwQueryValueKey<br />
RtlInitUnicodeString<br />
ZwOpenKey<br />
wcsncat<br />
wcscpy<br />
PsSetCreateProcessNotifyRoutine<br />
IoDeleteDevice<br />
IoCreateSymbolicLink<br />
IoCreateDevice<br />
IofCompleteRequest<br />
ZwWriteFile<br />
ZwCreateFile<br />
IoRegisterFsRegistrationChange<br />
KeInitializeMutex<br />
ObReferenceObjectByName<br />
IoDriverObjectType<br />
RtlAppendUnicodeToString<br />
ZwQueryDirectoryObject<br />
ZwOpenDirectoryObject<br />
KeReleaseMutex<br />
KeWaitForSingleObject<br />
memcpy<br />
ExAllocatePoolWithTag<br />
ExFreePoolWithTag<br />
MmIsAddressValid<br />
CmRegisterCallback<br />
ExInitializeResourceLite<br />
KeLeaveCriticalRegion<br />
ExReleaseResourceLite<br />
ExAcquireResourceExclusiveLite<br />
KeEnterCriticalRegion<br />
RtlCopyUnicodeString<br />
RtlCompareUnicodeString<br />
ExAcquireResourceSharedLite<br />
ObQueryNameString<br />
ZwEnumerateValueKey<br />
ExQueueWorkItem<br />
ZwSetValueKey<br />
ZwCreateKey<br />
ZwQuerySystemInformation<br />
PsLookupThreadByThreadId<br />
wcscmp<br />
KeUnstackDetachProcess<br />
KeStackAttachProcess<br />
ZwAllocateVirtualMemory<br />
ZwOpenProcess<br />
KeInsertQueueApc<br />
KeInitializeApc<br />
NtBuildNumber<br />
ntoskrnl.exe</p>
<p>memcpy<br />
ExFreePoolWithTag<br />
ExAllocatePoolWithTag<br />
ZwQuerySystemInformation<br />
ntoskrnl.exe</p>
<p>\SystemRoot\system32\drivers\<br />
services.exe<br />
ImagePath<br />
Start<br />
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\<br />
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\<br />
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\<br />
\DosDevices\Prot3<br />
\Device\Prot3<br />
\FileSystem<br />
CSDVersion<br />
\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Control\Windows</p>
</blockquote>
<p>So this rootkit looks like to has got a name:<br />
<strong>siberia2</strong></p>
<p>We can see that the driver add itself to the <strong>Safe Boot</strong>:</p>
<blockquote><p>\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\<br />
\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\</p>
</blockquote>
<p>This mean that if you will start Windows in <strong>Safe Mode</strong> the driver will be automatic loaded with the other trusted drivers !</p>
<p>Report of the scan of <strong>tcpsr.sys</strong>:</p>
<blockquote><p>Report Generated 	20.11.2008 at 15.21.44 (GMT 1)<br />
Time for scan: 	24 seconds<br />
Filename: 	tcpsr.dmp<br />
File size: 	8 KB<br />
MD5 Hash: 	D29B23728B03BED296C9DF4AC1B34303<br />
SHA1 Hash: 	34BCB3149A57C9B7A95BE29EA96EA5B18E678E42<br />
CRC32: 	2830732520<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nothing found [Overlay] *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<span style="color: red;">2</span> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<span style="color: green;">Nothing found!</span><br />
Avira AntiVir 	<span style="color: green;">Nothing found!</span><br />
Avast 	<span style="color: green;">Nothing found!</span><br />
AVG 	<span style="color: red;">Trojan horse SpamBot.G</span><br />
BitDefender 	<span style="color: red;">Rootkit.Cutwail.A</span><br />
ClamAV 	<span style="color: green;">Nothing found!</span><br />
Comodo 	<span style="color: green;">Nothing found!</span><br />
Dr.Web 	<span style="color: green;">Nothing found!</span><br />
Ewido 	<span style="color: green;">Nothing found!</span><br />
F-PROT 6 	<span style="color: green;">Nothing found!</span><br />
G DATA 	<span style="color: green;">Nothing found!</span><br />
IkarusT3 	<span style="color: green;">Nothing found!</span><br />
Kaspersky 	<span style="color: green;">Nothing found!</span><br />
McAfee 	<span style="color: green;">Nothing found!</span><br />
NOD32 v3 	<span style="color: green;">Nothing found!</span><br />
Norman 	<span style="color: green;">Nothing found!</span><br />
Panda 	<span style="color: green;">Nothing found!</span><br />
QuickHeal 	<span style="color: green;">Nothing found!</span><br />
Solo Antivirus 	<span style="color: green;">Nothing found!</span><br />
Sophos 	<span style="color: green;">Nothing found!</span><br />
TrendMicro 	<span style="color: green;">Nothing found!</span><br />
VBA32 	<span style="color: green;">Nothing found!</span><br />
VirusBuster 	<span style="color: green;">Nothing found!</span></p>
</blockquote>
<p>We can extract other interested strings from the code:</p>
<blockquote><p>hxxp://bestdiabetesdrugs.com/?<br />
hxxp://mexicandrugstor.com/?<br />
hxxp://superdrugsworld.com/?<br />
hxxp://superdrugssite.com/?<br />
hxxp://bestanxietydrugs.com/?<br />
hxxp://georgescheapdrugs.com/?<br />
hxxp://buydrugsonlinehere.com/?<br />
hxxp://ulcerdrugsonline.com/?<br />
hxxp://bestdrugsinternational.com/?<br />
hxxp://besttopicaldrugs.com/?</p>
<p><strong>d:\programs\mailgrab\drv\objchk_wxp_x86\i386\filt.pdb</strong><br />
IoDeleteDevice<br />
IoCreateSymbolicLink<br />
IoCreateDevice<br />
RtlInitUnicodeString<br />
IofCompleteRequest<br />
IoDeleteSymbolicLink<br />
ExFreePoolWithTag<br />
ExAllocatePool<br />
memcpy<br />
memset<br />
MmMapLockedPages<br />
KeTickCount<br />
KeBugCheckEx<br />
ntoskrnl.exe<br />
KfReleaseSpinLock<br />
KfAcquireSpinLock<br />
HAL.dll<br />
NdisDeregisterProtocol<br />
NdisRegisterProtocol<br />
NdisInitUnicodeString<br />
NDIS_BUFFER_TO_SPAN_PAGES<br />
NdisQueryBufferOffset<br />
NdisAllocateMemory<br />
NdisFreeMemory<br />
NDIS.SYS</p>
<p>\DosDevices\Filt<br />
\Device\Filt<br />
ndarProtocol</p>
</blockquote>
<p>So this rootkit should be named as:<br />
<strong>mailgrab</strong></p>
<p>And should be used for spam activity as we can see also from the detection name of AVG:<br />
<strong>Trojan horse SpamBot.G</strong></p>
<p>And now lets do a little analysis:</p>
<p>This rootkit variants seem pretty nasty, there aren&#8217;t <strong> SSDT / ShadowSSDT Hooks detected</strong>, if you use certain Anti-Rootkit software you&#8217;ll get a BSOD, rootkit driver is started also in Safe Mode Normal / Network Support, you cannot modify/change/delete any registry key that is related to the rootkit drivers, you cannot modify/change/delete the 2 files with extension .SYS that were created !!! The drivers seem to install hooks not only in Ntfs.sys and Fastfat.sys, but (if I am not wrong) also in:<br />
-FltMgr.sys<br />
-mrxdav.sys<br />
-mrxsmb.sys<br />
-Msfs.sys<br />
-Mup.sys<br />
-Npsf.sys<br />
-Netbios.sys<br />
-rdbss.sys<br />
-sr.sys<br />
-srv.sys</p>
<p>Also if you boot Windows in Safe Mode (at least in my case) the second driver named <strong>tcpsr.sys</strong> will be automatic deleted !</p>
<p>Apparently this rootkit seems to be the boss of the OS : )</p>
<p>Now lets see some images:</p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>Suspicious drivers modifications/hooks</strong>:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers1.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers2.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers3.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers4.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers5.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers6.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers7.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers8.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers9.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers10.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers11.gif" alt="" /><br />
<img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_drivers12.gif" alt="" /></p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>No SSDT hooks detected</strong></p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_No_SSDT.gif" alt="" /></p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>Stealth code detected</strong></p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_stealth_code.gif" alt="" /></p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>Visible processes</strong></p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_processi.gif" alt="" /></p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>Kernel Modifications</strong> (here I used Kernel Detective by GamingMasteR of at4re)</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_KrnMods.gif" alt="" /></p>
<p><img src="http://novirusthanks.org/images/arrow.gif" alt="" /> <strong>registry startup keys</strong></p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Rootkit_Siberia2_Analysis_startup.gif" alt="" /></p>
<p>Below there is some (different from the other analysis) Internet Traffic that we received with the malware:</p>
<blockquote><p>GET /?bot_id=0&amp;mode=1 HTTP/1.1<br />
User-Agent: imrabot<br />
Host: sys368.3fn.net:3084<br />
Cache-Control: no-cache</p>
</blockquote>
<p>When I browsed the link it looked like a Spam Control Panel or similar related to spam:</p>
<blockquote><p>&lt;form name = &#8220;request&#8221; action=&#8221;./?bot_id=1998477142&#8243; method=&#8221;POST&#8221;&gt;<br />
&lt;input type=hidden name=&#8221;bot_id&#8221; value=&#8221;1998477142&#8243;&gt;</p>
<p>&lt;szXML&gt;<br />
&lt;SCID&gt;1100000&lt;/SCID&gt;<br />
&lt;Cookie&gt;*@live[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*.live[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*hotmail*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*@msn[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*.msn[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*@msnaccountservices.*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*@atdmt[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*@advertising[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*msnportal*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*pointroll[*&lt;/Cookie&gt;<br />
&lt;Cookie&gt;*doubleclick[*&lt;/Cookie&gt;<br />
&lt;scriptRegAcc&gt;<br />
&lt;Navigate&gt;http://get.live.com/mail/overview&lt;/Navigate&gt;<br />
&lt;WaitAnyPagesWithText&gt;<br />
&lt;Debug&gt;2, fail wait page with GetFree button&lt;/Debug&gt;<br />
&lt;Text&gt;OmnitureInterface.buttonNotification&lt;/Text&gt;<br />
&lt;/WaitAnyPagesWithText&gt;</p>
<p>&lt;!--button get free--&gt;<br />
&lt;ToLink&gt;<br />
&lt;Debug&gt;3, fail click GetFree button&lt;/Debug&gt;<br />
&lt;TagName&gt;a&lt;/TagName&gt;<br />
&lt;outerHTML&gt;OmnitureInterface.buttonNotification&lt;/outerHTML&gt;<br />
&lt;/ToLink&gt;<br />
&lt;WaitAnyPagesWithText&gt;<br />
&lt;Debug&gt;4, fail wait reg page&lt;/Debug&gt;<br />
&lt;Text&gt;join.msn.com&lt;/Text&gt;<br />
&lt;Text&gt;signup.live.com&lt;/Text&gt;<br />
&lt;Text&gt;logout.aspx&lt;/Text&gt;<br />
&lt;/WaitAnyPagesWithText&gt;<br />
&lt;!--LOG OUT--&gt;<br />
&lt;If_ValidateInBodyHTML&gt;logout.aspx&lt;/If_ValidateInBodyHTML&gt;<br />
&lt;Then_ToLink&gt;<br />
&lt;TagName&gt;a&lt;/TagName&gt;<br />
&lt;outerHTML&gt;logout.aspx&lt;/outerHTML&gt;<br />
&lt;/Then_ToLink&gt;<br />
&lt;WaitAnyPagesWithText&gt;<br />
&lt;Debug&gt;14, fail wait reg page after logout&lt;/Debug&gt;<br />
&lt;Text&gt;join.msn.com&lt;/Text&gt;<br />
&lt;Text&gt;signup.live.com&lt;/Text&gt;<br />
&lt;/WaitAnyPagesWithText&gt;</p>
<p>&lt;!--To english page registration--&gt;<br />
&lt;Navigate&gt;https://signup.live.com/newuserdl.aspx?mkt=en-us&amp;amp;revipc=US&amp;amp;ru=http://mail.live.com/?newuser=yes&amp;amp;rx=http://get.live.com/mail/options&amp;amp;rollrs=04&amp;amp;lic=1&lt;/Navigate&gt;<br />
&lt;WaitAnyPagesWithText&gt;<br />
&lt;Debug&gt;5, fail wait English reg page&lt;/Debug&gt;<br />
&lt;Text&gt;submitForCP&lt;/Text&gt;<br />
&lt;Text&gt;reg&lt;/Text&gt;<br />
&lt;Text&gt;logout.aspx&lt;/Text&gt;<br />
&lt;/WaitAnyPagesWithText&gt;<br />
&lt;!--LOG OUT--&gt;<br />
&lt;If_ValidateInBodyHTML&gt;logout.aspx&lt;/If_ValidateInBodyHTML&gt;<br />
&lt;Then_ToLink&gt;<br />
&lt;TagName&gt;a&lt;/TagName&gt;<br />
&lt;outerHTML&gt;logout.aspx&lt;/outerHTML&gt;<br />
&lt;/Then_ToLink&gt;</p>
<p>&lt;!--Anketa--&gt;<br />
&lt;!--Name--&gt;<br />
&lt;AttrFillForm&gt;<br />
&lt;AttrName&gt;id&lt;/AttrName&gt;<br />
&lt;AttrValueNI&gt;iFirstName&lt;/AttrValueNI&gt;<br />
&lt;ValueForFillRndFromBase&gt;Names&lt;/ValueForFillRndFromBase&gt;<br />
&lt;/AttrFillForm&gt;<br />
&lt;!--Surname--&gt;<br />
&lt;AttrFillForm&gt;<br />
&lt;AttrName&gt;id&lt;/AttrName&gt;<br />
&lt;AttrValueNI&gt;iLastName&lt;/AttrValueNI&gt;<br />
&lt;ValueForFillRndFromBase&gt;Surnames&lt;/ValueForFillRndFromBase&gt;<br />
&lt;/AttrFillForm&gt;<br />
&lt;!--Sex--&gt;<br />
&lt;ClickTag&gt;<br />
&lt;TagName&gt;input&lt;/TagName&gt;<br />
&lt;AttrName&gt;id&lt;/AttrName&gt;<br />
&lt;AttrValueNI&gt;iGenderMale&lt;/AttrValueNI&gt;<br />
&lt;Click/&gt;<br />
&lt;/ClickTag&gt;<br />
&lt;!--Born--&gt;<br />
&lt;AttrFillForm&gt;<br />
&lt;AttrName&gt;id&lt;/AttrName&gt;<br />
&lt;AttrValueNI&gt;iBirthYear&lt;/AttrValueNI&gt;<br />
&lt;ValueForFillRndFromBase&gt;YearsOfBorn&lt;/ValueForFillRndFromBase&gt;<br />
&lt;/AttrFillForm&gt;</p>
<p>...</p>
<p>...</p>
</blockquote>
<p>After, started again the same aggressive Spam Activity as all the other rootkit analysis.</p>
<p>And below there is the <strong>HiJackThis Log</strong>:</p>
<blockquote><p>Logfile of Trend Micro HijackThis v2.0.0 (BETA)<br />
Scan saved at 4:12:49 PM, on 11/20/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
Boot mode: Normal</p>
<p>Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\savedump.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\DOCUME~1\user899\LOCALS~1\Temp\winlogin.exe<br />
C:\Documents and Settings\user899\Application Data\gadcom\gadcom.exe<br />
C:\WINDOWS\system32\wscntfy.exe</p>
<p>O2 - BHO: C:\WINDOWS\system32\jsne87fidgf.dll - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\jsne87fidgf.dll (file missing)<br />
O4 - HKLM\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe<br />
O4 &#8211; HKLM\..\Run: [xsjfn83jkemfofght] C:\DOCUME~1\user899\LOCALS~1\Temp\winlogin.exe<br />
O4 &#8211; HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
O4 &#8211; HKCU\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe<br />
O4 &#8211; HKCU\..\Run: [xsjfn83jkemfofght] C:\DOCUME~1\user899\LOCALS~1\Temp\winlogin.exe<br />
O4 &#8211; HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\user899\LOCALS~1\Temp\csrssc.exe<br />
O4 &#8211; HKCU\..\Run: [gadcom] &#8220;C:\Documents and Settings\user899\Application Data\gadcom\gadcom.exe&#8221; 61A847B5BBF72813349838466188719AB689201522886B092CBD44BD8689220221DD3257<br />
O4 &#8211; HKCU\..\Run: [12CFG94-z641-2SF-N31P-5M1ER6H6L1] C:\RECYCLER\S-1-5-21-3997352701-5278103066-943349985-9760\winigon.exe<br />
O9 &#8211; Extra button: Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:\Program Files\Messenger\msmsgs.exe<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Windows Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:\Program Files\Messenger\msmsgs.exe<br />
O20 &#8211; Winlogon Notify: bdedabafadb &#8211; C:\WINDOWS\system32\bdedabafadb.dll<br />
O22 &#8211; SharedTaskScheduler: Browseui preloader &#8211; {438755C2-A8BA-11D1-B96B-00A0C90312E1} &#8211; C:\WINDOWS\system32\browseui.dll<br />
O22 &#8211; SharedTaskScheduler: Component Categories cache daemon &#8211; {8C7461EF-2B13-11d2-BE35-3078302C2030} &#8211; C:\WINDOWS\system32\browseui.dll<br />
O22 &#8211; SharedTaskScheduler: mcb7uehuj3n8weuhejsw &#8211; {C5BF49A2-94F3-42BD-F434-3604812C897D} &#8211; C:\WINDOWS\system32\jsne87fidgf.dll (file missing)</p>
</blockquote>
<p>End of Analysis.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/11/rootkitcutwaila-rootkitsiberia2-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

