Sophos

W32/Kassbot-J

Aliases
  • Backdoor.Win32.Nanspy.b
  • BackDoor-CPV
  • W32.Kassbot
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 6 October 2005 20:33:12 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Kassbot-J is a network worm with backdoor component.

When run the worm will copy itself to the Windows system folder as spools.exe.

W32/Kassbot-J will set the following registry entry in order to run automatically each time a user logs in:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Spools Service Controller
<System>\spools.exe

W32/Kassbot-J will send an email to a pre-defined email address containing system information from the infected computer.

W32/Kassbot-J will attempt to spread by exploiting the following
vulnerabilities:

LSASS (MS04-011 ).

W32/Kassbot-J will connect to an IRC server and provide backdoor access to the
infected computer.

W32/Kassbot-J will append the following lines to the HOSTS file in an attempt toredirect access from anti-virus and related websites:

17.145.117.11 d-ru-1f.kaspersky-labs.com
17.145.117.11 d-ru-1h.kaspersky-labs.com
17.145.117.11 d-ru-2f.kaspersky-labs.com
17.145.117.11 d-ru-2h.kaspersky-labs.com
17.145.117.11 d-eu-2f.kaspersky-labs.com
17.145.117.11 d-eu-2h.kaspersky-labs.com
17.145.117.11 d-eu-1f.kaspersky-labs.com
17.145.117.11 d-eu-1h.kaspersky-labs.com
17.145.117.11 d-us-1f.kaspersky-labs.com
17.145.117.11 d-us-1h.kaspersky-labs.com
17.145.117.11 downloads1.kaspersky.ru
17.145.117.11 downloads2.kaspersky.ru
17.145.117.11 downloads3.kaspersky.ru
17.145.117.11 downloads4.kaspersky.ru
17.145.117.11 downloads5.kaspersky.ru

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer