CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer
image Vulnerabilities: Gruel.E, Gruel.F and Cuydoc image
Worms
Patience is bitter, but the fruit is sweet.
French proverb.

- Weekly virus report -
Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)

Madrid, July 27, 2003 - In this report, we will focus on three worms,
Gruel.E, Gruel.F and Cuydoc.

The 'E' and F' variants of the worm Gruel spread via e-mail and through the
P2P (peer-to-peer) file sharing program KaZaA. In addition, both of them
have the following characteristics:

- They are highly damaging, since they eliminate a series of files (like
AUTOEXEC.BAT and CONFIG.SYS), that Windows needs to work correctly.

- Their actions include: opening several windows in the Control Panel;
opening and closing the CD-ROM tray; disabling the Taskbar and making it
disappear; hiding the C: drive, preventing file searches from being
performed; etc.

- Once the infection has been carried out, these worms display a fake
Windows error message on screen.

- They create several entries in the Windows Registry, with different values
-depending on whether the computer has been restarted or not-. By creating
these entries, Gruel.E and Gruel.F ensure that they are run whenever a file
with an 'EXE', 'COM', 'BAT', 'PIF', or 'HyperTerminal' extension is run.

The main difference between these two variants is that they spread via
attached files with different names. OFFICEXPTRIAL.EXE is the name of the
file in which Gruel.E spreads, and PROTECT_REMOVE_TOOL.EXE is the file in
which Gruel.F spreads.

The third worm analyzed in this report is Cuydoc which, apart from spreading
through the means normally used by viruses, can also spread across floppy
disk drives. Specifically, Cuydoc automatically copies itself to the floppy
disk drive under the name CUPIDO.EXE.

Cuydoc has damaging effects, since it deletes all of the Word documents
(files with a 'DOC' extension) from the My Documents directory in the
affected computer. In addition, in Spanish versions of Windows Me/98/95,
Cuydoc prevents the user from running the 'REGEDIT.EXE' program, which
allows the user to edit the entries in the Windows Registry, and the
'MSCONFIG.EXE' program, which allows the user to configure which programs
will be loaded when Windows starts.

For further information about these and other viruses, visit Panda
Software's Virus Encyclopedia:
http://www.pandasoftware.com/virus_info/encyclopedia/

Additional information

- Directory / Folder: Divisions or sections used to structure and organize
information contained on a disk. They can contain files or other
sub-directories.

- Windows Registry: This is a file that stores all configuration and
installation information of programs installed, including information about
the Windows operating system.

More definitions of virus and antivirus terminology at:
http://www.pandasoftware.com/virus_info/glossary/default.aspx

NOTE: The addresses above may not show up on your screen as single lines.
This would prevent you from using the links to access the web pages. If this
happens, just use the 'cut' and 'paste' options to join the pieces of the
URL.


To contact with Panda Software, please visit:
http://www.pandasoftware.com/about/contact/
------------------------------------------------------------

Posted on Sunday, 27 July 2003 @ 09:55:36 UTC by phoenix22 (1451 reads)
[ Trackback ]
image

"Vulnerabilities: Gruel.E, Gruel.F and Cuydoc" | Login/Create an Account | 1 comment | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Gruel.E, Gruel.F and Cuydoc (Score: 0)
by Anonymous  on Monday, 28 July 2003 @ 11:57:40 UTC
First off, only a no brainer would use plain KaZaa.
Most intelligent people would use a plus version.
And what makes it plus?
No ads, no limitations, no option to bump people, no annoying messages, no RIAA bullsh!t and internal security.
Further, only a fool would open a file without scanning it.
Especially an executable type file!
And, if that is the case, I should think companies would be happy to get these persons and the security risk they propose, out of the gene pool.

And, oh my gosh, what's that you say, a virus that spreads via floppy disks!
Get real.
That is a virus feature that was new 20 years ago.
If that is being passed off as a new feature, who ever wrote that report should have fingers broken.

Further, looking at all those problems...
huh, seems to me they are reading the owners manual on what to expect from Windows ME icon_twisted.gif

There are two major problems here...
The first, are the idiots who would fall prey to this sort of attack.
Those, monkeys with guns, who are amused by the toys, but have no understanding of the seriouness.
To them, I say, be gone with you.

The second, are the people who promote the fear and needlessly escalate the perceived nature of the threat.
I know that Panda is a good company and with good ethics.
Which suggests that it is the writters causing the stir.
To them, I say, shame on you.

A responcible person, if they are going to be using the internet, and especially shadier aspects of it, will have adaquit security.
This includes Anti-Trojan, Anti-Spyware/Parasite and routinely updated Anti-Virus.

At present, my AV stands at:
Date/Time of last virus update
------------------------------
Sun 2003-07-27 20:15:42

Last update result
------------------------------
Success

Virus engine statistics
------------------------------
Engine version: 4.0.1.14
Engine date: 2003/06/25
Definition count: 71405
Definition date: 2003/07/27

That is correct. At present, over 71 thousand virii are present on the net.
If your AV isn't handling that many, it is simply not sufficient.
If anyone can propose an AV that can do better, please, let me know.

And believe me, Norton, McAfee... jokes.
Those use to be programs, are simply more interested in sales today.

Panda is very good for the don't care how, just do it, home user.
Kaspersky is very good for the technically minded, want control of every aspect, business level users.

Why is it that most countries demand a person take a test to prove they can opperate a mechanical vehicle, yet when it comes to a highly complex, globaly interactive, high tech item like a computer, any shmo with enough money can get one without even having a clue how to properly use it?

Power to the Thinking People!


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· HotScripts
· W3 Consortium
· More about Worms
· News by phoenix22


Most read story about Worms:
Kama Sutra/Blackworm Worm Timebomb

block bottom
Article Rating
spacer
Average Score: 4
Votes: 1


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer