Content
W32/Graps.worm
- Type
- Virus
- SubType
- Internet Worm
- Discovery Date
- 07/07/2003
- Length
- 53,248 bytes
- Minimum DAT
- 4276 (07/09/2003)
- Updated DAT
- 4655 (12/21/2005)
- Minimum Engine
- 5.1.00
- Description Added
- 07/07/2003
- Description Modified
- 03/17/2004 6:49 AM (PT)
Tab Navigation
Characteristics
This is a remote access trojan, and share jumping worm. It propagates via the default administrator share, admin$. When run, the worm creates a registry run key to load itself at system startup:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "Windows Management Instrumentation" = %worm path%\mwd.exe
- wds.bat
- wds2.bat
- wds3.bat
- mwd.exe (a copy of the worm)
- psexec.exe (RemoteProcessLaunch application)
- mswinsk.ocx (innocent Microsoft Winsock Control DLL)
The worm scan scans the local class a subnet (#.*.*.*) for target systems. The worm creates a remote access server by listening on TCP port 45836. This server allows a remote attacker to perform the following tasks:
- Retrieve the following information
- Uptime
- Download speed
- CPU information
- RAM
- Disk Usage
- Specify a target IP address to ICMP/HTTP flood
- Download/execute files
- Internet Relay Chat (IRC) functions
- IP Port Redirection (to create proxies)
Symptoms
Compromised system attempting to connect to the following addresses
- frozenhighlands.skiebus.com
- frozenhighlands.rock-slides.com
- jjljsmlmjo.no-ip.com
- llqrlmspmm.dyndns.org
- qplfdempqo.dyndns.org
Method of Infection
This worm spreads via the ADMIN$ share on Windows NT/2K/XP systems.
Removal
All Users:
Use specified engine and DAT files for detection and removal of virus and trojan files related to this threat.
- net share c$ /delete
- net share d$ /delete
- net share e$ /delete
- net share ipc$ /delete
- net share admin$ /delete
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Aliases
- W32/Graps.bat
Characteristics
Characteristics -
This is a remote access trojan, and share jumping worm. It propagates via the default administrator share, admin$. When run, the worm creates a registry run key to load itself at system startup:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "Windows Management Instrumentation" = %worm path%\mwd.exe
- wds.bat
- wds2.bat
- wds3.bat
- mwd.exe (a copy of the worm)
- psexec.exe (RemoteProcessLaunch application)
- mswinsk.ocx (innocent Microsoft Winsock Control DLL)
The worm scan scans the local class a subnet (#.*.*.*) for target systems. The worm creates a remote access server by listening on TCP port 45836. This server allows a remote attacker to perform the following tasks:
- Retrieve the following information
- Uptime
- Download speed
- CPU information
- RAM
- Disk Usage
- Specify a target IP address to ICMP/HTTP flood
- Download/execute files
- Internet Relay Chat (IRC) functions
- IP Port Redirection (to create proxies)
Symptoms
Symptoms -
Compromised system attempting to connect to the following addresses
- frozenhighlands.skiebus.com
- frozenhighlands.rock-slides.com
- jjljsmlmjo.no-ip.com
- llqrlmspmm.dyndns.org
- qplfdempqo.dyndns.org
Method of Infection
Method of Infection -
This worm spreads via the ADMIN$ share on Windows NT/2K/XP systems.
Removal -
Removal -
All Users:
Use specified engine and DAT files for detection and removal of virus and trojan files related to this threat.
- net share c$ /delete
- net share d$ /delete
- net share e$ /delete
- net share ipc$ /delete
- net share admin$ /delete
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A