Viral Rewind Revisited: IRC-Worm.Win32.Fagot

  Рет қаралды 352

MB Education

MB Education

7 ай бұрын

Visit my Linktree to access my socials and other channels: linktr.ee/mausolfb
-----------------------------------------------------------
. Revisiting the Fagot mIRC worm as the last video on this malware didnt get very far • Viral Rewind: IRC-Worm... ... Fagot (yes that is its given name by researchers from part of what the worm does to the user's username) does quite a bit of damage to a computer... not necessarily all files but it does delete and replace many key Windows programs with copies of itself and for the most part wrecks the Windows registry. I only had ~10 minutes left of time on my camera so my XP version had to be rushed a bit...
It all starts when a mIRC user receives the following message in their mIRC client:
"www.angelfire.com/celeb2/picsx... <- uuh, check it out !! :D"
If the user clicked the link it would download not a picture of Britney but actually an HTML file that opened in Internet Explorer that was embedded with downloader/run scripts. It would download a file called "PATCH.EXE" and overwrite Windows Media Player with said file. A following script would then run the executable file.
At launch the worm first kills the following processes so their programs can be deleted and overwritten later:
Ad-watch.exe
regedit.exe
taskmgr.exe
It will then make two copies of itself in the system32 directory with corresponding run keys in the Windows registry (to support Windows NT and 9X versions):
C:\Windows\system32\userinit32.exe
C:\Windows\system32\dllhost32.exe
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit" = "C:\Windows\system32\userinit32.exe"
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "dllhost32" = "C:\Windows\system32\dllhost32.exe"
It then searches and kills many different anti-virus/malware processes if they're present...
At this point it begins to alter and change items as no programs would be running to try and stop its infection and spread. It first changes the start page of Internet Explorer to "www.blacksnake.com"
It will then alter the default Windows usernames to "COCK_SUCKING_FAGGOT" (which is where the name stems from)
Afterwards it deletes many key Windows programs (mostly from the system32 folder) if they are present. Then it makes copies of itself replacing most of the deleted Windows programs in their original locations with original names. Then it will delete several entire key branches from the Windows registry. Lastly it displays a fake error messagebox when all is completed
It will periodically send the same aforementioned mIRC message to other mIRC users on the machine spreading itself and starting the routine over on another machine.
If you want all the details of the files that are deleted, replaced and the registry branches that are deleted then visit F-Secure's page about it here: www.f-secure.com/v-descs/fago...
#malware #windows #worm #win9x #win32 #winnt #irc
----------------------
Like the Facebook page: / brian.mausolf
Follow me on Twitter: / mausolfb

Пікірлер: 2
@OctoomyYTOfficial
@OctoomyYTOfficial 6 ай бұрын
interesting channel!
@thomasslone1964
@thomasslone1964 6 ай бұрын
I'm getting the idea most of these viruses were made by people who aren't very good at making decent software
Viral Rewind Revisited: Email-Worm.Win32.Happy (Happy99)
8:32
IRC-Worm.Win32.Jer
2:27
danooct1
Рет қаралды 63 М.
ВОДА В СОЛО
00:20
⚡️КАН АНДРЕЙ⚡️
Рет қаралды 30 МЛН
Дарю Самокат Скейтеру !
00:42
Vlad Samokatchik
Рет қаралды 8 МЛН
Why Is He Unhappy…?
00:26
Alan Chikin Chow
Рет қаралды 15 МЛН
Viral Rewind: Virus.DOS.Sov (1193/1205)
4:50
MB Education
Рет қаралды 101
Virus.Win16.CyberRiot
13:34
danooct1
Рет қаралды 287 М.
What happens if you connect Windows XP to the Internet in 2024?
20:35
Viral Rewind: Virus.DOS.Casino
9:05
MB Education
Рет қаралды 176
What Enterprise-Grade malware looks like
20:09
Eric Parker
Рет қаралды 52 М.
Virus.DOS.Digi
2:10
danooct1
Рет қаралды 47 М.
Obnox OS: The Worst Operating System
7:59
Kenneth Perrine
Рет қаралды 485 М.
Windows | Microsoft's Biggest Mistake
19:05
NationSquid
Рет қаралды 103 М.
Здесь упор в процессор
18:02
Рома, Просто Рома
Рет қаралды 422 М.
iPhone 15 Pro Max vs IPhone Xs Max  troll face speed test
0:33
Как удвоить напряжение? #электроника #умножитель
1:00
Hi Dev! – Электроника
Рет қаралды 1,1 МЛН
iPhone, Galaxy или Pixel? 😎
0:16
serg1us
Рет қаралды 1,3 МЛН