Results 1 to 5 of 5

Thread: Virus Info Required

  1. #1
    Join Date
    12 May 2006
    Location
    Pakistan
    Age
    38
    Posts
    2,919
    Threads
    65
    Credits
    960
    Thanked
    0

    Question Virus Info Required

    Assalam-o-likum,

    kiya ahl han app sab kay . Umeed hay kay sab theek thak . or hansii khussi hon gay .

    to janab ajj ka humara masla yah hay kay . Mujhay ak virus kay baray may info cahyah agar kissi to pata hay kay yah virus kiya karta hay to zaror batayah ga .. han g .. virus ka name bata doun .. dantay kune ho .. . yah hay virus ka name

    "W32.Netsky.Z@mm" (yah ziyadah tar emails may bhi paya giyah hay . lakin mujhay samjh nahi aa rahi kay yah kiya karta hay . kune kay yahoo download nahi karnay dayta rok layta hay)

    ok ab calta hon . jawab ka intazar
    Allah Hafiz
    .......

  2. #2
    Mozilla's Avatar
    Mozilla is offline Member
    Last Online
    23rd December 2006 @ 12:18 PM
    Join Date
    11 Aug 2006
    Posts
    179
    Threads
    33
    Thanked
    0

    Default

    Brother Ya Lo

    The risk assessment of this threat has been updated to Low-Profiled due to media attention at:http://searchsecurity.techtarget.com...961097,00.html

    This detection is for a new variant of W32/Netsky. It bears the following characteristics:
    harvests email addresses from the victim machine
    contains its own SMTP engine to construct outgoing messages
    attaches itself within a ZIP archive to emails
    spoofs the From: address
    delivers a denial of service payload to certain web sites upon a date condition

    Mail Propagation

    The virus harvests email addresses from files on the victim machine with the following extensions:
    .adb
    .asp
    .cfg
    .cgi
    .dbx
    .dhtm
    .doc
    .eml
    .htm
    .html
    .jsp
    .mbx
    .mdx
    .mht
    .mmf
    .msg
    .nch
    .oft
    .php
    .ods
    .pl
    .ppt
    .rtf
    .sht
    .shtm
    .stm
    .tbb
    .txt
    .uin
    .vbs
    .wab
    .wsh
    .xls
    .xml

    Messages are constructed using the virus' own SMTP engine. They bear the following characteristics:

    From: spoofed (using harvested email addresses)Subject: selected from one of the following:
    Document
    Hello
    Hi
    Important
    Important bill!
    Important data!
    Important details!
    Important document!
    Important informations!
    Important notice!
    Important textfile!
    Important!
    Information
    Attachment: ZIP archive with one of the following filenames:

    Bill.zip
    Data.zip
    Details.zip
    Important.zip
    Informations.zip
    Notice.zip
    Part-2.zip
    Textfile.zip

    The ZIP archive contains the worm. It is not password protected. The filename of the worm within the ZIP is chosen to match the subject and ZIP name:
    Bill.txt (many spaces) .exe
    Data.txt (many spaces) .exe
    Details.txt (many spaces) .exe
    Important.txt (many spaces) .exe
    Informations.txt (many spaces) .exe
    Notice.txt (many spaces) .exe
    Part-2.txt (many spaces) .exe
    Textfile.txt (many spaces) .exe

    Denial of Service Payload

    Upon a certain date condition, the virus targets the following domains in a denial of service attack (HTTP):
    www.nibis.de
    www.medinfo.ufl.edu
    www.educa.ch

    System Changes

    The virus installs itself on the victim machine as JAMMER2ND.EXE:
    %WinDir%\JAMMER2ND.EXE

    The following Registry key is added to hook system startup:
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run "Jammer2nd" = %WinDir%\JAMMER2ND.EXE

    Copies of the worm in a ZIP archive (some Base64 encoded) are written to the victim machine:
    PK_ZIPn.LOG

    (where n is an integer).

  3. #3
    Mozilla's Avatar
    Mozilla is offline Member
    Last Online
    23rd December 2006 @ 12:18 PM
    Join Date
    11 Aug 2006
    Posts
    179
    Threads
    33
    Credits
    0
    Thanked
    0

    Default

    This worm spreads by email, constructing messages using its own SMTP engine.

  4. #4
    Mozilla's Avatar
    Mozilla is offline Member
    Last Online
    23rd December 2006 @ 12:18 PM
    Join Date
    11 Aug 2006
    Posts
    179
    Threads
    33
    Credits
    0
    Thanked
    0

    Default

    This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

  5. #5
    Join Date
    12 May 2006
    Location
    Pakistan
    Age
    38
    Posts
    2,919
    Threads
    65
    Credits
    960
    Thanked
    0

    Default

    hum thanks bahi . Very informatic ..

Similar Threads

  1. New Virus need info
    By thair jani in forum Ask an Expert
    Replies: 9
    Last Post: 15th June 2013, 09:24 PM
  2. info required
    By kaleem11 in forum Overseas Study
    Replies: 0
    Last Post: 10th September 2012, 11:28 AM
  3. Solved info required abt xtgem.com
    By seehaseeb in forum Solved Problems (IT)
    Replies: 10
    Last Post: 26th June 2012, 08:17 PM
  4. Info Required
    By mwaleedarshad in forum Ask an Expert
    Replies: 4
    Last Post: 13th July 2009, 01:23 AM
  5. virus info
    By adeelghani in forum Ask an Expert
    Replies: 4
    Last Post: 4th July 2009, 03:52 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •