1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. HTTP Remacc MultiWebSurv Activity

HTTP Remacc MultiWebSurv Activity

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects activities of remote access software Remacc.MultiWebSurv.

Additional Information

When the program is executed, it creates the following files:

* C:\Documents and Settings\Administrator\Desktop\Multi-Webcam Surveillance System(Client).lnk
* %Temp%\irsetup.exe
* C:\Documents and Settings\All Users\Start Menu\Programs\Multi-Webcam Surveillance System\Multi-Webcam Surveillance System(Client).lnk
* C:\Documents and Settings\All Users\Start Menu\Programs\Multi-Webcam Surveillance System\Multi-Webcam Surveillance System(Server).lnk
* C:\Documents and Settings\All Users\Start Menu\Programs\Multi-Webcam Surveillance System\Uninstall Multi-Webcam Surveillance System.lnk
* %ProgramFiles%\Multi-Webcam Surveillance System\Client\MSRDClient.dll
* %ProgramFiles%\Multi-Webcam Surveillance System\Client\ScreenClient.exe
* %ProgramFiles%\Multi-Webcam Surveillance System\Client\setup.cfg
* %ProgramFiles%\Multi-Webcam Surveillance System\irunin.dat
* %ProgramFiles%\Multi-Webcam Surveillance System\irunin.ini
* %ProgramFiles%\Multi-Webcam Surveillance System\irunin.lng
* %ProgramFiles%\Multi-Webcam Surveillance System\Server\MSRDServer.exe
* %ProgramFiles%\Multi-Webcam Surveillance System\Server\MSRDService.exe
* %ProgramFiles%\Multi-Webcam Surveillance System\Server\othread2.dll
* %ProgramFiles%\Multi-Webcam Surveillance System\Server\sshooks.dll
* %ProgramFiles%\Multi-Webcam Surveillance System\Server\VideoService.exe
* %ProgramFiles%\Multi-Webcam Surveillance System\sys.ini
* %Windir%\system32\xvid.inf
* %Windir%\system32\xvidcore.dll
* %Windir%\system32\xvidvfw.dll
* %Windir%\iun6002.exe
* %Windir%\Multi-Webcam Surveillance System Setup Log.txt



Next, the program creates the following registry subkeys:

* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Multi_Screen_Spy_2.2
* HKEY_CURRENT_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Multi-Webcam Surveillance System



It then creates the folllowing registry entry:
HKEY_LOCAL_MACHINE\SYSTEM\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\"C:\Program Files\Multi-Webcam Surveillance System\Client\ScreenClient.exe" = "C:\Program Files\Multi-Webcam Surveillance System\Client\ScreenClient.exe"

The program can be used to secretly monitor and control any computer on the local area network.

Affected

  • Windows 98
  • Windows 95
  • Windows XP
  • Windows Me
  • Windows Vista
  • Windows NT
  • Windows Server 2003
  • Windows 2000

Response

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Run a full system scan.
4. Delete any values added to the registry.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube