W32/Kassbot-J

Category: Viruses and Spyware
Type: Win32 worm
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Kassbot-J is a network worm with backdoor component.

When run the worm will copy itself to the Windows system folder as spools.exe.

W32/Kassbot-J will set the following registry entry in order to run automatically each time a user logs in:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Spools Service Controller
<System>\spools.exe

W32/Kassbot-J will send an email to a pre-defined email address containing system information from the infected computer.

W32/Kassbot-J will attempt to spread by exploiting the following
vulnerabilities:

LSASS (MS04-011 ).

W32/Kassbot-J will connect to an IRC server and provide backdoor access to the
infected computer.

W32/Kassbot-J will append the following lines to the HOSTS file in an attempt toredirect access from anti-virus and related websites:

17.145.117.11 d-ru-1f.kaspersky-labs.com
17.145.117.11 d-ru-1h.kaspersky-labs.com
17.145.117.11 d-ru-2f.kaspersky-labs.com
17.145.117.11 d-ru-2h.kaspersky-labs.com
17.145.117.11 d-eu-2f.kaspersky-labs.com
17.145.117.11 d-eu-2h.kaspersky-labs.com
17.145.117.11 d-eu-1f.kaspersky-labs.com
17.145.117.11 d-eu-1h.kaspersky-labs.com
17.145.117.11 d-us-1f.kaspersky-labs.com
17.145.117.11 d-us-1h.kaspersky-labs.com
17.145.117.11 downloads1.kaspersky.ru
17.145.117.11 downloads2.kaspersky.ru
17.145.117.11 downloads3.kaspersky.ru
17.145.117.11 downloads4.kaspersky.ru
17.145.117.11 downloads5.kaspersky.ru

download Try Sophos products for free
Download now