wipe-deletion-erasure-purge


Net-Worm.Win32.Maslan.a

Net-Worm.Win32.Maslan.a

CyberScrub AntiVirus
Research Bank

This worm spreads via the Internet as an attachment to infected messages, and also via file-sharing networks.

It sends itself to all email addresses harvested from the infected computer. It also utilizes the LSASS and RPC DCOM vulnerabilities to spread. Information about these vulnerabilities can be found in Microsoft Security Bulletins MS04-011 and MS03-039 respectively.

The worm itself is a PE EXE file approximately 49KB in size, packed using FSG. The unpacked file is approximately 81KB in size.

The worm contains a backdoor function, which receives commands by IRC channels.

Installation

Once launched, the worm creates the following files in the Windows system directory:

%System%\___r.exe
%System%\___j.dll
%System%\___n.EXE
%System%\___t
%System%\___AlaMail
%System%\___AlaScan
%System%\___AlaDdos
%System%\___AlaFtp
%System%\___Prior
%System%\___e
%System%\___m
%System%\___m

It then registers itself in the system registry:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Windows DHCP" = "%System%\___r.exe" 
"Microsoft Synchronization Manager" = "___synmgr.exe"

Maslan.a also creates a unique identifier " ALAxALA" to flag its presence in the system. This ensures that only one copy of the worm will infect the system.

Propagation via email

The worm harvests email addresses from the Microsoft Outlook address book and also from files with the following extensions:

adb
asp
cfg
cgi
dbx
dhtm
eml
htm
jsp
mbx
mdx
mht
mmf
msg
nch
ods
oft
php
pl
sht
shtm
stm
tbb
txt
uin
wab
wsh
xls
xml

The worm does not send itself to addresses which contain the following text strings:

abuse 
acketst
anyone
arin.
avp
berkeley
borlan
bsd
bugs
ca
contact
example
feste
fido
foo.
fsf.
gnu
gold-certs
google
help
iana
ibm.com
ietf
info
inpris
isc.o
isi.e
kernel
linux
math
me
mit.e
mozilla
mydomai
mysql
no
nobody
nodomai
noone
not
nothing
page
panda
pgp
postmaster
privacy
rating
rfc-ed
ripe.
root
ruslis
samples
secur
sendmail
service
site
soft
somebody
someone
sopho
spam
spm
submit
syma
tanford.e
test
the.bat
unix
usenet
utgers.ed
webmaster
www
you
your

When sending infected emails, the worm attempts to establish a direct connection to recipient's SMTP servers.

Infected messages Sender (created from the following components

Name:

accoun
admin
Alan
Andrew
Angel
Anna
Arnold
Bernard
Carter
certific
Chris
Christian
Conor
Ghisler
Goldberg
Green
Helen
Ivan
Jackson
John
Kramer
Kutcher
listserv
Liza
Lopez
Mackye
Maria
Miller
Nelson
ntivi
Peter
Robert
Ruben
Sarah
Scott
Smith
Steven
subscribe

Sender's domain:

aol.com
freemail.com
hotmail.com
mail.com
msn.com
yahoo.com

Message subject:

123

Message body

Hello <random name>, 
--Best regards,
Attachment name
Playgirls2.exe
Payload

When using a file-sharing network to propagate, Maslan.a searches the hard disk for .exe files in directories with the following text in their names:

share 
upload 
downlo
setup
distr

It then replaces the original file with itself, and copies these files to a directory named ___b which it creates in the C:\ root.

The worm also attempts to delete a range of firewall and antivirus applications from the victim machine.

The worm also conducts DoS attacks on the following sites:

kavkazcenter.com
kavkazcenter.net
kavkazcenter.info
kavkaz.uk.com
kavkaz.org.uk
kavkaz.tv
chechenpress.com
chechenpress.info
Remote administration

The worm opens a random TCP port on the victim machine in order to receive commands via IRC.

Other

Maslan.a contains the following text string:

'Hah: Mydoom, Bagle, etc: since then you do not have future more!'

Check out if we have free removal tool for this virus


CyberScrub AntiVirus provides state of the art security protection for five years- at one low price. Our award winning technology ensures protection against viruses, worms and trojans backed by top customer support and value.

 
Five Year Cost Comparison
Product Initial Cost Yearly Subscription X Four Years Total
Norton 2004 AntiVirus $49.95* $29.95 $119.80 $169.75
McAfee VirusScan $49.95* $19.95 $79.80 $129.75
CyberScrub AntiVirus $49.95 Included No Additional Cost $49.95
*All prices MSRP as published on respective sites.




It is only a matter of time before a virus, worm or Trojan horse wrecks havoc on your important data. Important files, records, family pictures- all at risk. Some dangerous programs can even ruin your hard drive beyond repair.

CyberScrub AntiVirus offers the most effective protection from all known and unknown viruses.

CyberScrub AntiVirus is powered by a unique integrated technology for virus detection, based on principles of multi-generation heuristic analysis. This allows the program to protect you from suspect “viral behavior”. This highly effective methodology repelled all attacks of each “I LOVEYOU’ viral variation without any additional antivirus database updates. No other technology, including Norton, Trend, or McAfee was able to accomplish this.

CyberScrub AntiVirus is powerful, yet its exceptional ease of use and installation make it acceptable for beginner to pro



CyberScrub Antivirus constantly scans your hard drive and files to identify, clean and destroy infected objects. With updates available every three hours, 24 hours a day, 365 days a year, you can count on CyberScrub to protect your valued data.

CyberScrub AntiVirus
Lifetime Edition

"For the Life of Your Computer"

Save $10 Now!
Limited Time

 


Net-Worm.Win32.Maslan.a


Symantec Warns Of Flaw In Antivirus Program. More>>

CNN Legend Lynne Russell reports on CyberScrub AntiVirus for Tech Headline News.


















 
 

delete,deletion, file deletion, Internet clean up,privacy, HIPAA, Internet privacy, cookies, erase, erasure, shredder, wipe, overwrite, purge, deletion, security, file wipe, data destruction