DiMan Forums

Knowledge Management and Collaboration Platform
Welcome to DiMan Forums Sign in | Join | Help
in
Home Blogs Forums Photos Files Reader Roller

Viruses

Win32/Fantibag.U

Description Published: Monday, March 06, 2006
Description Modified: Wednesday, March 08, 2006

Characteristics

Type: Trojan
Category: Win32
Also known as Win32.Fantibag.U, Win32/Glieder.DH!Trojan, Trojan.Tooso (Symantec), Email-Worm.Win32.Bagle.fu (Kaspersky)
Description
Win32.Fantibag.U is a trojan that creates filters for IPv4 packets to block access to many and varied antivirus company domains. It has been dropped as a 19,456-byte Win32 executable by Win32/Bagdrop.H.

Method of Infection
When the main executable is launched it drops the following file:

%System%\mloader32.dll (size: 16,384 bytes)

It makes the following modifications to the registry to install "mloader32.dll" as a Winlogon Notification Package:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mloader32\Asynchronous = 0x0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mloader32\DllName = "mloader32.dll"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mloader32\Impersonate = 0x0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mloader32\Startup = "Startup"

Note: '%System%' is a variable location. The malware determines the location of the current System folder by querying the operating system. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; and for XP is C:\Windows\System32.

Payload

Modifies Network Behavior

Win32.Fantibag.U contains a list of over 150 antivirus-related domain names, presumably in order to stop users from visiting websites or downloading scanner updates from these domains. The trojan accomplishes this by creating both input and output filters to drop all packets between the user's machine and any of the filtered IP addresses.

For each of the specified domain names, a DNS lookup is performed. Win32.Fantibag then creates filters for each IP address within the same class C (255.255.255.0) network. Antivirus companies targeted include Computer Associates, McAfee, Sophos, Kaspersky, F-Secure, Trend etc.

Terminates Processes

The DLL component ("winlog.dll") attempts to kills the following processes (associated with antivirus and other security-related applications):

_AVP32.EXE
_AVPCC.EXE
_AVPM.EXE
AckWin32.exe
ALERTSVC.EXE
ALOGSERV.EXE
Anti-Trojan.exe
ANTS.EXE
APVXDWIN.EXE
ashAvast.exe
ashDisp.exe
ashEnhcd.exe
ashMaiSv.exe
ashPopWz.exe
ashServ.exe
ashSimpl.exe
ashSkPck.exe
ashWebSv.exe
aswUpdSv.exe
ATCON.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
Avconsol.exe
AVENGINE.EXE
avgcc.exe
AVGCC32.EXE
AVGCTRL.EXE
avgemc.exe
AVGNT.EXE
AVGSERV.EXE
AVGUARD.EXE
AvkServ.exe
AVP.EXE
AVP32.EXE
avpcc.exe
avpm.exe
AVPUPD.EXE
AVSCHED32.EXE
avsynmgr.exe
AVWUPD32.EXE
AVWUPSRV.EXE
AVXMONITOR9X.EXE
AVXMONITORNT.EXE
AVXQUAR.EXE
BackWeb-4476822.exe
bdmcon.exe
bdnews.exe
bdsubmit.exe
bdswitch.exe
blackd.exe
blackice.exe
cafix.exe
ccApp.exe
ccEvtMgr.exe
ccProxy.exe
ccSetMgr.exe
CFIAUDIT.EXE
ClamTray.exe
ClamWin.exe
Claw95.exe
Claw95cf.exe
cleaner.exe
cleaner3.exe
CliSvc.exe
CMGrdian.exe
cpd.exe
DefWatch.exe
DOORS.EXE
DrVirus.exe
drwadins.exe
drweb32w.exe
drwebscd.exe
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
F-AGNT95.EXE
F-PROT95.EXE
F-StopW.EXE
FAMEH32.EXE
FAST.EXE
FCH32.EXE
FIREWALL.EXE
fpavupdm.exe
freshclam.exe
FRW.EXE
fsav32.exe
fsavgui.exe
fsbwsys.exe
fsdfwd.exe
FSGK32.EXE
fsgk32st.exe
fsguiexe.exe
FSM32.EXE
FSMA32.EXE
FSMB32.EXE
fspex.exe
fssm32.exe
gcasDtServ.exe
gcasServ.exe
GUARD.EXE
GUARDGUI.EXE
GuardNT.exe
iamapp.exe
iamserv.exe
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFACE.EXE
INETUPD.EXE
InocIT.exe
InoRpc.exe
InoRT.exe
InoTask.exe
InoUpTNG.exe
IOMON98.EXE
isafe.exe
ISRV95.EXE
ISSVC.exe
JEDI.EXE
KAV.exe
kavmm.exe
KAVPF.exe
LOCKDOWN2000.EXE
LogWatNT.exe
LUALL.EXE
LUCOMSERVER.EXE
Luupdate.exe
MCAGENT.EXE
Mcshield.exe
MCUPDATE.EXE
MINILOG.EXE
MONITOR.EXE
MonSysNT.exe
MOOLIVE.EXE
navapsvc.exe
NAVAPW32.EXE
NavLu32.exe
NAVW32.EXE
NDD32.EXE
NeoWatchLog.exe
NeoWatchTray.exe
NISSERV
NISUM.EXE
NMAIN.EXE
nod32.exe
nod32kui.exe
NORMIST.EXE
notstart.exe
NPFMNTOR.EXE
npfmsg.exe
NPROTECT.EXE
NSCHED32.EXE
NTXconfig.exe
NUPGRADE.EXE
NVC95.EXE
Nvcod.exe
Nvcte.exe
Nvcut.exe
NWService.exe
OUTPOST.EXE
PAV.EXE
PavFires.exe
pavProxy.exe
pavsrv51.exe
PAVSS.EXE
pccguide.exe
PCCIOMON.EXE
PcCtlCom.exe
PERSFW.EXE
pertsk.exe
PERVAC.EXE
POP3TRAP.EXE
POPROXY.EXE
QHPF.EXE
Realmon.exe
REALMON95.EXE
Rescue.exe
Rtvscan.exe
RTVSCN95.EXE
RuLaunch.exe
SAVScan.exe
SERVIC~1.EXE
SiteCli.exe
smc.exe
SNDSrvc.exe
SPBBCSvc.exe
SPHINX.EXE
spiderml.exe
Spiderui.exe
SpybotSD.exe
SPYXX.EXE
SS3EDIT.EXE
SWNETSUP.EXE
symlcsvc.exe
SymProxySvc.exe
SymSPort.exe
SymWSC.exe
SYNMGR.EXE
TAUMON.EXE
TC.EXE
tca.exe
TCM.EXE
TDS-3.EXE
TeaTimer.exe
TFAK.EXE
Tmas.exe
Tmntsrv.exe
TmPfw.exe
tmproxy.exe
TNBUtil.exe
TRJSCAN.EXE
Up2Date.exe
UPDATE.EXE
upgrepl.exe
Vba32ECM.exe
Vba32ifs.exe
vba32ldr.exe
Vba32PP3.exe
vcrmon.exe
VetTray.exe
VPTRAY.EXE
vrfwsvc.exe
VRMONNT.EXE
vrmonsvc.exe
VSECOMR.EXE
Vshwin32.exe
vsmon.exe
VsStat.exe
WATCHDOG.EXE
Webscanx.exe
WEBTRAP.EXE
WGFE95.EXE
Winaw32.exe
WRADMIN.EXE
WRCTRL.EXE
zatutor.exe
ZAUINST.EXE
zlclient.exe
zonealarm.exe

Stops and Disables Services

Win32.Fantibag.U attempts to stop, then disable the following services:

Ahnlab task Scheduler
alerter
AlertManger
AntiVir Service
aswUpdSv
Ati HotKey Poller
avast! Antivirus
AVEService
AVExch32Service
avg7alrt
avg7updsvc
AvgCore
AvgFsh
AvgServ
AVIRAMailService
AVIRAService
avpcc
AVUPDService
AVWUpSrv
AvxIni
awhost32
backweb client - 4476822
BackWeb Client - 7681197
backweb client-4476822
bdss
BlackICE
CAISafe
ccEvtMgr
ccPwdSvc
ccSetMgr
ccSetMgr.exe
DefWatch
dvpapi
dvpinit
F-Secure Gatekeeper Handler Starter
fsbwsys
fsdfwd
FSMA
Guard NT
InoRpc
InoRT
InoTask
KAVMonitorService
kavsvc
KLBLMain
McAfee Firewall
McAfeeFramework
McShield
McTaskManager
mcupdmgr.exe
MCVSRte
MonSvcNT
navapsvc
Network Associates Log Service
nipsvc
NISSERV
NISUM
NOD32ControlCenter
NOD32Service
Norman NJeeves
Norman Type-R
Norman ZANDA
Norton Antivirus Server
NPFMntor
NProtectService
NSCTOP
nvcoas
NVCScheduler
nwclntc
nwclntd
nwclnte
nwclntf
nwclntg
nwclnth
NWService
Outbreak Manager
Outpost Firewall
OutpostFirewall
PASSRV
PAVFNSVR
Pavkre
PavProt
PavPrSrv
PAVSRV
PCCPFW
PersFW
PREVSRV
PSIMSVC
ravmon8
SAVFMSE
SAVScan
SBService
schscnt
SharedAccess
SmcService
SNDSrvc
SPBBCSvc
SpiderNT
SweepNet
SWEEPSRV.SYS
Symantec AntiVirus Client
Symantec Core LC
Tmntsrv
V3MonNT
V3MonSvc
Vba32ECM
Vba32ifs
Vba32Ldr
Vba32PP3
VexiraAntivirus
VisNetic AntiVirus Plug-in
vsmon
vsserv
wuauserv
xcomm

Modifies System Settings/Lowers Security Settings

Fantibag.U attempts to delete the following registry values if they exist:

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\McAfee.InstantUpdate.Monitor
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\APVXDWIN
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\KAV50
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\McAfee Guardian
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NAV CfgWiz
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SSC_UserPrompt
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Symantec NetDriver Monitor
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Zone Labs Client
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\avg7_cc
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\avg7_emc
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ccApp

as well as the following registry keys:

HKLM\SOFTWARE\Agnitum
HKLM\SOFTWARE\KasperskyLab
HKLM\SOFTWARE\McAfee
HKLM\SOFTWARE\Panda Software
HKLM\SOFTWARE\Symantec
HKLM\SOFTWARE\Zone Labs
HKLM\SOFTWARE\Trend Micro

Fantibag.U searches fixed drives for the following files and attempts to delete them. If the file cannot be deleted it then tries to rename them. The new file name is listed in the corresponding right hand column for each entry of the following list:

ashAvast.exe
ashDisp.exe
ashEnhcd.exe
ashPopWz.exe
ashShA64.dll
ashSimpl.exe
ashSkPck.exe
ashWebSv.exe
AUPDATE.EXE
Avconsol.exe
avgcc.exe
AVGCMSG.DLL
avgemc.exe
AVGNT.EXE
AVSCHED32.DLL
AVSCHED32.EXE
Avsynmgr.exe
AVWUPD32.EXE
BCGCB59.dll
bdmcon.exe
bdnews.exe
bdsubmit.exe
bdswitch.exe
cafix.exe
ccApp.exe
CCEVTMGR.EXE
ccl30.dll
CCSETMGR.EXE
ccvrtrst.dll
ClamTray.exe
ClamWin.exe
CMGrdian.exe
D2htls32.dll
drwadins.exe
drweb32w.exe
drwebscd.exe
drwebupw.exe
FFJMPWEB.DLL
freshclam.exe
GUARDEVT.DLL
GUARDGUI.EXE
GUARDMSG.DLL
GuardNT.exe
IksysT32.dll
INETUPD.EXE
InocIT.exe
InoOEM.dll
InoOption.dll
InoUpTNG.exe
isafe.exe
KAV.exe
kavmm.exe
KAVPF.exe
LUALL.EXE
LUINSDLL.DLL
Luupdate.exe
Mcshield.exe
NAVAPSVC.EXE
nod32.exe
nod32api.dll
nod32kui.exe
NPFMNTOR.EXE
npfmsg.exe
Nvccf0D.dll
Nvcevlog.dll
Nvcod.exe
Nvcte.exe
Nvcut.exe
OCONNDLG.DLL
OCOOKDLG.DLL
outpost.exe
pccguide.exe
PcCtlCom.exe
python23.dll
QHPF.EXE
Realmon.exe
RuLaunch.exe
schface.dll
SNDSrvc.exe
SPBBCSvc.exe
spiderml.exe
symlcsvc.exe
T2w32.dll
Tmntsrv.exe
TmPfw.exe
tmproxy.exe
Up2Date.exe
upgrepl.exe
Vba32ECM.exe
Vba32ifs.exe
vba32ldr.exe
Vba32PP3.exe
vbaifps.dll
vetredir.dll
Vshwin32.exe
VsStat.exe
vsvault.dll
XT1922.dll
zatutor.exe
zlavscan.dll
zlclient.exe
zonealarm.exe
1ashAvast.exe
1ashDisp.exe
1ashEnhcd.exe
1ashPopWz.exe
1ashShA64.dll
1ashSimpl.exe
1ashSkPck.exe
1ashWebSv.exe
1AUPDATE.EXE 
1Avconsol.exe
1avgcc.exe   
1AVGCMSG.DLL
1avgemc.exe  
1AVGNT.EXE   
1AVSCHED32.DLL
1AVSCHED32.EXE
1Avsynmgr.exe
1AVWUPD32.EXE
1BCGCB59.dll 
1bdmcon.exe  
1bdnews.exe  
1bdsubmit.exe
1bdswitch.exe
1cafix.exe   
1ccApp.exe   
1CCEVTMGR.EXE
1ccl30.dll   
1CCSETMGR.EXE
1ccvrtrst.dll
1ClamTray.exe
1ClamWin.exe 
1CMGrdian.exe
1D2htls32.dll
1drwadins.exe
1drweb32w.exe
1drwebscd.exe
1drwebupw.exe
1FFJMPWEB.DLL
1freshclam.exe
1GUARDEVT.DLL
1GUARDGUI.EXE
1GUARDMSG.DLL
1GuardNT.exe 
1IksysT32.dll
1INETUPD.EXE 
1InocIT.exe  
1InoOEM.dll  
1InoOption.dll
1InoUpTNG.exe
1isafe.exe   
1KAV.exe     
1kavmm.exe   
1KAVPF.exe   
1LUALL.EXE   
1LUINSDLL.DLL
1Luupdate.exe
1Mcshield.exe
1NAVAPSVC.EXE
1nod32.exe   
1nod32api.dll
1nod32kui.exe
1NPFMNTOR.EXE
1npfmsg.exe  
1Nvccf0D.dll 
1Nvcevlog.dll
1Nvcod.exe   
1Nvcte.exe   
1Nvcut.exe   
1OCONNDLG.DLL
1OCOOKDLG.DLL
1outpost.exe 
1pccguide.exe
1PcCtlCom.exe
1python23.dll
1QHPF.EXE    
1Realmon.exe
1RuLaunch.exe
1schface.dll 
S1NDSrvc.exe 
S1PBBCSvc.exe
s1piderml.exe
s1ymlcsvc.exe
T12w32.dll   
T1mntsrv.exe 
Tm1Pfw.exe   
tm1proxy.exe 
U1p2Date.exe 
u1pgrepl.exe 
V1ba32ECM.exe
V1ba32ifs.exe
v1ba32ldr.exe
V1ba32PP3.exe
vb1aifps.dll 
v1etredir.dll
Vs1hwin32.exe
Vs1Stat.exe  
vs1vault.dll 
XT11922.dll  
za1tutor.exe 
zla1vscan.dll
zl1client.exe
zo1nealarm.exe

Published Wednesday, March 08, 2006 1:55 PM by bud

Comments

No Comments
Anonymous comments are disabled

This Blog

Post Calendar

<March 2006>
SuMoTuWeThFrSa
2627281234
567891011
12131415161718
19202122232425
2627282930311
2345678

Syndication

Powered by Community Server, by Telligent Systems