BD Glacier 2.2
Severity: High
This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.
Description
This signature detects Backdoor Glacier 2.2 activity.
Additional Information
Backdoor Glacier 2.2 is a Trojan that opens up a backdoor program that, once installed on a system, permits unauthorized users to remotely perform a variety of operations, such as changing the registry, executing commands, starting services, listing files, and uploading or downloading files. Glacier typically runs from the server files "C:\WINDOWS\SYSTEM\KERNEL32.EXE" and "C:\WINDOWS\SYSTEM\SYSEXPLR.EXE" over port 7626 via TCP.
Aliases: Backdoor.Delf.ax, Backdoor.G_Door, Trojan.PSW.Glacier
Affected:
Microsoft Windows 2000 Advanced Server SP1, SP2, SP3, SP4
Microsoft Windows 2000 Datacenter Server SP1, SP2, SP3, SP4
Microsoft Windows 2000 Professional SP1, SP2, SP3, SP4
Microsoft Windows 2000 Resource Kit
Microsoft Windows 2000 Server SP1, SP2, SP3, SP4
Microsoft Windows 2000 Server Japanese Edition
Microsoft Windows 2000 Terminal Services SP1, SP2, SP3, SP4
Microsoft Windows 2000 Workstation rev.2031, rev.2072, rev.2195, SP1, SP2, SP3
Microsoft Windows 95 Build 490.R6, j, SP1, SR2
Microsoft Windows 98 a, b, j, SP1
Microsoft Windows 98 With Plus! Pack
Microsoft Windows 98SE
Microsoft Windows CE 2.0, 3.0, 4.2
Microsoft Windows ME
Microsoft Windows NT 3.5, 3.5.1, 3.5.1 SP1, 3.5.1 SP2, 3.5.1 SP3, 3.5.1 SP4, 3.5.1 SP5, 3.5.1 SP5 alpha, 4.0, 4.0 alpha, 4.0 SP1, 4.0 SP1 alpha, 4.0 SP2, 4.0 SP2 alpha, 4.0 SP3, 4.0 SP3 alpha, 4.0 SP4, 4.0 SP4 alpha, 4.0 SP5, 4.0 SP5 alpha, 4.0 SP6, 4.0 SP6 alpha, 4.0 SP6a, 4.0 SP6a alpha
Microsoft Windows NT 4.0 Option Pack
Microsoft Windows NT Enterprise Server 4.0, 4.0 SP1, 4.0 SP2, 4.0 SP3, 4.0 SP4, 4.0 SP5, 4.0 SP6, 4.0 SP6a
Microsoft Windows NT Server 4.0, 4.0 SP1, 4.0 SP2, 4.0 SP3, 4.0 SP4, 4.0 SP5, 4.0 SP6, 4.0 SP6a
Microsoft Windows NT Terminal Server 4.0, 4.0 alpha, 4.0 SP1, 4.0 SP2, 4.0 SP3, 4.0 SP4, 4.0 SP5, 4.0 SP6, 4.0 SP6a
Microsoft Windows NT Workstation 4.0, 4.0 SP1, 4.0 SP2, 4.0 SP3, 4.0 SP4, 4.0 SP5, 4.0 SP6, 4.0 SP6a
Microsoft Windows Server 2003 Datacenter Edition SP1, SP1 Beta 1
Microsoft Windows Server 2003 Datacenter Edition Itanium SP1, SP1 Beta 1
Microsoft Windows Server 2003 Datacenter x64 Edition
Microsoft Windows Server 2003 Enterprise Edition SP1, SP1 Beta 1
Microsoft Windows Server 2003 Enterprise Edition Itanium SP1, SP1 Beta 1
Microsoft Windows Server 2003 Enterprise x64 Edition
Microsoft Windows Server 2003 Standard Edition SP1, SP1 Beta 1
Microsoft Windows Server 2003 Standard x64 Edition
Microsoft Windows Server 2003 Web Edition SP1, SP1 Beta 1
Microsoft Windows Vista beta
Microsoft Windows XP
Microsoft Windows XP 64-bit Edition SP1
Microsoft Windows XP 64-bit Edition Version 2003 SP1
Microsoft Windows XP Embedded SP1
Microsoft Windows XP Home SP1, SP2
Microsoft Windows XP Media Center Edition SP1, SP2
Microsoft Windows XP Professional SP1, SP2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows XP Tablet PC Edition SP1, SP2
Response
There are several Backdoor detection programs on the market that are said to be able to scan for and detect a Backdoor Glacier 2.2 server on your system. Some of the better known AntiVirus vendors have included detection strings in their virus definitions.
Possible False Positives
There are no known false positives associated with this signature.
Additional References
|