Slashdot Mirror


PhatBot Trojan Spreading Rapidly On Windows PCs

prostoalex writes "The Washington Post alerts Windows users about a new peer-to-peer backdoor client that is installed maliciously on broadband-connected computers around Asia and the United States. The client is then used for distributed DOS attacks and sending out large amounts of spam. Phatbot, according to government sources, is installed on hundreds of thousands machines already. Phatbot snoops for passwords on infected computers and tries to disable firewall and antivirus software, albeit it is detectable by antivirus packages." An anonymous reader submits a link to this description of the beast.

59 of 645 comments (clear)

  1. Is it just me... by FortKnox · · Score: 4, Funny

    ... or does this sound dirty to you too??

    a new peer-to-peer backdoor client that is installed maliciously

    --
    Good quote, too many chars. Seriously, the slashdot 120 char limit sucks!
    1. Re:Is it just me... by CreatureComfort · · Score: 5, Funny


      The Register just had a story about how a lot of the new virii are as small as 12kb, and how you could almost silk screen the code for one onto an XL T-shirt.

      I would love to have a pair of boxers with this code printed on them, and in large letters overlaying the code, "Let's install my peer-to-peer backdoor client."

      --
      "Unheard of means only it's undreamed of yet,
      Impossible means not yet done." ~~ Julia Ecklar
    2. Re:Is it just me... by Ralph+Wiggam · · Score: 4, Funny

      FatBot was one of the members of Robot House, Bender's former fraternity. The episode is an Animal House take off and FatBot is supposed to be Flounder.

      No idea if there's a connection.

      -B

    3. Re:Is it just me... by nlindstrom · · Score: 5, Interesting
      I remember Monkey-B. I once went on a field service call to a large business in downtown Los Angeles, and discovered that most of their PCs were infected with it. "Most of their PCs" being defined as around 100 boxes.

      I informed their IT person that Monkey-B encrypts the files on the disk, so before we went willy-nilly removing the virus, we needed to backup the user data. They told me I was full of crap, and proceeded to clean the PCs themselves. Big mistake!

      Oddly enough, their VP later complained to the service company I worked for that I had not done my job, since his IT people were fuck-heads. He didn't exactly state it this way, of course, but that was the gist of the statement. When I started to explain what had happened to my boss, I only got as far as "...and I discovered that most of their PCs were infected with Monkey-B."

      He started laughing, and finished my sentence for me with "and their stupid IT people went around removing it, right? Idiots!"

  2. Virizzle by DomCurtis187 · · Score: 4, Funny

    Since when did Snoop Dogg start writing code? Shizzle, dawg, dis virizzle be PHAT!

    1. Re:Virizzle by dasmegabyte · · Score: 4, Funny

      Dude, he's a PIMP.

      He has the bitches write code for him.

      --
      Hey freaks: now you're ju
  3. nice features list by Anonymous Coward · · Score: 5, Informative

    # Has the ability to polymorph on install in an attempt to evade antivirus signatures as it spreads from system to system
    # Checks to see if it is allowed to send mail to AOL, for spamming purposes
    # Can steal Windows Product Keys
    # Can run an IDENT server on demand
    # Starts an FTP server to deliver the trojan binary to exploited hosts - ends the FTP session with the message "221 Goodbye, have a good infection :)."
    # Can run a socks, HTTP or HTTPS proxy on demand
    # Can start a redirection service for GRE or TCP protocols
    # Can scan for and use the following exploits to spread itself to new victims: * DCOM * DCOM2 * MyDoom backdoor * DameWare * Locator Service * Shares with weak passwords * WebDav * WKS - Windows Workstation Service
    # Attempts to kill instances of MSBlast, Welchia and Sobig.F
    # Can sniff IRC network traffic looking for logins to other botnets and IRC operator passwords
    # Can sniff FTP network traffic for usernames and passwords
    # Can sniff HTTP network traffic for Paypal cookies
    # Contains a list of nearly 600 processes to kill if found on an infected system.Some are antivirus software, others are competing viruses/trojans
    # Tests the available bandwidth by posting large amounts of data to the following websites:
    * www.st.lib.keio.ac.jp
    * www.lib.nthu.edu.tw
    * www.stanford.edu
    * www.xo.net
    * www.utwente.nl
    * www.schlund.net
    # Can steal AOL account logins and passwords
    # Can steal CD Keys for several popular games
    # Can harvest emails from the web for spam purposes
    # Can harvest emails from the local system for spam purposes

    1. Re:nice features list by Joe+U · · Score: 5, Funny

      I would really like to see a worm/virus/trojan that makes the user's hard drive rip itself out of the computer, beat the user with a bat and run screaming down the hall.

      Can someone code that feature?

      Seriously, I would love to see one of these programs that just turns the victims internet connection OFF. Granted, I don't think it would spread very well.

    2. Re:nice features list by EndlessNameless · · Score: 5, Funny

      :::# Checks to see if it is allowed to send mail to AOL, for spamming purposes:::

      Best. Feature. Ever.

      --

      ---
      According to the latest ruleset, this post should be modded as Vorpal Flamebait +5.
    3. Re:nice features list by bfg9000 · · Score: 5, Funny

      If only Microsoft gave us this much cool stuff with their godforsaken updates. I just KNOW Longhorn is gonna be WinXP with DRM (YAY!), just like XP was Win2000 with Prettiness Plus(TM), just like 2000 was WinNT with a blue default background, just like NT was Win98 with less games, just like 98 was Win95 with double the base install size, just like 95 was Win3.1 with less speed and stability, just like Win3.1 was DOS with a mouse.

      What better resume than a good virus or trojan?

      --

      I'm not normally an irrational zealous dickhead, but I figure "When in Rome..."

    4. Re:nice features list by Platinum+Dragon · · Score: 5, Insightful

      Granted, I don't think it would spread very well.

      Just code it to kill the connection after, say, fifty successful infections.

      You know what the real innovation would be, though? Writing an OS so that one process can't stomp on other processes it doesn't have permission to. It would also be nice to write something where worms couldn't just land on the system as executable files by default and scripts that do things like install other programs and do stuff without the user's knowledge can't be automatically run by a freaking e-mail program. Gee, too bad there's nothing around like that...

      --

      Someday, you're going to die. Get over it.
    5. Re:nice features list by Joe+U · · Score: 5, Insightful

      Writing an OS so that one process can't stomp on other processes it doesn't have permission to.

      I agree 100%. The windows developer community needs to totally and outright kill 95/98/Me support, and start using the built in security in 2000/XP.

      Having absolutely everything running as an administrator is a huge mistake.

    6. Re:nice features list by Platinum+Dragon · · Score: 4, Informative

      *nods*

      Checking out the vulnerabilities used by Phatbot, I'm guessing most, if not all, of these holes were patched long ago. Short of forcing regular patching and upgrades, I guess there's not much that can be done to get around this. I get a shocking number of people through the store who never, ever use Windows Update.

      One part bad security model, one part careless users. Really, if there was an announced problem with your car that might lead to a thief getting in and driving off with it, wouldn't you get it fixed? Would you leave your door unlocked because it makes entering your car easier when you're in a rush?

      Computers have been sold as appliances, when they should be sold as flexible tools that aren't difficult to use, but take a minor bit of effort to maintain. I bet I could make big bucks just going to people's homes and carrying out basic upgrading and patching activities. $50/hr for running Windows Update, Ad-Aware and AVG, here I come...

      --

      Someday, you're going to die. Get over it.
    7. Re:nice features list by Sowbug · · Score: 4, Funny
      Simple. Just spam 10 million people with the following e-mail:
      This is your system administrator. DO NOT DELETE THIS E-MAIL. Your computer has been infected with the latest trojan worm rotovirus. Please take the following steps to remove this infection:

      1. Open your computer and remove the hard drive. If you are not able to do this on your own, ask the nearest IS worker for help. Inform him that this is to be done on direct orders from his superior.

      2. Attach the hard drive to a bat using duct tape. Beat yourself severely with it.

      3. While clutching the hard drive, run screaming down the hall.

      4. Forward this e-mail to all your direct reports. Please instruct them to comply IMMEDIATELY.

      Thank you for your assistance in stopping this infection.

      Sincerely yours,

      The Management
      OK, so maybe you can't get the hard drive to do it on its own, but if you make the e-mail look official enough, at least 10 people will do it for you.

    8. Re:nice features list by Platinum+Dragon · · Score: 4, Insightful

      I know you're a troll, but you have no idea how many:

      a) people who still run Win98/ME, with their total lack of a permissions model, come into the store, and
      b) how many people give their XP accounts administrator-level powers just to "make things easier". Shit, the TRON 2.0 demo required administrator privileges to run! We (ie, me and the other employees) have no idea why, it was the most fucking crackheaded thing I've seen since Windows ME, but there it was. I can't imagine how many other programs require admin access to run. And geeks wonder why people have no concept of why it's dangerous to run as root/admin...

      --

      Someday, you're going to die. Get over it.
    9. Re:nice features list by red+floyd · · Score: 4, Insightful

      Plus...

      <RANT type="favorite">
      Then there's programs that, because of sloppy/lazy coding, insist on being run as Admin on NT/2K/XP. Two that come to mind immediately are Mavis Beacon Teaches Typing 15 and The Sims.

      There is absolutely NO REASON WHATSOEVER for a typing tutor to require Admin, nor should there really be any for the Sims. AFAICT, they both write to the installation directory and HKLM instead of the user's "Application Data" and HKCU.

      </RANT>

      --
      The only reason we have the rights we have is that people just like us died to gain those rights. -- Cheerio Boy
    10. Re:nice features list by Lumpy · · Score: 4, Insightful

      Having absolutely everything running as an administrator is a huge mistake.

      I so agree, so can ypu PLEASE tell corperate america IT managers this?

      Here I am IT professional in one of the worlds LARGEST telecommunications companies and EVERYONE's W2K domain profile is set to put them as administrator rights... repeated calls to the NOC about the security hole are unanswered, and my attempts to fix it locally get me reprimanded for messing with domain security settings.

      It's fine to have the ability to lock it down, but it's worthless when the people in charge of it are too stupid or spineless to use it.

      --
      Do not look at laser with remaining good eye.
    11. Re:nice features list by KevCo · · Score: 5, Informative
      I can't imagine how many other programs require admin access to run

      I'm currently working at a company that is migrating to WinXP in a very locked down environment. Everyone is a user and software restriction policies only allow files to be executed from specific locations. Users have no write access to C: at all... all user profiles and data are on D: (which is not allowed to execute anything).

      My job is to make the apps work. It's horrible. We have to give write access to the app's dir in Program Files to probably 40% of the apps. Some apps require write access to the root of C:\. Many want to create/modify files in Windows and System32. Far too many insist on writing to HKLM and even HKCR.

      We repackage all the apps as MSIs and include the needed permissions changes in the installer. By the time the apps are loaded, most machines security have been drastically compromised.

    12. Re:nice features list by yeggman · · Score: 5, Insightful

      Really, if there was an announced problem with your car that might lead to a thief getting in and driving off with it, wouldn't you get it fixed?
      Not if he always brought it back in the morning ;)
      That's why people don't give a crap, cuz the machine still kinda runs. Most people probably chuck it up to: "God this old machine dosen't run like it use to could! I should have never upgraded to IE6."

    13. Re:nice features list by Platinum+Dragon · · Score: 5, Insightful

      So the problem is partly a company that trained users to live as all-powerful administrator, then wonders why people keep running as admin even when user accounts are introduced.

      The other part of the problem is a company that trained programmers to assume the same thing, and write their programs accordingly. Now that the new versions of the company's primary OS implement some security, the programmers that were used to having complete power are running into justifiable roadblocks.

      Nice security culture Microsoft created. The Unix folks learned the folly of getting lax on security long, long ago, thanks to stuff like the Morris worm. How many Morris worms will it take for the Windows world to do the necessary overhaul, on the OS (partly already done, from what I gather), programs, and attitudes of users along with programemrs?

      --

      Someday, you're going to die. Get over it.
    14. Re:nice features list by WhiteKnight07 · · Score: 4, Informative

      Win2k has this feature as well. Hold shift while clicking the right mouse button on any program in the start menu or on the desktop and "Run as..." will be an option in the resulting menu. Enter the desired user name and password and your set.

      --


      We're going to make information free Mr. Anderson, whether you like it, or not.
    15. Re:nice features list by HSpirit · · Score: 4, Informative

      I've been in regular contact with an antivirus vendor's support people over 2 weeks trying to explain to them that it is NOT acceptable for users to have Power User privileges in order for their AV definitions to auto-update... It's like talking to a brick wall, here's an example of their 'support' verbatim:

      You may need to change the permissions on your c drive or the vet folder to everyone

      Double click on My Computer
      Right click on C drive

      Left click on properties
      Left click on Sharing
      left click on permissions
      Choose everyone a click ok
      Then click o.k

      Then perform an autodownload

      Double click on My Computer
      Double left click on the Vet
      Right click on C drive

      Left click on properties
      Left click on Sharing
      Then click on share this folder left click on permissions
      Choose everyone a click ok
      Then click o.k

      This should allow you to perform an autodownload.

      You may have to do the same on the c:\temp or c:\windows\temp
      folder or c:\document and settingsyour username\temp

      Sorry? Do you mean give everyone full control to my system drive, as well as your AV definitions, configuration files and executable code? You've got to be kidding!

      And surely you'd think that AV vendors would understand better than most the need for their software to operate under the principle of least privilege.

      Give me a Mac (or other *nix) box anyday is what I say...

  4. Skynet by 3cents · · Score: 5, Funny

    How long before someone bootstraps a distributed Artificial life simulator to their virus and then we all watch in amazement as the first AI evolves and owns all our computers. This could never happen though...right?

    Slashrank

    1. Re:Skynet by NaugaHunter · · Score: 4, Funny

      Yeah, but running only on poorly setup windows boxes would probably depress it pretty quick. We can only hope it would go full cycle of sentience-self actualization-massive disillusionment-depression-suicide before reaching anything useful.

      Or it will start ordering from it's own spam and get really confused.

      --
      R: That voice. Where have I heard that voice before? B: In about 365 other episodes. But I don't know who it is either.
    2. Re:Skynet by Ryosen · · Score: 4, Funny

      Or it will start ordering from it's own spam

      Great, just what I need. A trojan that needs bigger Trojans than me.

      --

      Ryosen
      One man's "Troll, +1" is another man's "Insightful, +1".
  5. Idea? by Anonymous Coward · · Score: 5, Interesting

    When a virus attempts to disable anti-virus and firewalls, there needs to be a better way to keep those programs operational and "clean". What if a virus altered your norton or mcafee to make it appear as though it is working(and not finding any viruses) when in fact it is not working at all?

    What if anti-virus, firewalls, and other critical software could somehow run in read-only memory space, which would have a physical barrier so that no bugs in software could be exploited to alter this space?

    What if we could "burn" memory space of a program to a CD rom so that a proper working, unaltered anti-virus and firewall could run without fear of being disabled?

    1. Re:Idea? by hawkbug · · Score: 4, Insightful

      Sadly, what you're suggesting is what TCPA or whatever the hell the trust computing platform is all about. I'm against the whole movement, because I think we need more secure OS software to begin with, not "trusted memory space" to protect us.

  6. I'm TRULY not attempting to Troll by slycer9 · · Score: 4, Insightful

    But I'm getting so tired of these virus 'alerts' constantly bombarding me day in and day out!

    It's as bad as spam! It's EVERYWHERE!!

    I frequent a couple other message boards (damn, I almost said BBS'), and every few days, we get the same ol' thread...'VIRUS ALERT!!!!!!!'

    We live in the information age. The information has been disseminated that Windows users are:

    A) Prone to constant viral and security intrusions.
    B) In desperate need to constantly update their AV software.

    The SysAdmins who aren't keeping their servers locked down is another thing entirely...*grumble*

    But really, ABC, NBC, CBS, all these guys have done several stories on system security...EVERYONE's got a nephew that 'knows a lot 'bout dem 'puters'...

    I really don't understand why we're still being subjected to this crap. Virus news isn't news. It's spam.

    (See! A whole post about viruses and I never mentioned the fact that I run OS X and Yellow Dog Linux exclusively!!! Not once have I mentioned that I've never had to worry about a virus at all!!!)

    Yay me.

    --
    Don't park drunk, accidents cause people.
  7. Grr... by MalaclypseTheYounger · · Score: 5, Insightful

    Just once, JUST ONCE, I'd like our knee-jerking media to actually provide details to the public on how to combat a virus, or trojan horse, or whatever, in the text of their article. I understand the unwashed masses read Yahoo News and Washington Post, but maybe if we started to inform the public on how to find out if you're infected, and how to remove the offending virus, more people would actually check to see if they are infected, and might re-think their surfing & downloading habits.

    I understand the average user can't use Registry Editor, but maybe provide a simple link or website to get a tool to remove the Phatbot thing a ma jig. /end rant

    Happy St. Paddy's Day everyone, btw.

    --
    Check out the best P2P sharing website: MEDIACHEST.COM
  8. paypal? by 2MuchC0ffeeMan · · Score: 5, Insightful

    Joe Stewart, a researcher at the Chicago-based security firm Lurhq, has catalogued Phatbot's many capabilities in an online posting. Those capabilities include: the "ability to polymorph on install in an attempt to evade antivirus signatures as it spreads from system to system"; "steal AOL account logins and passwords"; "harvest emails from the web for spam purposes" and "sniff [Internet] network traffic for Paypal cookies."

    aol, go for it... emails from the web are already public, go for it... paypal cookies? now that's just plain wrong, the feds are going to love that one.

    --
    Runnin' On Empty .... I'm Still Alive
    1. Re:paypal? by justMichael · · Score: 4, Informative

      PayPal Sucks
      PayPal Warning
      About PayPal
      Google

      That ougth to keep you busy for a few days ;)

  9. Description of trojan is slashdotted by phoneboy · · Score: 4, Funny

    I can't find out how the gory details of backdooring a computer. Oh well, I guess I'll have to settle for the more traditional form of pr0n.

    -- PhoneBoy

    --
    The views expressed herein are not necessarily those of anyone, including the poster.
  10. anyone else think by Savatte · · Score: 5, Funny

    PhatBot Trojan would be a good name for a hip-hop group?

  11. Spammer-Sponsored by fembots · · Score: 5, Insightful

    It's hard to believe these kind of trojans are not in any way related to spammers.

    Just take a look at the feature list, it probably has more bells and whistles than most of the software out there.

    Is there a way to trace back the master of these trojans and do something about it? Surely these trojans need to do something for their masters at some stage, probably waiting for commands somewhere.

    1. Re:Spammer-Sponsored by arbitrary+nickname · · Score: 4, Funny

      But with all those features, how big is it? if Microsoft wrote something with all those features it'd probably come on 4 CDs.....

  12. Still Countergrabbable by nweaver · · Score: 4, Insightful

    The authors are getting better at designing control networks, but all it will take is one grayhat with an infected node to watch a command being executed and use that information to take out the entire botnet.

    Too bad it would be both grossly illegal and probably disruptive, because it would be a great favor to the rest of the net, to counter these botnets and squish-them into oblivion (at least this generation, until the attackers learn how to do authentication of commands correctly).

    --
    Test your net with Netalyzr
  13. Re:Detection/Removal instructions? by pwroberts · · Score: 5, Informative

    From the article:

    "Manual Removal
    Look for the following registry keys:

    HKLM\Software\Microsoft\Windows\CurrentVersion\R un \Generic Service Process
    HKLM\Software\Microsoft\Windows\CurrentVe rsion\Run Services\Generic Service Process

    The associated binary may be srvhost.exe, svrhost.exe or a variation of the same. Kill the associated process in the Task Manager, then remove the "Generic Service Process" registry key. Remove the executable from the Windows system directory."

  14. Want to statr the revolution in a hurry? by beacher · · Score: 5, Funny

    1) Extract Windows product keys
    2) ???^H^H^H Email software keys to software@bsa.net and tell them that you think your employer is not running legitimate software. Include a paypal link for the reward
    3) Profit

    This bot looks NASTY.
    -B

    1. Re:Want to statr the revolution in a hurry? by prockcore · · Score: 4, Interesting

      that's pretty ingenius.

      The quickest way to get people to take viruses seriously is to write a virus that reports all their pirated software.

      Most people don't care if their computer has a virus, but once a virus can bust them for all their illegal software, people will wise up in a hurry.

  15. Related links and info by DR+SoB · · Score: 5, Informative

    This is also known as the "Agobot"

    http://news.yahoo.com/fc?tmpl=fc&cid=34&in=tech& ca t=hackers_and_crackers

    http://www.f-secure.com/v-descs/agobot_fo.shtml

    Detailed Description

    First of all, this new variant has 'Phatbot3' identifier and there are a few 'phat' string in its body. This may indicate that this version was not made by the original Agobot backdoor author, who calls himself TheAgo, but by a different person/group who got the source code of this backdoor.

    The backdoor's file is a PE executable 115738 bytes long compressed with PE-Diminisher file compressor. The unpacked file's size is over 245 kilobytes.

    Installation to system

    The Agobot.FO backdoor copies itself as NVCHIP4.EXE file to Windows System folder and creates startup keys for this file in System Registry:
    [HKLM\Software\Microsoft\Windows\Curren tVersion\Ru n]
    "nVidia Chip4" = "nvchip4.exe"
    [HKLM\Software\Microsoft\Windows\Cu rrentVersion\Ru nServices]
    "nVidia Chip4" = "nvchip4.exe"

    This allows the backdoor's file to start with every Windows session. On Windows NT-based systems the backdoor can start as a service.
    Scanning for vulnerable computers

    The backdoor can scan subnets for exploitable computers and send a list of their IPs to the bot operator. The scan is performed on ports 80, 135 and 445 for RPC/DCOM (MS03-026), RPC/Locator (MS03-001) and WebDAV (MS03-007) vulnerabilities. The backdoor can also scan for computers infected with MyDoom worm (port 3127), Bagle worm (port 2745) and also for computers where DameWare remote system management software is installed (port 6129).

    Performing a DDoS attack
    The backdoor can perform the following types of DDoS (Distributed Denial of Service) attacks:
    * HTTP flood * SYN flood * UDP flood * ICMP flood
    When performing a DDoS attack, the backdoor uses 33 unique client identifiers including Mozilla, Wget, Scooter, Webcrawler and Google bot.

    The backdoor sends 256000 bytes of random data to the following websites and checks the response times:
    www.schlund.net
    www.utwente.nl
    www.xo.net
    www.stanford.edu
    www.lib.nthu.edu.tw
    www.st.lib.keio.ac.jp

    Collecting e-mail addresses
    The bot can harvest e-mail addresses. It has the functionality to read user's Address Book and send the list of e-mail addresses to the bot operator.

    Obtainint Registry info
    The backdoor has the functionality to obtain System Registry info from an infected computer. This is a new feature for Agobot backdoor. Information obtained from the Registry can give a hacker a full overview of an infected system.

    Spreading to local network
    Agobot backdoor can scan computers on local network and copy itself there. The scan is initiated by a remote hacker. When spreading to local network, Agobot.FO probes the following shares:
    admin$ c$ d$ e$ print$ c

    Agobot.FO tries to connect using the following account names:
    (SEE LINKS AT TOP FOR INFORMATION)

    When connecting, Agobot.FO uses the following passwords:
    (SEE LINKS AT TOP FOR DETAILS)

    If the worm succeeds connecting to the above listed shares, it copies itself to a remote share and attempts to start that file as a service. The alternative way of infecting a remote host is to create a scheduled task on a remote computer that will start the backdoor's file.

    Teminating processes of security and anti-virus programs
    Agobot.FO has a huge list of process file names hardcoded in its body. The backdoor tries to terminate processes that have the following names:
    (NAMES REMOVED SO POST WOULD WORK, FOLLOW LINKS AT TOP)

    This functionality allows the backdoor to successfully disable anti-virus and security software that can not detect this backdoor before it's file is started. In most cases special tools are required to clean a computer infected with this backdoor.

    Additionally the

    --
    Mod +5 Drunk
  16. Lucky me by mixtape5 · · Score: 5, Funny

    is installed maliciously on broadband-connected computers...
    who knew that dial up internet was a form of virus protection? I dont feel so bad anymore!


    --
    WoW: Scheod 70 orc warlock on Shadowmoon
  17. virus news = spam by erikdotla · · Score: 4, Insightful

    I see where you're coming from here. However, there's other considerations. Some of us must operate Windows boxes, so we must deal with it.

    Obviously the "security-by-news-alert" method of keeping your systems secure is stupid. We must still update our AVs and Spy cleaners and run them regularly. If we do that, we'll get almost every virus and spyware and never have to worry.

    But some of like to know what the virus writers are doing. Trends in the virus business, as they evolve.

    Some of us may have firewalls that we might wish to alter based on major recent virus activity. I'm sure the Blaster variants caused several admins to alter the RPC port configuration of their firewalls.

    Isn't it better to be proactive rather than reacting to a virus-based DOS?

    I agree, of course, that people shouldn't email their buddies "OMG VIRUS ALERT!!!111one!!11" as we are able to keep up on virus news ourselves. We don't need these emails.

    The value of Slashdot posting a breaking story about a virus is early-warning in the event that we're sitting around reading Slashdot instead of doing our jobs and monitoring the other virus news systems. :)

    --
    # Erik
  18. The power of viruses by mcrbids · · Score: 4, Interesting

    I have a client who sends out an aviation newsletter, with a list size in the tens of thousands. They have their own dedicated mail server, running RH Linux that I set up for them. Email is virus filtered with MailScanner and f-prot.

    No complaints for months. And then, I add a new account to the mail server and restart sendmail.

    Within a few hours, I got complaints that the volume of email had at least tripled, and that *all* of the increase were viruses, being caught by McAffee! So bad it was difficult to simply empty out the inbox from all the popup notices of virus detection!

    Turns out when I restarted sendmail, I didn't restart MailScanner, so it was not running, letting everything through.

    Very sobering, to realize how bad viruses online have gotten...

    --
    I have no problem with your religion until you decide it's reason to deprive others of the truth.
    1. Re:The power of viruses by thedillybar · · Score: 4, Funny
      Very sobering, to realize how bad viruses online have gotten...

      Oh good...I'm not the only one that restarts sendmail when I'm drunk...

  19. For a mainframe version... by Ungrounded+Lightning · · Score: 4, Informative

    How long before someone bootstraps a distributed Artificial life simulator to their virus and then we all watch in amazement as the first AI evolves and owns all our computers. This could never happen though...right?

    For a mainframe version of the story see _The Adolescence of P1_.

    (I'd dig up an Amazon link but I'm busy right now.)

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
    1. Re:For a mainframe version... by Phexro · · Score: 4, Funny

      Jesus god, Amazon needs to partner with Google. Searching for that title got me several search results, including:

      * 'The Phallus Palace: Female to Male Transsexuals'
      * 'Clinical Neurology: A Modern Approach (Paper)'
      * 'The World Almanac and Book of Facts 2004'
      * 'When Girls Feel Fat: Helping Girls Through Adolescence'
      * 'Principles of Frontal Lobe Function'

      Whoever coded their search engine could use some advice from that last title.

      Here's the correct link.

  20. Mirror by httptech · · Score: 4, Informative
    Here's a mirror of my analysis:

    http://www.joestewart.org/phatbot.html

    -Joe

  21. Interesting that by Doofus · · Score: 4, Interesting

    I find it interesting that I submitted this story shortly after 0900 EST in an effort to get the word out to /. readers, but it was rejected.

    Was I wrong to consider using /. as an effective way to communicate issues like this to the technical community, or am I just bitching because my story was rejected?

    Good luck everyone out there who should be checking/cleaning your systems -

    --
    If the Government becomes a lawbreaker, it breeds contempt for law; ... it invites anarchy. - Brandeis
  22. Suspicious... by Phisbut · · Score: 4, Interesting

    A quick search on McAfee and Symantec websites yielded no result for "phatbot" on Symantec, and a 18 months old virus on McAfee...

    If the US government is announcing this publically, and the virus has already infected "hundreds of thousands of computers already", wouldn't the anti-virus companies *know* that?!?

    --
    After 3 days without programming, life becomes meaningless
    - The Tao of Programming
    1. Re:Suspicious... by httptech · · Score: 4, Informative

      Some AV companies consider this a variant of Agobot/Gaobot, since it shares a lot of the same code base. Which is funny, because when I analyzed Doomjuice and called it "MyDoom.C", they all said it was too different to be called a MyDoom variant (even though it was the same code with functionality removed).

      I consider the addition of the WASTE code and removal of the IRC code to be significant enough to call this by a new name. Not to mention all the other added features that are not part of the Agobot code.

      -Joe

  23. The good 'ol days by Ibanez · · Score: 4, Insightful

    What the hell happened to them? You know, when you used to download a program off of FTP or Firstclass, forgot to scan it for viruses, installed it, had your harddrive wiped clean. And then you had to reinstall from your backup floppies, and had no one to blame but your own stupid self?

    Now its not your fault, and it hurts you as well as everyone else!

  24. From the LURHQ alert by burgburgburg · · Score: 4, Informative
    Google cache:

    Manual Removal
    Look for the following registry keys:

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run \Generic Service Process
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services\Generic Service Process

    The associated binary may be srvhost.exe, svrhost.exe or a variation of the same. Kill the associated process in the Task Manager, then remove the "Generic Service Process" registry key. Remove the executable from the Windows system directory.

    Snort Signatures
    Here are some Snort signatures to detect Phatbot on a network:

    alert tcp any any -> any any (msg:"Agobot/Phatbot Infection Successful"; flow:established; content:"221 Goodbye, have a good infection |3a 29 2e 0d 0a|"; dsize:40; classtype:trojan-activity; reference:url,www.lurhq.com/phatbot.html; sid:1000075; rev:1;)

    alert tcp any any -> any any (msg:"Phatbot P2P Control Connection"; flow:established; content:"Wonk-"; content:"|00|#waste|00|"; within:15; classtype:trojan-activity; reference:url,www.lurhq.com/phatbot.html; sid:1000076; rev:1;)

  25. Nullsoft Waste code used? Open source scariness.. by Anubis333 · · Score: 4, Interesting


    Here is a problem I had never thought about with open source initiatives. What happens when someone steals your source without obeying GPL or anything and turns it into a monster? It would have ben *MUCH* harder for the PhatBot authors to code their own Waste-like clustering P2P system. Perhaps they might not have even been able to do so. Instead they grab an open source app and use it to create something ilegal, and in this case even dangerous.

    These are the same problems faced in the emulation field. Many open source emu programmers do not allow any game from the past 2-3 years to be played, mainly to appease the corporations that still make arcade titles (SNK etc). But people open up their source and release renegade versions of their own apps without their permission and in violation of GPL and everything, often packaging them with illegal arcade ROMs.

  26. Re:what else is new? by rixstep · · Score: 4, Insightful

    hey really only seem to hurt people who are already pretty ignorant

    The word 'only' is misplaced. The Internet is full of idiots. They're in the majority.

    They get the shit kicked out of them every time they go online. They take their junky Gateways back to PC shops to 'wipe and reinstall' every six months. They lose files because 'I know I didn't download that file to my hard drive - I downloaded it to my desktop instead' and then they can't find it.

    You tell them the simplest things to get them out of the most complex situations and they demand 'user friendly'. They want products that cure only the latest ill and demand at most one mouse click.

    Wonder of wonders the world (the Internet) is as it is. And wonder of wonders is that it's taken the sophisticated malware engineers so long to get sophisticated.

    There's a slaughter going on, and although MS are responsible with their crappy stuff, the users are also responsible - for using it. And I hope we've heard the last of that classic line 'it only affects Windows users', because it should be evident to even the most brain-dead MS fanatic at this point that the entire Internet is affected.

    It's time to put up some housing ordinances so MS users aren't allowed to ruin the neighbourhood. High time and beyond.

  27. Re:Jesus. by grub · · Score: 4, Funny


    "Problem lies between Keyboard and Chair".

    At work we say "It was a Layer 8 problem". You can say that in front of non-geeks without them catching on.

    --
    Trolling is a art,
  28. possible hoax? by KaiserZoze_860 · · Score: 4, Interesting

    Hi Everyone

    As many people have pointed out there is an utter lack of response by the top three anti-virus companies to this threat. I find this disturbing and also, unlikely. Why would the Department of Homeland Defense have better intelligence on a clearly US based threat (Phat is not an international phrase by any means) than the people who make their lively hood based on threat detection and elimination?

    This has to me the markings of a hoax. The list of *features* as one poster put it is indeed staggering. That, coupled with the silence coming from Symantec, McAfee et al. makes it look fishy. A google search shows one recent post and a bunch of older hits (possibly the same as in the McAfee search ).

    So that leaves me with 3 questions:
    1 - Is it real
    2 - How do we detect it
    3 - How do we kill it.

    --KS

  29. The meaning of "Trojan" by groomed · · Score: 4, Insightful

    Well, I suppose it's a lost cause (as with the "hacker" term), but I it can't hurt to point out that it really doesn't make much sense to call this program a "trojan".

    The article suggests that this is a "trojan" because it lets attackers stealthily take control of your computer. But that was not what was remarkable about the historical Trojan horse. What was remarkable about it is that it was presented as a gift. The distinguishing characteric of a trojan is that it has a friendly outward appearance but contains a deadly payload. That's certainly not the case with Phatbot.

    Rather, I'd say that Phatbot is a virus, because a) it is malicious and b) it doesn't rely on deception to spread itself. This is, again, subtly different from a worm, which generally aren't malicious, just annoying.

    Of course it's water under the bridge at this point.

  30. Stories rejected by slashdot by LinuxParanoid · · Score: 4, Interesting

    I've never had a story accepted either, and on a number of occassions I've submitted stories hours, days or weeks before the topic appeared on Slashdot. It's pretty common; I wouldn't make anything out of it. It's quite possible that someone submitted the story before you did even earlier in the morning and the editors put that one in the queue to go up at 2:43PM. They pre-scheduled the various stories that go up hours (and sometimes even days?) in advance. Or perhaps they decided it was a worthy story after they saw the 27th submission of it.

    I realized one day that we could essentially have a user-contributed, user-moderated article queue of sorts using the journaling system here. I've dedicated my journal to it. I haven't figured out how to draw larger traffic to it without making this a part-time job, but you're welcome to contribute to it and I welcome suggestions.

    --LP

  31. even better by Anonymous Coward · · Score: 5, Funny

    Have it grep the HD for pr0n keywords, and mail the results to Outlook's Adressbook. After that, nobody would think little of viruses ever again...
    (here in double-moral country, that is)