Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 9th, 2003, 04:13 PM
FanJ
 
Posts: n/a
Default WORM_DELODER.A

As of March 9, 2:49 AM (US Pacific Time), a significant number of infection reports have reached TrendLabs about this new Internet worm, which has been found to be rapidly spreading in China.

This worm usually arrives bearing the file name, Dvldr32.exe. It uses the valid network utility, psexec.exe, to connect to remote machines via port 445.

To gain full access, it tries to log on as administrator by trying passwords from a fixed list.

If the logon attempt is successful, it drops a copy of itself on target machines with a read-only attribute. On remote machines, it drops a backdoor program with the file name, inst.exe, on the following startup folders:

\%s\C$\WINNT\All Users\Start Menu\Programs\Startup\
\%s\C\WINDOWS\Start Menu\Programs\Startup\
\%s\C$\Documents
Settings\All Users\Start Menu\Programs\Startup\

(Note: %s is the network name of the remote machine.)

To enable its automatic execution, this worm creates the following autorun registry entry so that its copy executes at every Windows startup:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
messnger = Dvldr32.exe

This worm, which runs on Windows 2000 and XP, also disables remote shares.

http://www.trendmicro.com/vinfo/viru...WORM_DELODER.A
  #2  
Old March 9th, 2003, 04:16 PM
FanJ
 
Posts: n/a
Default Re:WORM_DELODER.A

And Sophos:

Name: W32/Deloder-A
Type: Win32 worm
Date: 9 March 2003


More information about W32/Deloder-A can be found at
http://www.sophos.com/virusinfo/anal...2delodera.html

  #3  
Old March 9th, 2003, 07:13 PM
root's Avatar
root root is offline
Retired Moderator
 
Join Date: Feb 2002
Location: Missouri, USA
Posts: 1,723
Default Re:WORM_DELODER.A

This bad boy jumped right in and took the place of Bugbear.
I am getting hammered!
__________________
"There is a principle which is a bar against all information, which is proof against all arguments and which cannot fail to keep a man (and a woman) in everlasting igonorance- that principle is: Contempt prior to Investigation."
-Herbert Spencer
  #4  
Old March 10th, 2003, 12:07 AM
Randy_Bell's Avatar
Randy_Bell Randy_Bell is offline
Updates Team
 
Join Date: May 2002
Location: Santa Clara, CA
Posts: 3,053
Default Re:WORM_DELODER.A

McAfee and Symantec have info on this worm too:

McAfee: W32/Deloder.worm
http://vil.mcafee.com/dispVirus.asp?virus_k=100127

Symantec: W32.HLLW.Deloder
http://securityresponse.symantec.com...w.deloder.html
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:08 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums