»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 01-05-2004, 07:12 PM   #1 (permalink)
Registered User
 
Brangwen's Avatar
 
Join Date: Oct 2001
Location: "Now?"
Posts: 3,154
Brangwen is on a distinguished road
Virus question: Win.exe

Fellow Members:

I've been made a fool of before inquiring about something my AV has netted.

Better safe than sorry:

Okay ... Win.exe ...

Ever hear of this (dare I write) bug?

It's in my quarantine.

Brangwen

OS = Win2KPro

Brangwen is offline   Reply With Quote
Old 01-05-2004, 07:32 PM   #2 (permalink)
Registered User
 
crystaldragon's Avatar
 
Join Date: Oct 2001
Location: Springfield,Mo
Posts: 564
crystaldragon is on a distinguished road
Send a message via Yahoo to crystaldragon
here you go.

from trend micro
__________________
Those who cannot remember the past are condemned to repeat it
crystaldragon is offline   Reply With Quote
Old 01-05-2004, 07:48 PM   #3 (permalink)
Registered User
 
StealthyV's Avatar
 
Join Date: Jan 2003
Location: comfy 5yr old chair
Posts: 495
StealthyV is on a distinguished road
well I did a bit of searching and found a few sites which may help you understand what you have here.
it appears that this virus was detected in the second half of October 2003, and has been added to the latest McAffee detections (and I'd imagine, the updated av software of whatever company you use).
A few names such as "Win32/Bugbear.B@mm," "'Klez'", and "W32.Maldal.D@mm" appear in regards to this vulnerability.
The virus: "W32.Maldal.D@mm" behaves as follows (from QuickHeal)
Quote:
Changes Made to the system:
WIN.EXE files is copies into Windows directory
Following entry is made into the registry to run WIN.EXE on every boot:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\run\System
Computer name is changed to ZaCker
Quick Heal reports that "The detection and removal as a known virus has been provided in the special update provided on 3rd January 2002."
I would suggest downloading the latest Stinger Scanner from McAffee's parent company. This is a free utility which scans for 30 of the most recent viri and will clean/remove them safely from your system.

I'm glad you asked this question...in helping you out, I've learned something too!

good luck!

~Branson

*crystaldragon, you beat me to it!
__________________
I'm an Eagle Scout! (1997)

Last edited by StealthyV; 01-05-2004 at 07:51 PM.
StealthyV is offline   Reply With Quote
Old 01-05-2004, 08:20 PM   #4 (permalink)
Registered User
 
Brangwen's Avatar
 
Join Date: Oct 2001
Location: "Now?"
Posts: 3,154
Brangwen is on a distinguished road
Crystaldragon & StealthyV:

Thanks! You put me at ease. It's been quaranined for a couple of weeks, and I wanted to be certain.

I've been hit by "Klez" months ago, but I thought this might be a hoax.

Thanks for all your great effort!

Brangwen

"TechIMO works!"
Brangwen is offline   Reply With Quote
Old 01-08-2004, 01:03 AM   #5 (permalink)
Registered User
 
StealthyV's Avatar
 
Join Date: Jan 2003
Location: comfy 5yr old chair
Posts: 495
StealthyV is on a distinguished road
no prob, brangwen.

techimo has been good to me as well, and it's fun to help others out!

~B
__________________
I'm an Eagle Scout! (1997)
StealthyV is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 12:41 PM.