Author Topic: New Agobot?  (Read 3787 times)

0 Members and 1 Guest are viewing this topic.

Marxist ßastard

  • Guest
New Agobot?
« on: March 23, 2004, 01:06:59 PM »
Avast didn't pick up this new (?) Agobot variant -- sorry if this isn't correct procedure, but I couldn't get an actual mail address to send the report to.

Originally winnt\system32\systems.exe.  IRC is not a possibility for infection, nor is mail; file was likely implanted and executed through RPC vulnerability (fresh install was online without firewall for two hours and picked up this along with blaster -- yikes).  On first run, created registry items "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\System Loader=systems.exe" and "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\System Loader=systems.exe."  The specimen tried to phone to something along the lines of AtHerSite.com yesterday, got suspicious when I looked it up in a file browser and found that it didn't have the same version information as the executables put out by Microsoft -- it didn't, in fact, have a version tab at all in its Properties window.  Attempting to terminate the process resulted in Access Denied.  Malware blocks execution of registry editors, forcing their termination every few seconds.  The executable also does the same with Microsoft RPC vulnerability patches.  Was cured by a simple reboot into safe mode with command prompt and renaming of the file, though the registry entries were removed just in case.
« Last Edit: March 23, 2004, 08:09:12 PM by igor »

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re:New Agobot?
« Reply #1 on: March 23, 2004, 01:39:15 PM »
Thanks for the description - but to update the virus database, we would need the virus file... preferably sent to virus@avast.com.

Offline raman

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1062
Re:New Agobot?
« Reply #2 on: March 23, 2004, 06:12:44 PM »
igor, the Trojan is attached to the first thread!;)
MfG Ralf

Marxist ßastard

  • Guest
Re:New Agobot?
« Reply #3 on: March 23, 2004, 06:44:44 PM »
Yerp, just download that text file and change the extension back to EXE.  Instant "Systems Loader."

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re:New Agobot?
« Reply #4 on: March 23, 2004, 08:13:49 PM »
Oops, I missed the attachment :-[
Next time, please, send the files to the address mentioned above - don't post them on a public forum. Thanks!