Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 19th, 2002, 01:25 AM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default New Worm/Trojan (destructive)

Just a quick warning about a new worm, another one that looks targeted at Andreas Haak like the Ants worm was..

As of tonight's database update this will be detected by TDS-3 as Worm.YAW 2.0. The new worm looks from initial analysis as though it arrives as a newsletter from the hosting page of YAW - Yet Another Warner. It is supposedly YAW 2.0, the current available download is 1.0. YAW is a tool to detect dialler software.

The worm arrives attached as yawsetup.exe, 437,760 bytes with a standard setup executable icon. If executed it will backup your notepad.exe (to notedpad.exe) and copy itself as that file. It will copy itself to the RunOnce key in the registry as a random key name as well, with a random (matching) filename. Unsure if this is needed, as the worm has a very destructive payload, deleting as many folders and files as it can from your C drive, other drives appeared unaffected. This occurred in a short time in the first test run, so it most likely is very quickly taking its destructive action. It may not take this action for some time depending on conditions, this has not yet been established. Upon rebooting the drive had an invalid FAT.

It does save 2 files in the Windows folder for spreading, with an 'open' SMTP server list saved as KerneI.das and a list of gathered email addresses as KerneI.daa.

  #2  
Old February 20th, 2002, 03:37 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: New Worm/Trojan (destructive)

Currently, seven variants are known. Two are really common (MD5 sums):

0c32628e76d9e716a4efab028022364c 1.ex$
054d80acac8bd69f322b2dcea357ef2d 2.ex$

Here the MD5 sums of the other variants:

2336aac901724a107d2725c4e6caeacd 3.ex$
a533f828347b2eca6d8784ef593b388d 4.ex$
3fb44cf79640c1112eee98a86bb15abf 5.ex$
860d6a82e2fbf887038f6e2b0cde3651 6.ex$
8ee1fbdb4eba48dda7d35b0adca8d83a 7.ex$

regards.

paul

__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 01:11 AM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums