Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 22nd, 2002, 07:39 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Up front warning: Optix Pro v1.0

As it seems, within a shortwhile the new version from Optix: Optix Pro v1.0 will be out in the wild.

The previous version(s) from optix have had devastating capacities; the upcoming new version will have no doubt even more nasty ones, although no specs can be provided at this moment.

As always, there will the various anti-trojan softwares will update their databases as soon as possible. An 'in between period" nevertheless will be unavoidable.

Bottom line: be careful (as always...).

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #2  
Old March 26th, 2002, 08:33 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: Up front warning: Optix Pro v1.0

Courtesy to Gavin Coe from DCS (who apparently grabbed a copy before we managed to do so - no surprise really * *):

Specs from this nastie:

Set features for Version 1:

Power Options (turn off comp, restart, logoff)
Get Server Information, uninstall/close server
Get Computer Information (Speed, HDSpace, username, windows ver.)
Get Passwords (Cached, Aim, RAS)
File Mang.
Process Mang.
Registry Mang.
Window Mang.
Message Boxes
Keylogger
Client2Client Chat
Matrix Chat(Client2Server)
Send Keys
Screen Capture
WebCam Spy
Numerous "Humor" things (Better than just open/close cdrom *)

SERVER FEATURES
Configurable:
Port
Password
Victim Name
Edit Server Password
No-Edit server after initial edit
Fake Error Message
5 different startup methods
windir/sysdir/stay in original location
registry key (startup)
server file .exe name
melt server
ICQ, CGI, MAIL, and IRC notify. Mail has built in smtp-relay.
Kill Firewalls/Anti-Virus .exe's.
Add your own configurable .exe and nt/2k/xp services.
------

regards.

paul


__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #3  
Old March 26th, 2002, 08:38 AM
Checkout's Avatar
Checkout Checkout is offline
Security Rhinoceros
 
Join Date: Feb 2002
Posts: 1,227
Default Re: Up front warning: Optix Pro v1.0

Blimey...the thing must be as big as Windows itself! *Can it also make good toast? *
__________________
My Novel
  #4  
Old March 26th, 2002, 09:45 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: Up front warning: Optix Pro v1.0

Hi Checkout,

Quote:
the thing must be as big as Windows itself!


Not at all. It's mainly the server part that counts for victims.

Quote:
Can it also make good toast?

It depends on your perspective; having the server on your system no doubt can make you toast *

regards.

paul * *

__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #5  
Old March 26th, 2002, 09:46 AM
FanJ
 
Posts: n/a
Default Re: Up front warning: Optix Pro v1.0

Paul,

Oops, what means "Mang." like in for example "File Mang."? Management?
  #6  
Old March 26th, 2002, 10:14 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: Up front warning: Optix Pro v1.0

Quote:
Paul,

Oops, what means "Mang." like in for example "File Mang."? Management?

Jan, you can call it that way - "fooling around with" on the client configuration side.

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #7  
Old April 1st, 2002, 03:32 PM
Gobo
 
Posts: n/a
Default Re: Up front warning: Optix Pro v1.0

I would say that Gavin from TDS is lying if he says he has a copy
Firstly it's not been released yet, the set date is April 7th, although it may be avaliabe before hand.
Secondsly that list of features he has "written" is a direct copy and past from the EvilEye (Otix authors) message board.

Optix Pro (Version 1.o at least) is not different to any of other trojan out there. Nothing from it's feature list stands out or is special by any means. The only extra I expect to see from this trojan is stability, as there optix lite range have been tightly coded so far, except for that small password validation but, but they fixed that in 0.4b.

Gobo
  #8  
Old April 16th, 2002, 09:16 AM
TonyKlein's Avatar
TonyKlein TonyKlein is online now
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,092
Default Re: Up front warning: Optix Pro v1.0

Someone at abother board said The Cleaner has had this one covered as of April 3rd.

Can they be believed, I wonder?

http://www.helpmij.nl/forum/attachme...achmentid=6084
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #9  
Old April 16th, 2002, 09:38 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: Up front warning: Optix Pro v1.0

Tony,

Yep. Daniel has indeed a copy - and it's implemented in his The Cleaner database (as it is in all good anti-trojans nowadays).

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #10  
Old April 16th, 2002, 09:53 AM
TonyKlein's Avatar
TonyKlein TonyKlein is online now
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,092
Default Re: Up front warning: Optix Pro v1.0

Good to hear that Paul!

I just posted the Diamond CS Advisory at my home board in order to inform everyone about the arrival of this nasty piece of malware.

Thanks!
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #11  
Old April 16th, 2002, 10:00 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: Up front warning: Optix Pro v1.0

Tony,

Quote:
I just posted the Diamond CS Advisory at my home board in order to inform everyone about the arrival of this nasty piece of malware.

Nice work *

regards.

paul



__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #12  
Old April 30th, 2002, 11:28 AM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re: Up front warning: Optix Pro v1.0

Hi TonyKlein,

See the post in this thread about our advanced signature scanning and its detection of these trojans

http://www.security-pro.co.uk/yabb/YaBB.pl?board=trojansbackdoors;action=display;num=1017817591;start=0
  #13  
Old April 30th, 2002, 11:31 AM
TonyKlein's Avatar
TonyKlein TonyKlein is online now
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,092
Default Re: Up front warning: Optix Pro v1.0

Thanks Gavin,

Great work! Thanks for the heads up.

Cheers, * Tony
__________________
Tony < > CLSID List - A Collection of Autostart Locations
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 07:25 AM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums