View Single Post
Staro 13.09.2007., 19:35   #3
domy_os
EMP moderator
 
domy_os's Avatar
 
Datum registracije: Apr 2005
Lokacija: Osijek
Postovi: 18,828
Arrival and Installation

This worm usually arrives on a system as a dropped file of other malware, or as a downloaded file from the Internet by an unsuspecting user when visiting malicious Web sites.

Upon execution, it opens the root folder, which is usually C:\, and creates a folder named RECYCLED inside it.

It then drops a copy of itself as CTFMON.EXE in the following folders:

* C:\Recycled\Recycled
* %User Startup%

Note that a legitimate file also named CTFMON.EXE exists in the Windows system folder.

It also creates its own AUTORUN.INF file in the root folder. The said file contains the following strings:

Citiraj:
[AutoRun]
shellexecute=Recycled\Recycled\ctfmon.exe
shell\Open(O)\command=Recycled\Recycled\ctfmon.exe
shell=Open(0).
It adds the option Open(o) to the normal Context Menu. Once a user chooses the said option, the worm is automatically executed.

It also drops the following non-malicious files in the created RECYCLED folder:

* desktop.ini
* INFO2

DESKTOP.INI contains the following strings:

Citiraj:
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
The said CLSID refers to the Recycle Bin. Once this file is present in a specific folder, the said folder uses the default icon of the Recycle Bin. This technique is a stealth mechanism done to trick users into thinking that the said folder is the legitimate Recycle Bin folder.

When DESKTOP.INI is deleted, the fake folder's icon changes back to the standard folder icon.

The file INFO2 is a harmless data file.

Propagation via Removable and Mapped Drives

This worm drops copies of itself in removable drives and mapped drives as CTFMON.EXE. It also drops the same AUTORUN.INF file described above to automatically execute the mentioned dropped copies when the drives are accessed.

Other Details

On Windows XP systems, this worm creates the following registry keys and entries, which ensure the execution of the Context Menu Open(o):

Citiraj:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\MountPoints2\{random CLSID}
\Shell\Open(O)\command
(Default) = "C:\Recycled\Recycled\ctfmon.exe"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\MountPoints2\{random CLSID}
\Shell\AutoRun\command
(Default) = "RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\Recycled\ctfmon.exe"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\MountPoints2\
##%Server name%#%Share name%\Shell\Open(O)\command
(Default) = "%Drive letter%\Recycled\ctfmon.exe"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\MountPoints2\
##%Server name%#%Share name%\Shell\AutoRun\command
(Default) = "%Drive letter%\Recycled\ctfmon.exe"
(Note: %Server name% is the name of the server where the mapped folder is located. %Share name% is the name of the mapped folder.)

This worm runs on Windows 98, ME, NT, 2000, XP, and Server 2003.
__________________
"Kako su krojači novog svjetskog poretka uspjeli u tako kratko vrijeme slomiti intelektualne sposobnosti društva, uništiti kritičku svijest i ljudima nametnuti izvrnutu logiku?"

Nisu slomili u kratko vrijeme. Slamali su godinama, desetljećima pa i stoljećima. Svaka odgledana epizoda Big Brothera, svaki dečko koji ne zna niti promijeniti žarulju, a kamoli uzeti sjekiru i pocijepati drva, svaka cura koja misli da je briga za vlastitu obitelj robija, ali rad za par tisuća kuna u korporaciji 12 sati dnevno blagodat, svako promicanje terora političke korektnosti, svaka podrška promociji svih oblika poremećenosti… Sve to nas je dovelo do ovdje. Korona je samo zakucavanje lopte u gol nakon što je obrana već izigrana i golman odletio u prazno.




Lenovo ThinkPad T14 Gen 2 + Lenovo ThinkPad Universal Thunderbolt 4 Dock

CPU: Intel Core i7-1165G7 @ 2.8 GHz
RAM: 2 x 16 GB DDR4-3200
SSD: Samsung 970 EVO Plus 2 TB NVMe M.2
LCD: 14" FHD IPS 400nits Low Power
WLAN: Intel Wi-Fi 6 AX201
WWAN: Quectel EM120R-GL 4G LTE CAT12
OS: Windows 11 Pro

LCD monitor: AOC AG493UCX
Keyboard: Razer Huntsman V2 Analog
Mice: Logitech G502 Proteus Spectrum
SB: Mackie Onyx Producer 2x2
Speakers: 2 x JBL LSR305
MFP: Canon Pixma MP240
NAS: Synology DS420+ with 4 x WD Red Pro 8 TB
HDD Dock: LC Power LC-DOCK-U3-CR + 12 x Hitachi/Samsung/Seagate/WD 1/2 TB

domy_os je offline   Reply With Quote