<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>emka.web.id &#187; Analisis Virus</title>
	<atom:link href="http://emka.web.id/blog/category/computer-security/analisis-virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://emka.web.id</link>
	<description>menulis jejak, mewarta bijak</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:33:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Update Virus Definition untuk Virus DorkBot.bx</title>
		<link>http://emka.web.id/computer-security/analisis-virus/2011/update-virus-definition-untuk-virus-dorkbot-bx/</link>
		<comments>http://emka.web.id/computer-security/analisis-virus/2011/update-virus-definition-untuk-virus-dorkbot-bx/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 03:28:39 +0000</pubDate>
		<dc:creator>Luthfi Emka</dc:creator>
				<category><![CDATA[Analisis Virus]]></category>
		<category><![CDATA[Analisis virus]]></category>
		<category><![CDATA[Virus DorkBot]]></category>
		<category><![CDATA[Virus DorkBot.Bx]]></category>
		<category><![CDATA[Virus Downloader-CMU.d]]></category>

		<guid isPermaLink="false">http://emka.web.id/?p=6149</guid>
		<description><![CDATA[Berikut adalah update virus definition untuk membasmi file-file Virus DorkBot. Patut dicatat,saya hanya menyajikan dua file update virus definition: untuk ClamAV dan McAfee (dua produk yang saya gunakan). Untuk database tambahan ClamAV (panahbiruav-dorkbot.hdb) bisa anda unduh dari disini. Sedangkan untuk database tambahan McAfee untuk virus DorkBot (atau Downloader-CMU.d) dapat anda unduh dari sini. Silakan gunakan [...]]]></description>
			<content:encoded><![CDATA[<p>Berikut adalah update virus definition untuk membasmi file-file Virus DorkBot. Patut dicatat,saya hanya menyajikan dua file update virus definition: untuk ClamAV dan McAfee (dua produk yang saya gunakan).</p>
<p>Untuk database tambahan ClamAV (<em>panahbiruav-dorkbot.hdb</em>) bisa anda unduh dari <a href="http://emka.web.id/wp-content/uploads/2011/12/panahbiru-dorkbot.zip">disini</a>. Sedangkan untuk database tambahan McAfee untuk virus DorkBot (atau Downloader-CMU.d) dapat anda unduh dari <a href="http://emka.web.id/wp-content/uploads/2011/12/extra.zip">sini</a>. Silakan gunakan opsi tambahan <em>-db ./panahbiru-dorkbot.hdb</em> pada command line untuk ClamAV dan copy file <em>extra.dat</em> pada folder database virus milik McAfee (biasanya di C:\Program Files\Common Files\McAfee\Engines\).</p>
<p>Selamat mencoba!  :D</p>
<p>NB. Jika punya sample virus, silakan kirim ke saya. Upload dulu via salah satu layanan sharing file (4Shared, MediaFire, Uploaded dll) kemudian kirim URL-nya ke <em>panahbiru[padadomain]gmail.com</em></p>
<strong>Hasil pencarian tentang artikel ini:</strong><p> <a href="http://emka.web.id/computer-security/analisis-virus/2011/update-virus-definition-untuk-virus-dorkbot-bx/" title="dorkbot virus">dorkbot virus</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/update-virus-definition-untuk-virus-dorkbot-bx/" title="membasmi dorkbot bx">membasmi dorkbot bx</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/update-virus-definition-untuk-virus-dorkbot-bx/" title="memberantas virus dorkbot">memberantas virus dorkbot</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/update-virus-definition-untuk-virus-dorkbot-bx/" title="virus definition terbaru">virus definition terbaru</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/update-virus-definition-untuk-virus-dorkbot-bx/" title="virus dorkbot bx">virus dorkbot bx</a></p>]]></content:encoded>
			<wfw:commentRss>http://emka.web.id/computer-security/analisis-virus/2011/update-virus-definition-untuk-virus-dorkbot-bx/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tentang Virus DorkBot.Bx</title>
		<link>http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/</link>
		<comments>http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 02:35:28 +0000</pubDate>
		<dc:creator>Luthfi Emka</dc:creator>
				<category><![CDATA[Analisis Virus]]></category>
		<category><![CDATA[Analisis virus]]></category>
		<category><![CDATA[Virus DorkBot]]></category>
		<category><![CDATA[Virus DorkBot.Bx]]></category>
		<category><![CDATA[Virus Downloader-CMU.d]]></category>

		<guid isPermaLink="false">http://emka.web.id/?p=6139</guid>
		<description><![CDATA[Virus DorkBot.Bx sedang menyebar luas di negeri ini. Berikut ciri-ciri PC yang terinfeksi virus ini: 1. CPU 100% Sama seperti pendahulunya (BitCoinMiner), DorkBot.Bx juga akan membuat CPU menjadi lamban. Penggunaan CPU menunjukkan persentase 100%. Ini karena aktivitas dari trojan yang berusaha menembus kriptografi blok BitCoin dan mencoba aktif terus untuk melakukan pengiriman data. 2. Boros [...]]]></description>
			<content:encoded><![CDATA[<p>Virus DorkBot.Bx sedang menyebar luas di negeri ini. Berikut ciri-ciri PC yang terinfeksi virus ini:</p>
<p>1. CPU 100%</p>
<p>Sama seperti pendahulunya (BitCoinMiner), DorkBot.Bx juga akan membuat CPU menjadi lamban. Penggunaan CPU menunjukkan persentase 100%. Ini karena aktivitas dari trojan yang berusaha menembus kriptografi blok BitCoin dan mencoba aktif terus untuk melakukan pengiriman data.</p>
<p>2. Boros bandwith</p>
<p>Dengan seringnya melakukan aktivitas kriptografi yang menggunakan sumber daya dari komputer, tentunya akan membuat penggunaan CPU menjadi lambat (100%). Tetapi di balik itu perlu diperhatikan dari aktivitas penggunaan bandwith internet, karena akibat dari trojan DorkBot.Bx justru membuat bandwith anda menjadi boros.</p>
<p><span id="more-6139"></span></p>
<p>3. Menyembunyikan folder pada drive USB atau removable disk</p>
<p>Sama seperti trojan BitCoinMiner, trojan DorkBot.Bx pun juga melakukan hal yang sama yaitu dengan menyembunyikan folder-folder pada USB atau removable disk dan membuat shortcut palsu yang mirip nama folder tersebut. Sepertinya tren shortcut juga menginspirasi trojan DorkBot.Bx</p>
<p>4. Melakukan koneksi ke Server BitCoin</p>
<p>Trojan DorkBot.Bx berusaha melakukan koneksi ke Server BitCoin untuk melakukan pengiriman kriptografi blok-blok BitCoin menggunakan akun pembuat malware pada BitCoin. Dengan cara tersebut, pembuat malware diuntungkan karena dapat dengan cepat dan mudah melakukan kriptografi blok-blok BitCoin melalui bantuan komputer-komputer yang sudah terinfeksi.</p>
<p>5. Melakukan koneksi ke IRC/Remote Server</p>
<p>Trojan DorkBot.Bx juga berusaha melakukan koneksi ke IRC/Remote Server untuk melakukan pengiriman informasi BitCoin pengguna komputer yang dibutuhkan oleh pembuat malware.</p>
<p>6. Mendownload file malware</p>
<p>Agar mempermudah aksinya, trojan DorkBot.Bx juga melakukan download beberapa file malware tertentu dari IRC/Remote Server agar tetap terupdate dan tidak mudah dikenali oleh antivirus. File malware yang berbeda-beda inilah yang kadang membuat antivirus sulit mendeteksi keberadaan trojan DorkBot.Bx.</p>
<p>7. Mendownload file Certificate Authority (CA)</p>
<p>Pada dasarnya, Certificate Authority (CA) digunakan pada transaksi pembayaran online seperti bank, PayPal, dan ribuan situs lain yang menggunakan protokol SSL. Dengan mendownload file CA, pembuat malware ingin memastikan bahwa komputer korban yang terinfeksi sudah memiliki CA yang terupdate sehingga dapat melakukan transaksi BitCoin dengan aman.</p>
<p>8. Melakukan transfer data yang telah didapatkan</p>
<p>Tujuan utama dari trojan DorkBot.Bx adalah mendapatkan informasi dari pengguna komputer yang sudah terinfeksi.</p>
<p>9. Membuka berbagai port</p>
<p>Trojan DorkBot.Bx juga membuka berbagai port pada komputer korban agar dapat dengan mudah terkoneksi oleh IRC/Remote Server, serta melakukan berbagai aksi dengan leluasa.</p>
<p>10. Mengadopsi Facebook Chat</p>
<p>Metode ini yang mungkin paling sering ditemukan pengguna. DorkBot.Bx memberikan link URL yang telah diubah menjadi singkat, sehingga pengguna akan mudah tertipu. Jika link tersebut dibuka, maka pengguna akan mengunduh file yang menggunakan nama file dan icon yang cukup &#8216;sexy&#8217;.</p>
<p>Ciri lainnya adalah memodifikasi registry dan membuat beberapa file agar menginfeksi komputer. Agar dapat langsung aktif saat pengguna menghubungkan USB atau removable drive, trojan DorkBot.Bx memanfaatkan celah keamanan Windows yaitu Windows Icon handler yang membuat file shortcut dari trojan akan aktif begitu mengakses drive tersebut.</p>
<h4>Analisis Virus</h4>
<p>Sample yang dikirim ke 2 vendor analisis malware menghasilkan hasil uji sebagai berikut:</p>
<p><strong>1. Menurut McAfee Threat Inteligence</strong></p>
<div style="font-size: 8pt;">
<strong>This is a Trojan</strong></p>
<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr bgcolor="silver">
<th align="left" bgcolor="silver"><strong>File Properties</strong></th>
<th align="right" bgcolor="silver"><strong>Property Values</strong></th>
</tr>
<tr>
<td align="left">McAfee Detection</td>
<td align="right">Downloader-CMU.d</td>
</tr>
<tr>
<td align="left">Length</td>
<td align="right">135681 bytes</td>
</tr>
<tr>
<td align="left">MD5</td>
<td align="right">62466ae813448aec7621b25e3102e2c2</td>
</tr>
<tr>
<td align="left">SHA1</td>
<td align="right">02127b7c97893f9fc76c72a46e5690b259bff7d8</td>
</tr>
</tbody>
</table>
<p><strong>Other Common Detection Aliases</strong></p>
<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr bgcolor="silver">
<th align="left" bgcolor="silver"><strong>Company Names</strong></th>
<th align="right" bgcolor="silver"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">avast</td>
<td align="right">Win32:Malware-gen</td>
</tr>
<tr>
<td align="left">avira</td>
<td align="right">TR/Dropper.Gen</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Backdoor.Win32.Ruskill.p</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Gen:Heur.IPZ.3</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">BackDoor.IRC.Bot.835</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/Ruskill.P!tr.bdr</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">Worm:Win32/Dorkbot</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Injector.FTN trojan (probably variant)</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">W32/Suspicious_Gen2.KZIYM</td>
</tr>
<tr>
<td align="left">rising</td>
<td align="right">Trojan.Win32.Generic.128630D2</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">BKDR_RUSKILL.AA</td>
</tr>
<tr>
<td align="left">vba32</td>
<td align="right">BScope.FakeAV.xd</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Backdoor.Ruskill!rVOox3DhmwU (trojan)</td>
</tr>
</tbody>
</table>
<p><em>Other brands and names may be claimed as the property of others.</em></p>
<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr bgcolor="silver">
<th align="left" bgcolor="silver"><strong>Activities</strong></th>
<th align="right" bgcolor="silver"><strong>Risk Levels</strong></th>
</tr>
<tr>
<td align="left">Attempts to load and execute remote code in explorer process</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_High.jpg" alt="High" /></td>
</tr>
<tr>
<td align="left">Attempts to load and execute remote code in a system process.</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_High.jpg" alt="High" /></td>
</tr>
<tr>
<td align="left">Attempts to write to a memory location of a protected process.</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_High.jpg" alt="High" /></td>
</tr>
<tr>
<td align="left">Attempts to write to a memory location of a Windows system process</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_High.jpg" alt="High" /></td>
</tr>
<tr>
<td align="left">Attempts to write to a memory location where winlogon resides</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_High.jpg" alt="High" /></td>
</tr>
<tr>
<td align="left">Attempts to load and execute remote code in a previously loaded process</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_med.jpg" alt="Medium" /></td>
</tr>
<tr>
<td align="left">Attempts to write to a memory location of a previously loaded process.</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_med.jpg" alt="Medium" /></td>
</tr>
<tr>
<td align="left">Enumerates many system files and directories.</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_low.jpg" alt="Low" /></td>
</tr>
<tr>
<td align="left">Enumerates process list</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_low.jpg" alt="Low" /></td>
</tr>
<tr>
<td align="left">Process attempts to call itself recursively</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_low.jpg" alt="Low" /></td>
</tr>
<tr>
<td align="left">Attempts to write to a memory location of an unknown process</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_low.jpg" alt="Low" /></td>
</tr>
<tr>
<td align="left">No digital signature is present</td>
<td align="right"><img src="http://vil.nai.com/images/VIL_ACT_info.jpg" alt="Informational" /></td>
</tr>
</tbody>
</table>
<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr bgcolor="silver">
<th align="left" bgcolor="silver"><strong>McAfee Scans</strong></th>
<th align="right" bgcolor="silver"><strong>Scan Detections</strong></th>
</tr>
<tr>
<td align="left">McAfee Beta</td>
<td align="right">Downloader-CMU.d</td>
</tr>
<tr>
<td align="left">McAfee Supported</td>
<td align="right">Downloader-CMU.d</td>
</tr>
</tbody>
</table>
<p><strong><span style="text-decoration: underline;">System Changes</span></strong></p>
<p><em>Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</em></p>
<p><strong>The following files were analyzed:</strong></p>
<p>1dd.tmp</p>
<table>
<tbody>
<tr>
<td width="35" height="35"><img src="http://vil.nai.com/images/vdisk_ico.jpg" alt="" /></td>
<td><strong>The following files have been added to the system:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>%APPDATA%\Cdvmvo.exe</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"><img src="http://vil.nai.com/images/vdisk_ico.jpg" alt="" /></td>
<td><strong>The following files have been changed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>%WINDIR%\SYSTEM32\catroot2\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\catdb</li>
</ul>
<ul>
<li>%WINDIR%\SYSTEM32\catroot2\edb.chk</li>
</ul>
<ul>
<li>%WINDIR%\SYSTEM32\catroot2\edb.log</li>
</ul>
<ul>
<li>%WINDIR%\SYSTEM32\catroot2\{127d0a1d-4ef2-11d1-8608-00c04fc295ee}\catdb</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"><img src="http://vil.nai.com/images/vdisk_ico.jpg" alt="" /></td>
<td><strong>The following files were temporarily written to disk then later removed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>%WINDIR%\SYSTEM32\catroot2\tmp.edb</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"><img src="http://vil.nai.com/images/vreg_ico.jpg" alt="" /></td>
<td><strong>The following registry elements have been changed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\CDVMVO = %APPDATA%\Cdvmvo.exe</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"><img src="http://vil.nai.com/images/vnet_ico.jpg" alt="" /></td>
<td><strong>The applications attempted the following network connection(s):</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>173.246.103.**:4949 (irc) : NICK n{US|XPa}qqonxsj</li>
</ul>
<ul>
<li>hxxp://api.wipmania.com/</li>
</ul>
</td>
</tr>
</tbody>
</table>
</div>
<p><strong>2. Menurut ThreatExpert</strong></p>
<div style="font-size: 8pt;">
<ul>
<li>Submission details:</li>
<ul>
<li>Submission received: 30 November 2011, 18:07:02</li>
<li>Processing time: 14 min 26 sec</li>
<li>Submitted sample:</li>
<ul>
<li>File MD5: 0xE87E6EE3BCB95A9851AE53D46DE583D6</li>
<li>File SHA-1: 0x8A2239F360D0F3A206D9ABE4550AD44A5343EA1D</li>
<li>Filesize: 1,903,189 bytes</li>
<li>Alias:</li>
<ul>
<li>Trojan.Gen.2 [Symantec]</li>
<li>Worm.Win32.Ngrbot.hel [Kaspersky Lab]</li>
<li>Worm.Win32.Dorkbot [Ikarus]</li>
</ul>
</ul>
</ul>
</ul>
<ul>
<li>Summary of the findings:</li>
</ul>
<table width="570px" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td>What&#8217;s been found</td>
<td>Severity Level</td>
</tr>
<tr>
<td>Produces outbound traffic.</td>
<td><img src="http://www.threatexpert.com/resources/level1.gif" alt="" /></td>
</tr>
<tr>
<td>Downloads/requests other files from Internet.</td>
<td><img src="http://www.threatexpert.com/resources/level1.gif" alt="" /></td>
</tr>
<tr>
<td>Creates a startup registry entry.</td>
<td><img src="http://www.threatexpert.com/resources/level2.gif" alt="" /></td>
</tr>
<tr>
<td>Contains characteristics of an identified security risk.</td>
<td><img src="http://www.threatexpert.com/resources/level10.gif" alt="" /></td>
</tr>
</tbody>
</table>
<h2>Technical Details:</h2>
<ul>
<li>The new window was created, as shown below:</li>
</ul>
<p><img src="http://www.threatexpert.com/getimage.aspx?uid=edd49a89-534d-4c9f-9c1b-a1c1661c0c7a&amp;image=screen&amp;sub=1" alt="" /></p>
<div>
<p><strong>NOTICE:</strong> The content shown in the above window is captured automatically and is not controlled or endorsed by ThreatExpert.<br />
<strong>Please contact us on this <a href="http://www.threatexpert.com/contact.aspx">link</a> should any material be offensive or inappropriate</strong> and we will ensure any such content is blocked from future viewers of the report.</p>
</div>
<table cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td><img src="http://www.threatexpert.com/resources/threat.gif" alt="" /></td>
<td width="100%">Possible Security Risk</td>
</tr>
</tbody>
</table>
<ul>
<li><span style="color: #990000;"><strong>Attention! </strong></span>The following threat categories were identified:</li>
</ul>
<table cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td>Threat Category</td>
<td>Description</td>
</tr>
<tr>
<td><img src="http://www.threatexpert.com/resources/cats/trojan.gif" alt="" /></td>
<td>A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment</td>
</tr>
<tr>
<td><img src="http://www.threatexpert.com/resources/cats/backdoor.gif" alt="" /></td>
<td>A malicious backdoor trojan that runs in the background and allows remote access to the compromised system</td>
</tr>
<tr>
<td><img src="http://www.threatexpert.com/resources/cats/worm.gif" alt="" /></td>
<td>A network-aware worm that attempts to replicate across the existing network(s)</td>
</tr>
</tbody>
</table>
<table cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td><img src="http://www.threatexpert.com/resources/file_mod.gif" alt="" /></td>
<td width="100%">File System Modifications</td>
</tr>
</tbody>
</table>
<ul>
<li>The following files were created in the system:</li>
</ul>
<table cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td>#</td>
<td>Filename(s)</td>
<td>File Size</td>
<td>File Hash</td>
<td>Alias</td>
</tr>
<tr>
<td>1</td>
<td>%AppData%\1.tmp<br />
%AppData%\2.tmp<br />
%AppData%\Fbxaxf.exe</td>
<td>282,624 bytes</td>
<td>MD5: 0x4419BA71E46C2B6180D8C5FB5F14EFB0<br />
SHA-1: 0x6187916D3C3511B9AE9874A3868B175659D46EC4</td>
<td>(not available)</td>
</tr>
<tr>
<td>2</td>
<td>%AppData%\<a href="http://www.threatexpert.com/files/3.exe.html" target="_blank">3.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>327,680 bytes</td>
<td>MD5: 0xACB887FE28C2D1206B8835935506E6B8<br />
SHA-1: 0x9E0E8218B3BCAC5931CE448EE8FEFF1333813F2E</td>
<td>(not available)</td>
</tr>
<tr>
<td>3</td>
<td>%AppData%\<a href="http://www.threatexpert.com/files/5.exe.html" target="_blank">5.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>474,829 bytes</td>
<td>MD5: 0x2D04724F3EACF65CB140B8B3F36C5C97<br />
SHA-1: 0xE195798A6F76010673B457B2D8CEADC29E3E22A5</td>
<td>(not available)</td>
</tr>
<tr>
<td>4</td>
<td>%AppData%\<a href="http://www.threatexpert.com/files/6.exe.html" target="_blank">6.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>388,535 bytes</td>
<td>MD5: 0x7781C1145869CDF87CF61D671247E80E<br />
SHA-1: 0xE2F76F546D3E4FF3E748FB6D4B1B3D2890C3B1DA</td>
<td>(not available)</td>
</tr>
<tr>
<td>5</td>
<td>%AppData%\<a href="http://www.threatexpert.com/files/7.exe.html" target="_blank">7.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>398,081 bytes</td>
<td>MD5: 0x37FBCA12ADFF251A3B0BC75EF81CE752<br />
SHA-1: 0x951C62AB205B7CD0C783273170D1DEF56EA25AFE</td>
<td>Trojan.ADH [PCTools]<br />
Trojan.Gen.2 [Symantec]<br />
not-a-virus:RiskTool.Win32.HideExec.r [Kaspersky Lab]<br />
W32/IRCbot.gen.bc [McAfee]<br />
<a href="http://www.threatexpert.com/threats/trojan-win32-sisproc.html" target="_blank">Trojan:Win32/Sisproc<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Microsoft]<br />
Trojan.BAT.Miner [Ikarus]</td>
</tr>
<tr>
<td>6</td>
<td>%AppData%\9.tmp<br />
%AppData%\Wcxaxw.exe</td>
<td>294,912 bytes</td>
<td>MD5: 0xDAFF13B10AD87D9F578555B641758FA1<br />
SHA-1: 0x377E0C14DCF65A9B027748775BC7ACD3E06BAB67</td>
<td>(not available)</td>
</tr>
<tr>
<td>7</td>
<td>%AppData%\<a href="http://www.threatexpert.com/files/A.exe.html" target="_blank">A.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>137,024 bytes</td>
<td>MD5: 0x7DBB979C1CBCFAEBC9792D47E05A841C<br />
SHA-1: 0xC73BB9319146F6AD76FFE143685578E51B097587</td>
<td>(not available)</td>
</tr>
<tr>
<td>8</td>
<td>%AppData%\kakao3\fuckHDZSDP.exe<br />
%Temp%\fuckHDZSDP.exe</td>
<td>278,528 bytes</td>
<td>MD5: 0xAE9C07D9B2EA9C1F58E32D3C44B0F33E<br />
SHA-1: 0xE1E72AE01919BC8F0BD236AA00EED4D029C7CCE7</td>
<td><a href="http://www.threatexpert.com/threats/trojan-gen.html" target="_blank">Trojan.Gen<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [PCTools]<br />
<a href="http://www.threatexpert.com/threats/trojan-gen.html" target="_blank">Trojan.Gen<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Symantec]<br />
Trojan.Win32.FakeAv.irgx [Kaspersky Lab]<br />
BackDoor-DOQ.gen.as [McAfee]<br />
<a href="http://www.threatexpert.com/threats/mal-generic-l.html" target="_blank">Mal/Generic-L<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Sophos]<br />
<a href="http://www.threatexpert.com/threats/trojan-win32-malagent.html" target="_blank">Trojan:Win32/Malagent<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Microsoft]<br />
<a href="http://www.threatexpert.com/threats/trojan-win32-buzus.html" target="_blank">Trojan.Win32.Buzus<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Ikarus]</td>
</tr>
<tr>
<td>9</td>
<td>%AppData%\kakao3\<a href="http://www.threatexpert.com/files/new.exe.html" target="_blank">new.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a><br />
%Temp%\<a href="http://www.threatexpert.com/files/new.exe.html" target="_blank">new.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>57,344 bytes</td>
<td>MD5: 0xC31027010355FD8F52FE3640048ACD37<br />
SHA-1: 0x5DD50D63D76B8E1CEFBC019CFD414C57FFFEAA72</td>
<td>(not available)</td>
</tr>
<tr>
<td>10</td>
<td>%AppData%\PickaVamMaterina2\HDZ.exe</td>
<td>57,344 bytes</td>
<td>MD5: 0x7A8DF56F23106AD0D9D786BAE4ED75BC<br />
SHA-1: 0xBD78A2F8FEAA92C5B18BBFFD0EB1399A0644F5BC</td>
<td>(not available)</td>
</tr>
<tr>
<td>11</td>
<td>%AppData%\PickaVamMaterina2\Ivo_Sanader.exe</td>
<td>389,120 bytes</td>
<td>MD5: 0x0A4EB0CB242A27AEC20A281F4293FC5E<br />
SHA-1: 0x4BA9C00EAC0317346A0AAC3AE8AFB7D4057863EA</td>
<td>(not available)</td>
</tr>
<tr>
<td>12</td>
<td>%AppData%\jqycpqe.exe<br />
%Temp%\zxjidmw.exe</td>
<td>344,576 bytes</td>
<td>MD5: 0x6D6BD4C8256D75B314BDD644C1240917<br />
SHA-1: 0x1ACCD82D27F6511375F5635BDAAC8B3BAFF0E624</td>
<td><a href="http://www.threatexpert.com/threats/trojan-fakeav.html" target="_blank">Trojan.FakeAV<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [PCTools]<br />
Trojan.FakeAV!gen64 [Symantec]<br />
Trojan.Win32.FakeAV.dvjc [Kaspersky Lab]<br />
FakeAlert-SecurityTool.bt [McAfee]<br />
Mal/FakeAV-KL [Sophos]<br />
<a href="http://www.threatexpert.com/threats/trojan-win32-fakeav.html" target="_blank">Trojan.Win32.FakeAV<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Ikarus]</td>
</tr>
<tr>
<td>13</td>
<td>%Temp%\<a href="http://www.threatexpert.com/files/about.exe.html" target="_blank">about.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>57,344 bytes</td>
<td>MD5: 0xC52F6C51034FD72CB65483DAB4E51438<br />
SHA-1: 0xB0039E980891438B76419E0CEF9040FA1C413E93</td>
<td>(not available)</td>
</tr>
<tr>
<td>14</td>
<td>%Temp%\<a href="http://www.threatexpert.com/files/del.exe.html" target="_blank">del.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>159,232 bytes</td>
<td>MD5: 0x99D3FD2985012D43C3D532CF1F70B342<br />
SHA-1: 0xD0018933F627CD668DFEBC1B3AAD8D4C25D2D82B</td>
<td>Malware.W95-CIH [PCTools]<br />
<a href="http://www.threatexpert.com/threats/w95-cih-damaged.html" target="_blank">W95.CIH.damaged<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Symantec]<br />
Generic.dx!xon [McAfee]<br />
<a href="http://www.threatexpert.com/threats/mal-generic-l.html" target="_blank">Mal/Generic-L<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Sophos]<br />
Trojan:Win32/Dynamer!dtc [Microsoft]<br />
<a href="http://www.threatexpert.com/threats/virus-win9x-cih.html" target="_blank">Virus.Win9x.CIH<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Ikarus]</td>
</tr>
<tr>
<td>15</td>
<td>%Temp%\<a href="http://www.threatexpert.com/files/hid.exe.html" target="_blank">hid.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>44,040 bytes</td>
<td>MD5: 0xC1C769D742F88E441DED76BF57A5A45C<br />
SHA-1: 0x06872DABD41E70DC4EF8FD5131B334BE8A17DB3C</td>
<td><a href="http://www.threatexpert.com/threats/net-worm-sillyfdc.html" target="_blank">Net-Worm.SillyFDC<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [PCTools]<br />
not-a-virus:RiskTool.Win32.HideExec.r [Kaspersky Lab]</td>
</tr>
<tr>
<td>16</td>
<td>%Temp%\HRSearchC.exe</td>
<td>287,744 bytes</td>
<td>MD5: 0x5E03A535C8BEF1AB056074D68CE7A5E0<br />
SHA-1: 0x689974AE94DF135E21F5711C06B5DC72DA3F9128</td>
<td><a href="http://www.threatexpert.com/threats/trojan-gen.html" target="_blank">Trojan.Gen<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [PCTools]<br />
Trojan.Gen.2 [Symantec]<br />
Generic.dx!banc [McAfee]<br />
<a href="http://www.threatexpert.com/threats/trojan-atraps.html" target="_blank">Trojan.ATRAPS<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Ikarus]<br />
<em>packed with </em>PE_Patch.PECompact [Kaspersky Lab]</td>
</tr>
<tr>
<td>17</td>
<td>%Temp%\Jttetn.exe</td>
<td>139,264 bytes</td>
<td>MD5: 0x585F2F27EF6D87CD4CC9A8501EAAA6FE<br />
SHA-1: 0x0AB77FD8C68025F4E579C4C58C05874108F20F5A</td>
<td><a href="http://www.threatexpert.com/threats/trojan-gen.html" target="_blank">Trojan.Gen<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [PCTools]<br />
<a href="http://www.threatexpert.com/threats/trojan-gen.html" target="_blank">Trojan.Gen<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Symantec]<br />
Backdoor.Win32.Ruskill.g [Kaspersky Lab]<br />
Downloader-CMU.d [McAfee]<br />
<a href="http://www.threatexpert.com/threats/mal-generic-l.html" target="_blank">Mal/Generic-L<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Sophos]<br />
Worm:Win32/Dorkbot.A [Microsoft]<br />
Worm.Win32.Dorkbot [Ikarus]</td>
</tr>
<tr>
<td>18</td>
<td>%Temp%\Mstetq.exe</td>
<td>143,360 bytes</td>
<td>MD5: 0x167F4EF7C1225451EF69DB10D3B16611<br />
SHA-1: 0xE5D356E142ED28AB5A0748CD04BB792C9514192A</td>
<td>Worm.Win32.Ngrbot.hdy [Kaspersky Lab]<br />
BackDoor-DOQ.gen.as [McAfee]<br />
Mal/EncPk-AAQ [Sophos]<br />
Worm:Win32/Dorkbot.A [Microsoft]<br />
Worm.Win32.Dorkbot [Ikarus]</td>
</tr>
<tr>
<td>19</td>
<td>%Temp%\newmoon17.exe</td>
<td>367,889 bytes</td>
<td>MD5: 0x1CE65C3C14F7F09C08C50FBB6A8C1CC4<br />
SHA-1: 0x46E4FD565736FF96A94F5B762C1F875C32585A1B</td>
<td>Trojan.Win32.FakeAv.irgx [Kaspersky Lab]<br />
Generic FakeAlert!tz [McAfee]<br />
<a href="http://www.threatexpert.com/threats/mal-generic-l.html" target="_blank">Mal/Generic-L<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Sophos]<br />
<a href="http://www.threatexpert.com/threats/trojan-win32-buzus.html" target="_blank">Trojan.Win32.Buzus<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Ikarus]</td>
</tr>
<tr>
<td>20</td>
<td>%Temp%\x30811.exe</td>
<td>1,012,224 bytes</td>
<td>MD5: 0x4BC19BC59EC9C4A987079A618CF18C68<br />
SHA-1: 0xC4EC15672E96CEC3411CCE377BFFEAB55BA8C88D</td>
<td><a href="http://www.threatexpert.com/threats/trojan-gen.html" target="_blank">Trojan.Gen<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [PCTools]<br />
Trojan.Gen.2 [Symantec]<br />
Generic.tfr!r [McAfee]<br />
<a href="http://www.threatexpert.com/threats/trojan-win32-orsam-rts.html" target="_blank">Trojan:Win32/Orsam!rts<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Microsoft]<br />
<a href="http://www.threatexpert.com/threats/win32-suspectcrc.html" target="_blank">Win32.SuspectCrc<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Ikarus]</td>
</tr>
<tr>
<td>21</td>
<td>%Temp%\yz.bat</td>
<td>180 bytes</td>
<td>MD5: 0xD6C231471750C153641E292D746814B5<br />
SHA-1: 0x16EC0A913564D18A6D03711415B272FDECC3E867</td>
<td>Trojan.BAT.Miner.i [Kaspersky Lab]<br />
Trojan.BAT.Miner [Ikarus]</td>
</tr>
<tr>
<td>22</td>
<td>%Programs%\Startup\Demokratska2.exe</td>
<td>418,008 bytes</td>
<td>MD5: 0xCF4C9FA0F9B2AB5CA96C7C2AF8B26C75<br />
SHA-1: 0x6B9F44527B91AD9DAC7AD1D396787496DBE37BEE</td>
<td>(not available)</td>
</tr>
<tr>
<td>23</td>
<td>%Programs%\Startup\<a href="http://www.threatexpert.com/files/dxdiag.exe.html" target="_blank">dxdiag.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>23,552 bytes</td>
<td>MD5: 0x9EA5BEFAB3FAB1D19D70F8D917463D13<br />
SHA-1: 0xBCABE617AF58EFB8B0E759111044BDBB8F3F6152</td>
<td><a href="http://www.threatexpert.com/threats/trojan-gen.html" target="_blank">Trojan.Gen<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [PCTools]<br />
<a href="http://www.threatexpert.com/threats/trojan-gen.html" target="_blank">Trojan.Gen<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Symantec]<br />
Trojan.Win32.Jorik.Aspxor.y [Kaspersky Lab]<br />
<a href="http://www.threatexpert.com/threats/generic-downloader-z.html" target="_blank">Generic Downloader.z<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [McAfee]<br />
Troj/Bredo-IK [Sophos]<br />
<a href="http://www.threatexpert.com/threats/trojan-agent-r.html" target="_blank">Trojan.Agent_r<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a> [Ikarus]</td>
</tr>
<tr>
<td>24</td>
<td>%Programs%\Startup\stepx2.exe</td>
<td>348,530 bytes</td>
<td>MD5: 0x0764BEF5D967DCE3784E18D204BB90E6<br />
SHA-1: 0x896A45B21C554B723503BC5865677733C025FC23</td>
<td>Trojan.ADH [PCTools]<br />
Trojan.Gen.2 [Symantec]<br />
Trojan.BAT.Miner.i, not-a-virus:RiskTool.Win32.HideExec.r [Kaspersky Lab]<br />
Generic.tfr!r [McAfee]<br />
Trojan.BAT.Miner [Ikarus]</td>
</tr>
<tr>
<td>25</td>
<td>%Programs%\Startup\<a href="http://www.threatexpert.com/files/taskmgr.exe.html" target="_blank">taskmgr.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>826,184 bytes</td>
<td>MD5: 0x47CFDF331A80B2028A1B8ACA61BD191B<br />
SHA-1: 0xD10BD40A735C6EFBFA4FBFA6C842B4DB5DBA9445</td>
<td>(not available)</td>
</tr>
<tr>
<td>26</td>
<td>[file and pathname of the sample #1]</td>
<td>1,903,189 bytes</td>
<td>MD5: 0xE87E6EE3BCB95A9851AE53D46DE583D6<br />
SHA-1: 0x8A2239F360D0F3A206D9ABE4550AD44A5343EA1D</td>
<td>Trojan.Gen.2 [Symantec]<br />
Backdoor.Win32.Ruskill.g, Worm.Win32.Ngrbot.hdy, Trojan.Win32.Jorik.Aspxor.y, Trojan.Win32.FakeAv.irgx, Trojan.Win32.FakeAV.dvjc, Worm.Win32.Ngrbot.hel [Kaspersky Lab]<br />
Worm.Win32.Dorkbot [Ikarus]</td>
</tr>
</tbody>
</table>
<ul>
<li>Notes:</li>
<ul>
<li>%AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.</li>
<li>%Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).</li>
<li>%Programs% is a variable that refers to the file system directory that contains the user&#8217;s program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.</li>
</ul>
</ul>
<ul>
<li>The following directories were created:</li>
<ul>
<li>%AppData%\kakao3</li>
<li>%AppData%\PickaVamMaterina2</li>
</ul>
</ul>
<table cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td><img src="http://www.threatexpert.com/resources/mem_mod.gif" alt="" /></td>
<td width="100%">Memory Modifications</td>
</tr>
</tbody>
</table>
<ul>
<li>There was a new process created in the system:</li>
</ul>
<table cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td>Process Name</td>
<td>Process Filename</td>
<td>Main Module Size</td>
</tr>
<tr>
<td><a href="http://www.threatexpert.com/files/del.exe.html" target="_blank">del.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>%Temp%\<a href="http://www.threatexpert.com/files/del.exe.html" target="_blank">del.exe<img src="http://www.threatexpert.com/resources/flag.gif" alt="" /></a></td>
<td>184,320 bytes</td>
</tr>
</tbody>
</table>
<table cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td><img src="http://www.threatexpert.com/resources/reg_mod.gif" alt="" /></td>
<td width="100%">Registry Modifications</td>
</tr>
</tbody>
</table>
<ul>
<li>The following Registry Keys were created:</li>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\HRSearch</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\HRSearch\Data</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce</li>
<li>HKEY_CURRENT_USER\Software\gnzyyfavskozwffiqimedkeykicvah</li>
<li>HKEY_CURRENT_USER\Software\jnbsjxsrphezdokcyofecvybrkjlrh</li>
<li>HKEY_CURRENT_USER\Software\WinRAR SFX</li>
</ul>
</ul>
<ul>
<ul>
<li>The newly created Registry Values are:</li>
<ul>
<li>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]</li>
<ul>
<li>Scxaxs = &#8220;%AppData%\Scxaxs.exe&#8221;</li>
<li>Lcxaxl = &#8220;%AppData%\Lcxaxl.exe&#8221;</li>
<li>Wcxaxw = &#8220;%AppData%\Wcxaxw.exe&#8221;</li>
<li>Fbxaxf = &#8220;%AppData%\Fbxaxf.exe&#8221;</li>
</ul>
</ul>
</ul>
</ul>
<p><em>so that Wcxaxw.exe runs every time Windows starts</em><br />
<em>so that Fbxaxf.exe runs every time Windows starts</em></p>
<ul>
<ul>
<li>[HKEY_CURRENT_USER\Software\gnzyyfavskozwffiqimedkeykicvah]</li>
<ul>
<li>wfdijwaopfddvmieihccsyrbpsbqhy = &#8220;&#8221;</li>
</ul>
<li>[HKEY_CURRENT_USER\Software\jnbsjxsrphezdokcyofecvybrkjlrh]</li>
<ul>
<li>dncirhudbpmysvlqkzovzmfcsemsko = &#8220;&#8221;</li>
</ul>
<li>[HKEY_CURRENT_USER\Software\WinRAR SFX]</li>
<ul>
<li>C%%Documents and Settings%%UserName%%Application Data%kakao3 = &#8220;%AppData%\kakao3&#8243;</li>
<li>C%%Documents and Settings%%UserName%%Start Menu%Programs%Startup = &#8220;%Programs%\Startup&#8221;</li>
<li>C%%Documents and Settings%%UserName%%Application Data%PickaVamMaterina2 = &#8220;%AppData%\PickaVamMaterina2&#8243;</li>
<li>C%%DOCUME~1%%UserName%%LOCALS~1%Temp = &#8220;%UserProfile%\LOCALS~1\Temp&#8221;</li>
</ul>
</ul>
</ul>
<table cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td><img src="http://www.threatexpert.com/resources/other_mod.gif" alt="" /></td>
<td width="100%">Other details</td>
</tr>
</tbody>
</table>
<ul>
<li>There were registered attempts to establish connection with the remote hosts. The connection details are:</li>
</ul>
<table cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td>Remote Host</td>
<td>Port Number</td>
</tr>
<tr>
<td>199.15.234.7</td>
<td>80</td>
</tr>
<tr>
<td>70.38.98.239</td>
<td>80</td>
</tr>
<tr>
<td>92.243.20.57</td>
<td>3212</td>
</tr>
</tbody>
</table>
<ul>
<li>The data identified by the following URLs was then requested from the remote web server:</li>
<ul>
<li>http://api.wipmania.com/</li>
<li>http://img105.herosh.com/2011/11/30/745759013.gif</li>
</ul>
</ul>
<table cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td><img src="http://www.threatexpert.com/resources/traffic_mod.gif" alt="" /></td>
<td width="100%">Outbound traffic (potentially malicious)</td>
</tr>
</tbody>
</table>
<ul>
<li>There was an outbound traffic produced on port 3212:</li>
</ul>
<p>00000000 | 1703 0000 1DAB E65A 5272 636E 2145 D536 | &#8230;&#8230;.ZRrcn!E.6<br />
00000010 | DE93 29D5 30B1 C61D 332C 9A67 949A BC7A | ..).0&#8230;3,.g&#8230;z<br />
00000020 | 9E5B 1703 0000 274F ADFB BF5C 4E3A FB4E | .[....'O...\N:.N<br />
00000030 | D8CC C0CA 0050 D50D 9575 5A23 C707 EC0B | .....P...uZ#....<br />
00000040 | 7581 0719 F6AE 5AD5 F944 AE93 A1AA 1703 | u.....Z..D......<br />
00000050 | 0000 2BD7 208A C1F7 256B F9F6 9CDE A553 | ..+. ...%k.....S<br />
00000060 | 9E96 B39D A07E 1DAD B1C6 97A4 3724 EC7E | .....~......7$.~<br />
00000070 | 3C85 F623 B80B 6153 9522 16E0 3A10 1703 | <..#..aS."..:...<br />
00000080 | 0000 2B17 0300 0021 DA71 8326 C5E8 AA2A | ..+....!.q.&#038;...*<br />
00000090 | 9569 1FB6 841A 28FF 3CFD E0B3 CAED 2701 | .i....(.<.....'.<br />
000000A0 | 1E3B 92FF EAA9 C7EA F58C F1E4 D1DA 5265 | .;............Re<br />
000000B0 | 3174 9F17 0300 002B B706 D784 55DF CA99 | 1t.....+....U...<br />
000000C0 | F14D 26E9 7B04 A824 A720 6035 1958 3851 | .M&#038;.{..$. `5.X8Q<br />
000000D0 | 62B7 EF3D D371 4100 05A9 261E 9405 6B9A | b..=.qA...&#038;...k.<br />
000000E0 | 391E C3A9 1497 5C92 EE8B FF97 4DC9 F64B | 9.....\.....M..K<br />
000000F0 | 0686 843D 1503 0000 12C0 9AF5 9FE9 9F49 | ...=...........I<br />
00000100 | D9E3 B6AD 3696 8DE8 80F7 AA16 0300 0041 | ....6..........A<br />
00000110 | 0100 003D 0300 4ED6 E189 B267 390E FDB0 | ...=..N....g9...<br />
00000120 | F1DE 8842 4A95 84E3 FB81 300E 64F0 39B7 | ...BJ.....0.d.9.<br />
00000130 | A36E 5D63 987C 0000 1600 0400 0500 0A00 | .n]c.|&#8230;&#8230;&#8230;.<br />
00000140 | 0900 6400 6200 0300 0600 1300 1200 6301 | ..d.b&#8230;&#8230;&#8230;c.<br />
00000150 | 0015 0300 0002 0129 1603 0000 8410 0000 | &#8230;&#8230;.)&#8230;&#8230;..<br />
00000160 | 807F CF33 A19D 39EE 435D ED5D 92EF 7B8E | &#8230;3..9.C].]..{.<br />
00000170 | 5BCF AB87 2357 E0F2 1505 1282 6EE9 A547 | [&#8230;#W&#8230;&#8230;n..G<br />
00000180 | 4E1F 9858 939A 5769 3956 3625 8F42 893B | N..X..Wi9V6%.B.;<br />
00000190 | 1E8B 4CF4 FD81 33EA B29E F34C 60CE 341B | ..L&#8230;3&#8230;.L`.4.<br />
000001A0 | 1C77 896E 6C8B E959 F873 F09A 1E96 DB05 | .w.nl..Y.s&#8230;&#8230;<br />
000001B0 | 9A35 3ABB 0986 976E 5283 1942 1B35 58DC | .5:&#8230;.nR..B.5X.<br />
000001C0 | 1452 FBA5 76CA FEED 54E9 CD6D 3C4D FA84 | .R..v&#8230;T..m<M..<br />
000001D0 | B3F1 6AE7 0CE6 9CA6 DA64 511A C0AE E2EF | ..j......dQ.....<br />
000001E0 | EB14 0300 0001 0116 0300 0038 D6F1 B74A | ...........8...J<br />
000001F0 | 6314 38F3 E899 A02A BF38 5088 2AF8 E066 | c.8....*.8P.*..f<br />
00000200 | 2877 20CA DB84 5C66 E13C 6708 20C9 BD26 | (w ...\f.<g. ..&#038;<br />
00000210 | F737 82A8 5F21 37D8 A7B8 3AF5 7F65 2F82 | .7.._!7...:..e/.<br />
00000220 | D0D9 7802                               | ..x.
</p>
</div>
<p><strong>3. VirusTotal</strong></p>
<p>Berikut hasil sample yang diperiksa dengan VirusTotal dengan 43 antivirusnya.</p>
<table id="tablaMotores" width="98%" border="1" cellspacing="0" cellpadding="0" style="font-size: 9pt;">
<tbody>
<tr>
<th>Antivirus</th>
<th>Version</th>
<th>Last Update</th>
<th>Result</th>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>2011.05.11.01</td>
<td>2011.05.11</td>
<td>Win-Trojan/Injector.135681.C</td>
</tr>
<tr>
<td>AntiVir</td>
<td>7.11.7.216</td>
<td>2011.05.11</td>
<td>TR/Dropper.Gen</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>2.0.3.7</td>
<td>2011.05.11</td>
<td>Backdoor/Win32.Ruskill.gen</td>
</tr>
<tr>
<td>Avast</td>
<td>4.8.1351.0</td>
<td>2011.05.11</td>
<td>Win32:Malware-gen</td>
</tr>
<tr>
<td>Avast5</td>
<td>5.0.677.0</td>
<td>2011.05.11</td>
<td>Win32:Malware-gen</td>
</tr>
<tr>
<td>AVG</td>
<td>10.0.0.1190</td>
<td>2011.05.10</td>
<td>Dropper.Generic3.BCMM</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.2</td>
<td>2011.05.11</td>
<td>Gen:Trojan.Heur.JP.iu1@aOHdEdmi</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>11.00</td>
<td>2011.05.11</td>
<td>Backdoor.Ruskill.p</td>
</tr>
<tr>
<td>ClamAV</td>
<td>0.97.0.0</td>
<td>2011.05.11</td>
<td>-</td>
</tr>
<tr>
<td>Commtouch</td>
<td>5.3.2.6</td>
<td>2011.05.11</td>
<td>-</td>
</tr>
<tr>
<td>Comodo</td>
<td>8659</td>
<td>2011.05.11</td>
<td>UnclassifiedMalware</td>
</tr>
<tr>
<td>DrWeb</td>
<td>5.0.2.03300</td>
<td>2011.05.11</td>
<td>BackDoor.IRC.Bot.835</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>5.1.0.5</td>
<td>2011.05.11</td>
<td>Gen.Trojan.Heur!IK</td>
</tr>
<tr>
<td>eSafe</td>
<td>7.0.17.0</td>
<td>2011.05.09</td>
<td>-</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>36.1.8320</td>
<td>2011.05.11</td>
<td>-</td>
</tr>
<tr>
<td>F-Prot</td>
<td>4.6.2.117</td>
<td>2011.05.11</td>
<td>-</td>
</tr>
<tr>
<td>F-Secure</td>
<td>9.0.16440.0</td>
<td>2011.05.11</td>
<td>Gen:Trojan.Heur.JP.iu1@aOHdEdmi</td>
</tr>
<tr>
<td>Fortinet</td>
<td>4.2.257.0</td>
<td>2011.05.11</td>
<td>W32/Ruskill.P!tr.bdr</td>
</tr>
<tr>
<td>GData</td>
<td>22</td>
<td>2011.05.11</td>
<td>Gen:Trojan.Heur.JP.iu1@aOHdEdmi</td>
</tr>
<tr>
<td>Ikarus</td>
<td>T3.1.1.103.0</td>
<td>2011.05.11</td>
<td>Gen.Trojan.Heur</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>13.0.900</td>
<td>2011.05.11</td>
<td>-</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>9.103.4614</td>
<td>2011.05.10</td>
<td>Backdoor</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>9.0.0.837</td>
<td>2011.05.11</td>
<td>Backdoor.Win32.Ruskill.p</td>
</tr>
<tr>
<td>McAfee</td>
<td>5.400.0.1158</td>
<td>2011.05.11</td>
<td>Generic PWS.bfr!c</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>2010.1D</td>
<td>2011.05.10</td>
<td>Heuristic.BehavesLike.Win32.Suspicious.D</td>
</tr>
<tr>
<td>Microsoft</td>
<td>1.6802</td>
<td>2011.05.11</td>
<td>Worm:Win32/Dorkbot</td>
</tr>
<tr>
<td>NOD32</td>
<td>6111</td>
<td>2011.05.11</td>
<td>probably a variant of Win32/Injector.FTN</td>
</tr>
<tr>
<td>Norman</td>
<td>6.07.07</td>
<td>2011.05.10</td>
<td>W32/Suspicious_Gen2.KZIYM</td>
</tr>
<tr>
<td>nProtect</td>
<td>2011-05-10.01</td>
<td>2011.05.10</td>
<td>-</td>
</tr>
<tr>
<td>Panda</td>
<td>10.0.3.5</td>
<td>2011.05.10</td>
<td>Generic Malware</td>
</tr>
<tr>
<td>PCTools</td>
<td>7.0.3.5</td>
<td>2011.05.11</td>
<td>-</td>
</tr>
<tr>
<td>Prevx</td>
<td>3.0</td>
<td>2011.05.11</td>
<td>-</td>
</tr>
<tr>
<td>Rising</td>
<td>23.57.01.05</td>
<td>2011.05.10</td>
<td>Trojan.Win32.Generic.128630D2</td>
</tr>
<tr>
<td>Sophos</td>
<td>4.65.0</td>
<td>2011.05.11</td>
<td>Mal/Behav-103</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>4.40.0.1006</td>
<td>2011.05.11</td>
<td>-</td>
</tr>
<tr>
<td>Symantec</td>
<td>20101.3.2.89</td>
<td>2011.05.11</td>
<td>-</td>
</tr>
<tr>
<td>TheHacker</td>
<td>6.7.0.1.195</td>
<td>2011.05.11</td>
<td>-</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>9.200.0.1012</td>
<td>2011.05.11</td>
<td>BKDR_RUSKILL.AA</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>9.200.0.1012</td>
<td>2011.05.11</td>
<td>BKDR_RUSKILL.AA</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.12.16.0</td>
<td>2011.05.11</td>
<td>BScope.FakeAV.xd</td>
</tr>
<tr>
<td>VIPRE</td>
<td>9250</td>
<td>2011.05.11</td>
<td>Trojan.Win32.Generic!BT</td>
</tr>
<tr>
<td>ViRobot</td>
<td>2011.5.11.4452</td>
<td>2011.05.11</td>
<td>-</td>
</tr>
<tr>
<td>VirusBuster</td>
<td>13.6.347.2</td>
<td>2011.05.10</td>
<td>Backdoor.Ruskill!rVOox3DhmwU</td>
</tr>
</tbody>
</table>
<table id="metadata-table" width="700" border="0" cellspacing="0" cellpadding="0" style="font-size: 9pt;">
<tbody>
<tr>
<th>
<div>Additional information</div>
</th>
</tr>
<tr>
<td>MD5   : 62466ae813448aec7621b25e3102e2c2</td>
</tr>
<tr>
<td>SHA1  : 02127b7c97893f9fc76c72a46e5690b259bff7d8</td>
</tr>
<tr>
<td>SHA256: 0e3c6dc183696540c724a848b3f142338d046099c9efc460e9ab4ad67df51299</td>
</tr>
</tbody>
</table>
<p>Sumber: <a href="http://www.detikinet.com/read/2011/12/06/155222/1784163/323/10-ciri-pc-yang-terinfeksi-malware-dorkbotbx?i991102105">detikINET</a>, <a href="http://www.threatexpert.com/report.aspx?md5=e87e6ee3bcb95a9851ae53d46de583d6">ThreatExpert</a>, <a href="http://www.mcafee.com/threat-intelligence/malware/default.aspx?id=526227">McAfee ThreatInteligence</a>, dan <a href="http://www.virustotal.com/file-scan/report.html?id=0e3c6dc183696540c724a848b3f142338d046099c9efc460e9ab4ad67df51299-1305101587">VirusTotal</a></p>
<strong>Hasil pencarian tentang artikel ini:</strong><p> <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="menghilangkan virus dorkbot">menghilangkan virus dorkbot</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="virus dorkbot">virus dorkbot</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="ruskill virus">ruskill virus</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="mengatasi virus dorkbot a">mengatasi virus dorkbot a</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="virus who am i">virus who am i</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="virus membuat prosesor 100%">virus membuat prosesor 100%</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="penggunaan cpu 100% komputer lambat">penggunaan cpu 100% komputer lambat</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="penangkal virus dorkbot">penangkal virus dorkbot</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="mengenai virus trojan jorik">mengenai virus trojan jorik</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="menghilangkan virus dorkbot bx">menghilangkan virus dorkbot bx</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="virus x30811">virus x30811</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="antivirus untuk dorkbot bx">antivirus untuk dorkbot bx</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="a variant of win32/dorkbot a worm - unable to">a variant of win32/dorkbot a worm - unable to</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="antivirus yang mampu mendeteksi dorkbot">antivirus yang mampu mendeteksi dorkbot</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/" title="backdoor:win32/ircbot gen!k">backdoor:win32/ircbot gen!k</a></p>]]></content:encoded>
			<wfw:commentRss>http://emka.web.id/computer-security/analisis-virus/2011/tentang-virus-dorkbot-bx/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Menghapus Trojan VBNA</title>
		<link>http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/</link>
		<comments>http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 13:16:11 +0000</pubDate>
		<dc:creator>Luthfi Emka</dc:creator>
				<category><![CDATA[Analisis Virus]]></category>

		<guid isPermaLink="false">http://emka.web.id/?p=5536</guid>
		<description><![CDATA[Trojan VBNA atau Trojan Bancos, adalah trojan yang cukup berbahaya bagi sistem operasi Windows. Trojan ini dikenali oleh hampir semua database virus terkini (kecuali ClamAV) dengan nama-nama yang berbeda seperti Generic.bfr (McAfee), Agent2.ABFV (AVG), Worm.win32.VBNA.cc dll. Semua merujuk pada satu karakteristik varian dari trojan VBNA. Untuk menghapus trojan ini, hapuslah beberapa file berikut: %WINDIR%\SYSTEM32\lowsec\user.ds %WINDIR%\SYSTEM32\lowsec\local.ds [...]]]></description>
			<content:encoded><![CDATA[<p>Trojan VBNA atau Trojan Bancos, adalah trojan yang cukup berbahaya bagi sistem operasi Windows. Trojan ini dikenali oleh hampir semua database virus terkini (kecuali ClamAV) dengan nama-nama yang berbeda seperti Generic.bfr (McAfee), Agent2.ABFV (AVG), Worm.win32.VBNA.cc dll. Semua merujuk pada satu karakteristik varian dari trojan VBNA.</p>
<p>Untuk menghapus trojan ini, hapuslah beberapa file berikut:</p>
<ul>
<li>%WINDIR%\SYSTEM32\lowsec\user.ds</li>
</ul>
<ul>
<li>%WINDIR%\SYSTEM32\lowsec\local.ds<span id="more-5536"></span></li>
</ul>
<ul>
<li>%WINDIR%\SYSTEM32\sdra64.exe</li>
</ul>
<p>Hapus file tersebut dengan LiveCD Linux/Windows</p>
<p>Kemudian login Windows dan hapus registry yang terinfeksi dengan Regedit:</p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\USERINIT = %WINDIR%\SYSTEM32\userinit.exe,%WINDIR%\SYSTEM32\sdra64.exe,</li>
</ul>
<p>atau kalau tidak mau repot, silakan scan dengan McAfee SDAT terbaru.</p>
<p><strong>NB.</strong> Bagi kolektor dan pengembang antivirus, hash MD5 dari virus ini adalah 533564e5fb4cdaf57f9f09032584614cd97ac347, silakan tambahkan pada database antivirus anda!</p>
<strong>Hasil pencarian tentang artikel ini:</strong><p> <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="menghapus trojan">menghapus trojan</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="virus analisis">virus analisis</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="trojan hapus">trojan hapus</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="menghilangkan trojan">menghilangkan trojan</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="hapus trojan">hapus trojan</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="cara membersihkan virus trojan system32">cara membersihkan virus trojan system32</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="antivirus buat membersihkan trojan virus">antivirus buat membersihkan trojan virus</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="penjelasan tentang virus win32 genome">penjelasan tentang virus win32 genome</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="MENGHILANGKAN VIRUS TROJAN PADA SYSTEM32">MENGHILANGKAN VIRUS TROJAN PADA SYSTEM32</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="menghilangkan trojan pada script web">menghilangkan trojan pada script web</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="antivirus untuk membersihkan trojan system32">antivirus untuk membersihkan trojan system32</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="menghapus virus trojan tanpa menghapus file">menghapus virus trojan tanpa menghapus file</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="antivirus utk membersihkan trojan">antivirus utk membersihkan trojan</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="membersihkan Trojan Win32 Genome">membersihkan Trojan Win32 Genome</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/" title="bancos adalah">bancos adalah</a></p>]]></content:encoded>
			<wfw:commentRss>http://emka.web.id/computer-security/analisis-virus/2011/menghapus-trojan-vbna/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analisis virus Stuxnet</title>
		<link>http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/</link>
		<comments>http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/#comments</comments>
		<pubDate>Sat, 24 Jul 2010 10:25:38 +0000</pubDate>
		<dc:creator>Luthfi Emka</dc:creator>
				<category><![CDATA[Analisis Virus]]></category>
		<category><![CDATA[Analisis virus]]></category>
		<category><![CDATA[stuxnet]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://emka.web.id/?p=469</guid>
		<description><![CDATA[Tahun ini, Zero-day exploit diramaikan dengan perbincangan soal virus Stuxnet, virus yang spesifik menyerang software-software Industri (SCADA, WinCC, PCS 7 dari Siemens dll). Nah, berikut adalah hasil analisis sebuah sampel dari Stuxnet yang berhasil dianalisis dengan framework milik ThreatExpert. Nama alias: Malware.Stuxnet [PCTools], W32.Stuxnet [Symantec], Trojan-Dropper.Win32.Stuxnet.e [Kaspersky Lab], Stuxnet [McAfee], Troj/Stuxnet-A [Sophos], TrojanDropper:Win32/Stuxnet.A [Microsoft], Trojan-Dropper.Win32.Stuxnet [...]]]></description>
			<content:encoded><![CDATA[<p>Tahun ini, Zero-day exploit diramaikan dengan perbincangan soal virus Stuxnet, virus yang spesifik menyerang software-software Industri (SCADA, WinCC, PCS 7 dari Siemens dll). Nah, berikut adalah hasil analisis sebuah sampel dari Stuxnet yang berhasil dianalisis dengan framework milik ThreatExpert.</p>
<p><strong>Nama alias</strong>: Malware.Stuxnet [PCTools], W32.Stuxnet [Symantec], Trojan-Dropper.Win32.Stuxnet.e [Kaspersky Lab], Stuxnet [McAfee], Troj/Stuxnet-A [Sophos], TrojanDropper:Win32/Stuxnet.A [Microsoft], Trojan-Dropper.Win32.Stuxnet [Ikarus], Win-Trojan/Stuxnet.517632.F [AhnLab]<span id="more-469"></span></p>
<p><strong>Hasil MD5</strong>: 0xA2FEB4862A0E30E7AC1EF34505ACD356 (a2feb4862a0e30e7ac1ef34505acd356)<br />
<strong> Hasil SHA-1</strong>: 0xDC4B68CA78EDECBD94B2CB2501303D849FB605A5<br />
<strong> Ukuran</strong>: 517,632 bytes</p>
<p><strong>Level</strong>: High-risk</p>
<p><strong>Security-risk (Possible)</strong>:</p>
<ul>
<li>Worm yang menyebar ke seluruh bagian jaringan</li>
<li>Mungkin mengandung metode rootkit-spesifik ke sejumlah versi OS, software dan driver,</li>
</ul>
<p><strong>Membuat file-file berikut:</strong></p>
<ul>
<li>%Windir%\inf\mdmcpq3.PNF</li>
<li>%Windir%\inf\mdmeric3.PNF</li>
<li>%Windir%\inf\oem6C.PNF</li>
<li>%Windir%\inf\oem7A.PNF</li>
<li>%System%\drivers\mrxcls.sys</li>
<li>%System%\drivers\mrxnet.sys</li>
</ul>
<p><strong>Teknik Injeksi modul serupa Rootkit ke Kernel:</strong></p>
<ul>
<li>KERNEL32.DLL.ASLR.000241c5 (Process name: services.exe, Process filename: %System%\services.exe, Address space: 0xE50000 &#8211; 0xF88000)</li>
<li>KERNEL32.DLL.ASLR.000247cc (Process name: svchost.exe, Process filename: %System%\svchost.exe, Address space: 0x9D0000 &#8211; 0xB08000)</li>
<li>KERNEL32.DLL.ASLR.0002329f (Process name: svchost.exe, Process filename: %System%\svchost.exe, Address space: 0x24D0000 &#8211; 0&#215;2608000)</li>
</ul>
<p><strong>Membuat key baru di Registry Windows:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MRXCLS</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MRXCLS\0000</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MRXCLS\0000\Control</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MRXNET</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MRXNET\0000</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MRXNET\0000\Control</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MRxCls</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MRxCls\Enum</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MRxNet</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MRxNet\Enum</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MRXCLS</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MRXCLS\0000</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MRXCLS\0000\Control</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MRXNET</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MRXNET\0000</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MRXNET\0000\Control</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxCls</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxCls\Enum</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxNet</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxNet\Enum</li>
</ul>
<h3>Solusi membasmi Stuxnet</h3>
<p>Silakan update antivirus anda, minimal menggunakan vendor-vendor yang telah mengenali Virus ini (lihat bagian alias).</p>
<h3>Koleksi Hash</h3>
<p>Bagi yang ingin mengkoleksi hash dari virus ini berikut file yang dibuat (barangkali bermanfaat untuk dimasukkan ke antivirus buatan sendiri atau database ClamAV) ini adalah hash MD5 yang bisa anda tambahkan:</p>
<ul>
<li>9CD03CB160D20B686A0CE7AD2048C52A</li>
<li>B834EBEB777EA07FB6AAB6BF35CDF07F</li>
<li>AC64C5A7ED0D8C6C3A10FE584F2DCF90</li>
<li>AD19FBAA55E8AD585A97BBCDDCDE59D4</li>
<li>F8153747BAE8B4AE48837EE17172151E</li>
<li>CC1DB5360109DE3B857654297D262CA1</li>
<li>A2FEB4862A0E30E7AC1EF34505ACD356</li>
</ul>
<strong>Hasil pencarian tentang artikel ini:</strong><p> <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="virus stuxnet">virus stuxnet</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="anti virus stuxnet">anti virus stuxnet</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="membasmi stuxnet">membasmi stuxnet</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="hilangkan virus dorkbot">hilangkan virus dorkbot</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="membersihkan virus dorkbot">membersihkan virus dorkbot</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="menghapus virus dorkbot">menghapus virus dorkbot</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="menghapus virus dorkbot bx">menghapus virus dorkbot bx</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="nama virus yang menyerang scada">nama virus yang menyerang scada</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="software analisa virus">software analisa virus</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="-inurl: nama virus yang menyerang scada">-inurl: nama virus yang menyerang scada</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="makalah tentang virus stuxnet">makalah tentang virus stuxnet</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="database dorkbot bx untuk avg">database dorkbot bx untuk avg</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="cara meremove dorkbot bx">cara meremove dorkbot bx</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="apa nama virus yang menyerang scada ?">apa nama virus yang menyerang scada ?</a>, <a href="http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/" title="antivirus stuxnet">antivirus stuxnet</a></p>]]></content:encoded>
			<wfw:commentRss>http://emka.web.id/computer-security/analisis-virus/2010/analisis-virus-stuxnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

