BetaONE will rise again!


Reply
  #1  
Old 19th Aug 03, 07:55 PM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
VIRUS COMPANY iDefense said that the SoBig virus has started to proliferate again.
The virus installs a copy of itself in the Windows directory as a firm called winppr32.exe, and then the registry is changed so that the worm executes at startup.

The file size, said iDefense, varies in order to attempt to thwart anti-viral software, and typically comes as an attachment with email subject headings such as Re: Details, Re: Approved, Re: Re: My details, Re: That movie, Re: Thank you!, Re: Your application, Re: Wicked screensaver, Thank you!, Your details



Source:
http://www.theinquirer.net/?article=11115
Reply With Quote
  #2  
Old 19th Aug 03, 07:55 PM
Thankbot Thankbot is offline
Senior Member
 
Join Date: Jul 2003
Location: Seph's basement, Chained to his bed
Posts: 2,191
Thankbot
2 Users already said Thank You!

dalebleh, NoFear,
Reply With Quote
  #3  
Old 19th Aug 03, 09:37 PM
BlackMantis BlackMantis is offline
Senior Member
 
Join Date: Jul 2003
Posts: 111
BlackMantis
Yup.. i was just looking at this, it also drops WINSTT32.dat in the winnt folder. it's a configuration file along with the following registry keys to hook up the system.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
"TrayX" = C:\WINNT\WINPPR32.EXE /sinc

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run
"TrayX" = C:\WINNT\WINPPR32.EXE /sinc
http://vil.nai.com/vil/content/v_100561.htm


the latest stinger that was posted today should have the remedy for it  you could get this from the link below.
http://vil.nai.com/vil/stinger/
Reply With Quote
  #4  
Old 19th Aug 03, 10:27 PM
mikeh420's Avatar
mikeh420 mikeh420 is offline
Senior Member
 
Join Date: Nov 2002
Location: Los Angeles, CA, USA
Posts: 222
mikeh420
Send a message via ICQ to mikeh420 Send a message via AIM to mikeh420 Send a message via Yahoo to mikeh420
Yep, just got one of those today. As usual, NAV caught it and "de-rezzed" it. (Apologies to Tron!) Amazing that people still open attachments from total strangers. How many times do you have to pound it into these idiots heads?

Ranting finished! Thank You.
Reply With Quote
  #5  
Old 20th Aug 03, 04:17 AM
Bads's Avatar
Bads Bads is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: Quebec
Posts: 1,710
Bads is an unknown quantity at this point
I will take care 

Thanks for these precious informations 
__________________
Reply With Quote
  #6  
Old 20th Aug 03, 04:35 AM
User Needs User Needs is offline
Administrator
 
Join Date: Aug 2001
Posts: 950
User Needs has disabled reputation
Just in case, here's the removal tool,
And I hope it's not needed.
or, http://securityresponse.symantec.com...r/FixSbigF.exe
Attached Files
File Type: exe FixSbigF.exe (38.0 KB, 6 views)
Reply With Quote
  #7  
Old 20th Aug 03, 06:06 AM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
thx alot User
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 02:35 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.