Proaktiv IT sikkerhed
 Startside  Nyheder  Produkt & tjenester  Virus & sikkerhed  Support  Download  Forhandlere  Køb
Vælg land
Vælg produkt
W32/Ryknos.A Destructivity: Medium Spreading: None Overall risk: Low
Detected by virus detection files published: 10 Nov. 2005
Virus characteristics first published: 10 Nov. 2005
Virus characteristics latest update: 28 Nov. 2005
Type: Backdoor
Alias: Win32.Ryknos.A, Backdoor.Breplibot.B,Troj/Stinx-E
Spreading mechanism:
Overall risk: Low
Payload: Gives unauthorized access to computer.
Type Spreading mechanism Destructivity & payload Additional descriptions Detection & removal

This is a backdoor trojan. File size is 10240 bytes. It is very closely related to the Breplibot series of backdoors. It is extremely buggy, and many of its features will not work. The trojan copies itself to the System directory, where it will attempt to use the same file name as one of the components used by the First 4 Internet Digital Rights Management software. This can in certain settings hide the presence of this backdoor on the system.

The backdoor will attempt to add itself as a trusted process with the Windows Firewall.

File system changes:

Creates file <SYSTEMDIR>\$sys$drv.exe

Registry changes:

Creates key "HKCU\Software\WkbpsevaXImgvkwkbpXSmj`kswXGqvvajpRavwmkjXVqj "$sys$drv"="$sys$drv.exe"
Creates key "HKLM\Software\WkbpsevaXImgvkwkbpXSmj`kswXGqvvajpRavwmkjXVqj "$sys$drv"="$sys$drv.exe"

The mangled registry keys is another example of bugs in the code. These keys will not autostart the backdoor from bootup.


 It will create the mutex "$sys$drv.exe" if installed correctly.

 

VIRUSADVARSLER
Medium risk
24 Oct 07 Pidief.A
24 Jan 07 Tibs
25 Sep 06 Stration
18 Jan 06 Small.KI
12 Sep 05 Bagle.CS
17 Aug 05 Zotob.B
08 Jun 05 Mytob
17 Feb 05 MyDoom.AQ
26 Jul 04 MyDoom.L
25 Mar 04 Netsky.P
Low risk
05 Mar 07 Viking.GT
27 Jan 06 Feebs
16 Jan 05 MyDoom.AH
22 Apr 04 SDBot
30 Mar 04 Netsky.Q
Frigivelsesdato for seneste definitionsfiler
2008-07-18

Norman er en af verdens ledende virksomheder indenfor datasikkerhed. Med produkter som antivirus, personlig firewall og antispam, spiller Norman en vigtig rolle i dagens dataindustri.