W32/Kassbot-J is a network worm with backdoor component.
When run the worm will copy itself to the Windows system folder as spools.exe.
W32/Kassbot-J will set the following registry entry in order to run automatically each time a user logs in:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Spools Service Controller
<System>\spools.exe
W32/Kassbot-J will send an email to a pre-defined email address containing system information from the infected computer.
W32/Kassbot-J will attempt to spread by exploiting the following
vulnerabilities:
LSASS (MS04-011 ).
W32/Kassbot-J will connect to an IRC server and provide backdoor access to the
infected computer.
W32/Kassbot-J will append the following lines to the HOSTS file in an attempt toredirect access from anti-virus and related websites:
17.145.117.11 d-ru-1f.kaspersky-labs.com
17.145.117.11 d-ru-1h.kaspersky-labs.com
17.145.117.11 d-ru-2f.kaspersky-labs.com
17.145.117.11 d-ru-2h.kaspersky-labs.com
17.145.117.11 d-eu-2f.kaspersky-labs.com
17.145.117.11 d-eu-2h.kaspersky-labs.com
17.145.117.11 d-eu-1f.kaspersky-labs.com
17.145.117.11 d-eu-1h.kaspersky-labs.com
17.145.117.11 d-us-1f.kaspersky-labs.com
17.145.117.11 d-us-1h.kaspersky-labs.com
17.145.117.11 downloads1.kaspersky.ru
17.145.117.11 downloads2.kaspersky.ru
17.145.117.11 downloads3.kaspersky.ru
17.145.117.11 downloads4.kaspersky.ru
17.145.117.11 downloads5.kaspersky.ru