1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. HTTP TrafficJam Activity

HTTP TrafficJam Activity

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detect Adware.TrafficJam communicating and requesting information from its controlling server.

Additional Information

Once Dialer.Trafficjam is executed, it creates the following files:

* %CommonProgramFiles%\tjd\tjeeze.exe
* %CommonProgramFiles%\tjd\amstercam uk.exe
* %CommonProgramFiles%\tjd\amstercam.exe
* %SystemDrive%\Documents and Settings\All Users\Start Menu\tjeeze.lnk
* %SystemDrive%\Documents and Settings\All Users\Start Menu\amstercam uk.lnk
* %SystemDrive%\Documents and Settings\All Users\Start Menu\amstercam.lnk
* %SystemDrive%\Documents and Settings\All Users\Desktop\amstercam uk.lnk
* %SystemDrive%\Documents and Settings\All Users\Desktop\amstercam.lnk
* %SystemDrive%\Documents and Settings\All Users\Desktop\tjeeze.lnk

It may also drop the following file:
C:\Program Files\Common Files\delsim\del.exe

It then adds a section called "[tjeeze]" to the following file:
%SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk

It also creates the following registry subkey:
HKEY_CURRENT_USER\Software\Trafficjam

The risk then modifies the following registry key so that Internet Explorer navigates to http://yourxs.nl when it is executed:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Start Page" = "http://yourxs.nl"

The security risk then opens a dialog box to dial preset high-cost numbers using a modem.

Affected

  • Windows 2000
  • Windows 95
  • Windows 98
  • Windows Me
  • Windows NT
  • Windows XP

Response

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Run a full system scan.
4. Delete any values added to the registry.
5. Delete the entries added to the RAS phonebook file.
6. Reset the Internet Explorer home page.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube