[virusinfo] Troj/Goldun-O

  • From: "Mike" <mikebike@xxxxxxxxx>
  • To: virusinfo@xxxxxxxxxxxxx
  • Date: Fri, 04 Mar 2005 15:02:20 -0800

From; Sophos Alert System:

Name: Troj/Goldun-O
Aliases: PWS-Banker.k.gen
Type: Trojan
Date: 4 March 2005

A virus identity (IDE) file which provides protection is
available now from the Sophos website, and will be incorporated
into the April 2005 (3.92) release of Sophos Anti-Virus.

Customers using EM Library, PureMessage or any of our Sophos
small business solutions will be automatically protected at
their next scheduled update.

At the time of writing, Sophos has received a small number of
reports of this Trojan from the wild.


Information about Troj/Goldun-O can be found at:
http://www.sophos.com/virusinfo/analyses/trojgolduno.html

Troj/Goldun-O is a password-stealing Trojan. 
Troj/Goldun-O monitors outgoing HTTP requests for traffic going to specific 
internet banking sites. On encountering such a request the Trojan will attempt 
to extract account details from the returned page and submit these details to 
the Trojan's autho using an HTTP form submission. 
The Trojan creates the file "csrss.dll" (also detected by Sophos as 
Troj/Goldun-O) in the Windows system folder and installs this as an Internet 
Explorer plugin by creating the following registry entries: 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{92617934-9abc-def0-0fed-fad48c654321} 
HKCR\CLSID\{92617934-9abc-def0-0fed-fad48c654321}\InprocServer32\
""
<Windows system folder>\csrss.dll 
The Trojan also creates a number of registry entries for its own use under 
HKCR\CLSID\{92617934-9abc-def0-0fed-fad48c654321} 

This IDE file also includes detection for:

Troj/Delf-WH
http://www.sophos.com/virusinfo/analyses/trojdelfwh.html
Troj/Dloader-IY
http://www.sophos.com/virusinfo/analyses/trojdloaderiy.html
Troj/Bancban-BS
http://www.sophos.com/virusinfo/analyses/trojbancbanbs.html
Troj/Krepper-M
http://www.sophos.com/virusinfo/analyses/trojkrepperm.html
Troj/Prutec-A
http://www.sophos.com/virusinfo/analyses/trojpruteca.html
Troj/Sharp-D
http://www.sophos.com/virusinfo/analyses/trojsharpd.html

Download the IDE file from:
http://www.sophos.com/downloads/ide/goldun-o.ide

Download all the IDE files available for the current version of 
Sophos Anti-Virus in a single compressed file. The file is
available in two formats:

Zip file:
http://www.sophos.com/downloads/ide/ides.zip

Self-extracting file:
http://www.sophos.com/downloads/ide/ides.exe

Read about how to use IDE files at
http://www.sophos.com/downloads/ide/using.html


*********** MIKE"S REPLY SEPARATOR  ***********
Mike ~ It is a good day if I learned something new.
Editor MikesWhatsNews see a sample on my web page
http://www3.telus.net/mikebike
<mikeswhatsnews-request@xxxxxxxxxxxxx?Subject=subscribe>
http://www3.telus.net/mikebike/worm_removal.htm
See my Anti-Virus pages  http://virusinfo.hackfix.org/index
<virusinfo-request@xxxxxxxxxxxxx?Subject=subscribe>
A Technical Support Alliance  and OWTA Charter Member 




Other related posts:

  • » [virusinfo] Troj/Goldun-O