• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

New virus/variant out today

Joemonkey

Diamond Member
Click Me

Some people were asking me about emails they received with .zip attachments with price in the name. Virus scan wasn't picking it up, so I checked out Trend's website and did a manual update. Anyway:


Malware type: Trojan

Aliases: No Alias Found

In the wild: Yes

Destructive: Yes

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating: Low

--------------------------------------------------------------------------------

Reported infections: Low

Damage potential: Medium

Distribution potential: Low



--------------------------------------------------------------------------------

Description:



This memory-resident Trojan arrives on a system as an attachment to spammed email messages. The attachment is an archived file using any of the following file names:

09_price.zip
new__price.zip
new_price.zip
newprice.zip
price2.zip
price_09.zip
price_new.zip
The following is a sample screenshot of the email message this Trojan arrives with:

Screenshot

This Trojan bears an icon similar to the application Notepad. It also opens a Notepad window upon execution, possibly to trick unsuspecting users that they are opening a normal application.

It drops a copy of itself in the Windows system folder as the file WINSHOST.EXE. It also drops its DLL component named WIWSHOST.EXE in the same folder. This dropped DLL component contains this Trojan's malicious routines, and is injected in the EXPLORER.EXE process to avoid immediate detection and to ensure its automatic execution every time Windows Explorer is accessed.

This Trojan then terminates several processes running on an affected system. Moreover, it disables any antivirus applications running on an affected system by deleting several registry keys and entries, as well as by disabling a number of services related to these applications.

It also attempts to download a file from several Web sites. As of this writing, however, the said sites are already inaccessible.

This Trojan also renames certain files. The said routine may cause corresponding applications to malfunction.



 
Looks like McAfee will be unusually slow on those, the Wednesday DATs should cover it. In the meantime, if you happen to have VirusScan Enterprise 8 then you can create an Access Protection rule that arbitrarily forbids creation or execution of files named **\price*.zip by processes * and sleep a little easier.
 
Originally posted by: Gravity
hasn't reached the shores of LA yet......hope the DAT's update prior to that.
4585's were released early, go get 'em 🙂 There's one new Bagle that'll be in the 4586's though (tomorrow ~9AM probably).


 
after I applied the new signatures to my scanmail, I only received about 8 more emails w/ the virus all day...

weird virus though
 
I had someone with an email address very similar to mine email me and asked me why I sent her the zip file. I don't have the virus so that was kind of odd. 😕 I assume it modifies the sender address.
 
Anyone know what it actually does?

(besides replicate itself via email)

Spam bot?

Key logger?

I have gotten it a few times today but my pcCillin got it right away.
 
Back
Top