TechTalkz.com Logo

Go Back   TechTalkz.com Technology & Computer Troubleshooting Forums > Tech Support Archives > Microsoft > Windows XP

Reply
 
Thread Tools Display Modes
Old 14-11-2007, 05:27 PM   #1
hanisimo
Guest
 
Posts: n/a
A new self-replicating Malware (Virus and Worm) attacks!!!

Dear Sir or Madam,

A new computer worm is attacking the computers around the world, the
serious problem is the most of the anti viruses cannot detect & clean
it... also the removal tool was not available on the Internet... other
serious problem presents when some of current anti viruses detect this
virus as other kind of virus (Worm 32 family) ... and usually these
antivirus delete the whole infected file (exe & autorun.inf ... ext)...

This virus infects computer, for instance by:

- Infecting the local hard disk drivers & executable applications

- Carrying himself on a removable medium such as a floppy disk, CD, or
USB drive.

- Sending himself over a local network or the Internet. This virus can
spread to other computers by infecting files on a network file system
or a file system that is accessed by another computer.

- Adding keys into Windows registry

This virus is mixture between worms, virus and maybe Trojan; he is a
self-replicating computer program, attaches itself to existing
programs in the infected PC (modify files on a targeted computer). It
confused with computer worms. He can spread itself to other computers
without needing to be transferred as part of a host. And usually this
mixture of a computer worm and virus may be a Trojan horse too...

This virus blurring the line between viruses and worms (maybe Trojan
too) actually it is self-replicating Malware.

Description:
Nobody sure yet about the name of this new virus... Saturday, November
03, 2007 I submitted the virus exe file to "Virustotal" (Virustotal is
a service that analyzes suspicious files and facilitates the quick
detection of viruses, worms, Trojans, and all kinds of Malware
detected by antivirus engines) and I got these results:

Antivirus Result

AVG Worm/Generic.DKD

BitDefender Win32.Worm.P2P.VBT

CAT-QuickHeal Worm.AutoRun.tk

F-Secure Virus.Win32.AutoRun.tk

Ikarus Win32.Worm.P2P.VBT

Kaspersky Virus.Win32.AutoRun.tk

Panda Suspicious file

Sophos W32/Dawin-A

VBA32 Virus.Win32.AutoRun.tk

The manger antivirus engines give different name for this virus
(Malware); I think that means two things:

1- There is no specific name of this virus

2- Each antivirus engine handles this virus in a different way. And
does not detect the latest version of him (detects him as other kind
of virus - Worm 32 family)

Technical Details:

When executed, the virus drops file / component (a copy of itself)
"KB915865.exe" in all physical drives. That includes too all removable
drives, such as flash disks. It creates the folder "\MSOCache
\90000804-6000-11D3-8CFE-0150048383C9\" in drives it affects, and
drops a copy of itself as "KB915865.exe" This folder is set to Hidden
and System.

\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe

Also it drops an AUTORUN.INF file to automatically execute dropped
copies when the drives are accessed. The said file contains the
following strings:

[AutoRun]

open=.\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe .

shellexecute=.\MSOCache
\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe .

shell\Open\command=.\MSOCache
\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe .

shell=Open

open=.

This virus creates registry entries to enable its automatic execution
at every system startup.

Platform:

This worm affects systems running on Windows 98, ME, NT, 2000, XP, and
Server 2003.

Solution:
I wrote a specific removal tool for this virus (e-nil! Virus Cleaner),
it is free and available on my blog:

http://www.e-nil.com/blogs/?page_id=32


For more information or details please do not hesitation to contact me

Best regards and have a nice day,
Hani Simo

  Reply With Quote
Old 14-11-2007, 06:27 PM   #2
Malke
Guest
 
Posts: n/a
Re: A new self-replicating Malware (Virus and Worm) attacks!!!

hanisimo wrote:
> Dear Sir or Madam,
>
> A new computer worm is attacking the computers around the world, the
> serious problem is the most of the anti viruses cannot detect & clean
> it... also the removal tool was not available on the Internet... other
> serious problem presents when some of current anti viruses detect this
> virus as other kind of virus (Worm 32 family) ... and usually these
> antivirus delete the whole infected file (exe & autorun.inf ... ext)...


(snippage)

There's nothing new about this and there are tried and true ways of
removing the infection. Your tool might be 100% legitimate and excellent
but I wouldn't suggest that Windows users run an executable from an
unknown person. Please do not take this as an insult to your honor or
mad skilz; it is not meant that way at all.

You might want to post in one of the known specialty forums for fighting
malware to introduce yourself and your removal tool.

http://www.atribune.org/forums/index.php?showforum=9
http://aumha.net/viewforum.php?f=30
http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/...splay.php?f=25
http://www.geekstogo.com/forum/Malwa..._Here-f37.html


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
  Reply With Quote
Old 14-11-2007, 07:27 PM   #3
Xandros
Guest
 
Posts: n/a
Re: A new self-replicating Malware (Virus and Worm) attacks!!!

Thank you.

--

Xandros


"hanisimo" <hanisimo@gmail.com> wrote in message
news:1195041429.119517.103540@50g2000hsm.googlegro ups.com...
> Dear Sir or Madam,
>
> A new computer worm is attacking the computers around the world,

[snip]
> Solution:
> I wrote a specific removal tool for this virus (e-nil! Virus Cleaner),
> it is free and available on my blog:
>
> Best regards and have a nice day,
> Hani Simo
>



  Reply With Quote
Old 14-11-2007, 09:27 PM   #4
David B.
Guest
 
Posts: n/a
Re: A new self-replicating Malware (Virus and Worm) attacks!!!

For all we know this cleaning app may contain more viri or malware.

--

----
Crosspost, do not multipost http://www.blakjak.demon.co.uk/mul_crss.htm
How to ask a question http://support.microsoft.com/kb/555375
__________________________________________________ _______________________________


"Xandros" <arron.neus*remove*@gmailcom> wrote in message
news:%23nt1fwsJIHA.4684@TK2MSFTNGP06.phx.gbl...
> Thank you.
>
> --
>
> Xandros
>
>
> "hanisimo" <hanisimo@gmail.com> wrote in message
> news:1195041429.119517.103540@50g2000hsm.googlegro ups.com...
>> Dear Sir or Madam,
>>
>> A new computer worm is attacking the computers around the world,

> [snip]
>> Solution:
>> I wrote a specific removal tool for this virus (e-nil! Virus Cleaner),
>> it is free and available on my blog:
>>
>> Best regards and have a nice day,
>> Hani Simo
>>

>
>


  Reply With Quote
Old 15-11-2007, 06:27 PM   #5
Xandros
Guest
 
Posts: n/a
Re: A new self-replicating Malware (Virus and Worm) attacks!!!

Well I just ran it and it does a lot of false reporting which makes it
malware to be certain!!!!!
--

Xandros


"David B." <brooks.dj@nomail.com> wrote in message
news:eZwPChtJIHA.3356@TK2MSFTNGP02.phx.gbl...
> For all we know this cleaning app may contain more viri or malware.
>
> --
>
> ----
> Crosspost, do not multipost http://www.blakjak.demon.co.uk/mul_crss.htm
> How to ask a question http://support.microsoft.com/kb/555375
> __________________________________________________ _______________________________
>
>
> "Xandros" <arron.neus*remove*@gmailcom> wrote in message
> news:%23nt1fwsJIHA.4684@TK2MSFTNGP06.phx.gbl...
>> Thank you.
>>
>> --
>>
>> Xandros
>>
>>
>> "hanisimo" <hanisimo@gmail.com> wrote in message
>> news:1195041429.119517.103540@50g2000hsm.googlegro ups.com...
>>> Dear Sir or Madam,
>>>
>>> A new computer worm is attacking the computers around the world,

>> [snip]
>>> Solution:
>>> I wrote a specific removal tool for this virus (e-nil! Virus Cleaner),
>>> it is free and available on my blog:
>>>
>>> Best regards and have a nice day,
>>> Hani Simo
>>>

>>
>>

>



  Reply With Quote
Old 15-11-2007, 06:27 PM   #6
Xandros
Guest
 
Posts: n/a
Re: A new self-replicating Malware (Virus and Worm) attacks!!!

Hey hanisimo. I take back me Thank you. I just ran your app and it is giving
off a ton of false reports! tsk, tsk, tsk

--

Xandros


"hanisimo" <hanisimo@gmail.com> wrote in message
news:1195041429.119517.103540@50g2000hsm.googlegro ups.com...
> Dear Sir or Madam,
>

snip
>
> Solution:
> I wrote a specific removal tool for this virus (e-nil! Virus Cleaner),
> it is free and available on my blog:
>

snip
> For more information or details please do not hesitation to contact me
>
> Best regards and have a nice day,
> Hani Simo
>



  Reply With Quote
Old 15-11-2007, 10:27 PM   #7
Poprivet
Guest
 
Posts: n/a
Re: A new self-replicating Malware (Virus and Worm) attacks!!!

Xandros wrote:
> Hey hanisimo. I take back me Thank you. I just ran your app and it is
> giving off a ton of false reports! tsk, tsk, tsk
>
>
> "hanisimo" <hanisimo@gmail.com> wrote in message
> news:1195041429.119517.103540@50g2000hsm.googlegro ups.com...
>> Dear Sir or Madam,
>>

> snip
>>
>> Solution:
>> I wrote a specific removal tool for this virus (e-nil! Virus
>> Cleaner), it is free and available on my blog:
>>

> snip
>> For more information or details please do not hesitation to contact
>> me Best regards and have a nice day,
>> Hani Simo


I hope you're not really surprised. I also hope it didn't drop a bunch of
other malware on your machine in the process; that's typical of these kinds
of spams.

NEVER, EVER, respond to, or click any link in any unsolicited e-mails, in
newsgroups or in your Inbox. It's a sure way to become infected eventually,
and to propogate personal information to anyone from a spammer to an
identification theft outfit. Spammers even know now how to handle common
address obfuscations such as *REMOVE* and pull an address out of it.
You'd be much better off switching to an impossible address such as
invalid.invalid.invalid or one of the many others offered by various web
sites for the purpose. Check my Headers for one of those if you're curious;
I don't want to spam it here.

The ONLYresponses acceptable to spam is to delete it unread, or to submit
complaints about it to the relevant ISPs that originated it, but you have to
know how to parse for forged Headers to do that.

Pop`


  Reply With Quote
Old 15-11-2007, 10:27 PM   #8
David B.
Guest
 
Posts: n/a
Re: A new self-replicating Malware (Virus and Worm) attacks!!!

Hopefully that's all it's doing.

--

----
Crosspost, do not multipost http://www.blakjak.demon.co.uk/mul_crss.htm
How to ask a question http://support.microsoft.com/kb/555375
__________________________________________________ _______________________________


"Xandros" <arron.neus*remove*@gmailcom> wrote in message
news:uxKBU34JIHA.5400@TK2MSFTNGP04.phx.gbl...
> Hey hanisimo. I take back me Thank you. I just ran your app and it is
> giving off a ton of false reports! tsk, tsk, tsk
>
> --
>
> Xandros
>
>
> "hanisimo" <hanisimo@gmail.com> wrote in message
> news:1195041429.119517.103540@50g2000hsm.googlegro ups.com...
>> Dear Sir or Madam,
>>

> snip
>>
>> Solution:
>> I wrote a specific removal tool for this virus (e-nil! Virus Cleaner),
>> it is free and available on my blog:
>>

> snip
>> For more information or details please do not hesitation to contact me
>>
>> Best regards and have a nice day,
>> Hani Simo
>>

>
>


  Reply With Quote
Old 16-11-2007, 02:27 AM   #9
Gerry
Guest
 
Posts: n/a
Re: A new self-replicating Malware (Virus and Worm) attacks!!!

http://en.wikipedia.org/wiki/Xandros



~~~~


Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Poprivet wrote:
> Xandros wrote:
>> Hey hanisimo. I take back me Thank you. I just ran your app and it is
>> giving off a ton of false reports! tsk, tsk, tsk
>>
>>
>> "hanisimo" <hanisimo@gmail.com> wrote in message
>> news:1195041429.119517.103540@50g2000hsm.googlegro ups.com...
>>> Dear Sir or Madam,
>>>

>> snip
>>>
>>> Solution:
>>> I wrote a specific removal tool for this virus (e-nil! Virus
>>> Cleaner), it is free and available on my blog:
>>>

>> snip
>>> For more information or details please do not hesitation to contact
>>> me Best regards and have a nice day,
>>> Hani Simo

>
> I hope you're not really surprised. I also hope it didn't drop a
> bunch of other malware on your machine in the process; that's typical
> of these kinds of spams.
>
> NEVER, EVER, respond to, or click any link in any unsolicited
> e-mails, in newsgroups or in your Inbox. It's a sure way to become
> infected eventually, and to propogate personal information to anyone
> from a spammer to an identification theft outfit. Spammers even know
> now how to handle common address obfuscations such as *REMOVE* and
> pull an address out of it. You'd be much better off switching to an
> impossible address such as invalid.invalid.invalid or one of the many
> others offered by various web sites for the purpose. Check my
> Headers for one of those if you're curious; I don't want to spam it
> here.
> The ONLYresponses acceptable to spam is to delete it unread, or to
> submit complaints about it to the relevant ISPs that originated it,
> but you have to know how to parse for forged Headers to do that.
>
> Pop`



  Reply With Quote
Old 16-11-2007, 06:27 AM   #10
Xandros
Guest
 
Posts: n/a
Re: A new self-replicating Malware (Virus and Worm) attacks!!!

"Poprivet" <poprivet@devnull.spamcop.net> wrote in message
news:O$%23cQ56JIHA.1620@TK2MSFTNGP03.phx.gbl...
> Xandros wrote:
>> Hey hanisimo. I take back me Thank you. I just ran your app and it is
>> giving off a ton of false reports! tsk, tsk, tsk
>>
>>
>> "hanisimo" <hanisimo@gmail.com> wrote in message
>> news:1195041429.119517.103540@50g2000hsm.googlegro ups.com...
>>> Dear Sir or Madam,
>>>

>> snip
>>>
>>> Solution:
>>> I wrote a specific removal tool for this virus (e-nil! Virus
>>> Cleaner), it is free and available on my blog:
>>>

>> snip
>>> For more information or details please do not hesitation to contact
>>> me Best regards and have a nice day,
>>> Hani Simo

>
> I hope you're not really surprised. I also hope it didn't drop a bunch of
> other malware on your machine in the process; that's typical of these
> kinds of spams.
>
> NEVER, EVER, respond to, or click any link in any unsolicited e-mails, in
> newsgroups or in your Inbox. It's a sure way to become infected
> eventually, and to propogate personal information to anyone from a spammer
> to an identification theft outfit. Spammers even know now how to handle
> common address obfuscations such as *REMOVE* and pull an address out of
> it.
> You'd be much better off switching to an impossible address such as
> invalid.invalid.invalid or one of the many others offered by various web
> sites for the purpose. Check my Headers for one of those if you're
> curious; I don't want to spam it here.
>
> The ONLYresponses acceptable to spam is to delete it unread, or to submit
> complaints about it to the relevant ISPs that originated it, but you have
> to know how to parse for forged Headers to do that.
>
> Pop`
>



My arron.neus account is quite safe (erroneus) But thanks anyway.

--

Xandros



  Reply With Quote
Reply
Tags: , , , ,


Thread Tools
Display Modes


Google
 


All times are GMT +5.5. The time now is 04:41 AM.


vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO
Copyright © 2005-2008, TechTalkz.com. All Rights Reserved - Privacy Policy
Valid XHTML 1.0 Transitional