Re: New PowerPoint Trojan installs itself as LSP



Is this 'mechanism' very common and is it difficult to detect by AV?

No, but you have to be damned careful removing something installed as an
LSP. I've seen literally hundreds of PCs with their network stack
buggered because the owner tried to remove NewDotNet. NewDotNet inserts
itself as an LSP.

Regards,
Mike Healan
www.spywareinfo.com

Juha-Matti Laurio wrote:
It appears that there is a new type of PowerPoint 0-day Trojan spreading,
more details at this write-up:
http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2
006-071812-3213-99

What the technical details section says is:
"Installs the file SNootern.dll as a layered service provider (LSP)"

Wikipedia has only stub type article
http://en.wikipedia.org/wiki/Layered_Service_Provider

Is this 'mechanism' very common and is it difficult to detect by AV?

This new Trojan entitled as Riler.F opens a back door and tries to
connect to 8800.org,
earlier Bifrose Trojan uses (or used) this domain too.

There is a new C variant of Trojan.PPDropper as well, but no information
about the file name of PowerPoint attachment etc.
Symantec reports Infection Length as 220,160 bytes, same as used by
Trojan.PPDropper.B.
This size information is from Trojan description of another vendor,
however.

This summary has been updated to related PowerPoint 0-day FAQ document.

Regards,
Juha-Matti
http://blogs.securiteam.com/index.php/archives/author/juha-matti/



Relevant Pages

  • [Full-disclosure] Re: New PowerPoint Trojan installs itself as LSP
    ... itself as an LSP. ... "Installs the file SNootern.dll as a layered service provider " ... This new Trojan entitled as Riler.F opens a back door and tries to ... about the file name of PowerPoint attachment etc. ...
    (Full-Disclosure)
  • Re: My Windows XP system is 100% secure - nobody can get in
    ... the methods you need are within the Winsock DLL but they are not ... it to the next LSP layer in the long chain of LSPs ... ... Now, our firewall is throwing away packets it doesn't like, and its doing it ... a DLL Trojan is sitting in the protocol stack at a lower ...
    (alt.computer.security)
  • Re: LSP on WINCE 4.2 (extremly painful)
    ... The SSLLSP installs using PROTOCOL_TLS. ... The "Flags" registry value allows the SSL socket to be created on the default ... > Now that you understand this problem, does your LSP work? ... > is the FLAG value in register table under the SSL key. ...
    (microsoft.public.pocketpc.developer)
  • Re: Xchat.org trojan ads
    ... The other installs a "Transponder Parasite" ...... ... The trojan was stealth installed via javascript from ... Windows Media Player 9 wmplayer.exe file was overwritten by javascript ... stealth installed and executed to install the trojan. ...
    (microsoft.public.security.virus)
  • Re: LSP blocks all network traffic
    ... either app that were having a LSP that was not working with mine (use ... compiles fine and it installs, ... I am running Win2k server. ...
    (microsoft.public.win32.programmer.networks)