Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 11th, 2004, 05:23 AM
Skookum's Avatar
Skookum Skookum is offline
Infrequent Poster
 
Join Date: Oct 2004
Posts: 10
Default Heads up: Stealth Virus Attack

In KAV Personal Pro, the Kaspersky Inspector gave me a Stealth Virus alert for PED0D6~1.DAT file size 16384 kb.
This turned out to be Perfib_Perfdata_628.dat in C:\WINNT\System32\

When discovered ie: my using file operations on it, the file kept reproducing itself as .dat files then changed to a .tmp extension size is the one constant that being 16384 kb. Some of the file names are
{MSIMGIZ.dat , Index.dat} { ~DF274D.tmp , ~ DF37D7.tmp and several other ~DF followed by a Intiger}

Noticed something interesting. There are other files of like names and different sizes

~DFEAA9.tmp is 49152 kb or 3 times 16384 kb
Created: Friday, October 01, 2004, 5:46:41 PM
Accessed: Yesterday, October 10, 2004, 11:47:47 PM

~DF3998.tmp is 81920 kb or 5 times 16384 kb
Created: Monday, October 04, 2004, 9:12:41 PM
Accessed Yesterday,October 10, 2004, 11:47:47 PM

There are 12 variations of ~DF3998.tmp such as ~DF4658.tmp and other intigers
with the ~DF lead in, in my machine, all created at a different times and
all accessed yesterday, October 10, 2004, 11:47:47 PM.

Thats when I was running file search operations by size and extension, on the 16384 kb files and deleting them.

Looks like this file adapts to various methods of locating and removing it.
How clever.

I did manage to get a couple files into a 3.5 floppy for research on the thing.
Would like to submit these files to help get a handle on this monster. Any ideas?

What a mess this is.

Last edited by Skookum : October 11th, 2004 at 05:27 AM. Reason: Mayby Wrong Forum
  #2  
Old October 11th, 2004, 05:34 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: Heads up: Stealth Virus Attack

Can you please send a zipped sample of the virus to samples@nod32.com

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #3  
Old October 11th, 2004, 06:17 AM
Don Pelotas's Avatar
Don Pelotas Don Pelotas is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 2,257
Default Re: Heads up: Stealth Virus Attack

And also newvirus@kaspersky.com .
__________________
Errare humanum est
  #4  
Old October 11th, 2004, 07:41 AM
dvk01's Avatar
dvk01 dvk01 is offline
Global Moderator
 
Join Date: Oct 2003
Location: Loughton, Essex. UK
Posts: 3,129
Default Re: Heads up: Stealth Virus Attack

I think you will find that they are harmless files being created by windows when it does whatever it does

I assume that they are in the local settings/temp folder

everybody with XP gets them and the number and file sizes cahnfge with the wind

You can run them through any scanner and they come up harmless,

It's a waste of time deleting them as they get recreated by windows

just every few days or so clear out that temp folder comp[letely
  #5  
Old October 11th, 2004, 07:50 AM
dvk01's Avatar
dvk01 dvk01 is offline
Global Moderator
 
Join Date: Oct 2003
Location: Loughton, Essex. UK
Posts: 3,129
Default Re: Heads up: Stealth Virus Attack

As this doesn't seem to be a NOD issue and is more general virus I will move it to the appropriate forum
  #6  
Old October 11th, 2004, 07:54 AM
dvk01's Avatar
dvk01 dvk01 is offline
Global Moderator
 
Join Date: Oct 2003
Location: Loughton, Essex. UK
Posts: 3,129
Default Re: Heads up: Stealth Virus Attack

and perflib data is a windows system file

http://forums.computing.co.uk/thread...0&thread=18596

its the performance counter library
  #7  
Old October 11th, 2004, 07:55 AM
FanJ
 
Posts: n/a
Default Re: Heads up: Stealth Virus Attack

PS:

See also posting from Skookum here in the TDS-forum:
http://www.wilderssecurity.com/showthread.php?t=49753


Edit :

I just saw that Derek already pointed in that thread to this one
Sorry Derek
  #8  
Old October 11th, 2004, 09:29 AM
Skookum's Avatar
Skookum Skookum is offline
Infrequent Poster
 
Join Date: Oct 2004
Posts: 10
Default Re: Heads up: Stealth Virus Attack

Yes I see your point. I'm just beginning to ues KAV PRO and considered the
possability of a false alarm. Just felt the best thing was to get it out here with the pros for some feedback. Still would like to have it looked at by someone with the proper skills. Guess what got my attention was the way so many files, with different names and extentions had the exact size and appeared as quickly as I would delete the suspect files. also all the performance dat files in sys32 had the same size and the size never changed. That still gives me pause. I just checked my wifes machine and the only perf type .dat file to have the same file size is this one and it was just created Perflib_Perfdata_4c4.dat (16,384 bytes created: Today, October 11, 2004, 4:50:33 Ill send a zipped copy to Blackspear
and Kaspersky


Heres to life May all live well
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:31 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums