trojan.xombe, xombe, win32/xombe.a, trojan.win32.xombe, downloader-gj tipo: troyano tama?o: 4,096 bytes origen: internet destructivo: no en la calle (in the wild): si detección y eliminación: the hacker 5.6 al 09/01/2004 descripción: w32/xombe , es un troyano de tipo downloader, descarga un archivo adicional desde un determinado sitio en internet, este se difunde a trav?s de e-mail y simula ser un archivo de actualizaci?n de microsoft, solicitando que se desactive el antivirus del computador atacado para poder instalar un archivo de actualizaci?n de windows xp. caracter?sticas del mensaje de email: desde: windowsupdate@microsoft.com asunto: windows xp service pack 1 (express) - critical update. cuerpo: window update has determined that you are running a beta version of windows xp service pack 1 (sp1). to help improve the stability of your computer, microsoft recommends that you remove the beta version of windows xp sp1 and re-install windows xp sp1. if you cannot remove the beta version, you should still reinstall windows xp sp1. windows xp sp1 provides the latest security, reliability, and performance updates to the windows xp family of operating systems. windows xp sp1 is designed to ensure windows xp platform compatibility with newly released software and hardware, and includes updates to resolve issues discovered by customers or by microsofts internal testing team. the maximum download size is approximately 3 mb, however the size of the download and time required may be less for computers that have had updates previously installed. to minimize the download time needed for installation, setup will only download those files which are required to bring your computer up to date. windows xp sp1 includes internet explorer 6 sp1. anti-virus software programs may interfere with the installation of windows xp sp1. please disable anti-virus software while installing the service pack. just run the file winxp_sp1.exe in attach and make sure to restart your pc after installation will be completed. ?2004 microsoft corporation. all rights reserved. terms of use < http://www.microsoft.com/info/cpyright.htm > privacy statement <http://www.microsoft.com/info/privacy.htm > archivo adjunto: winxp_sp1.exe -------------------------------- cuando el gusano se ejecuta se copia a s? mismo como: system \winxp_sp1.exe (crea el archivo principal del troyano) system \msvchost.exe (archivo del troyano, descarga el archivo http_f.dll) system \http_f.dll (archivo descargado desde internet) nota: - system representa la carpeta system dentro de windows (ej. c:\windows\system, c:\winnt\system32) adem?s modifica una entrada en el registro para poder ejecutarse en el siguiente reinicio del sistema: hkey_local_machine\software\microsoft\windows\currentversion\run mssvc= system \msvchost.exe |