

Also, the filename's changed from
ecard.exe to sony.exe and/or video.exe.

ecard.exe to sony.exe and/or video.exe.vivacodec, hosted at www.vivacodec.com (do NOT visit that website). Similar to the old ones, this new fake codec drops a rootkit. This rootkit uses Winlogon\System subkey to load itself during system startup. Here are the screenshots of rootkit's Registry entry, and hidden file as detected by RootkitRevealer:

spooldr.exe and spooldr.sys. The dropper - ecard.exe - patches genuine system files to load its driver.tcpip.sys file and adds code to load spooldr.sys, when tcpip.sys is loaded. Here's a screenshot, which shows ecard.exe patching tcpip.sys:
tcpip.sys. It can be observed that there is a reference to rootkit driver spooldr.sys:
spooldr.sys as a driver and have Windows to load it during startup), this rootkit makes use of Windows system files to load itself! However, this patched driver can be detected by sigverif tool, and moreover most of the AVs detect patched drivers as a malicious file.







fast-ticket2006.exe, is a Zlob/DNSChanger variant and is hosted at www.fast-ticket.net. However, this installer is a fairly old variant of Zlob and most of the AVs detect it. It installs a rootkit which hooks APIs in Ntdll.dll. Here's a screenshot of rooted file and some of the APIs hooked by the rootkit:

70.85.246.49 and 70.85.246.49 . Here's a Whois lookup, from SamSpade, for some of the sites:1freemp3s.cn = [ 70.85.246.48 ]
(Asked whois.cnnic.net.cn:43 about 1freemp3s.cn)
Domain Name: 1freemp3s.cn
ROID: 20070720s10001s27391265-cn
Domain Status: ok
Registrant Organization: SAVIHA SHENYI
Registrant Name: Hotis Navashit
Administrative Email: sto@gartwa.ch
Sponsoring Registrar:
Name Server: ns1.pro-mp3.cn
Name Server: ns2.pro-mp3.cn
Registration Date: 2007-07-20 20: 21
Expiration Date: 2008-07-20 20: 21
mp3mania.cn = [ 70.85.246.49 ]
(Asked whois.cnnic.net.cn:43 about mp3mania.cn)
Domain Name: mp3mania.cn
ROID: 20070720s10001s27538514-cn
Domain Status: ok
Registrant Organization: SAVIHA SHENYI
Registrant Name: Hotis Navashit
Administrative Email: sto@gartwa.ch
Sponsoring Registrar:
Name Server: ns1.pro-mp3.cn
Name Server: ns2.pro-mp3.cn
Registration Date: 2007-07-20 23: 47
Expiration Date: 2008-07-20 23: 47
mp3record.cn
hardmp3.cn
music4me.cn
supermp3s.cn
mp3stars.cn
mp3djs.cn
livemp3s.cn
freedlmusic.cn
freshmp3s.cn
listmp3.cn
musicforfun.cn
take4freemp3.cn
load4freemp3.cn
musicdreams.cn
mp3sfan.cn
soundwishes.cn
mp3library.cn
nocreditmp3.cn
zoneofmp3.cn
mp3for3.cn
mp3client.cn
musicstream.cn
musicstream.cn
freedlmusic.cn
mp3daily.cn
total-music.cn
filesmp3.cn
1freemp3s.cn
homemp3s.cn
mp3portal.cn
sound-online.cn
freesoundclub.cn
music-center.cn
freemp3lib.cn
muchmp3.cn
livemp3s.cn
directmp3.cn
mp3complete.cn
mp3mania.cn
allmp3s.cn
hotmp3ology.cn
mp3-downloads.cn
mp3area.cn
bestmp3s.cn
for3mp3.cn
soundwishes.cn
mp3archiv.cn
freshmp3.cn
mp3gifts.cn
mp3spider.cn
pro-mp3.cn
ecard.exe to view the ecard. But now, the gang behind this malware have changed their trojan dropper's name to msdataaccess.exe from ecard.exe! Similar to the old ecard.exe variant, this new one installs malware such as Tibs rootkit etc.Tibs rootkit:

"Partner() has created Holiday ecard for you"
at bristos.com.
To see your custom Holiday ecard, simply click on the following Internet address (if your mail program doesn't support this feature you will need to COPY and PASTE the address into your browser's address box):
http://81.71.5.34/?4ee8af5c23933166b19e3393b5ca09ff74e82d
Send a FREE greeting card from bristos.com whenever you want by visiting us at:
http://bristos.com/
This service is provided and hosted by bristos.com.

U.exe - drops following files/folders:\windows\system32\head.exe
\windows\system32\XPEntertainmentsUninstall.exe
\windows\system32\SoUI.dll
\program files\SoftPortal[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4748B0B3-B964-41C3-AE0A-F1345E0AC3C9}\InprocServer32]
@="C:\\WINDOWS\\system32\\\\SoUI.dll"
[HKEY_CURRENT_USER\Software\SoftPortal]
"BasePath"="C:\\Program Files\\SoftPortal\\"http://xpsite.org/head/?wmid=3&pid=1
http://api.automaticavupdate.com/UI/v1.1/Soft/
http://api.automaticavupdate.com/UI/v1.1/www.expertantivirus.com, which is the home of rogue software - ExpertAntivirus.Add/Remove Programs entry called XP Entertainments, as shown in below screen shot:
SoUI.dll is injected into Explorer.exe's address space:
