{"id":244,"date":"2003-08-29T00:19:41","date_gmt":"2003-08-29T03:19:41","guid":{"rendered":"http:\/\/www.hoogervorst.ca\/arthur\/?p=244"},"modified":"2003-08-29T00:19:41","modified_gmt":"2003-08-29T03:19:41","slug":"that-sobig-virus","status":"publish","type":"post","link":"http:\/\/www.hoogervorst.ca\/arthur\/?p=244","title":{"rendered":"That SO.Big virus"},"content":{"rendered":"<p><span class=dropcap>E<\/span>arlier this night, I dissected an SO.Big virus a couple times, the last time in front of my collegue-professionals, which went without real &#8216;accidents&#8217;.<\/p>\n<p><!--more--><\/p>\n<p>A couple of side notes: the virus was actually an <a href=\"http:\/\/securityresponse.symantec.com\/avcenter\/venc\/data\/w32.sobig.f@mm.html\"> So.Big type F virus<\/a> (thanks <a href=\"http:\/\/hoogervorst.dyndns.org\/~alfons\/weblog\/\">Alfons<\/a> for catching this one). When testing out the virus the first time at home, I was caught by surprise when I did the &#8216;traditional matching timestamp&#8217; file search. The virus itself (the executable) was created way before the accompanying datafile. After some logical backtracking, the clue was that the mailer&#8217;s extraction date of the pif file was exactly the same as the one of the winppr32.exe (the actual virus\/server) file. This means that, when the pif file is executed by the user, the virus copies itself as winppr32 to the System directory <em>instead of recreating itself<\/em>.<\/p>\n<p>Another interesting part was that the server apparantly connected to port 123. In the small timeframe I had, I wasn&#8217;t able to see the connection going through port 8898 UDP, let alone see the virus actually hunt for e-mail addresses (as the AV sites so colourfully describe).\n<\/p>\n<p>Cleaning up is rather easy in this case: remove the program from the processlist.  Then delete the winppr32.exe and winsst32.dat file in the sys-directory: in normal cases you would use the Find Files tool: this gives you on the forehand a chance to see which files were created at or around the same time. The last step is to look in the registry for the winppr32.exe file and delete the entries (Microsoft\/Windows\/CurrentVersion\/Run in both Local_machine and Current_User).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Earlier this night, I dissected an SO.Big virus a couple times, the last time in front of my collegue-professionals, which went without real &#8216;accidents&#8217;.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[14],"tags":[],"_links":{"self":[{"href":"http:\/\/www.hoogervorst.ca\/arthur\/index.php?rest_route=\/wp\/v2\/posts\/244"}],"collection":[{"href":"http:\/\/www.hoogervorst.ca\/arthur\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.hoogervorst.ca\/arthur\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.hoogervorst.ca\/arthur\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.hoogervorst.ca\/arthur\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=244"}],"version-history":[{"count":0,"href":"http:\/\/www.hoogervorst.ca\/arthur\/index.php?rest_route=\/wp\/v2\/posts\/244\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.hoogervorst.ca\/arthur\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.hoogervorst.ca\/arthur\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=244"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.hoogervorst.ca\/arthur\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}