New virus/variant out today

Joemonkey

Diamond Member
Mar 3, 2001
8,859
4
0
Click Me

Some people were asking me about emails they received with .zip attachments with price in the name. Virus scan wasn't picking it up, so I checked out Trend's website and did a manual update. Anyway:


Malware type: Trojan

Aliases: No Alias Found

In the wild: Yes

Destructive: Yes

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating: Low

--------------------------------------------------------------------------------

Reported infections: Low

Damage potential: Medium

Distribution potential: Low



--------------------------------------------------------------------------------

Description:



This memory-resident Trojan arrives on a system as an attachment to spammed email messages. The attachment is an archived file using any of the following file names:

09_price.zip
new__price.zip
new_price.zip
newprice.zip
price2.zip
price_09.zip
price_new.zip
The following is a sample screenshot of the email message this Trojan arrives with:

Screenshot

This Trojan bears an icon similar to the application Notepad. It also opens a Notepad window upon execution, possibly to trick unsuspecting users that they are opening a normal application.

It drops a copy of itself in the Windows system folder as the file WINSHOST.EXE. It also drops its DLL component named WIWSHOST.EXE in the same folder. This dropped DLL component contains this Trojan's malicious routines, and is injected in the EXPLORER.EXE process to avoid immediate detection and to ensure its automatic execution every time Windows Explorer is accessed.

This Trojan then terminates several processes running on an affected system. Moreover, it disables any antivirus applications running on an affected system by deleting several registry keys and entries, as well as by disabling a number of services related to these applications.

It also attempts to download a file from several Web sites. As of this writing, however, the said sites are already inaccessible.

This Trojan also renames certain files. The said routine may cause corresponding applications to malfunction.



 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Looks like McAfee will be unusually slow on those, the Wednesday DATs should cover it. In the meantime, if you happen to have VirusScan Enterprise 8 then you can create an Access Protection rule that arbitrarily forbids creation or execution of files named **\price*.zip by processes * and sleep a little easier.
 

Gravity

Diamond Member
Mar 21, 2003
5,685
0
0
hasn't reached the shores of LA yet......hope the DAT's update prior to that.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: Gravity
hasn't reached the shores of LA yet......hope the DAT's update prior to that.
4585's were released early, go get 'em There's one new Bagle that'll be in the 4586's though (tomorrow ~9AM probably).


 

Joemonkey

Diamond Member
Mar 3, 2001
8,859
4
0
after I applied the new signatures to my scanmail, I only received about 8 more emails w/ the virus all day...

weird virus though
 

JetBlack69

Diamond Member
Sep 16, 2001
4,580
1
0
I had someone with an email address very similar to mine email me and asked me why I sent her the zip file. I don't have the virus so that was kind of odd. I assume it modifies the sender address.
 

dhslammer

Golden Member
Nov 22, 2000
1,469
0
0
Anyone know what it actually does?

(besides replicate itself via email)

Spam bot?

Key logger?

I have gotten it a few times today but my pcCillin got it right away.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |