<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoVirusThanks Blog &#187; worm</title>
	<atom:link href="http://blog.novirusthanks.org/tag/worm/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Wed, 01 Feb 2012 13:34:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Small overview of Conficker Worm (PDF)</title>
		<link>http://blog.novirusthanks.org/2009/04/small-overview-of-conficker-worm-pdf/</link>
		<comments>http://blog.novirusthanks.org/2009/04/small-overview-of-conficker-worm-pdf/#comments</comments>
		<pubDate>Sat, 04 Apr 2009 21:35:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Downadup]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/2009/04/small-overview-of-conficker-worm-pdf/</guid>
		<description><![CDATA[I wrote this small PDF to make a small overview of the famous worm named Conficker (aka Downadup). The &#8220;history&#8221; starts when was discovered the vulnerability in Microsoft Windows Operating Systems named as MS08-067. Italian Version Size: 100 kb English Version Size: 99 kb]]></description>
			<content:encoded><![CDATA[<p>I wrote this small PDF to make a small overview of the famous worm named Conficker (aka Downadup). The &#8220;history&#8221; starts when was discovered the vulnerability in Microsoft Windows Operating Systems named as MS08-067.</p>
<div style="margin:20px;padding:10px;background:#CADFEE;border:1px solid #3399FF;color:black;height:80px;"><strong>Italian Version</strong> <a href="http://www.novirusthanks.org/dl.php?get=Small_overview_of_Conficker_Worm_ITALIAN.pdf"><img style="margin:0px;float:right;" src="http://blog.novirusthanks.org/wp-content/uploads/download1.gif" alt="" /></a><br />
<strong>Size:</strong> 100 kb
</div>
<div style="margin:20px;padding:10px;background:#CADFEE;border:1px solid #3399FF;color:black;height:80px;"><strong>English Version</strong> <a href="http://www.novirusthanks.org/dl.php?get=Small_overview_of_Conficker_Worm_ENGLISH.pdf"><img style="margin:0px;float:right;" src="http://blog.novirusthanks.org/wp-content/uploads/download1.gif" alt="" /></a><br />
<strong>Size:</strong> 99 kb
</div>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2009/04/small-overview-of-conficker-worm-pdf/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Worm.Win32.Sohanad &#8211; The Yahoo Messenger Worm</title>
		<link>http://blog.novirusthanks.org/2009/03/wormwin32sohanad-the-yahoo-messenger-worm/</link>
		<comments>http://blog.novirusthanks.org/2009/03/wormwin32sohanad-the-yahoo-messenger-worm/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 00:22:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Win32.Sohanad]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=1412</guid>
		<description><![CDATA[Worm.IM.Sohanad is a worm that spreads itself via Yahoo Messenger and can infect all the contacts present in your Yahoo Messenger Contacts List, by sending them a text message that can contain a malicious HTTP link pushing the users to download the worm. Its also possible for the worm to send a HTTP link that [...]]]></description>
			<content:encoded><![CDATA[<p>Worm.IM.Sohanad is a worm that spreads itself via Yahoo Messenger and can infect all the contacts present in your Yahoo Messenger Contacts List, by sending them a text message that can contain a malicious HTTP link pushing the users to download the worm. Its also possible for the worm to send a HTTP link that contains 0-day exploits for common web browsers, and in this case it is only necessary for users to visit the malicious link to become a victim. </p>
<p>&nbsp;</p>
<p>The worm can disable certain Windows functionalities and, in some cases, it can hijack the browser Internet Explorer homepage and other registry keys. The worm is also used for download other malware or other programs that can steal credit cards and personal information. </p>
<p>&nbsp;</p>
<p>It is also able to spread itself not only by Yahoo Messengers but also by infecting removable devices such as USB flash and hard drives. The worm can copy itself on the removable device and using the file autorun.ini it can infect every computer where will be inserted the removable device and that have the Autorun option enabled.</p>
<p>&nbsp;</p>
<p>The worm can performs these actions:</p>
<p>&nbsp;</p>
<ul>
<li>Copy itself to system32 or windows folder</li>
<li>Spread itself by sending spam messages on Y! Messenger Contacts</li>
<li>Spread itself by infecting removable devices</li>
<li>Disable important functionalities of Windows</li>
<li>Download other malware</li>
<li>Identity theft</li>
<li>Credit Card and Bank accounts theft</li>
</ul>
<p>&nbsp;</p>
<p>The worm can drop itself in the system using these file names:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">C:\WINDOWS\sclhosts.exe
C:\WINDOWS\scvhosts.exe
C:\WINDOWS\system32\blastclnnn.exe
C:\WINDOWS\system32\chrome.exe
C:\WINDOWS\system32\yahoooo.exe
C:\WINDOWS\system32\scvhost.exe
C:\WINDOWS\lsass.exe
C:\WINDOWS\chrome.exe
C:\WINDOWS\system32\chrome.exe
C:\WINDOWS\ffoxer.exe
C:\WINDOWS\foxr.exe</pre></td></tr></table></div>

<p>It installs the following registry key to ensure it starts up with Windows:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Yahoo Messengger</pre></td></tr></table></div>

<p>In some cases the worm disabled also TaskManager and Regedit by changing these registry values:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
DisableTaskMgr (1)
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
DisableRegistryTools (1)</pre></td></tr></table></div>

<p>The worm disabled the option to &#8220;Show hidden files&#8221; in Windows so it can stay hidden from explorer search:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\
Hidden\ShowAll (0)</pre></td></tr></table></div>

<p>The worm disabled the option to execute a System Restore to roll back to a good situation by changing this registry values:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\
DisableSR (1)
HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\
LimitSystemRestoreCheckpointing (1)</pre></td></tr></table></div>

<p>Other detections generated by other Antivirus are:</p>
<blockquote><p>
<font color="red">IM-Worm.Win32.Sohanad</font><br />
<font color="red">IM-Worm.Win32.AutoIt.g</font><br />
<font color="red">WORM_SOHANAD</font><br />
<font color="red">W32.Imaut</font><br />
<font color="red">W32/Sohana-AH</font>
</p></blockquote>
<p>How to remove Worm.Win32.Sohanad ?</p>
<p>&nbsp;</p>
<p>1) Kill malicious running processes associated with the worm<br />
2) Delete malicious files<br />
3) Delete malicious registry keys<br />
4) Restore all the disabled functionalities of Windows<br />
5) Check with your credit card company to see if your missing any money</p>
<p>&nbsp;</p>
<p>You can use the following script to re-enable the functionalities of Windows:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">Windows Registry Editor Version 5.00
&nbsp;
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
&quot;DisableTaskMgr&quot;=dword:00000000
&nbsp;
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
&quot;DisableRegistryTools&quot;=dword:00000000
&nbsp;
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden]
&quot;ShowAll&quot;=dword:00000001
&nbsp;
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
&quot;DisableSR&quot;=dword:00000000
&nbsp;
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer]
&quot;LimitSystemRestoreCheckpointing&quot;=dword:00000000</pre></td></tr></table></div>

<p>The script will perform these actions:</p>
<p>&nbsp;</p>
<p>1) Enable Task manager<br />
2) Enable Regedit<br />
3) Enable SystemRestore<br />
4) Enable Show Hidden Files option</p>
<p>&nbsp;</p>
<p>Save the script as <i>restore.reg</i> and double click it. </p>
<p>&nbsp;</p>
<p>You can also scan your system with <a href="http://www.novirusthanks.org/products/novirusthanks-malware-remover/">NoVirusThanks Malware Remover</a> to detect and remove other unwanted applications.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2009/03/wormwin32sohanad-the-yahoo-messenger-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

