![]() |
|
|
#1 |
|
Guest
Posts: n/a
|
A new self-replicating Malware (Virus and Worm) attacks!!!
Dear Sir or Madam,
A new computer worm is attacking the computers around the world, the serious problem is the most of the anti viruses cannot detect & clean it... also the removal tool was not available on the Internet... other serious problem presents when some of current anti viruses detect this virus as other kind of virus (Worm 32 family) ... and usually these antivirus delete the whole infected file (exe & autorun.inf ... ext)... This virus infects computer, for instance by: - Infecting the local hard disk drivers & executable applications - Carrying himself on a removable medium such as a floppy disk, CD, or USB drive. - Sending himself over a local network or the Internet. This virus can spread to other computers by infecting files on a network file system or a file system that is accessed by another computer. - Adding keys into Windows registry This virus is mixture between worms, virus and maybe Trojan; he is a self-replicating computer program, attaches itself to existing programs in the infected PC (modify files on a targeted computer). It confused with computer worms. He can spread itself to other computers without needing to be transferred as part of a host. And usually this mixture of a computer worm and virus may be a Trojan horse too... This virus blurring the line between viruses and worms (maybe Trojan too) actually it is self-replicating Malware. Description: Nobody sure yet about the name of this new virus... Saturday, November 03, 2007 I submitted the virus exe file to "Virustotal" (Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, Trojans, and all kinds of Malware detected by antivirus engines) and I got these results: Antivirus Result AVG Worm/Generic.DKD BitDefender Win32.Worm.P2P.VBT CAT-QuickHeal Worm.AutoRun.tk F-Secure Virus.Win32.AutoRun.tk Ikarus Win32.Worm.P2P.VBT Kaspersky Virus.Win32.AutoRun.tk Panda Suspicious file Sophos W32/Dawin-A VBA32 Virus.Win32.AutoRun.tk The manger antivirus engines give different name for this virus (Malware); I think that means two things: 1- There is no specific name of this virus 2- Each antivirus engine handles this virus in a different way. And does not detect the latest version of him (detects him as other kind of virus - Worm 32 family) Technical Details: When executed, the virus drops file / component (a copy of itself) "KB915865.exe" in all physical drives. That includes too all removable drives, such as flash disks. It creates the folder "\MSOCache \90000804-6000-11D3-8CFE-0150048383C9\" in drives it affects, and drops a copy of itself as "KB915865.exe" This folder is set to Hidden and System. \MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe Also it drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed. The said file contains the following strings: [AutoRun] open=.\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe . shellexecute=.\MSOCache \90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe . shell\Open\command=.\MSOCache \90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe . shell=Open open=. This virus creates registry entries to enable its automatic execution at every system startup. Platform: This worm affects systems running on Windows 98, ME, NT, 2000, XP, and Server 2003. Solution: I wrote a specific removal tool for this virus (e-nil! Virus Cleaner), it is free and available on my blog: http://www.e-nil.com/blogs/?page_id=32 For more information or details please do not hesitation to contact me Best regards and have a nice day, Hani Simo |
|
|
|
#2 |
|
Guest
Posts: n/a
|
Re: A new self-replicating Malware (Virus and Worm) attacks!!!
hanisimo wrote:
> Dear Sir or Madam, > > A new computer worm is attacking the computers around the world, the > serious problem is the most of the anti viruses cannot detect & clean > it... also the removal tool was not available on the Internet... other > serious problem presents when some of current anti viruses detect this > virus as other kind of virus (Worm 32 family) ... and usually these > antivirus delete the whole infected file (exe & autorun.inf ... ext)... (snippage) There's nothing new about this and there are tried and true ways of removing the infection. Your tool might be 100% legitimate and excellent but I wouldn't suggest that Windows users run an executable from an unknown person. Please do not take this as an insult to your honor or mad skilz; it is not meant that way at all. You might want to post in one of the known specialty forums for fighting malware to introduce yourself and your removal tool. http://www.atribune.org/forums/index.php?showforum=9 http://aumha.net/viewforum.php?f=30 http://www.bleepingcomputer.com/forums/forum22.html http://castlecops.com/forum67.html http://www.dslreports.com/forum/cleanup http://www.cybertechhelp.com/forums/...splay.php?f=25 http://www.geekstogo.com/forum/Malwa..._Here-f37.html Malke -- Elephant Boy Computers www.elephantboycomputers.com "Don't Panic!" MS-MVP Windows - Shell/User |
|
|
|
#3 |
|
Guest
Posts: n/a
|
Re: A new self-replicating Malware (Virus and Worm) attacks!!!
Thank you.
-- Xandros "hanisimo" <hanisimo@gmail.com> wrote in message news:1195041429.119517.103540@50g2000hsm.googlegro ups.com... > Dear Sir or Madam, > > A new computer worm is attacking the computers around the world, [snip] > Solution: > I wrote a specific removal tool for this virus (e-nil! Virus Cleaner), > it is free and available on my blog: > > Best regards and have a nice day, > Hani Simo > |
|
|
|
#4 |
|
Guest
Posts: n/a
|
Re: A new self-replicating Malware (Virus and Worm) attacks!!!
For all we know this cleaning app may contain more viri or malware.
-- ---- Crosspost, do not multipost http://www.blakjak.demon.co.uk/mul_crss.htm How to ask a question http://support.microsoft.com/kb/555375 __________________________________________________ _______________________________ "Xandros" <arron.neus*remove*@gmailcom> wrote in message news:%23nt1fwsJIHA.4684@TK2MSFTNGP06.phx.gbl... > Thank you. > > -- > > Xandros > > > "hanisimo" <hanisimo@gmail.com> wrote in message > news:1195041429.119517.103540@50g2000hsm.googlegro ups.com... >> Dear Sir or Madam, >> >> A new computer worm is attacking the computers around the world, > [snip] >> Solution: >> I wrote a specific removal tool for this virus (e-nil! Virus Cleaner), >> it is free and available on my blog: >> >> Best regards and have a nice day, >> Hani Simo >> > > |
|
|
|
#5 |
|
Guest
Posts: n/a
|
Re: A new self-replicating Malware (Virus and Worm) attacks!!!
Well I just ran it and it does a lot of false reporting which makes it
malware to be certain!!!!! -- Xandros "David B." <brooks.dj@nomail.com> wrote in message news:eZwPChtJIHA.3356@TK2MSFTNGP02.phx.gbl... > For all we know this cleaning app may contain more viri or malware. > > -- > > ---- > Crosspost, do not multipost http://www.blakjak.demon.co.uk/mul_crss.htm > How to ask a question http://support.microsoft.com/kb/555375 > __________________________________________________ _______________________________ > > > "Xandros" <arron.neus*remove*@gmailcom> wrote in message > news:%23nt1fwsJIHA.4684@TK2MSFTNGP06.phx.gbl... >> Thank you. >> >> -- >> >> Xandros >> >> >> "hanisimo" <hanisimo@gmail.com> wrote in message >> news:1195041429.119517.103540@50g2000hsm.googlegro ups.com... >>> Dear Sir or Madam, >>> >>> A new computer worm is attacking the computers around the world, >> [snip] >>> Solution: >>> I wrote a specific removal tool for this virus (e-nil! Virus Cleaner), >>> it is free and available on my blog: >>> >>> Best regards and have a nice day, >>> Hani Simo >>> >> >> > |
|
|
|
#6 |
|
Guest
Posts: n/a
|
Re: A new self-replicating Malware (Virus and Worm) attacks!!!
Hey hanisimo. I take back me Thank you. I just ran your app and it is giving
off a ton of false reports! tsk, tsk, tsk -- Xandros "hanisimo" <hanisimo@gmail.com> wrote in message news:1195041429.119517.103540@50g2000hsm.googlegro ups.com... > Dear Sir or Madam, > snip > > Solution: > I wrote a specific removal tool for this virus (e-nil! Virus Cleaner), > it is free and available on my blog: > snip > For more information or details please do not hesitation to contact me > > Best regards and have a nice day, > Hani Simo > |
|
|
|
#7 |
|
Guest
Posts: n/a
|
Re: A new self-replicating Malware (Virus and Worm) attacks!!!
Xandros wrote:
> Hey hanisimo. I take back me Thank you. I just ran your app and it is > giving off a ton of false reports! tsk, tsk, tsk > > > "hanisimo" <hanisimo@gmail.com> wrote in message > news:1195041429.119517.103540@50g2000hsm.googlegro ups.com... >> Dear Sir or Madam, >> > snip >> >> Solution: >> I wrote a specific removal tool for this virus (e-nil! Virus >> Cleaner), it is free and available on my blog: >> > snip >> For more information or details please do not hesitation to contact >> me Best regards and have a nice day, >> Hani Simo I hope you're not really surprised. I also hope it didn't drop a bunch of other malware on your machine in the process; that's typical of these kinds of spams. NEVER, EVER, respond to, or click any link in any unsolicited e-mails, in newsgroups or in your Inbox. It's a sure way to become infected eventually, and to propogate personal information to anyone from a spammer to an identification theft outfit. Spammers even know now how to handle common address obfuscations such as *REMOVE* and pull an address out of it. You'd be much better off switching to an impossible address such as invalid.invalid.invalid or one of the many others offered by various web sites for the purpose. Check my Headers for one of those if you're curious; I don't want to spam it here. The ONLYresponses acceptable to spam is to delete it unread, or to submit complaints about it to the relevant ISPs that originated it, but you have to know how to parse for forged Headers to do that. Pop` |
|
|
|
#8 |
|
Guest
Posts: n/a
|
Re: A new self-replicating Malware (Virus and Worm) attacks!!!
Hopefully that's all it's doing.
-- ---- Crosspost, do not multipost http://www.blakjak.demon.co.uk/mul_crss.htm How to ask a question http://support.microsoft.com/kb/555375 __________________________________________________ _______________________________ "Xandros" <arron.neus*remove*@gmailcom> wrote in message news:uxKBU34JIHA.5400@TK2MSFTNGP04.phx.gbl... > Hey hanisimo. I take back me Thank you. I just ran your app and it is > giving off a ton of false reports! tsk, tsk, tsk > > -- > > Xandros > > > "hanisimo" <hanisimo@gmail.com> wrote in message > news:1195041429.119517.103540@50g2000hsm.googlegro ups.com... >> Dear Sir or Madam, >> > snip >> >> Solution: >> I wrote a specific removal tool for this virus (e-nil! Virus Cleaner), >> it is free and available on my blog: >> > snip >> For more information or details please do not hesitation to contact me >> >> Best regards and have a nice day, >> Hani Simo >> > > |
|
|
|
#9 |
|
Guest
Posts: n/a
|
Re: A new self-replicating Malware (Virus and Worm) attacks!!!
http://en.wikipedia.org/wiki/Xandros
~~~~ Gerry ~~~~ FCA Stourport, England Enquire, plan and execute ~~~~~~~~~~~~~~~~~~~ Poprivet wrote: > Xandros wrote: >> Hey hanisimo. I take back me Thank you. I just ran your app and it is >> giving off a ton of false reports! tsk, tsk, tsk >> >> >> "hanisimo" <hanisimo@gmail.com> wrote in message >> news:1195041429.119517.103540@50g2000hsm.googlegro ups.com... >>> Dear Sir or Madam, >>> >> snip >>> >>> Solution: >>> I wrote a specific removal tool for this virus (e-nil! Virus >>> Cleaner), it is free and available on my blog: >>> >> snip >>> For more information or details please do not hesitation to contact >>> me Best regards and have a nice day, >>> Hani Simo > > I hope you're not really surprised. I also hope it didn't drop a > bunch of other malware on your machine in the process; that's typical > of these kinds of spams. > > NEVER, EVER, respond to, or click any link in any unsolicited > e-mails, in newsgroups or in your Inbox. It's a sure way to become > infected eventually, and to propogate personal information to anyone > from a spammer to an identification theft outfit. Spammers even know > now how to handle common address obfuscations such as *REMOVE* and > pull an address out of it. You'd be much better off switching to an > impossible address such as invalid.invalid.invalid or one of the many > others offered by various web sites for the purpose. Check my > Headers for one of those if you're curious; I don't want to spam it > here. > The ONLYresponses acceptable to spam is to delete it unread, or to > submit complaints about it to the relevant ISPs that originated it, > but you have to know how to parse for forged Headers to do that. > > Pop` |
|
|
|
#10 |
|
Guest
Posts: n/a
|
Re: A new self-replicating Malware (Virus and Worm) attacks!!!
"Poprivet" <poprivet@devnull.spamcop.net> wrote in message
news:O$%23cQ56JIHA.1620@TK2MSFTNGP03.phx.gbl... > Xandros wrote: >> Hey hanisimo. I take back me Thank you. I just ran your app and it is >> giving off a ton of false reports! tsk, tsk, tsk >> >> >> "hanisimo" <hanisimo@gmail.com> wrote in message >> news:1195041429.119517.103540@50g2000hsm.googlegro ups.com... >>> Dear Sir or Madam, >>> >> snip >>> >>> Solution: >>> I wrote a specific removal tool for this virus (e-nil! Virus >>> Cleaner), it is free and available on my blog: >>> >> snip >>> For more information or details please do not hesitation to contact >>> me Best regards and have a nice day, >>> Hani Simo > > I hope you're not really surprised. I also hope it didn't drop a bunch of > other malware on your machine in the process; that's typical of these > kinds of spams. > > NEVER, EVER, respond to, or click any link in any unsolicited e-mails, in > newsgroups or in your Inbox. It's a sure way to become infected > eventually, and to propogate personal information to anyone from a spammer > to an identification theft outfit. Spammers even know now how to handle > common address obfuscations such as *REMOVE* and pull an address out of > it. > You'd be much better off switching to an impossible address such as > invalid.invalid.invalid or one of the many others offered by various web > sites for the purpose. Check my Headers for one of those if you're > curious; I don't want to spam it here. > > The ONLYresponses acceptable to spam is to delete it unread, or to submit > complaints about it to the relevant ISPs that originated it, but you have > to know how to parse for forged Headers to do that. > > Pop` > My arron.neus account is quite safe (erroneus) But thanks anyway. -- Xandros |
|
![]() |
| Tags: attacks, malware, selfreplicating, virus, worm |
| Thread Tools | |
| Display Modes | |
|
|