Computing.Net > Forums > Security and Virus > NEW Worm

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

NEW Worm

Reply to Message Icon

Name: TIM
Date: November 6, 2002 at 13:50:39 Pacific
OS: :O[
CPU/Ram: :O[
Comment:

. Network Worm "Roron" - Red Alert!
Kaspersky Labs, an international data security software developer,
reports the appearance of a new network worm named "Roron", constructed
in Bulgaria. Presently six variations of the worm have already been
detected and have been credited with infecting computers in many regions
including the U.S.A., Russia and a slew of European countries.

Destructive functions and features include a built-in back-door intended
for unsanctioned remote control of victim computers and the ability to
spread via many communication channels - all of which places this worm
in an especially high danger category.

"Roron" spreads using several data transfer channels: via email as an
attached file, via local area networks and the KaZaA file-sharing
network. Systems become infected only if a user manually launches
(opens) the file containing the worm that was received via one of the
aforementioned sources. When penetrating a computer, "Roron" creates a
copy of itself in the Windows system directory and Program Files and
then registers one of these files in the system registry's auto-run key.
In this way the worm ensures its activation the each time the system is
booted. Sometimes, when infecting, the worm displays a false warning:


WinZip Self-Extractor License Confirmation

Your version of WinZip Self-Extractor is not licensed, or the license
information is missing or corrupted. Please contact the program vendor
or the web site (www.WinZip.com) for additional information.


After the infection routine is complete, "Roron" activates its spreading
routines:

- To spread via e-mail it clandestinely creates a message that
may have different subjects, texts and attached file names. Then it
sends this message to the recipients whose adresses it found in the
InBox folder of the infected computer.
- To spread via local area networks the worm searches available network
resources, allocates those having file-sharing resources and copies itself
under a random name. This way "Roron" may spawn its copies to the public file
servers that may lead other network users to download these files and infect
their own machines.
- To spread via the KaZaA network the worm searches for KaZaA file-sharing
folders where it inserts its copy, thus making it available for download by
other KaZaA users.

"Roron" carries a very impressive armory of extremely dangerous payload and
backdoor functions. In case the infected computer has a mIRC client installed
(software used to access Internet Relay Chat (IRC) channels) the worm infects
it with a backdoor component. This allows a mal-intended person to gain
unauthorized remote control over the infected computer: unnoticed a
malefactor can download, upload, execute files, send out e-mail messages
on behalf of the user, etc. The backdoor component also carries a
feature for performing DoS-attacks (Denial of Service) from the infected
computer launched against other computers specified by the hacker.
Therefore, if "Roron" causes a global outbreak infecting a high number
of systems such as Tanatos (BugBear) or Lentin (Yaha), it may enable
hackers to perform massive distributed DoS-attacks even more powerful
than the huge attack occurring two weeks ago when 13 Internet "backbone"
servers were attacked, ultimately bringing nine of them temporarily
down.

"Roron" also destroys data stored on hard drives. This payload is
activated when at least one of the following conditions is fulfilled:

- the current system date is the 9th or 19th (regardless of the current
month)
- one of the worm's core components is deleted (WINFILE.DLL)
- the worm's Windows system registry keys are deleted
- randomly, depending on the worm's internal counter

"Roron" also searches for some anti-virus software programs in the operating
memory and deactivates them. In addition the worm tries to delete this anti-
virus software from the hard drive.



Sponsored Link
Ads by Google

Response Number 1
Name: WhoDunnit
Date: November 6, 2002 at 13:53:53 Pacific
Reply:

Excellent post...thank you very much. This information will indeed prove valuable to those who are on constant gaurd for these threats. Thanks again Tim

WhoDunnit


0

Response Number 2
Name: Norm
Date: November 6, 2002 at 15:41:14 Pacific
Reply:
0

Response Number 3
Name: capt
Date: November 6, 2002 at 17:50:12 Pacific
Reply:

Thanks Tim, sounds like some more fun, especially for the unwary Kazaa users! All the best!


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: NEW Worm

new worm www.computing.net/answers/security/new-worm/3045.html

Symantec Creates New Worm Simulat. www.computing.net/answers/security/symantec-creates-new-worm-simulat/15779.html

New Worm Lurking www.computing.net/answers/security/new-worm-lurking/6448.html