Re[2]: [Full-Disclosure] Virus / Trojan

From: Papp Geza (pappgeza_at_tolna.net)
Date: 01/10/04

  • Next message: Dale Harris: "Re: [Full-Disclosure] gcc: Internal compiler error: program cc1 got fatal signal 11"
    To: "Exibar" <exibar@thelair.com>
    Date: Sat, 10 Jan 2004 01:04:10 +0100
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: MD5

    Hello

    This trojan:

    - From Sophos
    Troj/Dloader-L
    Aliases
    TrojanDownloader.Win32.Xombe

    Type Trojan

    Description
    Troj/Dloader-L is a downloading Trojan that downloads and executes another program from the internet. At the time of writing this downloaded Trojan is detected as Troj/Mssvc-A.
    The Trojan may arrive in an email with the following characteristics:
    From: windowsupdate@microsoft.com
    Subject line: Windows XP Service Pack 1 (Express) - Critical Update
    Message text:
    Window Update has determined that you are running a beta version of Windows XP Service Pack 1 (SP1). To help improve the stability of your computer, Microsoft recommends that you remove the beta version of Windows XP SP1 and re-install Windows XP SP1. If you cannot remove the beta version, you should still reinstall Windows XP SP1.

    Windows XP SP1 provides the latest security, reliability, and performance updates to the Windows XP family of operating systems. Windows XP SP1 is designed to ensure Windows XP platform compatibility with newly released software and hardware, and includes updates to resolve issues discovered by customers or by Microsoft's internal testing team.

    The maximum download size is approximately 3 MB, however the size of the download and time required may be less for computers that have had updates previously installed.

    To minimize the download time needed for installation, setup will only download those files which are required to bring your computer up to date. Windows XP SP1 includes Internet Explorer 6 SP1. Anti-virus software programs may interfere with the installation of Windows XP SP1. Please disable anti-virus software while installing the service pack.

    Just run the file winxp_sp1.exe in attach and make sure to restart your PC after installation will be completed.

    (c) 2004 Microsoft Corporation. All rights reserved. Terms of Use Privacy Statement
    Attached file: winxp_sp1.exe

    This is variant Troj/Mssvc-A, and maliciosus but executable file, what
    download.

    -- 
    Üdvözlettel,
        Geza Papp dr.
        Med. Foensic. (Criminal) and
        Networksecurity & Virusanalyst
        IT. Tittle and Designation from AVIEN
                                                                mailto:pappgeza@tolna.net
    www.gyik.com
    "VIRUS CORE TEAM"
    ============================================================================
    Regular Member of ComSec Online Limited Professional Services Company - >
    Company Secretarial Service | http://www.comseconline.com/en/about.php
    ----------------------------------------------------------------------------
    Time out of Mind Registered Active Associate SpamCop.net,
    and The SPAMHOUS Project - > (ROKSO and Spamhaus Block List)
    http://www.spamhaus.org/index.lasso | http://spamcop.net/
    ----------------------------------------------------------------------------
    One from charter member Public letter concerning the Writing of Viruses
    & How it Does Not Teach about Virus Prevention
    from Hungary | www.avien.org/publicletter.htm
    ============================================================================
    Fiat justitia, pereat mundus!
    This system protects Tiny Professional Personal Firewall(c)
    ============================================================================
    -----BEGIN PGP SIGNATURE-----
    Version: 2.6
    iQDVAwUAP/9A/z7s5En2+/4VAQFDkwX/abf+xjl7V1uLypwEPrnZ+45G3+sM9zEw
    U1AfHP2ylonN47J0QD1ETt0mRTb6RWr1XQmEkNuG0azYxHZOC/g/7usMkcUMgYIs
    h9/koQB+WiLw40UMrlSrG+5QbAhXNwMk4AImBuQCjieVJqQVSIRrlVWlKUFo75Oq
    TTAi8SioXCChlZAv0u5e1A0e5RxWEB0h1lWyjvobIfpKMdiPkgkVFfc4xjgQbTig
    DTlCnHSR7wJcbzRK2Kn1ttlN1Ar5CMLM
    =xQT5
    -----END PGP SIGNATURE-----
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Dale Harris: "Re: [Full-Disclosure] gcc: Internal compiler error: program cc1 got fatal signal 11"

    Relevant Pages

    • >>>> TROJAN DOWNLOAD <<<<
      ... adobe 8.1 download trojan virus, adware download trojan trial, adware ... trojan trial, download a trojan horse, download a trojan program, ...
      (comp.dcom.lans.ethernet)
    • Re: restore Cd how to use
      ... through what you suggested to get rid of the trojans ect. ... start by turning OFF the System Restore function.. ... > You will also need to download Spyware removal software.. ... >> hijacked and adds being thrown at me (normally for add stoppers and trojan ...
      (microsoft.public.windowsxp.newusers)
    • Re: Puper.dll
      ... McAfee kept finding the puper.dll trojan but did ... | There was even a toolbar in Internet Explorer with these shields on them, ... FireWall to allow it to download the needed AV vendor related files. ... This will bring up the initial menu of choices and should be executed in Normal Mode. ...
      (alt.comp.anti-virus)
    • Re: Puper.dll
      ... | I have a trojan on my system. ... Download and execute the following Multi AV scanning tool. ... Reboot the PC" and when the PC begins ... to restart, hit the F8 key and start in Safe Mode. ...
      (microsoft.public.security.virus)
    • Re: trojan virus PLEASE HELP!
      ... There are anti virus News Groups specifically for this type of discussion. ... How do you know you have a Trojan on your PC? ... This will bring up the initial menu of choices and should be executed in Normal Mode. ... You can choose to go to each menu item and just download the needed files or you can ...
      (microsoft.public.windowsupdate)

  • Quantcast