Trojan horse (Worm) Fred Cohen, Dean Dennis Michael shain
RAM
CIH Loveletter Sircam CodeRedII Nimda Klez Mylife VBS/Redolf
Loveletter
Code Red
Nimda
Klez.E
Mylife.A *.sys, *.com (from C:\ folder) *.com, *.sys, *.ini, *.exe (from Windows folder) *.sys, *.vxd, *.exe, *.dll (from Windows System folder)
JAVA ActiveX
c:\windows> cd\recycled c:\recycled>attrib r -h sirc32.exe c:\recycled>del sirc32.exe c:\recycled>cd.. c:\>cd windows c:\windows>attrib -r -h scam32.exe c:\windows>del scam32.exe
1 http://www.microsoft.com/technet/security/bulletin/ms01-033.asp Code Red http://www.microsoft.com/technet/security/bulletin/ms00-052.asp windows explorer.exe 2 3 '\inetpub\scripts\root.exe' '\progra~1\common~1\system\msadc\root.exe' '\explorer.exe' 4 'SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\Virtual Roots\C' 'SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\Virtual Roots\D' 5 217 'SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\Virtual Roots\Scripts' 'SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\Virtual Roots\MSADC'
http://www.microsoft.com/technet/security/bulletin/ms01-020.asp http://www.microsoft.com/technet/security/bulletin/ms00-078.asp Riched20.DLL System load.exe 57344 System.ini shell=explorer.exe load.exe-dontrunold shell=explorer.exe C:\ D:\ E:\ Admin.DLL \documents and settings\username\local settings\temp \Windows\Temp.tmp
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Network\LanMan\ HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\MapMail\ Administrator guest / Readme.eml <iframe src=3dcid:ea4dmgbp9p height=3d0 width=3d0></iframe> <scriptlanguage="javascript">window.open("readme.eml",null,"resizable=n o,top=6000,left=6000")</script>
WQK.exe Krn132.exe Regedit KEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun WINDOWSSYSTEMKRN132.EXE INDOWSSYSTEMWQK.EXE dos REGEDIT KEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun WINDOWSSYSTEMKRN132.EXE INDOWSSYSTEMWQK.EXE Sp2 IE6.0
VBS/Redolf VBS/Redolf HappyTime VBScript html htm jsp vbs php asp desktop.ini folder.htt indows\web indowsystem32 kjwall.gif Windows 9X indows\system Kernel.dll Windows 2000/XP Kernel32.dll htt html/htm jsp vbs php asp HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\R un\ Kernel32 HKEY_CLASSES_ROOT\dllFile\ HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Options\Mail Outlook 2000