New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 983
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
image trj: Commentaries: Backdoor trojans make their presence felt image
Trojans
Backdoor trojans make their presence felt

A virus never sleeps. And it seems they don't stop mutating and breeding, too, as there are two new threats to computer users: BDSinit-A and Webber-C.

Strictly speaking, they are back-door trojans rather than 'viruses', but they both allow a remote attacker to control your system. The anti-virus specialist Sophos has already received several reports from the wild for both the threats.

BDSinit-A works by copying itself into the Windows system folder as svcinit.exe and modifies the Registry for it to be executed on system start-up.

In terms of operation, it will open a random port on the PC in order to receive commands from a remote attacker.

Webber-C, believed to be of Eastern European (probably Polish) origin, is slightly more involved. Its loader component will download the cargo from a web address (www.valenok.red-host.com) into the Windows system folder, and then execute it, and its downloaded component is a password stealing trojan. This will attempt to extract sensitive information from several locations on the system - for example, files containing password info - and then send it to another part of the website.

The downloaded component is hard to detect because it will be stored using a random name. And the fact that the virus checks for orders from a website gives the attacker flexibility on what Webber-C will actually perform - it is not hard-coded into the trojan itself.

Sophos reports that Webber-C can also function as a web proxy, and it is believed it may be used to monitor users' web activity and retrieve information, possibly financial details, for example.

You can find more info on Troj/BDSinit-A and Troj/Webber-C on the Sophos Website.

Alun Williams

pcpro.co
Posted on Friday, 14 November 2003 @ 04:35:00 EST by phoenix22
image

 
Login
Nickname

Password

· New User? ·
Click here to create a registered account.
image
Related Links
· TrackBack (0)
· PHP HomePage
· Microsoft
· HotScripts
· W3 Consortium
· More about Trojans
· News by phoenix22


Most read story about Trojans:
Lover Spy

image
Article Rating
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


image
Options

Printer Friendly Page  Printer Friendly Page

image
"Login" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register