»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 12-10-2003, 07:33 PM   #1 (permalink)
MDS
Registered User
 
MDS's Avatar
 
Join Date: Oct 2001
Location: N-the-center-Kansas
Posts: 2,694
MDS is on a distinguished road
I-worm/kindal removal help

OK I run AVG anti virus and I get a pop-up that I have an infected email containing the I-worm/kindal virus so I deleted it without opening it, so I thought all was well but now I get another popup saying my system has been infected with the I-worm/kindal to run avg for windows to remove so I did and guess what no virus detected I did a few quick googles on it and found that it is suposed to make a reg key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
"SysService32" = %WinDir%\systask32l.exe

and hiden files and hiden folders:

%SysDir%\ln32k.DLL
%SysDir%\kindlyback
%WinDir%\systask32l.exe
%SysDir%\ln32k.exe


and to quote on site

"When the worm sends an email to each individual entry in the address book, it also puts in the BCC field all other email addresses in the WAB. This would mean that the email would get sent to each address as many times as there are WAB entries, plus one. This is also notable because it would expose every email address in the victim machine's WAB to every other person in that address book.

This worm has its own SMTP engine, and uses the default SMTP account information to find a server to send itself through.

The worm may also try to copy itself to shared folders for KaZaA, Overnet, LimeWire or Morpheus, but this was not observed in testing. If so, it may copy itself using the following list of filenames:


MyStuff Archive.exe
[eBook]The Hacker Zipped.exe
PornStar Pic.jpg.pif
Stacy Valentine.pif
Quake 3 Arena CD KeyGen.exe
[eBook] Sex And The City Zipped.exe
Warcraft 3 Crack.exe
[eBook] WebSite Design Zipped.exe
AGV Antivirus Pro.exe
WinZip 8.1 KeyGen.exe
Personal Firewall Pro.exe
Window Blinds + KeyGen.exe
Nero Burning Rom 5.5 KeyGen.exe
Eminem - 8 Mile Screensaver.scr
Adobe Photoshop 6 KeyGen.exe
HyperSnap-DX (Full + Crack).exe
Macromedia Flash MX 6.0 Crack.exe
SWiSH 2.0 KeyGen+Crack.exe
Kaspersky Anti-Virus Pro (KeyGen+Crack).exe
PC-Cillin 9.02 (Keygen+Crack).exe
GetRight 4.5e (KeyGen+Crack).exe
Age of Mythology (NoCD+Crack).exe
Easy CD Creator 5 Preview Crack.exe
Eminem 8 Mile Wallpaper.exe
WindowsXP SP KeyGen.exe
[eBook] The Black Art Of Hacking
ICQ Sniffer.exe
Lord Of The Rings Screensaver.scr
kaspersky Anti-Virus
Eminem Desktop.exe
Borland Delphi Trial Crack.exe
Civilization III (Latest Cracked Patch).exe
Old Games Collection I.exe
CuteFTP PRO (Serial included).exe
ACDSee 5.0 (Crack+Serial).exe
DivX Video Bundle
Diskeeper 7.0 (Trial Crack).exe
mIRC32 (Serial included).exe
ZoneAlarm Firewall.exe
Eminem 8 Mile Censored Scene.exe
Personal Web Server.exe
Paint Shop Pro 7 Crack.exe
Winzip 8.1 Full.exe
The Eminem Show (Full Album).exe
Porn Games Collection I.exe
MAME ROMS Archive I.exe
MAME ROMS Archive II.exe
Final Fantasy ROM collection I.exe
Nintendo64 Emulator (ROM included).exe
Castle Wolfstein Multiplayer KeyGen.exe
The Sims Online Crack.exe
The Sims Nude Patch.exe
XCOM 3 Apocalypse.exe
Leisure Suit Larry 6.exe
Virtual Valerie 2.exe
Queens Of The Stone Age (Complete Album).exe
DivX Codecs Pack (All Needed codecs).exe
Strip Poker 3.exe
Britney Spear (Nude Pics Pack).exe
Hacker Tools Pack.exe
[eBook] Visual Basic Programming Handlebook.exe
WinXP Themes Pack.exe
Unreal 2 0][0 3 (Official Crack).exe
Doom 3 Leaked Beta.exe
Lula The Sexy Empire (Full+Crack).exe
Paint Shop Pro7 KeyGen.exe
The filenames and email information are all encrypted, so they are not visible within the executable. "

So how do I get rid of this or make sure I don't have it?

MDS is offline   Reply With Quote
Old 12-10-2003, 07:49 PM   #3 (permalink)
MDS
Registered User
 
MDS's Avatar
 
Join Date: Oct 2001
Location: N-the-center-Kansas
Posts: 2,694
MDS is on a distinguished road
I have searched the reg for the keys listed there and the sites I found and have not found any of them I also searched using winders search for files list on sites I found info about and on the one you listed and have not found any of them. I don't know if avg stopped the virus or not as I can not find any signs of it on my computer. I am running housecall rightnow to see if it picks up anything. But so far main OS hd has come up clean.


edit: housecall complete no virus found on any of my hd's

I searched for keys that the links you add sugested and none of them were present so hopefully AVG did it's job and prevented it.

Last edited by MDS; 12-10-2003 at 07:58 PM.
MDS is offline   Reply With Quote
Old 12-10-2003, 08:57 PM   #4 (permalink)
MDS
Registered User
 
MDS's Avatar
 
Join Date: Oct 2001
Location: N-the-center-Kansas
Posts: 2,694
MDS is on a distinguished road
crap I just recieved another AVG message attached below

I also deleted my cantacts to be safe not to spread it.
Attached Images
File Type: jpg virus.jpg (32.3 KB, 126 views)

Last edited by MDS; 12-10-2003 at 10:01 PM.
MDS is offline   Reply With Quote
Old 12-10-2003, 10:10 PM   #5 (permalink)
MDS
Registered User
 
MDS's Avatar
 
Join Date: Oct 2001
Location: N-the-center-Kansas
Posts: 2,694
MDS is on a distinguished road
also sorry for the extra post but I could edit to attach another image but here is what I get win I run AVG for windows scan
Attached Images
File Type: jpg avg.jpg (35.6 KB, 72 views)
MDS is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 11:34 PM.