Content
Nordex
- Type
- Trojan
- SubType
- Win32
- Discovery Date
- 11/08/2006
- Length
- varies
- Minimum DAT
- 4891 (11/08/2006)
- Updated DAT
- 4892 (11/09/2006)
- Minimum Engine
- 5.1.00
- Description Added
- 11/08/2006
- Description Modified
- 11/08/2006 4:51 AM (PT)
Tab Navigation
Characteristics
-- Update November 3rd, 2006 --
A recent spamming has been reported intended to lure users to a fixed German Wikipedia article. The spammed email message supposedly from Wikipedia directs users to download a patch for a new variant of Blaster worm and is sent as follows:
From: Wikipedia
Subject: Wikipedia - Alarm. Neue Variante des W32.Blasters im Umlauf.
Body:
|
Direkter Link zum Wikipedia-Artikel Wikipedia schlägt Alarm. Neue Variante des W32.Blasters im Umlauf. Wurm-Fix W32.Blaster (auch: W32.Lovsan und MSBlast) ist ein Computerwurm, der sich Der Wurm kann allerdings bei einem Angriff nicht erkennen, ob das Der Wurm sollte am 16. August 2003 einen Distributed-Denial-of-Service Mutationen Mittlerweile tritt der Wurm auch in zahlreichen Mutationen auf. Eine dieser Diese Entwicklung stellt mittlerweile auch eine direkte Bedrohung für die Der Wurm tritt mittlerweile in fünf Varianten auf: 1. http://www.wikipedia-download.org/wiki/W32.Blaster.html |
Symptoms
The trojan dropper is named as if to appear as a genuine Microsoft windows patch and also contains legitimate files of the official patch. The following filenames are used:
- WindowsXP-KB823980-i64-DEU.exe
- WindowsXP-KB823980-x86-DEU.exe
- WindowsServer2003-KB823980-i64-DEU.exe
- WindowsServer2003-KB823980-x86-DEU.exe
When executed, it appears to install the patch but in the background also installs the trojan.
The trojan is registered as a Browser Helper Object:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4efb-9B51-7695ECA15670}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA15670}
"Yahoo! Toolbar Helper"
Drops a copy of itself in the following folder:
- %Windir%\%SysDir%\dbnmpntw32.dll
Connects to the following URL to download an updated copy of itself.
- http://nordex[removed]/res4.exe
It then proceeds to post encoded data back to the attacker.
Method of Infection
This trojan was mass spammed on November 3rd, 2006.
Removal
A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.
Variants
Variants
N/A
All Information
Overview -
Nordex is a trojan that is delivered via a spammed fake email directing users to visit a fixed Wikipedia article that claims to contain a patch for a new variant of the Blaster worm. This trojan program masquerades as a Microsoft windows patch and installs a Browser Helper Object which downloads further malware from a remote website.
Aliases
- Trojan-Dropper.Win32.Small.atq (Kaspersky)
- TrojanDropper:Win32/Small!8FFE (Microsoft)
- W32/Small.ATQ!tr.dldr (Fortinet)
Characteristics
Characteristics -
-- Update November 3rd, 2006 --
A recent spamming has been reported intended to lure users to a fixed German Wikipedia article. The spammed email message supposedly from Wikipedia directs users to download a patch for a new variant of Blaster worm and is sent as follows:
From: Wikipedia
Subject: Wikipedia - Alarm. Neue Variante des W32.Blasters im Umlauf.
Body:
|
Direkter Link zum Wikipedia-Artikel Wikipedia schlägt Alarm. Neue Variante des W32.Blasters im Umlauf. Wurm-Fix W32.Blaster (auch: W32.Lovsan und MSBlast) ist ein Computerwurm, der sich Der Wurm kann allerdings bei einem Angriff nicht erkennen, ob das Der Wurm sollte am 16. August 2003 einen Distributed-Denial-of-Service Mutationen Mittlerweile tritt der Wurm auch in zahlreichen Mutationen auf. Eine dieser Diese Entwicklung stellt mittlerweile auch eine direkte Bedrohung für die Der Wurm tritt mittlerweile in fünf Varianten auf: 1. http://www.wikipedia-download.org/wiki/W32.Blaster.html |
Symptoms
Symptoms -
The trojan dropper is named as if to appear as a genuine Microsoft windows patch and also contains legitimate files of the official patch. The following filenames are used:
- WindowsXP-KB823980-i64-DEU.exe
- WindowsXP-KB823980-x86-DEU.exe
- WindowsServer2003-KB823980-i64-DEU.exe
- WindowsServer2003-KB823980-x86-DEU.exe
When executed, it appears to install the patch but in the background also installs the trojan.
The trojan is registered as a Browser Helper Object:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4efb-9B51-7695ECA15670}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA15670}
"Yahoo! Toolbar Helper"
Drops a copy of itself in the following folder:
- %Windir%\%SysDir%\dbnmpntw32.dll
Connects to the following URL to download an updated copy of itself.
- http://nordex[removed]/res4.exe
It then proceeds to post encoded data back to the attacker.
Method of Infection
Method of Infection -
This trojan was mass spammed on November 3rd, 2006.
Removal -
Removal -
A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A