w32/gaobot.ee

Imagen biografía
Categoría: Troyanos
Valora este manual:





 
Enviada por: Administrador

Manual de informática de w32/gaobot.ee

w32.hllw.gaobot.ee

tipo: gusano, troyano
tama?o: 200,704 bytes
origen: internet
destructivo: si en la calle (in the wild): si detección y eliminación: the hacker 5.6 al 11/12/2003
w32/gaobot.ee, es un gusano que se difunde a trav?s de los recursos compartidos de la red, permite el acceso remoto y no permitido de un intruso a la computadora infectada a trav?s del irc.
el gusano act?a como un servidor proxy en la computadora infectada, haciendo la funci?n de un spam relay, convirtiendo de este modo a la computadora en un generador de spam.
este gusano tambi?n se aprovecha de las siguientes vulnerabilidades:
vulnerabilidad dcom rpc , descrito en el bolet?n de seguridad ms03-026 de microsoft. vulnerabilidad webdav vulnerability descrito en el bolet?n de seguridad ms03-007 de microsoft. vulnerabilidad rpc locator vulnerability descrito en el bolet?n de seguridad ms03-001 de microsoft. cuando el gusano se ejecuta se copia a si mismo como:
system \smssnt.exe
nota:
system representa la carpeta system dentro de windows (ej. c:\windows\system, c:\winnt\system32)
adem?s modifica una entrada en el registro para poder ejecutarse en el siguiente reinicio del sistema:
hkey_local_machine\software\microsoft\windowsnt\currentversion\winlogon
shell=explorer.exe smssnt.exe
el gusano se difunde a trav?s de los siguientes recursos compartidos:
admin$
c$
d$
e$
print$
utiliza la siguiente combinaci?n de usuarios y passwords, como tambi?n los usuarios encontrados en el api netuserenum()
usuarios:
administrador administrat\xf6r administrateur administrator convidado coordinatore default dell gast guest inviter oem owner ospite owner standard test user verwalter a aaa abc admin administrador administrator admins asdf computer database home kanri kanri-sha login mary mgmt mysql owner pc qwer root server student teacher temp test user win wwwadmin x xp xyz
passwords:
[enter] 0 000000 00000000 007 1 110 111 111111 11111111 12 121212 123 9 qwer 123abc 123asd 123qwe 2002 2003 2600 54321 654321 654321 69 88888888 admin administrador administrateur coordinatore default internet login ospite password verwalter a aaa abc abc abcd admin admin administrador administrator administrator admins alpha asdf asdfghjkl baby box changeme computer database database enable foobar god godblessyou home homework ihavenopass kids leet login love metal mybaby mybox mypass mypc oracle owner pass pass passwd password password pat patrick pc penis poiuytrewq porn private pussy pw pwd qwer qwerty qwertyuiop red root root school secret secret secrets server sex student super superman supersecret sybase teacher temp test test user vagina werty win work wwwadmin x xp xxx xxyyzz yxcv z zxcv zxcvbnm
el gusano intentar? establecer comunicaci?n con un determinado canal de chat irc, utilizando su propio cliente irc.
cuando el troyano se instala queda a la espera de ordenes remotas de su creador, las ordenes podr?an realizar las siguientes acciones:
enviar información de la computadora y de la red a su creador. manipula los archivos del sistema descargar archivos ejecuta programas inicia ataques de denegación de servicio(dos) actualiza el archivo del gusano finalizar? los siguientes procesos activos que encuentre en el computador atacado:
agentw.exe apvxdwin.exe avkpop.exe avkservice.exe avkwctl9.exe avpm.exe blackd.exe ccapp.exe ccevtmgr.exe ccpxysvc.exe cleaner.exe cleaner3.exe cpd.exe edefalert.exe defscangui.exe f-stopw.exe fameh32.exe fch32.exe fih32.exe fnrb32.exe fsaa.exe fsav32.exe fsgk32.exe fsm32.exe fsma32.exe fsmb32.exe gbmenu.exe gbpoll.exe iamapp.exe iamserv.exe lockdown2000.exe notstart.exe npscheck.exe ntrtscan.exe nvsvc32.exe pavproxy.exe pccntmon.exe pccwin97.exe pcscan.exe rapapp.exe rtvscan.exe sbserv.exe vbcmserv.exe vshwin32.exe vsmon.exe zapro.exe zonealarm.exe zauinst.exe _avp32.exe _avpcc.exe _avpm.exe ackwin32.exe ackwin32.exe advxdwin.exe agentsvr.exe alertsvc.exe alogserv.exe amon9x.exe anti-trojan.exe antivirus.exe ants.exe apimonitor.exe aplica32.exe apvxdwin.exe atcon.exe atguard.exe atro55en.exe atupdater.exe atwatch.exe aupdate.exe autodown.exe autotrace.exe autoupdate.exe avconsol.exe ave32.exe avgcc32.exe avgctrl.exe avgctrl.exe avgnt.exe avgserv.exe avgserv.exe avgserv9.exe avguard.exe avgw.exe avkserv.exe avnt.exe avp.exe avp32.exe avpcc.exe avpdos32.exe avpm.exe avptc32.exe avpupd.exe avsched32.exe avsynmgr.avsynmgr.exe avwin95.exe avwinnt.exe avwupd32.exe avwupsrv.exe avxmonitor9x.exe avxmonitornt.exe avxquar.exe bd_professional.exe bidef.exe bidserver.exe bipcp.exe bipcpevalsetup.exe bisp.exe blackd.exe blackice.exe blackice.exe bootwarn.exe borg2.exe bs120.exe cdp.exe cfgwiz.exe cfiadmin.exe cfiaudit.exe cfinet.exe cfinet32.exe claw95.exe claw95cf.exe claw95cf.exe clean.exe cleaner.exe cleaner3.exe cleanpc.exe cmgrdian.exe cmon016.exe connectionmonitor.exe cpd.exe cpf9x206.exe cpfnt206.exe ctrl.exe cv.exe cwnb181.exe cwntdwmo.exe defwatch.exe deputy.exe doors.exe dpf.exe dpfsetup.exe drwatson.exe drweb32.exe dvp95.exe dvp95_0.exe ecengine.exe efpeadm.exe ent.exe esafe.exe escanh95.exe escanhnt.exe escanv95.exe espwatch.exe etrustcipe.exe evpn.exe exantivirus-cnet.exe exe.avxw.exe expert.exe f-agnt95.exe f-prot.exe f-prot95.exe f-stopw.exe fast.exe findviru.exe firewall.exe flowprotector.exe fp-win.exe fp-win_trial.exe fprot.exe frw.exe fsav.exe fsav530stbyb.exe fsav530wtbyb.exe fsav95.exe gbmenu.exe gbpoll.exe generics.exe guard.exe guarddog.exe hacktracersetup.exe htlog.exe hwpe.exe iamapp.exe iamserv.exe iamstats.exe ibmasn.exe ibmavsp.exe icload95.exe icloadnt.exe icmon.exe icsupp95.exe icsuppnt.exe iface.exe ifw2000.exe iomon98.exe iparmor.exe iris.exe isrv95.exe jammer.exe jedi.exe kavlite40eng.exe kavpers40eng.exe kavpf.exe kerio-pf-213-en-win.exe kerio-wrl-421-en-win.exe kerio-wrp-421-en-win.exe killprocesssetup161.exe ldnetmon.exe ldpro.exe ldpromenu.exe ldscan.exe localnet.exe lockdown.exe lockdown2000.exe lookout.exe lsetup.exe luall.exe luau.exe lucomserver.exe luinit.exe luspt.exe mcagent.exe mcmnhdlr.exe mcshield.exe mctool.exe mcupdate.exe mcvsrte.exe mcvsshld.exe mfw2en.exe mfweng3.02d30.exe mgavrtcl.exe mgavrte.exe mghtml.exe mgui.exe minilog.exe monitor.exe monitor.exe moolive.exe mpfagent.exe mpfservice.exe mpftray.exe mrflux.exe msconfig.exe msinfo32.exe mssmmc32.exe mu0311ad.exe mwatch.exe n32scanw.exe nav auto-protect.nav80try.exe navap.navapsvc.exe navapsvc.exe navapw32.exe navdx.exe navengnavex15.navlu32.exe navlu32.exe navnt.exe navstub.exe navw32.exe navw32.exe navwnt.exe nc2000.exe ncinst4.exe ndd32.exe neomonitor.exe neowatchlog.exe netarmor.exe netinfo.exe netmon.exe netscanpro.exe netspyhunter-1.2.exe netstat.exe netutils.exe nisserv.exe nisum.exe nmain.exe nod32.exe normist.exe norton_internet_secu_3.0_407.exe npf40_tw_98_nt_me_2k.exe npfmessenger.exe nprotect.exe npssvc.exe nsched32.exe ntvdm.exe ntxconfig.exe nui.exe nupgrade.exe nvarch16.exe nvc95.exe nwinst4.exe nwservice.exe nwtool16.exe ostronet.exe outpost.exe outpostinstall.exe outpostproinstall.exe padmin.exe panixk.exe pavcl.exe pavproxy.exe pavsched.exe pavw.exe pcc2002s902.exe pcc2k_76_1436.exe pcciomon.exe pccwin98.exe pcdsetup.exe pcfwallicon.exe pcip10117_0.exe pdsetup.exe periscope.exe persfw.exe perswf.exe pf2.exe pfwadmin.exe pingscan.exe platin.exe pop3trap.exe poproxy.exe popscan.exe portdetective.exe portmonitor.exe ppinupdt.exe pptbc.exe ppvstop.exe processmonitor.exe procexplorerv1.0.exe programauditor.exe proport.exe protectx.exe pspf.exe purge.exe pview95.exe qconsole.exe qserver.exe rav7.exe rav7win.exe rav8win32eng.exe realmon.exe regedit.exe regedt32.exe rescue.exe rescue32.exe rrguard.exe rshell.exe rtvscn95.exe rulaunch.exe safeweb.exe sbserv.exe scan32.exe scan95.exe scanpm.exe scrscan.exe sd.exe serv95.exe setup_flowprotector_us.exe setupvameeval.exe sfc.exe sgssfw32.exe sh.exe shellspyinstall.exe shn.exe smc.exe sofi.exe spf.exe sphinx.exe sphinx.exe spyxx.exe ss3edit.exe st2.exe supftrl.exe supporter5.exe sweep95.exe sweepnet.sweepsrv.sys.swnetsup.exe symproxysvc.exe symproxysvc.exe symtray.exe sysedit.exe taskmon.exe taumon.exe tbscan.exe tc.exe tca.exe tcm.exe tds-3.exe tds2-98.exe tds2-nt.exe tfak.exe tfak5.exe tgbob.exe titanin.exe titaninxp.exe tracert.exe trjscan.exe trjsetup.exe trojantrap3.exe undoboot.exe update.exe vbcmserv.exe vbcons.exe vbcons.exe vbust.exe vbwin9x.exe vbwinntw.exe vcsetup.exe vet32.exe vet95.exe vet95.exe vettray.exe vettray.exe vfsetup.exe vir-help.exe virusmdpersonalfirewall.exe vnlan300.exe vnpc3000.exe vpc32.exe vpc42.exe vpfw30s.exe vptray.exe vscan40.exe vscenu6.02d30.exe vsched.exe vsecomr.exe vsisetup.exe vsmain.exe vsmon.exe vsstat.exe vswin9xe.exe vswinntse.exe vswinperse.exe w32dsm89.exe w9x.exe watchdog.exe webscanx.exe webtrap.exe wfindv32.exe wgfe95.exe whoswatchingme.exe wimmun32.exe winrecon.exe wnt.exe wradmin.exe wradmin.exe wrctrl.exe wrctrl.exe wsbgate.exe wyvernworksfirewall.exe xpf202en.exe zauinst.exe zapro.exe zapsetup3001.exe zatutor.exe zonalm2601.exe zonealarm.exe tambi?n intentar? eliminar los siguientes archivos:
s24evmon.exe regsrvc.exe agrsmmsg.exe update.exe view.exe prmvr.exe hpsrvui.exe hpsysdrv.exe tfswctrl.exe stms.exe xupiterstartup.exe ebrr.exe dsentry.exe mwmdmsvc.exe win32us.exe s3tray2.exe mwssw32.exe apoint.exe pctspk.exe hphipm11.exe save.exe jusched.exe mwd.exe igfxtray.exe wm.exe cusrvc.exe javaw.exe tgcmd.exe wjview.exe soap.exe ares.exe tbpanel.exe istsvc.exe msgsys.exe xcommsvr.exe dcfssvc.exe devldr32.exe mshta.exe hpztsb07.exe bipvfm.exe ezsp_px.exe bcmsmmsg.exe tpwrtray.exe tdispvol.exe mostat.exe 00thotkey.exe emsw.exe rle0hix.exe xmforgert.exe xco0b3.exe lrohe95f.exe mrtmngr.exe starter.exe slserv.exe bigfix.exe glconf.exe snmp.exe aucbpnp.exe carpserv.exe syncor.exe teekids.exe sk9910dm.exe runservice.exe nmssvc.exe basfipm.exe zcfgsvc.exe wmiprvse.exe uptodate.exe radiosvr.exe hpconfig.exe wsys.exe wssdtu.exe wssdsu.exe winsct32.exe desk98.exe loadqm.exe tvmd.exe rundll16.exe wltrysvc.exe msmgt.exe bcmwltry.exe s3apphk.exe ps2.exe wthost.exe ico.exe aupdate.exe winservn.exe rb32.exe qttask.exe notifyalert.exe realsched.exe asm.exe dw.exe apntex.exe sync.exe damon.exe wkufind.exe pgmonitr.exe ctsvccda.exe hbinst.exe weather.exe hbsrv.exe cmesys.exe exshow95.exe exshow.exe evntsvc.exe cnform.exe gmt.exe ntrtscan.exe dllhost.exe tmlisten.exe pccntmon.exe wcmdmgr.exe loader.exe wisptis.exe precisiontime.exe datemanager.exe dlg.exe defwatch.exe gwmdmmsg.exe winupdat.exe regsvc.exe lvcoms.exe sahagent.exe mspmspsv.exe cisvc.exe scardsvr32.exe cmdserv.exe cnfgldr.exe mstasks.exe sys32.exe cmd32.exe svchosts.exe mssql.exe syscfg32.exe sysmon16.exe regsvc32.exe system32.exe msbb.exe alogserv.exe acrotray.exe cthelper.exe msblast.exe netstat.exe tftp.exe packethsvc.exe hkcmd.exe av.exe ne.exe exchng32.exe mlset32.exe tfnf5.exe daemon.exe r_server.exe systemidle.exe wuaumqr.exe c:\av.exe c:\winupdat.exe c:\esm2\stms.exe c:\esm2\ebrr.exe c:\officescan nt\pccntmon.exe c:\officescan nt\ntrtscan.exe c:\officescan nt\tmlisten.exe c:\program files\commonname\toolbar\cnform.exe c:\program files\common files\services\wsys.exe c:\program files\common files\services\wssdtu.exe c:\program files\common files\microsoft shared\works shared\wkufind.exe c:\program files\common files\real\update_ob\realsched.exe c:\program files\common files\real\update_ob\evntsvc.exe c:\program files\common files\cmeii\cmesys.exe c:\program files\common files\gmt\gmt.exe c:\program files\common files\support.com\client\bin\tgcmd.exe c:\program files\xupiter\xupiterstartup.exe c:\program files\orbit\update.exe c:\program files\orbit\view.exe c:\program files\systemidle\systemidle.exe c:\program files\network essentials\v11\ne.exe c:\program files\ncase\msbb.exe c:\program files\istsvc\istsvc.exe c:\program files\ares\ares.exe c:\program files\system soap pro\soap.exe c:\program files\bigfix\bigfix.exe c:\program files\downloadware\dw.exe c:\program files\memorymeter\memorymeter.exe c:\program files\altnet\download manager\asm.exe c:\program files\apoint2k\apoint.exe c:\program files\apoint2k\apntex.exe c:\program files\clocksync\sync.exe c:\program files\dell\support\alert\bin\notifyalert.exe c:\program files\dell\support\alert\bin\damon.exe c:\program files\hotbar\bin\4.3.5.0\hbinst.exe c:\program files\hotbar\bin\4.1.8.0\reader\hbsrv.exe c:\program files\delfin\promulgate\pgmonitr.exe c:\program files\aws\weather\weather.exe c:\program files\clearsearch\loader.exe c:\program files\precisiontime\precisiontime.exe c:\program files\date manager\datemanager.exe c:\program files\digital line detect\dlg.exe c:\program files\navnt\defwatch.exe c:\program files\quicktime\qttask.exe c:\program files\rb32\rb32.exe c:\program files\javasoft\jre.3.1_04\bin\javaw.exe c:\program files\java\j2re1.4.2_01\bin\jushed.exe c:\program files\savenow\save.exe c:\program files\save\save.exe mww32\manager\mwmdmsvc.exe mww32\manager\mwssw32.exe wt\webdriver\wthost.exe wt\wcmdmgr.exe spool\drivers\w32x86\3\hpztsb07.exe wbem\wmiprvse.exe dla\tfswctrl.exe wins\svchost.exe wins\dllhost.exe drivers\dcfssvc.exe finalmente el gusano intentar? robar las claves de cd de varios juegos.


Comparte este manual:


Comparte este manual por email con un amigo/a:

Tu nombre
Tu email
El nombre de tu amigo
El email de tu amigo