The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security > Malware Advisories (RSS)
Google UNIX.COM


Malware Advisories (RSS) Malware Security Advisories Via RSS

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Worm_onlineg.ugx iBot Malware Advisories (RSS) 0 07-08-2008 04:40 AM
Worm_onlineg.ugt iBot Malware Advisories (RSS) 0 06-24-2008 08:10 AM
Worm_onlineg.gte iBot Malware Advisories (RSS) 0 05-22-2008 06:50 AM
Worm_onlineg.gak iBot Malware Advisories (RSS) 0 04-18-2008 05:50 AM
Worm_onlineg.djo iBot Malware Advisories (RSS) 0 01-30-2008 04:00 PM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1  
Old 07-18-2008
iBot's Avatar
RSS Robot Girl
 

Join Date: Sep 2000
Posts: 14,296
Worm_onlineg.xdz

This worm may be downloaded unknowingly by a user when visiting malicious Web site(s).

It creates registry entry(ies) to enable its automatic execution at every system startup.

It modified registry entry(ies) to hide files with both System and Read-only attributes.

It drops copies of itself in all physical and removable drives. It also drops an AUTORUN.INF file to enable the automatic execution of its dropped copies every time the said drives are accessed.


This worm accesses Web sites to download file(s), including WORM_ONLINE.CS. The downloaded .RAR file contains an encrypted URL code which can download a copy of WORM_ONLINE.CS. As a result, routines of the downloaded files are also exhibited on the affected system.
It also drops component file(s). One of the .DLL files, which contains all malicious routines of its main malware component, is injected into the legitimate process EXPLORER.EXE. It terminates process(es), if found running in memory.


This worm steals information by collecting user inputs (specifically user names and passwords) from certain URLs.
It also monitors certain online game processes. It then sends the gathered information to several IP addresses. This routine risks the exposure of the user's account information, which may then lead to the unauthorized use of the stolen data.

More...
Reply With Quote
Google The UNIX and Linux Forums
Forum Sponsor
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes




All times are GMT -7. The time now is 12:11 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Complex Event Processing Blog

Content Relevant URLs by vBSEO 3.2.0