Security Incidents mailing list archives
Re: unknown trojan (attached)
From: bkittler () EARTHLINK NET (Brandon Kittler)
Date: Sat, 10 Jun 2000 22:55:22 -0700
I had the same problem. The trojan resides in c:\windows\srvcp.exe. It is started at run time via the registry, in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. The program is listed as "Service Profiler". I came across it the other day, and wondering what it was, pulled all the strings out. It runs an ident daemon, as well as an IRC connection which it recives commands over (retrieval of FTP files, run cmds, etc). If you telnet to 113 and issue an invalid ident request, the trojan crashes immediatly. Extracted from srvcp.exe: ... 00529F ftp -s:c:\flog 0052B1 quit 0052BC c:\flog 0052CE CHAN 0052D3 REMSERVER 0052DD ADDSERVER 0052E7 SOUPCHAN 0052F0 SETNAME ... 00548C PRIVMSG %s :ok.. running 0054A6 PRIVMSG %s :couldn't spawn file 0054C7 PRIVMSG %s :successfully spawned ftp.exe 0054F1 PRIVMSG %s :couldn't spawn ftp.exe 005515 PRIVMSG %s :no more... 00552D PRIVMSG %s :ready and willing... ... Obviously, this isn't supposed to be there :) Brandon Kittler bkittler () iname com
Current thread:
- update on scans of tcp 12345 AUSCERT#36349 Russell Fulton (Jun 05)
- Re: update on scans of tcp 12345 AUSCERT#36349 Shaw Terwilliger (Jun 08)
- unknown trojan (attached) Jeremy L. Gaddis (Jun 08)
- ** New DDoS / Trojan ** nine (Jun 10)
- Re: ** New DDoS / Trojan ** Pierre Vandevenne (Jun 12)
- Re: unknown trojan (attached) Brandon Kittler (Jun 10)
- Re: unknown trojan (attached) Doug Kahler (Jun 12)
- .:: 14x :: Information :: New DDoS/Trojan ::. Erik Tayler (Jun 13)
- Re: .:: 14x :: Information :: New DDoS/Trojan ::. Lic. Rodolfo Gonzalez Gonzalez (Jun 15)
- IRC connect through apache ???? arhuman () HOTMAIL COM (Jun 14)
- Re: IRC connect through apache ???? Eric Vyncke (Jun 15)
- ** New DDoS / Trojan ** nine (Jun 10)
- <Possible follow-ups>
- Re: update on scans of tcp 12345 AUSCERT#36349 Bryan Scaringe (Jun 08)
- Re: update on scans of tcp 12345 AUSCERT#36349 Luke Dudney (Jun 10)