Trojan.Boxed.A

Printer Friendly Page

Discovered: June 15, 2004
Updated: June 16, 2004 12:15:21 AM
Systems Affected: Windows

Trojan.Boxed.A is a trojan that attempts to perform a Denial of Service attack on certain websites. It also terminates services associated with antivirus software, and denies access to antivirus websites.


Technical Description

When run, Trojan.Boxed.A attempts to delete the following services:
wuauserv
navapsvc
Symantec Core LC
SAVScan
kavsvc
Network Client
Network Client Monitor

It then sets itself to run as a service with the name "nwclnt", and the display name "Network Client". This service will automatically run at startup.

It performs a Denial of Service attack on the following websites:
images.gamemaniacs.org
secure.bootcom.com
pop3.bootcom.com
mail.bootcom.com
ftp.bootcom.com
www.bootcom.com

It replaces the existing %System%\drivers\etc\hosts file with one that contains the following text, so that any attempts to connect to these Web sites will fail:
127.0.0.1 ids.kaspersky-labs.com
127.0.0.1 downloads2.kaspersky-labs.com
127.0.0.1 downloads1.kaspersky-labs.com
127.0.0.1 downloads3.kaspersky-labs.com
127.0.0.1 downloads4.kaspersky-labs.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 update.symantec.com
127.0.0.1 download.mcafee.com
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com
127.0.0.1 www.grisoft.com