mandeleter Posted July 22, 2009 ID:101318 Share Posted July 22, 2009 Not detected at time by malware.Sorry im not speak english. Link to post Share on other sites More sharing options...
yardbird Posted July 22, 2009 ID:101393 Share Posted July 22, 2009 no trojan? all ok? and what language do you speak? If you still need help, Let us know? Link to post Share on other sites More sharing options...
Staff TeMerc Posted July 22, 2009 Staff ID:101405 Share Posted July 22, 2009 Not detected at time by malware.Sorry im not speak english. hi and welcome to the forumPlease sbmit the file to the link below:http://uploads.malwarebytes.org/ Link to post Share on other sites More sharing options...
mandeleter Posted July 22, 2009 Author ID:101426 Share Posted July 22, 2009 no trojan? all ok? and what language do you speak? If you still need help, Let us know?this not is as trojan its a worm the file appears again when I removed it and I connect to internetthis connects to many directions i testing with the firewall of NOD32.i speak spanishmuchas gracias a todosthanks for yours answers Link to post Share on other sites More sharing options...
yardbird Posted July 22, 2009 ID:101433 Share Posted July 22, 2009 Link to post Share on other sites More sharing options...
mandeleter Posted July 23, 2009 Author ID:101487 Share Posted July 23, 2009 Link to post Share on other sites More sharing options...
mandeleter Posted July 23, 2009 Author ID:101489 Share Posted July 23, 2009 The file remains hidden in windows but I could remove this in the zip attachment. Very careful as it is spreading very quickly and pollutes much the networks are not connected to the open.I hope to help take the first malware bytes, greetings and thanks.El archivo permanece oculto en windows aunque lo he podido remover, esta en el zip que adjunto.Mucho cuidado ya que se esta esparciendo muy rapidamente y contamina mucho las redes, al abrirlo no esten conectados. Espero servir de ayuda para que malware bytes tenga la primicia, saludos y gracias.Moderator can you change the name of the post to New Worm but this isn`nt a trojan I already send the file to the page Link to post Share on other sites More sharing options...
yardbird Posted July 23, 2009 ID:101491 Share Posted July 23, 2009 Moderator can you change the name of the post to New Worm but this isn`nt a trojan I already send the file to the pageThe file remains secret in windows although I could have removed it, this one in the zip that I enclose.A lot of care since it is scattering very quickly and contaminates very much the networks, on having opened it, do not be connected. I hope to serve as help so that malware bytes it has the novelty, greetings and thank you. Link to post Share on other sites More sharing options...
yardbird Posted July 23, 2009 ID:101492 Share Posted July 23, 2009 @ TeMercI downloaded the file & sent it up to mbam, any instructions Tom?EDIT: UploadNET Link to post Share on other sites More sharing options...
yardbird Posted July 23, 2009 ID:101495 Share Posted July 23, 2009 @ manleteder Link to post Share on other sites More sharing options...
Staff TeMerc Posted July 23, 2009 Staff ID:101508 Share Posted July 23, 2009 @ TeMercI downloaded the file & sent it up to mbam, any instructions Tom?EDIT: UploadNET Link to post Share on other sites More sharing options...
mandeleter Posted July 23, 2009 Author ID:101638 Share Posted July 23, 2009 No idea, I'll have to ask or maybe soneone will see this and reply.I have 26 years and I am a systems analyst, the virus is not revealed in malwarebytes I was detected when a virus appeared in the PCB (process control block) and the firewall node that detects the connections of the files I notice that the msddrv42.exe file is connected to other network connections blocking my connection the worm its to recent.Now searching in google i found anothers forums when the same problem, the worm is spreading fast.Now I find it also in the registry at the following location HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Runthis disguised as Windows Driver Setup and this reg really not excist. Link to post Share on other sites More sharing options...
Bobc11 Posted July 26, 2009 ID:102673 Share Posted July 26, 2009 I have 26 years and I am a systems analyst, the virus is not revealed in malwarebytes I was detected when a virus appeared in the PCB (process control block) and the firewall node that detects the connections of the files I notice that the msddrv42.exe file is connected to other network connections blocking my connection the worm its to recent.Now searching in google i found anothers forums when the same problem, the worm is spreading fast.Now I find it also in the registry at the following location HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Runthis disguised as Windows Driver Setup and this reg really not excist.Avira gets it.And i got it too!! Link to post Share on other sites More sharing options...
DaChew Posted July 26, 2009 ID:102677 Share Posted July 26, 2009 http://www.virustotal.com/analisis/6f75596...038a-1248617669It's really not a good idea to leave an infector posted in a public area of a forum Link to post Share on other sites More sharing options...
Noah Posted July 26, 2009 ID:102712 Share Posted July 26, 2009 Seems like the file [the virus] uses the names as * 786.EXE * 778.EXE * 485.EXE * FW[n].EXEFile size [on all of them] are/is * 98,304 bytesAnd the effect of it? * Added as a Registry auto start to load Program on Boot upDoesn't seem like much, but by the way you guys put it, this thing really doesn't want to be removed. Link to post Share on other sites More sharing options...
Staff TeMerc Posted July 26, 2009 Staff ID:102715 Share Posted July 26, 2009 http://www.virustotal.com/analisis/6f75596...038a-1248617669It's really not a good idea to leave an infector posted in a public area of a forum Thanks, I removed it. Link to post Share on other sites More sharing options...
mountaintree16 Posted July 26, 2009 ID:102724 Share Posted July 26, 2009 Oh no!Where does it come from? Avira gets it.And i got it too!! Link to post Share on other sites More sharing options...
Bobc11 Posted July 26, 2009 ID:102762 Share Posted July 26, 2009 Oh no!Where does it come from?No idea. Link to post Share on other sites More sharing options...
DaChew Posted July 26, 2009 ID:102765 Share Posted July 26, 2009 Did Avira stop all of it? Link to post Share on other sites More sharing options...
Bobc11 Posted July 26, 2009 ID:102767 Share Posted July 26, 2009 Did Avira stop all of it?From what i know now yes! Just finished cleanup actually! Link to post Share on other sites More sharing options...
mountaintree16 Posted July 26, 2009 ID:102791 Share Posted July 26, 2009 Oh good (glad its getting all cleaned up!)Did it come up on Avira with any particular site that you visited, just curious?From what i know now yes! Just finished cleanup actually! Link to post Share on other sites More sharing options...
DaChew Posted July 26, 2009 ID:102793 Share Posted July 26, 2009 The infector was attached in this thread, until Tom removed it Link to post Share on other sites More sharing options...
mountaintree16 Posted July 26, 2009 ID:102803 Share Posted July 26, 2009 Eak! That's not good.Could one get it simply by viewing the thread or would I have had to click on something?I viewed the thread when it was live (I think) but I did NOT click on any links in any posts, just the regular "reply" button.The infector was attached in this thread, until Tom removed it Link to post Share on other sites More sharing options...
Bobc11 Posted July 26, 2009 ID:102811 Share Posted July 26, 2009 Oh good (glad its getting all cleaned up!)Did it come up on Avira with any particular site that you visited, just curious?No Not a particular site.The guard came up without warning and the i scanned.The gaurd said i had a TR/Xpack.gen [C:\1.exe]Then i scaned and found it it took a long time but i got rid of it. Link to post Share on other sites More sharing options...
mountaintree16 Posted July 26, 2009 ID:102829 Share Posted July 26, 2009 Eak, that's pretty scary!Glad you caught it and its gone Hope I don't get it No Not a particular site.The guard came up without warning and the i scanned.The gaurd said i had a TR/Xpack.gen [C:\1.exe]Then i scaned and found it it took a long time but i got rid of it. Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now