This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.
|
Minimum DAT
4300 (2003-10-29) Updated DAT4317 (2004-01-21) |
Minimum Engine
5.1.00 File Length102,400 bytes |
Description Added
2003-10-28 Description Modified2003-10-30 |
This is a proxy server trojan, designed to turn an infected system into an email spam relay. The trojan opens two random IP ports and sends infection notification to the author.
When the trojan is run, it copies itself to the WINDOWS SYSTEM (%SysDir%) directory as syscpy.exe. A registry run key is created to load the trojan at startup:
The trojan contacts two anti-spam web sites to verify that the IP address of the infected system has not been blacklisted on abust.net or spamcop.net . Presumably noting that the IP address of the infected system has been blacklisted if/when this is the case.
A random TCP port and a random UDP port is opened. Information/notification is posted to a page on a remote website (note: several variants have been discovered, this is a partial list and new variants will likely use other sites)
Information sent to the page was likely entered into a database for future spam use. A remote attacker must send the appropriate packets to infected systems in order to expoit them.
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email spam, etc.
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).