Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

BACKDOOR.ZACCESS.AIU

 

 

Name:

Backdoor.ZAccess.aiu

Added:

November 22, 2011

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Malware problems?   We can help.  Free Removal Tools.

 

 

Description:

 

When Backdoor.ZAccess.aiu is executed, it performs the following activities:

After execution, Backdoor.ZAccess.aiu will replace a system driver (in the location %System%\drivers) with a copy of its rootkit driver. The Selection of what system driver to replace is done using an internal algorithm. Though it may avoid the following drivers: win32k.sys, ndis.sys. The rootkit will display the contents of the original system driver, presumably to hide its presence on the system.

Thirtyseven4 Antivirus detects the replaced file as RootKit.ZAccess.A

Backdoor.ZAccess.aiu will then create a hidden, encrypted volume that will be used to store the original system driver file that was replaced, as well as other component files used by it. The hidden volume has the following format inside the %Windir% directory:

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

It also creates a zero byte Alternate Data Stream file in %WINDIR%\{numbers_only_file} that will be silently executed and run in the background:

%Windir%\<Randamnumbers:Randamnumbers.exe> (3174600136:930268994.exe)

The Backdoor starts to create a hidden process  <Randamnumbers:Randamnumbers.exe> (3174600136:930268994.exe)

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

This ADS is disguised as a normal file on the disk but whenever accessed it will trigger the rootkit protection routine.

Note : An ADS is an NTFS structure that allows more than one data stream to be associated with a file. These ADSs are accessed by a file name like filename.ext:adsname. Whenever the ADS file or the process in memory is accessed by a security tool, the rootkit kernel component will kill the process from the kernel.

It modifies/creates the following registry entry:

ImagePath = "%Windir%\<Randamnumbers:Randamnumbers.exe> (3988143203:2630043922.exe)"
HKLM\System\CurrentControlSet\Services\f6dcfecc

Backdoors provide the author with remote-administration of the victim machines. They can be instructed to send, receive, execute and delete files, harvest confidential data from the computer, log activity on the computer and more.

This Backdoor opens a back door by contacting a Command and Control server on port 22292 or 80. The IP address of the server may be one of the following:

122.XXX.123.105
70.42.XXX.174
64.XXX.172.200

It may also send requests to the following URL:

http://dlmcdXXX.cn/stXXX.php?w=40&i=392af8440000000048d0c62..

http://dlmcXXX.cn/stXXX.php?w=40&i=392af8440000000048d0c627..

http://dlmcdXXX.cn/stXXX.php?w=40&i=392af8440000000048d0c62..

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4