Re: [Full-disclosure] wintcpmod.exe Hear of it?

From: Michael Holstein (michael.holstein_at_csuohio.edu)
Date: 05/06/05

  • Next message: Sune Kloppenborg Jeppesen: "[Full-disclosure] [ GLSA 200505-03 ] Ethereal: Numerous vulnerabilities"
    Date: Fri, 06 May 2005 13:09:09 -0400
    To: full-disclosure@lists.grok.org.uk
    
    

    Probably a <flavor_of_the_month>bot variant. Run it by Norman's sandbox
    and see what shakes out.

    http://sandbox.norman.no/live_4.html

    Try to Un-[upx|rar|zip] it first .. Norman's website dosen't handle
    programs that are compressed multiple times so well (and bot-kiddies
    like to do just that to hide them/frustrate us).

    Also .. check standard spots in the registry to see if it's set to run
    on startup (HKLM/Software/Microsoft/Windows/CurrentVersion/Run and
    RunServices).

    As mentioned in another post, http://www.virustotal.com is another good
    spot to run it through.

    Seeing the same file in those two places is fairly common bot behavior
    .. they want to ensure they get it at least one place that's in the $PATH.

    If all else fails, a VMware guest (with Ethereal on the host O/S) is
    your friend.

    Cheers,

    Michael Holstein CISSP GCIA
    Cleveland State Univeristy

    Dan Bambach wrote:
    > I noticed today that a program wintcpmod.exe, located in two places on
    > my hard drive, windows\system and windows\system32 was attempting to
    > access port 53. My firewall blocked it and sent an alert. I am on the
    > road, so I have not had time to fully investigate this yet, but a Google
    > search produced very little about this program. It sets a registry key
    > for local machine “run”, and can be seen on the process screen. It does
    > not appear in the services list. I was able to kill it, but in my Google
    > search, someone has claimed that they were unable to kill the process. I
    > am running WinXP SPk2 fully patched, and Symantec AntiVirus,
    > ZoneAlarmPro. Microsoft AntiSpyware does not report anything.
    >
    >
    >
    > Has anyone else seen this program?
    >
    >
    >
    > Dan Bambach
    >
    > Dan@dbambach.net <mailto:Dan@dbambach.net>
    >
    >
    >
    >
    > ------------------------------------------------------------------------
    >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    > Hosted and sponsored by Secunia - http://secunia.com/
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: Sune Kloppenborg Jeppesen: "[Full-disclosure] [ GLSA 200505-03 ] Ethereal: Numerous vulnerabilities"

    Relevant Pages

    • Re: Emberileg mar total veguk, mar olyan fasisztak, hogy mar mindenkinek tele van a toke a Google
      ... >>> Google ... >> KILL KILL KILL YOU WHITER WHITE. ... So one day this scientist noticed unusual radiation readings. ... that a group of beasts gathered together in Ireland in 2005 from around ...
      (soc.culture.magyar)
    • Re: About "filtering" Cross-Posted
      ... I curious as to why so many people use Google Groups, ... No kill file is just one of the ... I can't see the advantage to using a newsreader. ... Google does filter out some stuff. ...
      (rec.pets.cats.anecdotes)
    • Re: Emberileg mar total veguk, mar olyan fasisztak, hogy mar mindenkinek tele van a toke a Google
      ... >>> lawyer ... Google, ... >> If russians or chinese would be infringing on American labels and copyrights, ... > KILL KILL KILL YOU WHITER WHITE. ...
      (soc.culture.magyar)
    • Re: Google and Yoogee
      ... "Main" registry key houses many IE settings. ... > I get hijacked and redirected to either a Google or Yoogee ... > cookies and to prompt for 1st party cookies. ...
      (microsoft.public.win2000.security)
    • Re: How to reliably kill processes/applications?
      ... In Registry key HKCU\Control Panel\desktop, add or change the value named HungAppTimeout, changing its current data of to 1000. ... In Registry key HKCU\Control Panel\desktop, add or change the value named WaitToKillAppTimeout, changing its current data of to 1000. ... Is there a quicker way (something like 'kill -9' under Unix/Linux) to ... Any way to 'make it so' without a delay or prompt? ...
      (microsoft.public.vc.mfc)