Search Bitches Barmy Army
Main Menu
· Home
· Forum
· Arcade
· Events
Cod 2 Match Server
{-BBA-} Match | www.bba-clan.co.uk
mp_breakout
PLAYERS: 0 / 24
Cod 4 Match Server
-
-
PLAYERS: 0 / 0
Cod 2 CTF Public
-
-
PLAYERS: 0 / 0
Game Server
-
-
PLAYERS: 0 / 0
Counter
This page today ...
total: 0
unique: 0

This page ever ...
total: 12937
unique: 1061

Site ...
total: 92528
unique: 11274
Forums
Bitches Barmy Army :: Forums :: General Discussion :: Tech Chat And Other Computer Related News
 
<< Previous thread | Next thread >>
New Trojan Affecting P2P Networks !!!
Moderators: bba_admin, {BBA}PC Doc, grandad, RS, {-BBA-}Retah
Author Post
{BBA}PC Doc
Fri Apr 16 2010, 09:23PM
Cod2 Team Cod4 Team

Registered Member #2
Joined: Wed Apr 09 2008, 07:46AM
Posts: 595
Got this news from sam over at extra torrents.

If launched, the trojan installs the copy of itself in the WINDOWS directory together with a registry key enabling it to load on startup.

trojan-horse.jpg

Arbor Networks Security researchers have found an unknown botnet activated by Heloag Trojan, jeopardizing computers infected with it. Its purpose is to facilitate downloading and installation of numerous additional malicious applications.

The researches discovered after the detailed inspection that trojan does not have DDoS capabilities built-in, but only work upon managing downloads on the exposed machine.

How does it work?

Trojan can be downloaded from elwm.net or 7zsm.com. After getting stored on the exposed computer, it installs the copy of itself in the WINDOWS directory under the following names:

C:\WINDOWS\conme.exe
C:\WINDOWS\ThunderUpdate.exe
C:\WINDOWS\csrse.exe

After that malware mounts the above registry key enabling it to load on startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon = [one of the filenames above]

What it’s doing next is establishing a connection to the server C&C to provide the access for the botnet, usually on 8090 TCP port, in order to get registered and wait for further commands. Traffic is often preceded by a single byte indicating the aim of a message:

1 – hello
2 – staying alive
3 – downloading the above mentioned file
4 – connecting to other peers
5 – sending the host name to the server
6 – clearing
7 – shutting down the connection

Those hosts which are infected with Trojan.Heloag usually download some different malcode via HTTP from the central server, after which they are able to get connected to other bots via TCP ports 7000-7010 and therefore to other infected PCs. The researchers are not sure about the purpose of this yet, but it’s definitely some form of P2P. Be careful.


Fear not, i have written a couple of lines into somethin you can click on to get rid of it!!!

For those that arnt comfertable removing files from the windows folder and deleting registry keys, i have made a couple of files.
first one, (well 2) are to remove the files, if they exist in your windows folder.

http://www.storage.to/get/dGyBAX3y/remove+files.bat
or
http://www.storage.to/get/SCBPt74W/remove+files.exe

you should only need to run one of these, reason i made 2 are some computers dont like running .bat files by double clicking them.
If you get the error, file not found on all 3, its great, as its not any of the above files.

the second file will remove the registry entries.
right click on it and click install.

http://www.storage.to/get/UEEHSFas/remove+keys.inf

hope that helps!

Image Hosted by ImageShack.us
Back to top
{BBA}Bakerman
Sat Apr 17 2010, 03:58PM
{BBA}Bakerman
Registered Member #9
Joined: Wed Apr 09 2008, 03:47PM
Posts: 413
well done doccy :D

[ image disabled ]
Back to top
 

Jump:     Back to top

Syndicate this thread: rss 0.92 Syndicate this thread: rss 2.0 Syndicate this thread: RDF
Powered by e107 Forum System
Welcome
Username:

Password:


Remember me

[ ]
[ ]
[ ]
Teamspeak 3
Affiliates
WRS Gaming - Top Clans



www.thepcdoc.co.uk - Store & Services
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf
This site is powered by e107, which is released under the terms of the GNU GPL License.