RE: [Full-Disclosure] New Win32 Worm regsvc32.exe offers rootkit features

From: Aditya, ALD [Aditya Lalit Deshmukh] (aditya.deshmukh_at_online.gateway.technolabs.net)
Date: 03/31/04

  • Next message: Crist J. Clark: "Re: [Full-Disclosure] SMTP Encryption (S/MIME) for Outlook question"
    To: "Alex" <alexs@indefense.com>, <full-disclosure@lists.netsys.com>
    Date: Wed, 31 Mar 2004 09:32:33 +0530
    
    

    >
    >
    > Looks like IRC Backdoor
    > check registry:
    > HKLM\Software\Microsoft\Windows\CurrentVersion\Run and delete
    > entry with regsvc32.exe
    > (such as Registration Service = "regsvc32.exe")
    > Do the same with
    > HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    the port 1025 is good used for binding the task schuduler, is this doing something with the task schuduler. there are plenty of naughty things to do there ....

    -aditya

    ________________________________________________________________________
    Delivered using the Free Personal Edition of Mailtraq (www.mailtraq.com)

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Crist J. Clark: "Re: [Full-Disclosure] SMTP Encryption (S/MIME) for Outlook question"

    Relevant Pages

    • Re: ftdi installed - how to test serial connection!
      ... I don't know of a suitable program our SW engineer has searched the registry ... get the com port number. ...
      (microsoft.public.windowsce.platbuilder)
    • Re: Apple Pascal
      ... If the AppleWin Configuration in the Registry doesn't have a "Serial ... Port" entry, then it can internally set the COM port with a random ...
      (comp.emulators.apple2)
    • Re: Apple Pascal
      ... If the AppleWin Configuration in the Registry doesn't have a "Serial ... Port" entry, then it can internally set the COM port with a random value, ...
      (comp.emulators.apple2)
    • Re: Apple Pascal
      ... If the AppleWin Configuration in the Registry doesn't have a "Serial ... Port" entry, then it can internally set the COM port with a random ...
      (comp.emulators.apple2)