[Full-Disclosure] New Win32 Worm regsvc32.exe offers rootkit features

From: Markus Koetter (gumble_at_gmx.li)
Date: 03/30/04

  • Next message: Raymond Dijkxhoorn: "Re: [Full-Disclosure] New Win32 Worm regsvc32.exe offers rootkit features"
    To: full-disclosure@lists.netsys.com
    Date: Tue, 30 Mar 2004 18:29:29 +0200
    
    

    Hi,
    my girlfriend got a new? worm on her win2k desktop.
    The worm is quite aggressive in spreading, netstat -a did not find an
    end, i expect it to be a phatbot/agobot4 fork
    seems like it invaded on port 1025, i dont know which services were
    offerd there, but i saw several connections to port 1025.

    the virus offers rootkit capabilities, file and process hide, kills
    firewalls with specific names, and makes the system unusable after some
    uptime.

    i installed another firewall renamed the bin to "horst.exe" and got
    several connections to
    c:\winnt\services32\regsvc32.exe
    the file did not exists, neither the process in win2ks taskmanager.

    I was not able to remove the virus, so i plugged the machine of the net
    and told her to work offline.
    this worked well for ~4h, then the system became unstable and the floppy
    disk was screaming like a burning pig.

    I took my new knoppix cd 3.4, booted it, and used the live f-prot
    install to scan the system for viruses, the system got the latest
    definitions via web, and scanned ...
    No viruses were found.

    I mounted the hda1 windows partition and send me the "expected to be the
    virus file" on my own computer running linux
    the file is called regscv32.exe and has the
    md5sum 26a5dbd9add4b16b561cd916675c4439

    i expect it to be polymorph

    i lack solid skills in disassembler, but i would send this binary to
    fill-disc listed ppl asking for it.

    if i fail in my expectations, and this is a standard win32 binary, tell
    me (i cant check the md5sum myself, i lack a win32 system), and i will
    try to find the right binary again.

    my own conclusion,
    i will install debian unstable on her desktop for working, and win2k for
    printing on her linux incompatible lexmark printer.
    lilo offering 2 entries "write" "print"

    im sick off this ...

    Markus Koetter

    please mail me for the binary, im really intrested in a analysis report.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Raymond Dijkxhoorn: "Re: [Full-Disclosure] New Win32 Worm regsvc32.exe offers rootkit features"

    Relevant Pages

    • Re: Major issues with sharing violation error messages all the time!
      ... I tried to do an overlay install the second time believing ... Win2K can be in a home installation. ... I'm still left with the problem of the ID3 tags. ... I just bought an mp3 player so I'm moving MP3 files off of my back-up ...
      (microsoft.public.win2000.new_user)
    • Re: Format Hard Disk
      ... So it's like that - the 2 files reside only in the boot partition.. ... As you suggested, I opened Command ... No problem....I don't intend to use the programs existing in Win2K. ... - Buy a 100 GByte disk and install it as a slave drive. ...
      (microsoft.public.win2000.general)
    • Re: It gets worse -- Uninstall of W2k? Not simple for me!
      ... Multibooting WinXP and Win2K is easy and automatic, ... install them into separate volumes and always install the newest Windows ... the Active partition, load the first physical sector of that partition into ... NOT the "Boot Partition". ...
      (microsoft.public.win2000.file_system)
    • Re: It gets worse -- Uninstall of W2k? Not simple for me!
      ... Multibooting WinXP and Win2K is easy and automatic, ... install them into separate volumes and always install the newest Windows ... the Active partition, load the first physical sector of that partition into ... NOT the "Boot Partition". ...
      (microsoft.public.win2000.general)
    • Re: Major issues with sharing violation error messages all the time!
      ... command not available in Win2K boot disks, ... The set of four install disks can be created from your Windows 2000 ... When the Windows 2000 Professional ... existing partition, If you press D to delete an existing partition, you must ...
      (microsoft.public.win2000.new_user)