Page 1 of 1

WARNING!!! IRC Possible Virus Carrier

Posted: Thu Sep 11, 2003 2:58 pm
by Kazsam
Found this on my PC today, bastid to get rid of, only IRC i use is meginjarder, so just a heads up to look out for it!


Virus type: Worm

Destructive: No

Aliases: W32.Spybot.Worm, Worm.P2P.SpyBot.gen, Win32.HLLW.SpyBot, Worm.SpyBot.BH

Pattern file needed: 629

Scan engine needed: 6.150

Overall risk rating: Low

--------------------------------------------------------------------------------

Reported infections: Low

Damage Potential: High

Distribution Potential: Medium



--------------------------------------------------------------------------------

Description:



This memory-resident worm propagates via network shares and has several backdoor capabilities.

It connects to an Internet Relay Chat (IRC) server where it receives the following commands from a remote user to process on compromised machine:

Steal Windows cached passwords
Remotely activate a key logger
Act as HTTP Web page server
Open and close CD-ROM tray
Scan ports
Download file(s)
Perform Denial of Service (DOS) attack against other systems
List and terminate running processes
List system information
Browse files on the compromised system
Execute a file remotely
It allows malicious user to install copies of itself in several startup folders using the following file names:

BRITNEY_SPEARS_GAME.EXE
FILE.EXE
EXPLORER.EXE
To make the cleanup difficult, it terminates the following processes:

NETSTAT.EXE
TASKMGR.EXE
MSCONFIG.EXE
REGEDIT.EXE
This UPX-compressed worm runs on Windows 95, 98, ME, NT, 2000, and XP systems.

Posted: Thu Sep 11, 2003 2:59 pm
by Panzerfaust
Man! I wanted to play the Brittney game.


Thanks Kaz

Posted: Thu Sep 11, 2003 3:00 pm
by Kazsam
BTW I DO NOT HAVE A BRITNEY SPEARS GAME!!!!!!!!!!!!! :oops: :oops: :oops:

Re: WARNING!!! IRC Possible Virus Carrier

Posted: Thu Sep 11, 2003 11:00 pm
by Trekman
Kazsam wrote:Found this on my PC today, bastid to get rid of, only IRC i use is meginjarder, so just a heads up to look out for it!
http://securityresponse.symantec.com/av ... .worm.html

This article only mentions mIRC as possible IRC client to be used by the worm. Anyway caution is advised also when using MJ, ElComs, dIRCal,....

It also mentions the KAZAA network as possible distributor. Do you use KAZAA ?

According to that article the worm had been discovered April 16th.
So the latest update of the antivirus software you hopefully use already should be able to block/handle that worm ?!

Posted: Fri Sep 12, 2003 7:17 am
by Kazsam
No i do not use kazaa, and last virus check i did was 2 weeks ago. so have got it since then.#

Yeah there was a solution to rid it, after you spent hours trying to locate the infected files :(

Sorted now.