|
||||||||||||||||||

![]() ![]() ![]() |
|
W95/Babylonia
The virus uses WSOCK32.DLL to send emails with an attached infected executable called X-MAS.EXE. The attachment is displayed as an icon with the face of Father Christmas. When the attachment is executed, it displays two dialog boxes in succession: "API not found!" and "Windows NT required. This program will be terminated" This is a virus first distributed
on the newsgroup 'alt.crackers' in the form of a
The original file posted is 40,637 bytes, and if run, will infect PE files of EXE and HLP extension on the local Windows 9x system. A file is written to the local system named "KERNEL32.EXE" size 4096 bytes and the system registry is modified to load this at system startup- HKEY_LOCAL_MACHINE\SOFTWARE\ The KERNEL32.EXE process uses the following DLLs to monitor internet connection: C:\WINDOWS\SYSTEM\WSOCK32.DLL
In some cases, the files infected are damaged due to overwriting existing code or data. For example in testing, MS Outlook gave this error when run after being infected- OUTLOOK caused an invalid page fault in module KERNEL32.DLL at 0137:bff9a141. The virus will monitor for internet connection and if made, will attempt to connect to a website hosted in Japan and maintained by a Virus authoring group to download 'components' of the virus. The components are listed in a file named "virus.txt" - the names on the list are then used to download the other named files to the local system. When all files are downloaded, this virus will use them to further spread. If mIRC is installed, this virus will modify the script.ini configuration file to automatically send itself as the file "2KBug-MircFix.exe" when connecting to irc channels on the internet. The virus uses Wsock32.dll in order to send an email notification to the email address "babylonia_counter" at hotmail.com and the 'from:' information is set to "babylonia" at rasta.net. This possibly is to track the number of infections for statistical purposes. Strings within one of the downloaded components suggests that the virus monitors the system clock waiting for the right time to modify the AUTOEXEC.BAT with the following text: echo W95/Babylonia by Vecna
(c) 1999
All components of this virus will be detected according to their file content, including the modified AUTOEXEC.BAT. Indications Of Infection
Removal Instructions
1. Use IP filtering (WebScanx/WebShield SMTP) to block the IP address of the domain responsible for hosting the virus components downloaded- "210.169.20.21" - block any accesses to it and log anyone who attempts to access it 2. Replacing files detected with backup copies or from installation software 3. If IRC software is installed such as mIRC, read the section below regarding "IRC File Distribution Prevention Method" 3. Remove registry entry mentioned above as a final cleanup measure. Prevention
Method
1. Only
accept files from people that you know and trust. Never accept files from
people you don't know and never accept files without knowing their full
2. Files of executable extension such as .BAT, .EXE, .COM, .HLP, .DLL should never be accepted from others as they have the most potential to cause problems or be infected. 3. Scripts should not be accepted from others you do not know. Automation is another factor in the distribution of viruses and trojans. 4. Files which support macros should not be accepted, or if they are accepted, make sure to have macro virus protection enabled. If you are unable to verify if macro virus protection is enabled, use alternate viewers such as QuickView or Wordpad as they do not support macros. Office97 applications have viewers available from Microsoft such as Word97 Viewer. Using alternate viewers will minimize the risk of spreading macro virus infections. 5. Use Antivirus software to scan all files received on IRC channels. This is not a sure-fire way of detecting all viruses however known viruses can be prevented from running if vigilant scanning techniques are used. 6. Some IRC software applications such as mIRC support security settings or options to disable certain functions such as "send" or "get" and commands such as "/run" and "/dll". AVERT recommends setting these options if applicable. If your application supports changing options on "DCC" settings, choose to prompt or ignore requests for file send or receive transactions. |
||||||||
|
|
|||||||||
| [an error occurred while processing this directive] |
|
Howdy!!! Welcome to the McCann's PooR Farm I'm not with any school or schools, Just a disable grandpa with 17 grand kids, 1 Great grand Kid Sorry! about all of the adds, Our Cost just keeping going up. Please click on one of them and help us out. or Send $1.00 U.S. to: McCann's Poor Farm 20509 Lawrence 2207 Aurora, Mo. 65605-7275 Thank You, Junior McCann Webmaster and the GrandKids See what the experts have to say about the McCann's Poor Farm Web Page Legal Disclaimer - We Are in no way connected with any School and or Companies linked to this page. Links are provided as a courtesy only. |
Argentina, Australia, Austria, Belarus, Belgium, Bermuda, Brazil, Brunei Darussalam, Bulgaria, Canada, Chile, Columbia, Costa Rica, Croatia, Croatia/Hrvatska, Czech Republic, Denmark, Dominican Republic, Ecuador, Egypt, Estonia, Finland, France, Germany, Ghana, Greece, Hong Kong, Hungary, Iceland, India, Indonesia, Ireland, Israel, Italy, Japan, Jordan, Korea, Korea, Republic of, Latvia, Lebanon, Lithuania, Luxembourg, Macedonia, Malaysia, Mexico, Moldova, Netherlands, New Calendonia, New Zealand, Norway, Old style Arpanet, Papua New Guinea, Peru, Philippines, Poland, Portugal, Romania, Russian Federation, Saudi Arabia, Singapore, Slovakia, Slovenia, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, Thailand, Turkey, Uganda, Ukraine, United Arab Emirates, United Kingdom, United States, Uruguay, USA Government, USA Military, Viet Nam |
|
Tell A Friend about this Page |
Tell me when this page is updated |
|
|
Put a Link on your Web Page
- Legal Disclaimer - |