<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/">
  <title>blog.malwarelist.org</title>
  <link rel="alternate" href="http://blognew.aruba.it/blog.malwarelist.org/" />
  <subtitle>Analisi virus/malware ad opera del C.R.A.M. by TG Soft S.a.s</subtitle>
  <dc:creator>blog.malwarelist.org</dc:creator>
  <entry>
    <title>Trojan.Win32.FakeShell.AA</title>
    <link rel="alternate" href="http://blognew.aruba.it/blog.malwarelist.org/Trojan_Win32_FakeShell_AA_54013.shtml" />
    <category term="" />
    <category term="trojan" />
    <category term="," />
    <category term="fakeshell" />
    <category term="," />
    <category term="fake" />
    <category term="," />
    <category term="shell" />
    <category term="," />
    <category term="taskman" />
    <author>
      <name>blog.malwarelist.org</name>
    </author>
    <updated>2011-09-20T14:35:39Z</updated>
    <published>2011-09-20T13:08:23Z</published>
    <content>&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;Il &lt;strong&gt;Trojan&lt;/strong&gt; in analisi si presenta con il nome di aegvvp.exe.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font size="4"&gt;Informazioni Tecniche&lt;/font&gt;&lt;/strong&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" width="576" height="253"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;font size="2"&gt;Nome file:&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;font size="2"&gt;aegvvp.exe&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;font size="2"&gt;Dimensioni:&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;font size="2"&gt;89.600 byte&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;font size="2"&gt;Percorso di installazione: &lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;font size="2"&gt;%USERPROFILE%&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;font size="2"&gt;Chiave di registro modificata:&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;font size="2"&gt;HKLM\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon [Shell] = Explorer.exe,%USERPROFILE%\aegvvp.exe&lt;/font&gt; &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font size="4"&gt;Funzionamento&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;Il file aegvvp.exe una volta avviato modifica la chiave di registro in HKLM\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon [Shell] = Explorer.exe,%USERPROFILE%\aegvvp.exe. La chiave &amp;egrave; gi&amp;agrave; esistente ma il malware la modifica aggiungendosi al gi&amp;agrave; presente Explorer.exe cosicch&amp;eacute; possa essere eseguito all'avvio.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; NOTE:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; HKLM = HKEY_LOCAL_MACHINE&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; %USERPROFILE% = C:\Documents and Settings\{username}&lt;/font&gt;&lt;/p&gt;&lt;hr /&gt;&lt;font size="2"&gt;Rimozione: Vir.IT 6.9.88 - &lt;a href="http://www.tgsoft.it" target="_blank"&gt;www.tgsoft.it&lt;/a&gt;&lt;br /&gt;&lt;/font&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</content>
    <summary>&amp;nbsp;Il Trojan in analisi si presenta con il nome di aegvvp.exe.&amp;nbsp;&amp;nbsp;Informazioni Tecniche &amp;nbsp;&amp;nbsp;Nome file:&amp;nbsp;aegvvp.exe&amp;nbsp;Dimensioni:&amp;nbsp;89.600 byte&amp;nbsp;Percorso di installazione: &amp;nbsp;%USERPROFILE%&amp;nbsp;Chiave di registro modificata:&amp;nbsp;HKLM\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon ...</summary>
    <dc:creator>blog.malwarelist.org</dc:creator>
    <dc:date>2011-09-20T13:08:23Z</dc:date>
  </entry>
  <entry>
    <title>Trojan.Win32.Buzus.EG</title>
    <link rel="alternate" href="http://blognew.aruba.it/blog.malwarelist.org/Trojan_Win32_Buzus_EG_51551.shtml" />
    <category term="" />
    <category term="trojan" />
    <category term="win32" />
    <category term="buzus" />
    <category term="eg" />
    <category term="firewall" />
    <category term="antivirus" />
    <category term="allegato" />
    <category term="email" />
    <author>
      <name>blog.malwarelist.org</name>
    </author>
    <updated>2011-07-14T13:11:10Z</updated>
    <published>2011-07-13T12:47:05Z</published>
    <content>&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Il &lt;strong&gt;Trojan.Win32.Buzus.EG&lt;/strong&gt; si presenta come una email da parte della compagnia FedEx, che avverte l'utente del fallimento di una spedizione e di scaricare l'allegato in formato .zip, che dovrebbe contenere una copia della fattura, da stampare e consegnare all'ufficio FedEx piu' vicino, per poter ritirare il proprio pacco.&lt;/p&gt;&lt;p&gt;Ecco l'immagine della mail:&lt;/p&gt;&lt;p&gt;&lt;img src="http://blognew.aruba.it/blog.malwarelist.org/resized//gallery//uid_13128b47e3c.580.0.jpg" alt="" width="527" height="501" align="middle" /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="2" width="287" style="height: 217px"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;Nome Malware&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;Trojan.Win32.Buzus.EG&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;Dimensioni&lt;/td&gt;&lt;td&gt;&amp;nbsp;69.632 byte&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;Nome File&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;service.exe&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In realt&amp;agrave; il pacchetto zip in allegato, contiene un file eseguibile &lt;strong&gt;service.exe&lt;/strong&gt; (della dimensione di 69.632 byte) il quale, una volta avviato, si collega al sito linode.com e crea la cartella %USERPROFILE%\Dati Applicazioni\Security Solution\ dove scarica al suo interno 3 file icona: &lt;strong&gt;IcoActivate.ico&lt;/strong&gt;, &lt;strong&gt;IcoHelp.ico&lt;/strong&gt; ed &lt;strong&gt;IcoUnistall.ico&lt;/strong&gt;, (tutti della dimensione di 894 byte) ed altri 3 file eseguibili:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security Solution.exe (2.909.696 byte)&lt;/li&gt;&lt;li&gt;securityhelper.exe (4.675.587 byte)&lt;/li&gt;&lt;li&gt;securitymanager.exe (96.256 byte)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Di questi file eseguibili, ne mette 2 (Security Solution.exe e securitymanager.exe) in esecuzione automatica.&lt;/p&gt;&lt;p&gt;Crea inoltre una copia del file securityhelper.exe rinominandolo in &lt;strong&gt;840616042.exe&lt;/strong&gt; e inserendolo nella cartella %USERPROFILE%\Dati Applicazioni\ .&lt;/p&gt;&lt;p&gt;Tutti questi file hanno lo scopo di creare delle finte schermate di antivirus/firewall certificati da Microsoft, ma che ovviamente non lo sono.&lt;br /&gt;L'utente pu&amp;ograve; decidere di chiudere queste finestre, ma fintanto che i processi rimarranno attivi, continueranno a comparire queste finestre ad intervalli regolari.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Esempi di schermate:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src="http://blognew.aruba.it/blog.malwarelist.org/resized//gallery//uid_13123b00c33.250.0.jpg" alt="" /&gt;&lt;img src="http://blognew.aruba.it/blog.malwarelist.org/resized//gallery//uid_13123b0c6f5.250.0.jpg" alt="" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img src="http://blognew.aruba.it/blog.malwarelist.org/resized//gallery//uid_13123af363a.250.0.jpg" alt="" /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;NOTE:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;%USERPROFILE% = C:\Documents and Settings\{username} (in Windows XP)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Users\{username} (in Windows Vista/7) &lt;/p&gt;&lt;hr /&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Rimozione: VirIT Versione &lt;strong&gt;6.9.44 -&amp;nbsp; &lt;/strong&gt;&lt;a href="http://www.tgsoft.it/" title="http://www.tgsoft.it/"&gt;http://www.tgsoft.it/&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</content>
    <summary>&amp;nbsp;Il Trojan.Win32.Buzus.EG si presenta come una email da parte della compagnia FedEx, che avverte l'utente del fallimento di una spedizione e di scaricare l'allegato in formato .zip, che dovrebbe contenere una copia della fattura, da stampare e consegnare ...</summary>
    <dc:creator>blog.malwarelist.org</dc:creator>
    <dc:date>2011-07-13T12:47:05Z</dc:date>
  </entry>
  <entry>
    <title>Trojan.Win32.Agent.DIK</title>
    <link rel="alternate" href="http://blognew.aruba.it/blog.malwarelist.org/Trojan_Win32_Agent_DIK_51280.shtml" />
    <category term="" />
    <category term="trojan" />
    <category term="," />
    <category term="agent" />
    <category term="dik" />
    <category term="," />
    <category term="vmware" />
    <author>
      <name>blog.malwarelist.org</name>
    </author>
    <updated>2011-07-06T16:27:00Z</updated>
    <published>2011-07-06T16:06:38Z</published>
    <content>&lt;p&gt;&lt;font size="2"&gt;Il &lt;strong&gt;Trojan.Win32.Agent.DIK &lt;/strong&gt;si presenta in modo fraudolento come un aggiornamento per il software di virtualizzazione VMWare con il nome wmprwise.exe&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Informazioni Tecniche&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" width="552" height="323"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Nome file:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;wmprwise.exe&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Dimensioni:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;139.868 bytes&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Nome originale:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;VMUpgradeHelper.exe&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Versione:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;8.4.6.16648&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Societ&amp;agrave;:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;VMWare, Inc&lt;em&gt; (fasulla non &amp;egrave; stato prodotto da VMWare)&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Percorso di installazione:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;%USERPROFILE%\Dati Applicazioni &lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Funzionamento&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;Il file una volta avviato si copia in %USERPROFILE%\Dati Applicazioni ma non va a modificare alcuna chiave del registro. Effettua per&amp;ograve; molte operazioni malevoli a livello di rete:&amp;nbsp; &lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font size="2"&gt;Si connette all'indirizzo IP &lt;a href="http://www.dnsstuff.com/tools/whois/?tool_id=66&amp;amp;token=&amp;amp;toolhandler_redirect=0&amp;amp;ip=89.149.254.182" target="_blank"&gt;89.149.###.###&lt;/a&gt; &lt;em&gt;(cliccare per maggiori informazioni su proprietario e indirizzo web) &lt;/em&gt;loggandosi con username e password.&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="2"&gt;Inizia poi a inviare spam verso alcune caselle di posta elettronica di domini noti come &lt;em&gt;yahoo.com, gmail.com, hotmail.com, virgilio.it. &lt;/em&gt;Il mittente cambia durante i successivi invii passando per alcuni domini come &lt;em&gt;wow-europe.com, stainlessgames.com, 64bitsupport.com, qa.com, introversion.co.uk, game-era.com.&lt;/em&gt; Il contenuto della mail &amp;egrave; una pagina html con un link a un sito porno.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NOTE:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; %USERPROFILE% = C:\Documents and Settings\{username}&lt;/font&gt;&lt;/p&gt;&lt;hr /&gt;&lt;font size="2"&gt;Rimozione: VirIT 6.9.38 - &lt;a href="http://www.tgsoft.it" target="_blank"&gt;www.tgsoft.it&lt;/a&gt;&lt;/font&gt;&lt;br /&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</content>
    <summary>Il Trojan.Win32.Agent.DIK si presenta in modo fraudolento come un aggiornamento per il software di virtualizzazione VMWare con il nome wmprwise.exe&amp;nbsp;Informazioni Tecniche&amp;nbsp;&amp;nbsp;Nome file:&amp;nbsp;wmprwise.exe&amp;nbsp;Dimensioni:&amp;nbsp;139.868 bytes&amp;nbsp;Nome ...</summary>
    <dc:creator>blog.malwarelist.org</dc:creator>
    <dc:date>2011-07-06T16:06:38Z</dc:date>
  </entry>
  <entry>
    <title>Trojan.Win32.Banker.CO</title>
    <link rel="alternate" href="http://blognew.aruba.it/blog.malwarelist.org/Trojan_Win32_Banker_CO_51239.shtml" />
    <category term="" />
    <category term="trojan" />
    <category term="," />
    <category term="banker" />
    <category term="co" />
    <category term="," />
    <category term="live" />
    <category term="exe" />
    <author>
      <name>blog.malwarelist.org</name>
    </author>
    <updated>2011-07-06T16:29:25Z</updated>
    <published>2011-07-05T15:57:36Z</published>
    <content>&lt;p&gt;&lt;font size="2"&gt;Il &lt;strong&gt;Trojan.Win32.Banker.CO &lt;/strong&gt;si presenta come un prodotto di origine Microsoft, ovviamente non lo &amp;egrave;, dal nome live.exe con una icona simile a Internet Explorer.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Informazioni Tecniche&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" width="555" height="278"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Nome file:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;live.exe&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Dimensioni:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;4.377.088 bytes&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Percorso di installazione:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;%USERPROFILE%\Dati Applicazioni&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Chiave di registro modificata: &lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;HKCU\Software\Microsoft\Windows\CurrentVersion\Run [JComplemento] = %USERPROFILE%\Dati Applicazioni\live.exe &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;HKCU\Software\Microsoft\Windows\JComplemento [Live] = 0.1&lt;/font&gt; &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Funzionamento&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;Una volta avviato il file live.exe, oltre a modificare le chiavi di registro sopra riportate per configurarsi in esecuzione automatica, tenta di aprire due browsers installati nel computer, Firefox e Internet Explorer, alla pagina www.getwindow.info effettuando la ricerca delle seguenti tre parole chiave: telefoni, cellulari e radiotelefoni. Se si tenta di chiudere i browser aperti il trojan ne effettuer&amp;agrave; di nuovo l'apertura.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NOTE:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; HKCU = HKEY_CURRENT_USER&lt;/font&gt;&lt;/p&gt;&lt;hr /&gt;&lt;font size="2"&gt;Rimozione: VirIT 6.9.38 - &lt;a href="http://www.tgsoft.it" target="_blank"&gt;www.tgsoft.it&lt;/a&gt;&lt;br /&gt;&lt;/font&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</content>
    <summary>Il Trojan.Win32.Banker.CO si presenta come un prodotto di origine Microsoft, ovviamente non lo &amp;egrave;, dal nome live.exe con una icona simile a Internet Explorer.&amp;nbsp;Informazioni Tecniche&amp;nbsp;&amp;nbsp;Nome file:&amp;nbsp;live.exe&amp;nbsp;Dimensioni:&amp;nbsp;4.377.088 ...</summary>
    <dc:creator>blog.malwarelist.org</dc:creator>
    <dc:date>2011-07-05T15:57:36Z</dc:date>
  </entry>
  <entry>
    <title>Trojan.Win32.Agent.DII</title>
    <link rel="alternate" href="http://blognew.aruba.it/blog.malwarelist.org/Trojan_Win32_Agent_DII_51233.shtml" />
    <category term="" />
    <category term="trojan" />
    <category term="," />
    <category term="agent" />
    <category term="dii" />
    <author>
      <name>blog.malwarelist.org</name>
    </author>
    <updated>2011-07-06T13:06:24Z</updated>
    <published>2011-07-05T15:19:44Z</published>
    <content>&lt;p&gt;&lt;font size="2"&gt;Il &lt;strong&gt;Trojan.Win32.Agent.DII &lt;/strong&gt;in analisi si instaura come servizio del computer sotto il nome lkBsyijS.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Informazioni Tecniche&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" width="533" height="291"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Nome file:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;E001.exe&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Dimensioni:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;121.012 bytes&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Percorso di installazione:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;%SYSTEMROOT%\System32&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Chiavi di registro modificate:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;HKLM\System\CurrentControlSet\Services\lkBsyijS &lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Funzionamento&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;Il trojan in questione una volta eseguito si elimina dalla directory dove risiede e crea una copia di se stesso nella cartella %SYSTEMROOT%\System32\ con il nuovo nome ssoysu.exe. Effettua poi altre azioni:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&lt;u&gt;A livello di registro:&lt;/u&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font size="2"&gt;Crea le seguenti chiavi: HKLM\System\CurrentControlSet\Services\lkBsyijS&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ol&gt;&lt;li&gt;&lt;font size="2"&gt;[Description] = Oelk DbIjuk &lt;em&gt;(stringa casuale)&lt;/em&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="2"&gt;[DisplayName] = MzlDOb nPVOlVdSb &lt;em&gt;(stringa casuale)&lt;/em&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="2"&gt;[ImagePath] = %SYSTEMROOT%\System32\ssoysu.exe&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="2"&gt;[ObjectName] = Local System &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;font size="2"&gt;&lt;u&gt;A livello di rete:&lt;/u&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font size="2"&gt;Effettua del traffico verso il seguente indirizzo IP &lt;a href="http://www.dnsstuff.com/tools/whois/?tool_id=66&amp;amp;token=&amp;amp;toolhandler_redirect=0&amp;amp;ip=96.44.158.69" target="_blank"&gt;96.44.###.##&lt;/a&gt; &lt;em&gt;(cliccare per maggiori informazioni sul proprietario)&lt;/em&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NOTE:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; %SYSTEMROOT% = C:\Windows&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HKLM = HKEY_LOCAL_MACHINE&lt;/font&gt;&lt;/p&gt;&lt;hr /&gt;&lt;font size="2"&gt;Rimozione: VirIT 6.9.38 - &lt;a href="http://www.tgsoft.it" target="_blank"&gt;www.tgsoft.it&lt;/a&gt;&lt;/font&gt;&lt;br /&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</content>
    <summary>Il Trojan.Win32.Agent.DII in analisi si instaura come servizio del computer sotto il nome lkBsyijS.&amp;nbsp;Informazioni Tecniche&amp;nbsp;&amp;nbsp;Nome file:&amp;nbsp;E001.exe&amp;nbsp;Dimensioni:&amp;nbsp;121.012 bytes&amp;nbsp;Percorso di installazione:&amp;nbsp;%SYSTEMROOT%\System32&amp;nbsp;Chiavi ...</summary>
    <dc:creator>blog.malwarelist.org</dc:creator>
    <dc:date>2011-07-05T15:19:44Z</dc:date>
  </entry>
  <entry>
    <title>Trojan.Win32.Small.UR</title>
    <link rel="alternate" href="http://blognew.aruba.it/blog.malwarelist.org/Trojan_Win32_Small_UR_51231.shtml" />
    <category term="" />
    <category term="trojan" />
    <category term="," />
    <category term="small" />
    <category term="ur" />
    <category term="," />
    <category term="nero" />
    <category term="check" />
    <author>
      <name>blog.malwarelist.org</name>
    </author>
    <updated>2011-07-06T06:40:52Z</updated>
    <published>2011-07-05T14:46:43Z</published>
    <content>&lt;p&gt;&lt;font size="2"&gt;Il &lt;strong&gt;Trojan.Win32.Small.UR &lt;/strong&gt;si presenta sotto il falso nome di NeroCheck.exe &lt;em&gt;(nome che richiama un famoso software di masterizzazione)&lt;/em&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Informazioni Tecniche&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" width="536" height="306"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Nome file:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;NeroCheck.exe&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Dimensioni:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;20.992 bytes&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Percorso di installazione:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;%SYSTEMROOT%&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Chiave di registro modificata:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;HKLM\Software\Microsoft\Windows\CurrentVersion\Run [gcasServ] = %SYSTEMROOT%\gcasServ.exe&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Funzionamento&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;Una volta avviato il file NeroCheck.exe, si elimina dalla cartella residente ma creando preventivamente una nuova copia di se stesso dal nome gcasServ.exe in %SYSTEMROOT%. Modifica anche il registro configurandosi in esecuzione automatica. Non effettua alcun traffico di rete. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NOTE:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; %SYSTEMROOT% = C:\Windows&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; HKLM = HKEY_LOCAL_MACHINE&lt;/font&gt; &lt;/p&gt;&lt;hr /&gt;&lt;font size="2"&gt;Rimozione: VirIT 6.9.38 - &lt;a href="http://www.tgsoft.it"&gt;www.tgsoft.it&lt;/a&gt;&lt;/font&gt;&lt;br /&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</content>
    <summary>Il Trojan.Win32.Small.UR si presenta sotto il falso nome di NeroCheck.exe (nome che richiama un famoso software di masterizzazione)&amp;nbsp;Informazioni Tecniche&amp;nbsp;&amp;nbsp;Nome file:&amp;nbsp;NeroCheck.exe&amp;nbsp;Dimensioni:&amp;nbsp;20.992 bytes&amp;nbsp;Percorso di ...</summary>
    <dc:creator>blog.malwarelist.org</dc:creator>
    <dc:date>2011-07-05T14:46:43Z</dc:date>
  </entry>
  <entry>
    <title>Trojan.Win32.Agent.DHO</title>
    <link rel="alternate" href="http://blognew.aruba.it/blog.malwarelist.org/Trojan_Win32_Agent_DHO_51229.shtml" />
    <category term="" />
    <category term="trojan" />
    <category term="," />
    <category term="agent" />
    <category term="dho" />
    <category term="," />
    <category term="hidfind" />
    <author>
      <name>blog.malwarelist.org</name>
    </author>
    <updated>2011-07-06T07:58:57Z</updated>
    <published>2011-07-05T14:22:17Z</published>
    <content>&lt;p&gt;&lt;font size="2"&gt;Il &lt;strong&gt;Trojan.Win32.Agent.DHO&lt;/strong&gt; qui analizzato si presenta sotto il nome hidfind.exe&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Informazioni Tecniche&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" width="528" height="291"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Nome file:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;hidfind.exe&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Dimensioni:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;187.904 bytes&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Percorso di installazione:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;C:\Programmi&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Chiave di registro modificata:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;HKLM\Software\Microsoft\Windows\CurrentVersion\Run [hidfind] = C:\Programmi\hidfind.exe -update&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Funzionamento&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;Una volta avviato, il trojan hidfind.exe effettua una copia di se stesso su C:\Programmi\. Poi a livello di registro modifica la chiave sopra indicata per configurarsi in esecuzione automatica. A livello di rete invece cerca di connettersi a una serie diversa di siti porno ma senza mostrare nulla all'utente.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NOTE: &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HKLM = HKEY_LOCAL_MACHINE&lt;/font&gt;&lt;/p&gt;&lt;hr /&gt;&lt;font size="2"&gt;Rimozione: VirIT 6.9.38 - &lt;a href="http://www.tgsoft.it"&gt;www.tgsoft.it&lt;/a&gt;&lt;/font&gt;&lt;br /&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</content>
    <summary>Il Trojan.Win32.Agent.DHO qui analizzato si presenta sotto il nome hidfind.exe&amp;nbsp;&amp;nbsp;Informazioni Tecniche&amp;nbsp;&amp;nbsp;&amp;nbsp;Nome file:&amp;nbsp;hidfind.exe&amp;nbsp;Dimensioni:&amp;nbsp;187.904 bytes&amp;nbsp;Percorso di installazione:&amp;nbsp;C:\Programmi&amp;nbsp;Chiave ...</summary>
    <dc:creator>blog.malwarelist.org</dc:creator>
    <dc:date>2011-07-05T14:22:17Z</dc:date>
  </entry>
  <entry>
    <title>Trojan.Win32.Agent.DIF</title>
    <link rel="alternate" href="http://blognew.aruba.it/blog.malwarelist.org/Trojan_Win32_Agent_DIF_51055.shtml" />
    <category term="" />
    <category term="trojan" />
    <category term="," />
    <category term="agent" />
    <category term="dif" />
    <category term="," />
    <category term="ac32" />
    <category term="exe" />
    <category term="," />
    <category term="browseit" />
    <author>
      <name>blog.malwarelist.org</name>
    </author>
    <updated>2011-07-05T14:22:42Z</updated>
    <published>2011-06-30T13:51:11Z</published>
    <content>&lt;p&gt;&lt;font size="2"&gt;Il &lt;strong&gt;trojan &lt;/strong&gt;analizzato, dal nome ac32.exe, si comporta in modo molto malevolo configurandosi in esecuzione automatica e consumando quasi tutte le risorse di processore e memoria rallentando notevolmente l'uso del pc.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Informazioni Tecniche&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;table border="1" width="579" height="309"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Nome file:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;ac32.exe&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Dimensioni:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;85.504 bytes&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Percorso di installazione:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;%SYSTEMROOT%\System32&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Chiavi di registro modificate:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;HKLM\Software\Microsoft\Windows\CurrentVersion\Run&amp;nbsp;&amp;nbsp;&amp;nbsp; [ac32] = %SYSTEMROOT%\System32\ac32.exe&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Funzionamento&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;Una volta avviato il file malevolo, si copia in C:\Windows\System32 e modifica il registro configurandosi in esecuzione automatica. Il trojan effettua anche altre operazioni malevoli:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&lt;u&gt;A livello di File System:&lt;/u&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font size="2"&gt;Crea su %TEMP% due file: il primo &lt;em&gt;ac32_co.txt&lt;/em&gt; non contiene nulla di rilevante il secondo invece &lt;em&gt;ac32.bat&lt;/em&gt; contiene uno script il quale consente al trojan di eseguire un invio continuo di pacchetti verso la scheda di rete interna del pc, consente la continua chiusura e riapertura di un nuovo processo ac32.exe e, in caso di apertura di &lt;em&gt;ac32.bat&lt;/em&gt;, la sua automatica eliminazione.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font size="2"&gt;&lt;u&gt;A livello di rete:&lt;/u&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font size="2"&gt;Si connette al seguente indirizzo IP: &lt;a href="http://www.dnsstuff.com/tools/whois/?tool_id=66&amp;amp;token=&amp;amp;toolhandler_redirect=0&amp;amp;ip=64.111.199.221" target="_blank"&gt;64.111.###.###&lt;/a&gt; &lt;em&gt;(cliccare per maggiori informazioni sul proprietario) &lt;/em&gt;ed effettua del traffico HTTP_GET cercando di fare il download del file 472.jpg.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font size="2"&gt;Il trojan risulta presente tra le applicazioni attive con il nome &amp;quot;BrowseIt&amp;quot; ed &amp;egrave; veramente impossibile terminarlo dal&amp;nbsp; Task Manager di Windows perch&amp;egrave; il processo si chiude e si apre in continuazione senza sosta.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NOTE:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; %SYSTEMROOT% = C:\Windows&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; %TEMP% = C:\Documents and Settings\{username}\Impostazioni Locali\Temp\&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; HKLM = HKEY_LOCAL_MACHINE&lt;/font&gt; &lt;/p&gt;&lt;hr /&gt;&lt;font size="2"&gt;Rimozione: VirIT 6.9.35 - &lt;a href="http://www.tgsoft.it" target="_blank"&gt;www.tgsoft.it&lt;/a&gt;&lt;br /&gt;&lt;/font&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;h5&gt;&lt;font size="2"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/font&gt; &lt;br /&gt;&lt;/h5&gt;</content>
    <summary>Il trojan analizzato, dal nome ac32.exe, si comporta in modo molto malevolo configurandosi in esecuzione automatica e consumando quasi tutte le risorse di processore e memoria rallentando notevolmente l'uso del pc.&amp;nbsp;Informazioni Tecniche&amp;nbsp;Nome ...</summary>
    <dc:creator>blog.malwarelist.org</dc:creator>
    <dc:date>2011-06-30T13:51:11Z</dc:date>
  </entry>
  <entry>
    <title>Trojan.Win32.Letter.AK</title>
    <link rel="alternate" href="http://blognew.aruba.it/blog.malwarelist.org/Trojan_Win32_Letter_AK_51037.shtml" />
    <category term="" />
    <category term="trojan" />
    <category term="," />
    <category term="gpo" />
    <category term="exe" />
    <category term="," />
    <category term="letter" />
    <category term="ak" />
    <author>
      <name>blog.malwarelist.org</name>
    </author>
    <updated>2011-07-05T14:23:11Z</updated>
    <published>2011-06-30T07:45:04Z</published>
    <content>&lt;p&gt;&lt;font size="2"&gt;Il &lt;strong&gt;trojan &lt;/strong&gt;in analisi si presenta sotto il nome di Gpo.exe&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Informazioni Tecniche&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" width="586" height="293"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Nome file:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Gpo.exe&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Dimensioni:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;152.576 bytes&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Percorso di installazione: &lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;%TEMP%&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Chiavi di registro modificate:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;HKCU\Software\Microsoft\Windows\CurrentVersion\Run [R4B1ZAOPF5] = %TEMP%\Gpo.exe&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;HKCU\Software\R4B1ZAOPF5\ [VbiH] = xC53ydu..... &lt;em&gt;(stringa casuale di 76 caratteri)&lt;/em&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp; HKCU\Software\R4B1ZAOPF5\ [VbiS] = qH56b/h12..... &lt;em&gt;(stringa casuale di 413 caratteri)&lt;/em&gt;&amp;nbsp; &lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Funzionamento&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;Il file, una volta avviato, si copia nella cartella %TEMP% e si configura modificando il registro per avviarsi in esecuzione automatica. Effettua anche altre modifiche al registro creando le due chiavi sopracitate [VbiH] assegnando una stringa casuale di 76 caratteri e [VbiS] assegnando invece a questa una stringa di addirittura 413 caratteri di lunghezza.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NOTE:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; %TEMP% = C:\Documents and Settings\{username}\Impostazioni Locali\Temp&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HKCU = HKEY_CURRENT_USER&lt;/font&gt;&lt;/p&gt;&lt;hr /&gt;&lt;font size="2"&gt;Rimozione: VirIT 6.9.35 - &lt;a href="http://www.tgsoft.it"&gt;www.tgsoft.it&lt;/a&gt;&lt;/font&gt;&lt;br /&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</content>
    <summary>Il trojan in analisi si presenta sotto il nome di Gpo.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;Informazioni Tecniche&amp;nbsp;&amp;nbsp;&amp;nbsp;Nome file:&amp;nbsp;Gpo.exe&amp;nbsp;Dimensioni:&amp;nbsp;152.576 bytes&amp;nbsp;Percorso di installazione: &amp;nbsp;%TEMP%&amp;nbsp;Chiavi di registro modificate:&amp;nbsp;HKCU\Software\Microsoft\Windows\CurrentVersion\Run ...</summary>
    <dc:creator>blog.malwarelist.org</dc:creator>
    <dc:date>2011-06-30T07:45:04Z</dc:date>
  </entry>
  <entry>
    <title>Trojan.Win32.Buzus.EF</title>
    <link rel="alternate" href="http://blognew.aruba.it/blog.malwarelist.org/Trojan_Win32_Buzus_EF_51003.shtml" />
    <category term="" />
    <category term="trojan" />
    <category term="," />
    <category term="svchost" />
    <category term="exe" />
    <category term="," />
    <category term="keylogger" />
    <category term="," />
    <category term="buzus" />
    <category term="ef" />
    <author>
      <name>blog.malwarelist.org</name>
    </author>
    <updated>2011-07-05T14:23:42Z</updated>
    <published>2011-06-29T14:46:35Z</published>
    <content>&lt;p&gt;&lt;font size="2"&gt;Il &lt;strong&gt;trojan &lt;/strong&gt;in questione si presenta sotto il falso nome svchost.exe &lt;em&gt;(in Windows &amp;egrave; un processo del computer che ospita, o contiene, altri servizi singoli che vengono utilizzati dal SO per diverse funzioni)&lt;/em&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Informazioni Tecniche&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;table border="1" width="582" height="370"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Nome file:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;svchost.exe&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Nome originale:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Logger.exe&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Dimensioni:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;1.363.968 bytes&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Versione:&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;3.0.0.0&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Percorso di&amp;nbsp; installazione:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;%USERPROFILE%\Dati Applicazioni\&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font size="2"&gt;&amp;nbsp;Chiavi di registro modificate:&lt;br /&gt;&lt;/font&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;HKCU\Software\Microsoft\Windows\CurrentVersion\Run [ServicesHostforWindows] = %USERPROFILE%\Dati Applicazioni\svchost.exe&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;HKLM\Software\Microsoft\Windows\CurrentVersion\Run [ServicesHostforWindows] = %USERPROFILE%\Dati Applicazioni\svchost.exe&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;HKLM\Software\Microsot\Windows\CurrentVersion\Policies\Explorer\Run [SevicesHostforWindows] = %USERPROFILE%\Dati Applicazioni\svchost.exe &lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="4"&gt;&lt;strong&gt;Funzionamento&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;Una volta avviato, svchost.exe, presentando una piccola finestra con scritto &amp;quot;Loading&amp;quot; effettua molte operazionio dietro le quinte.&amp;nbsp; Innanzitutto: &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&lt;u&gt;A livello di registro:&lt;/u&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font size="2"&gt;Modifica la seguente chiave di registro configurandosi in esecuzione automatica sotto il nome di &amp;quot;Services Host for Windows&amp;quot;: &lt;em&gt;&lt;font size="2"&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Run [ServicesHostforWindows] = %USERPROFILE%\Dati Applicazioni\svchost.exe &lt;/font&gt;&lt;/em&gt;&lt;br /&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="2"&gt;Modifica anche la seguente chiave: &lt;em&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Run [ServicesHostforWindows] = %USERPROFILE%\Dati Applicazioni\svchost.exe&lt;/em&gt; &lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font size="2"&gt;&lt;u&gt;A livello di File System:&lt;/u&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font size="2"&gt;Crea una copia di se stesso su %USERPROFILE%\Dati Applicazioni&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="2"&gt;Crea un file sempre su %USERPROFILE%\Dati Applicazioni di nome pcinfo.dat&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font size="2"&gt;All'interno del file pcinfo.dat vengono registrati i programmi in esecuzione automatica, tutte le aperture di programmi durante l'uso del sistema che effettua l'utente e tutte le sue digitazioni sulla tastiera. In pratica il trojan effettua un'operazione di keylogger. Ad ogni riavvio visto che il trojan va in esecuzione automatica si presenta sempre la finestrella con la scritta &amp;quot;Loading&amp;quot;. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NOTE:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/font&gt;&lt;font size="2"&gt;%USERPROFILE% = C:\Documents and Settings\ {username}&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/font&gt;&lt;font size="2"&gt;HKCU = HKEY_CURRENT_USER&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; HKLM = HKEY_LOCAL_MACHINE&lt;/font&gt;&lt;/p&gt;&lt;hr /&gt;&lt;font size="2"&gt;Rimozione: VirIT 6.9.34 - &lt;a href="http://www.tgsoft.it"&gt;www.tgsoft.it&lt;/a&gt;&lt;br /&gt;&lt;/font&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</content>
    <summary>Il trojan in questione si presenta sotto il falso nome svchost.exe (in Windows &amp;egrave; un processo del computer che ospita, o contiene, altri servizi singoli che vengono utilizzati dal SO per diverse funzioni)&amp;nbsp;Informazioni Tecniche&amp;nbsp;Nome file:&amp;nbsp;svchost.exe&amp;nbsp;Nome ...</summary>
    <dc:creator>blog.malwarelist.org</dc:creator>
    <dc:date>2011-06-29T14:46:35Z</dc:date>
  </entry>
</feed>


