PDA

View Full Version : Wilders security forums being blocked by malware


Baz_kasp
January 13th, 2009, 06:52 PM
Kaspersky issued a "moderate" severity advisory on the "kido" worm...according to their write-up, looks like this forum has caught the attention of the malware creators.... you lot should be proud this place is that popular ;D


http://www.viruslist.com/en/viruses/encyclopedia?virusid=21782725

-{ Quote: "When launching, the worm injects its code into the address space of one of the “svchost.exe” system processes. This code is responsible for the worm’s malicious payload:
Disables system restore
Blocks addresses which contain the following strings:

.....
wilderssecurity
...

" }-

EraserHW
January 13th, 2009, 07:13 PM
It's a variant of Conficker/Downadup worm, already isolated at the end of December. It blocks DNS queries to various security related websites.

emperordarius
January 14th, 2009, 12:28 AM
Hooray!;D

GES/POR
January 14th, 2009, 01:06 PM
SSupdater anyone?

TonyW
January 14th, 2009, 02:12 PM
F-Secure have a few writeups in their blog about the Conficker/Downadup/Kido worm. (See http://www.f-secure.com/weblog)

xpsunny
January 15th, 2009, 10:31 AM
Whippy........bravo............;D

I am sooooooooooo unlucky that I didn't got hit by the malware. I would love to. You know, whenever my PC gets infected I get a warm fuzzy feeling. :)

@Baz_kasp

Just count your blessings.

rogervernon
January 15th, 2009, 11:46 AM
Does it block DNS look-up by inserting an entry into your hosts file?
If so, OA paid certainly monitors your hosts file to alert you to this.

Baz_kasp
January 15th, 2009, 12:05 PM
-{ Quote: "Does it block DNS look-up by inserting an entry into your hosts file?
If so, OA paid certainly monitors your hosts file to alert you to this." }-


Probably not... the "in" way at the moment is to use ndis to block/reroute requests from what I've read....

TechOutsider
January 17th, 2009, 09:42 AM
Don't understand why it disabled System Restore; many people automatically turn to Sys Restore to restore a clean copy. It could just manifest its self within Restore.