Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 20th, 2006, 05:36 AM
ALEX(XX) ALEX(XX) is offline
Infrequent Poster
 
Join Date: Mar 2006
Posts: 19
Default New p2p-virus?

What do you think of it? Whether there Is at you any information about Win32.Polipos? (Excuse for bad English. )

http://info.drweb.com/show/2815/en
  #2  
Old April 20th, 2006, 07:01 AM
Inspector Clouseau's Avatar
Inspector Clouseau Inspector Clouseau is offline
AV Expert (VP Sunbelt Software)
 
Join Date: Apr 2006
Location: Maidenhead, UK
Posts: 1,329
Default Re: New p2p-virus?

That's after a long time after ZMist one of the "best" viruses i've seen.
It's indeed highly complex - the encryption algo is medium difficult and the virus uses a lot of tricks. I've here some samples with nice antiemulation tricks, such as code performance speed tests (meaning the virus will know when it runs in a virtual environment) and registry dummy - writing tricks, such as trying to write a random value to the registry and trying to read it later and compare it. If not equ or if it doesn't exist the virus exits. The virus is able to act as space filler, same technic was used by the tschernobyl virus already (CIH). The virus is able to use EPO functionallity, it looks for common API calls after the entry point and hooks/redirects them. Means the virus does not execute its own code/decrypter at a fixed position after the entry point.

Cleaning becomes tricky as Dr. Web already stated correct, however, cleaner will be available soon via my weblog somehow during this week when i have some time.
__________________
My Pictures Meet me on facebook!
  #3  
Old April 20th, 2006, 07:15 AM
RejZoR's Avatar
RejZoR RejZoR is offline
Polymorphic Sheep
 
Join Date: May 2004
Location: Europe/Slovenia/Ljubljana
Posts: 5,366
Default Re: New p2p-virus?

Interesting, a must have piece of malware for a collector like myself then...
Now where did i put that Tenga.A hm...
__________________
RejZoR's Little Secrets
  #4  
Old April 20th, 2006, 08:15 AM
ALEX(XX) ALEX(XX) is offline
Infrequent Poster
 
Join Date: Mar 2006
Posts: 19
Default Re: New p2p-virus?

The description was specified: ~Win32.Polipos~ - added link and quote tags - dog

Quote:
Originally Posted by Dr.Web
Win32.Polipos is a complicated polymorphic virus.

The virus affects the Windows executable files putting the polymorphic descriptor code into vacant areas of the code sections. The main code-protected body of the virus goes into a new section of the infected executable file.

When launched, the virus injects its code into all active processes. The exceptions are the processes, which have the following names:
savedump, dumprep, dwwin, drwtsn32, drwatson, kernel32.dll, smss, csrss, spoolsv, ctfmon, temp.

Self-decoded and extracted copies of the virus become resident in the memory of each active application. Each copy is responsible for a certain type of action: searching for files which are appropriate for infection, the process of infection itself, P2P network (based on Gnutella networks) function control and so on. Infected files become available for all the users of the network.

Win32 Polipos intercepts the following API functions:
ExitProcess, CreateProcess, CreateFileA, LoadLibraryExA, SearchPathA, CreateProcessW, CreateFileW, LoadLibraryExW, SearchPathW.

When the abovementioned functions are executed, the infection of new files takes place. The virus puts the infected file with overlays (sfx-archives, distributors and so on) in control and creates a clean ptf*.tmp copy of the infected file in the temporary directory. Then it launches the clean copy of the infected executable file.

The virus removes the following antivirus program files:
drwebase.vdb, avg.avi, vs.vsn, antivir.dat, avp.crc, chklist.ms,ivb.ntz, ivp.ntz, chklist.cps, smartchk.ms, smartchk.cps, aguard.dat, avgqt.dat, lguard.vps.

Win32.Polipos does not infect files, whose names have the following combinations:
tb dbg f- nav pav mon rav nvc fpr dss ibm inoc scn pack vsaf vswp fsav adinf sqstart mc watch kasp nod setup temp norton mcafee anti tmp secure upx forti scan zone labs alarm symantec retina eeye virus firewall spider backdoor drweb viri debug panda shield kaspersky doctor trend micro sonique cillin barracuda sygate rescue pebundle ida spf assemble pklite aspack disasm gladiator ort expl process eliashim tds3 starforce safe'n'sec avx root burn aladdin esafe olly grisoft avg armor numega mirc softice norman neolite tiny ositis proxy webroot hack spy iss pkware blackice lavasoft aware pecompact clean hunter common kerio route trojan spyware heal alwil qualys tenable avast a2 etrust spy steganos security principal agnitum outpost avp personal softwin defender intermute guard inoculate sophos frisk alwil protect eset nod32 f-prot avwin ahead nero blindwrite clonecd elaborate slysoft hijack roxio imapi newtech infosystems adaptec swift sound copystar astonsoft gear software sateira dfrgntfs

The virus contains the line “Win32.Polipos v1.2 by Joseph”.

Last edited by dog : April 20th, 2006 at 08:41 AM. Reason: added the appropriate quote tags
  #5  
Old April 20th, 2006, 08:52 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Re: New p2p-virus?

well.... no other names from other vendros on DrWeb web site. Does NOD32 detects it?
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
  #6  
Old April 20th, 2006, 08:59 AM
Inspector Clouseau's Avatar
Inspector Clouseau Inspector Clouseau is offline
AV Expert (VP Sunbelt Software)
 
Join Date: Apr 2006
Location: Maidenhead, UK
Posts: 1,329
Default Re: New p2p-virus?

i submitted samples this morning.
__________________
My Pictures Meet me on facebook!
  #7  
Old April 20th, 2006, 09:09 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Re: New p2p-virus?

Quote:
Originally Posted by Inspector Clouseau
i submitted samples this morning.

Thx Inspector. Hope your samples are analysed faster than mine. Otherwise......
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
  #8  
Old April 20th, 2006, 10:42 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: New p2p-virus?

Surely faster than the old dos executables and joke programs.
  #9  
Old April 21st, 2006, 03:12 PM
izi's Avatar
izi izi is offline
Frequent Poster
 
Join Date: Jan 2004
Location: Slovenia
Posts: 354
Default Re: New p2p-virus?

Does NOD32 detect this virus?
  #10  
Old April 22nd, 2006, 10:32 AM
i_kenefick's Avatar
i_kenefick i_kenefick is offline
Regular Poster
 
Join Date: Nov 2005
Location: Cork, Ireland.
Posts: 135
Default Re: New p2p-virus?

Quote:
Originally Posted by izi
Does NOD32 detect this virus?

It doesn't detect the samples I have anyways - I guess they are waiting to figure out how to clean it rather than add 'detection' before this for fear of breaking many infected machines.

AntiVir 6.34.0.24 04.20.2006 no virus found
Avast 4.6.695.0 04.21.2006 no virus found
AVG 386 04.21.2006 no virus found
Avira 6.34.0.56 04.22.2006 no virus found
BitDefender 7.2 04.22.2006 Win32.Polipos.A
CAT-QuickHeal 8.00 04.21.2006 (Suspicious) - DNAScan
ClamAV devel-20060202 04.22.2006 no virus found
DrWeb 4.33 04.22.2006 Win32.Polipos
eTrust-InoculateIT 23.71.136 04.22.2006 Win32/Polipos!Worm
eTrust-Vet 12.4.2171 04.21.2006 no virus found
Ewido 3.5 04.22.2006 no virus found
Fortinet 2.71.0.0 04.22.2006 W32/Polipos.V12
F-Prot 3.16c 04.21.2006 no virus found
Ikarus 0.2.59.0 04.21.2006 no virus found
Kaspersky 4.0.2.24 04.22.2006 P2P-Worm.Win32.Polipos.a
McAfee 4746 04.21.2006 no virus found
NOD32v2 1.1502 04.22.2006 no virus found
Norman 5.90.16 04.21.2006 no virus found
Panda 9.0.0.4 04.22.2006 no virus found
Sophos 4.04.0 04.21.2006 W32/Polipos-A
Symantec 8.0 04.22.2006 no virus found
TheHacker 5.9.7.133 04.22.2006 no virus found
UNA 1.83 04.21.2006 no virus found
VBA32 3.11.0 04.22.2006 Virus.Win32.Polipos.A
  #11  
Old April 22nd, 2006, 11:36 AM
mackattack mackattack is offline
Infrequent Poster
 
Join Date: Apr 2006
Location: Dublin Ireland
Posts: 3
Default Re: New p2p-virus?

Hi,

Anyone know of a way to clean this virus it seems a site we have in Athlone, Ireland is infected and has wiped the machines they use. I have just got them to shut down everything untill I can find info on it.

A full site rebuild is not what I want to advise at this stage.
Any help would be great.

Regards
  #12  
Old April 22nd, 2006, 11:52 AM
Antarctica's Avatar
Antarctica Antarctica is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,365
Default Re: New p2p-virus?

Quote:
Originally Posted by mackattack
Hi,

Anyone know of a way to clean this virus it seems a site we have in Athlone, Ireland is infected and has wiped the machines they use. I have just got them to shut down everything untill I can find info on it.

A full site rebuild is not what I want to advise at this stage.
Any help would be great.

Regards

If you read at the end of the article from Dr. Web, they can remove it.

http://info.drweb.com/show/2815/en



At present, Virus monitoring service of Doctor Web, Ltd. designed the curing procedure for files infected with Win32.Polipos. It was done for users whose anti-virus programs still do not detect this virus and whose computers, though protected by other anti-virus programs, are infected with the virus and let it infect other computers. The curing technique is rather difficult, as it requires processing of a complicated crypt algorithm XTEA, and the decoding of the virus code can take much time. You should not download any additional curing utilities to cure the infected files, just use Dr.Web Anti-virus and update the virus bases on time.
__________________
One for all/All for one
  #13  
Old April 22nd, 2006, 11:58 AM
mackattack mackattack is offline
Infrequent Poster
 
Join Date: Apr 2006
Location: Dublin Ireland
Posts: 3
Default Re: New p2p-virus?

Hey,

Thanks for the quick reply, I have one of the users trying to find a machine thats not inected on the LAN to download as the infected machines can not do very much.

Mac
  #14  
Old April 22nd, 2006, 12:01 PM
i_kenefick's Avatar
i_kenefick i_kenefick is offline
Regular Poster
 
Join Date: Nov 2005
Location: Cork, Ireland.
Posts: 135
Default Re: New p2p-virus?

Quote:
Originally Posted by mackattack
Hi,

Anyone know of a way to clean this virus it seems a site we have in Athlone, Ireland is infected and has wiped the machines they use. I have just got them to shut down everything untill I can find info on it.

A full site rebuild is not what I want to advise at this stage.
Any help would be great.

Regards

AFAIK, vendors should have a disinfection routine added over the coming days. Dr Web's CureIT! tool can clean it, Mike (Inspector Clouseau) is developing his own disinfection tool also.

P.S. Greetings from Cork :-)
  #15  
Old April 22nd, 2006, 12:19 PM
Antarctica's Avatar
Antarctica Antarctica is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,365
Default Re: New p2p-virus?

Quote:
Originally Posted by mackattack
Hey,

Thanks for the quick reply, I have one of the users trying to find a machine thats not inected on the LAN to download as the infected machines can not do very much.

Mac


You're most welcome and I hope you can get back in business ASAP.
__________________
One for all/All for one
  #16  
Old April 22nd, 2006, 12:45 PM
mackattack mackattack is offline
Infrequent Poster
 
Join Date: Apr 2006
Location: Dublin Ireland
Posts: 3
Default Re: New p2p-virus?

Quote:
Originally Posted by i_kenefick
AFAIK, vendors should have a disinfection routine added over the coming days. Dr Web's CureIT! tool can clean it, Mike (Inspector Clouseau) is developing his own disinfection tool also.

P.S. Greetings from Cork :-)

Hello Cork, if I was closer a pint might have to be bought.

Do you know what the virus does to the machine after a few days. The users onsite are telling me the machine is wiped, from what I can gather all the documents are gone from mapped drives.

Thanks for the help.
  #17  
Old April 22nd, 2006, 01:33 PM
rothko's Avatar
rothko rothko is offline
Frequent Poster
 
Join Date: Jan 2005
Location: UK
Posts: 579
Default Re: New p2p-virus?

Quote:
Originally Posted by i_kenefick
It doesn't detect the samples I have anyways - I guess they are waiting to figure out how to clean it rather than add 'detection' before this for fear of breaking many infected machines.

AntiVir 6.34.0.24 04.20.2006 no virus found
Avast 4.6.695.0 04.21.2006 no virus found
AVG 386 04.21.2006 no virus found
Avira 6.34.0.56 04.22.2006 no virus found
BitDefender 7.2 04.22.2006 Win32.Polipos.A
CAT-QuickHeal 8.00 04.21.2006 (Suspicious) - DNAScan
ClamAV devel-20060202 04.22.2006 no virus found
DrWeb 4.33 04.22.2006 Win32.Polipos
eTrust-InoculateIT 23.71.136 04.22.2006 Win32/Polipos!Worm
eTrust-Vet 12.4.2171 04.21.2006 no virus found
Ewido 3.5 04.22.2006 no virus found
Fortinet 2.71.0.0 04.22.2006 W32/Polipos.V12
F-Prot 3.16c 04.21.2006 no virus found
Ikarus 0.2.59.0 04.21.2006 no virus found
Kaspersky 4.0.2.24 04.22.2006 P2P-Worm.Win32.Polipos.a
McAfee 4746 04.21.2006 no virus found
NOD32v2 1.1502 04.22.2006 no virus found
Norman 5.90.16 04.21.2006 no virus found
Panda 9.0.0.4 04.22.2006 no virus found
Sophos 4.04.0 04.21.2006 W32/Polipos-A
Symantec 8.0 04.22.2006 no virus found
TheHacker 5.9.7.133 04.22.2006 no virus found
UNA 1.83 04.21.2006 no virus found
VBA32 3.11.0 04.22.2006 Virus.Win32.Polipos.A

if Polipos is as bad as everyone is making out then it would be nice to have at least detection for it even if the cleaning comes later
__________________
kiss my pig
  #18  
Old April 22nd, 2006, 02:23 PM
i_kenefick's Avatar
i_kenefick i_kenefick is offline
Regular Poster
 
Join Date: Nov 2005
Location: Cork, Ireland.
Posts: 135
Default Re: New p2p-virus?

Quote:
Originally Posted by rothko
if Polipos is as bad as everyone is making out then it would be nice to have at least detection for it even if the cleaning comes later

agreed.
  #19  
Old April 24th, 2006, 05:00 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Re: New p2p-virus?

Quote:
Originally Posted by Marcos
Surely faster than the old dos executables and joke programs.

Well, Marcos thank you for the answer ...now I know you're not paying attention to these not-dangerous threats like jokes, DOS and phishing e-mails.

You concentrate on highly-dangerous threats like this p2p worm....which is still not detected by NOD32.
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
  #20  
Old April 24th, 2006, 08:45 AM
snowbound snowbound is offline
Retired Moderator
 
Join Date: Feb 2003
Location: The Big Smoke
Posts: 8,727
Default Re: New p2p-virus?

Reply by member i_kenefick, removed. TOS violation.



snowbound
  #21  
Old April 24th, 2006, 12:01 PM
i_kenefick's Avatar
i_kenefick i_kenefick is offline
Regular Poster
 
Join Date: Nov 2005
Location: Cork, Ireland.
Posts: 135
Default Re: New p2p-virus?

Quote:
Originally Posted by snowbound
Reply by member i_kenefick, removed. TOS violation.
snowbound
Pyko - at least we know the thread is being watched. You should get an answer soon... and maybe detection later
__________________
Regards,
Ian Kenefick
http://www.iansblog.org
  #22  
Old April 25th, 2006, 02:42 AM
Joliet Jake's Avatar
Joliet Jake Joliet Jake is offline
Frequent Poster
 
Join Date: Mar 2005
Location: Scotland
Posts: 911
Default Re: New p2p-virus?

Quote:
Originally Posted by i_kenefick
AFAIK, vendors should have a disinfection routine added over the coming days. Dr Web's CureIT! tool can clean it, Mike (Inspector Clouseau) is developing his own disinfection tool also.

P.S. Greetings from Cork :-)

Someone in the 'polipos' thread in the 'other AV' section of the forum claims that Dr Web didn't clean up this virus.

http://www.wilderssecurity.com/showp...7&postcount=37
__________________
Damn and blast
  #23  
Old April 25th, 2006, 02:50 AM
ctrlaltdelete ctrlaltdelete is offline
Frequent Poster
 
Join Date: Oct 2005
Location: Netherlands
Posts: 312
Default Re: New p2p-virus?

I noticed Win32/Polip in the latest NOD32 update v.1.1505.
  #24  
Old April 25th, 2006, 02:50 AM
i_kenefick's Avatar
i_kenefick i_kenefick is offline
Regular Poster
 
Join Date: Nov 2005
Location: Cork, Ireland.
Posts: 135
Default Re: New p2p-virus?

Detection was added for win32/Polip virus in 1.1505 (20060425)

Name:  polip.png
Views: 1277
Size:  37.8 KB
__________________
Regards,
Ian Kenefick
http://www.iansblog.org

Last edited by i_kenefick : April 25th, 2006 at 02:59 AM.
  #25  
Old April 25th, 2006, 03:18 AM
rothko's Avatar
rothko rothko is offline
Frequent Poster
 
Join Date: Jan 2005
Location: UK
Posts: 579
Default Re: New p2p-virus?

good to see! wonder is this will catch all variants and whether it cleans too?
__________________
kiss my pig
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:14 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums