Symantec

Symantec Security Response
http://securityresponse.symantec.com

W32.Gaobot.UM

Category 1
Discovered on: April 02, 2004
Last Updated on: April 04, 2004 10:18:26 AM


W32.Gaobot.UM is a variant of W32.Gaobot.gen. It attempts to spread through network shares that have weak passwords. It also allows attackers to access an infected computer through a predetermined IRC channel.

The worm uses multiple vulnerabilities to spread, including:


W32.Gaobot.UM is packed with ASPack.

Type: Worm
Infection Length: 90,112 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows XP
Systems Not Affected: Linux, Macintosh, UNIX, Windows 3.x

protection
  • Virus Definitions (Intelligent Updater) *
  • April 02, 2004

  • Virus Definitions (LiveUpdate™) **
  • April 04, 2004

    *

    Intelligent Updater definitions are released daily, but require manual download and installation.
    Click here to download manually.

    **

    LiveUpdate virus definitions are usually released every Wednesday.
    Click here for instructions on using LiveUpdate.

    threat assessment

    Wild:

    Threat Metrics

    Low Medium Medium

    Wild:
    Low

    Damage:
    Medium

    Distribution:
    Medium

    Damage

    Distribution

    technical details

    When W32.Gaobot.UL is executed, it performs the following actions:

    1. Copies and executes itself as %System%\Sysconf.exe.


      Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).


    2. Adds the value:

      "Video Process"="sysconf.exe"

      to the registry keys:
      • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
      • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
        RunServices

        so that the worm runs when you start Windows.

    3. Ends processes that are associated with antivirus and firewall software. Refer to "Processes" at the end of this section for a list of the process names.

    4. Attempts to end the following processes, which are associated with other worms:
      • taskmon.exe
      • bbeagle.exe
      • d3dupdate.exe
      • winsys.exe
      • ssate.exe
      • i11r54n4.exe
      • rate.exe
      • irun4.exe
      • Ssate.exe

    5. Appends the following lines to the infected computer's hosts file:

      127.0.0.1 www.trendmicro.com
      127.0.0.1 trendmicro.com127.0.0.1 rads.mcafee.com
      127.0.0.1 customer.symantec.com
      127.0.0.1 liveupdate.symantec.com
      127.0.0.1 us.mcafee.com
      127.0.0.1 updates.symantec.com
      127.0.0.1 update.symantec.com
      127.0.0.1 www.nai.com
      127.0.0.1 nai.com
      127.0.0.1 secure.nai.com
      127.0.0.1 dispatch.mcafee.com
      127.0.0.1 download.mcafee.com
      127.0.0.1 www.my-etrust.com
      127.0.0.1 my-etrust.com
      127.0.0.1 mast.mcafee.com
      127.0.0.1 ca.com
      127.0.0.1 www.ca.com
      127.0.0.1 networkassociates.com
      127.0.0.1 www.networkassociates.com
      127.0.0.1 avp.com
      127.0.0.1 www.kaspersky.com
      127.0.0.1 www.avp.com
      127.0.0.1 kaspersky.com
      127.0.0.1 www.f-secure.com
      127.0.0.1 f-secure.com
      127.0.0.1 viruslist.com
      127.0.0.1 www.viruslist.com
      127.0.0.1 liveupdate.symantecliveupdate.com
      127.0.0.1 mcafee.com
      127.0.0.1 www.mcafee.com
      127.0.0.1 sophos.com
      127.0.0.1 www.sophos.com
      127.0.0.1 symantec.com
      127.0.0.1 securityresponse.symantec.com
      127.0.0.1 www.symantec.com

    6. Connects to a predetermined IRC channel, using its own IRC client, and listens for commands. Some of the things that it can do are:
      • Take a screenshot of the system
      • Change the IRC server to which the worm connects
      • Force a connection to a specified IRC channel
      • Terminate the worm
      • Have the worm send messages to people or channels on IRC
      • Instruct the worm to send files from the system to the specified user over IRC (DCC Send)
      • Download and execute files
      • Steal system information
      • Harvest email addresses
      • Steal CD keys for various games
      • Connect to FTP servers to upload files
      • Terminate processes (other than those mentioned in step 4)
      • Connect to other systems using SSH
      • Run the worm as a SOCKS proxy server, making connections, which the attackers make, appear to come from the infected system.

    7. Attempts to spread to other computers by exploiting the following vulnerabilities:
    8. Probes the following shares:
    1. Copies itself to any computers it compromised using the above exploits.

    2. If you go to www.paypal.com, it tries to steal PayPal login information by logging keystrokes. The worm can also be instructed to steal login information for several AOL services, including AOL Instant Messenger service (AIM).

    Processes
    W32.Gaobot.UL attempts to end the following processes:

    recommendations

    Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

    removal instructions

    The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

    1. Disable System Restore (Windows Me/XP).
    2. Restart the computer in Safe mode or VGA mode.
    3. Restore the Hosts file.
    4. Reverse the changes made to the registry, and then restart the computer.
    5. Update the virus definitions.
    6. Run a full system scan and delete all the files detected as W32.Gaobot.UM.
    For details on each of these steps, read the following instructions.


    Before you begin:
    If you are running Windows NT/2000/XP, make sure that you do, or have done, the following:



    1. To disable System Restore (Windows Me/XP)
    If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

    Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

    Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

    For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:
    Note: When you are completely finished with the removal procedure and are satisfied that the threat has been removed, re-enable System Restore by following the instructions in the aforementioned documents.

    For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article, "Antivirus Tools Cannot Clean Infected Files in the _Restore Folder," Article ID: Q263455.

    2. To restart the computer in Safe mode or VGA mode
    Shut down the computer and turn off the power. Wait for at least 30 seconds, and then restart the computer in Safe mode or VGA mode.

    3. To restore the Windows Hosts file

    Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.

    Follow the instructions for your operating system:

    4. To reverse the changes made to the registry


    WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
    1. Click Start, and then click Run. (The Run dialog box appears.)
    2. Type regedit

      Then click OK. (The Registry Editor opens.)

    3. Navigate to the key:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    4. In the right pane, delete the value:

      "Video Process"="sysconf.exe"

    5. Do one of the following:
    6. Navigate to the key:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
      RunServices

    7. In the right pane, delete the value:

      "Video Process"="sysconf.exe"

    8. Exit the Registry Editor.

    9. Restart the computer in Normal mode. For instructions, read the section on returning to Normal mode in the document, "How to start the computer in Safe Mode."


    5. To update the virus definitions
    Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
    6. To scan for and delete the infected files
    1. Start your Symantec antivirus program and make sure that it is configured to scan all the files.
    2. Run a full system scan.
    3. If any files are detected as infected with W32.Gaobot.UM, click Delete.

    Revision History:

    April 4, 2004: Corrected LiveUpdate definition date.


    Write-up by: Fergal Ladley