Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 7th, 2010, 06:41 PM
SUPERIOR's Avatar
SUPERIOR SUPERIOR is offline
Regular Poster
 
Join Date: Dec 2007
Location: Syria
Posts: 161
Default New Worm Locks Documents with Password

Quote:
Malware researchers from Panda Security warn of a new worm, which locks all documents, presentations or emails found on infected computers with a password.

Dubbed Clippo.A, the worm copies itself as PICTURE.EXE and SOUND.EXE to all folders on the system, as well as to removable drives or network shares where it has write permissions.

full story
  #2  
Old September 7th, 2010, 06:51 PM
funkydude's Avatar
funkydude funkydude is offline
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,016
Default Re: New Worm Locks Documents with Password

Hardly call this new, but ok.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #3  
Old September 7th, 2010, 07:53 PM
SUPERIOR's Avatar
SUPERIOR SUPERIOR is offline
Regular Poster
 
Join Date: Dec 2007
Location: Syria
Posts: 161
Default Re: New Worm Locks Documents with Password

Quote:
Originally Posted by funkydude
Hardly call this new, but ok.
actually, never heard about any malware does the same thing i mean lock any kind of files .... its just puzzling why worm would lock documents..then doesnt lead to some ransomewares? they say it's just for annoying...
but as to their analyzing, i guess it's just skiddie worm...first it supports old version of windows not latest ones(like vista or seven)
second its way of propagation seems like simple
third, password long but only numbers ..which makes it more easily be bruteforced

the only thing i find interesting is "locking documents" as it's new symptom for me

but i was wondering, if file was set to "read only" does it have the ability to lock it? or thats impossible ?
  #4  
Old September 7th, 2010, 08:41 PM
funkydude's Avatar
funkydude funkydude is offline
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,016
Default Re: New Worm Locks Documents with Password

Searching ransom @ MMPC reveals a few of many types of variants that do this. For example, the search failed to bring up this from 2009: https://www.microsoft.com/security/p...Win32/Gpcode.H

It is very scary indeed
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #5  
Old September 7th, 2010, 09:11 PM
SUPERIOR's Avatar
SUPERIOR SUPERIOR is offline
Regular Poster
 
Join Date: Dec 2007
Location: Syria
Posts: 161
Default Re: New Worm Locks Documents with Password

Quote:
Originally Posted by funkydude
Searching ransom @ MMPC reveals a few of many types of variants that do this. For example, the search failed to bring up this from 2009: https://www.microsoft.com/security/p...Win32/Gpcode.H

It is very scary indeed

ooh...thanks alot for the info and links...actually never heard them before
so that worm has nothing new at all...then i am wondering why great company like panda would take this seriously

btw, do you know a good source to get samples of ransom trojans? or if you can pm me with links

Thanks in advance
  #6  
Old September 7th, 2010, 09:18 PM
wat0114
 
Posts: n/a
Default Re: New Worm Locks Documents with Password

From the article:

Quote:
Clippo affects Windows 2003 and XP, as well as previous versions of the operating system that are no longer actively supported by Microsoft.
  #7  
Old September 7th, 2010, 09:18 PM
funkydude's Avatar
funkydude funkydude is offline
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,016
Default Re: New Worm Locks Documents with Password

Quote:
Originally Posted by SUPERIOR
so that worm has nothing new at all...then i am wondering why great company like panda would take this seriously

One would hope that AV companies take all malware threats seriously ^^

But if you want my opinion of it, AV companies sometimes like to race to be "first" to document a new threat. This generally increases sales/awareness of product as the articles are technically advertising the product company writing it.

If you want to go further there are sometimes users that actively switch AV product because they are told AV product X detects new threat Y, but I don't think that's a very common thing.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #8  
Old September 8th, 2010, 07:20 AM
SUPERIOR's Avatar
SUPERIOR SUPERIOR is offline
Regular Poster
 
Join Date: Dec 2007
Location: Syria
Posts: 161
Default Re: New Worm Locks Documents with Password

Quote:
Originally Posted by funkydude
But if you want my opinion of it, AV companies sometimes like to race to be "first" to document a new threat. This generally increases sales/awareness of product as the articles are technically advertising the product company writing it.

very true, maybe they dont like but they have to
PS : i havent tried panda for long time, panda can fix this infection, i mean delete the password from infected files? anyone have an idea?
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:20 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums