Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 14th, 2005, 01:06 PM
zilla1126 zilla1126 is offline
Infrequent Poster
 
Join Date: Jun 2005
Posts: 4
Default New virus - VERY DANGEROUS!

Nod32 does not know what it is, but sees it as a "Unknown win32 virus" and it still stops it. This virus replaces nearly ALL of the exe files on a machine with virus inefected files. Most AV products do not detect it; McAfee discovered it yesterday.


This ended up on three machines yesterday at a client of mine; I had not
been out in quite a while (he is incredibly cheap) so all his stuff was
out of date or broken. His Norton AV would not have caught it anyway.



FYI:

AntiVir 6.31.0.9 07.14.2005 W32/Stanit
AVG 718 07.14.2005 Win32/Gaelicum.A
Avira 6.31.0.9 07.14.2005 W32/Stanit
BitDefender 7.0 07.14.2005 no virus found
CAT-QuickHeal 7.03 07.14.2005 no virus found
ClamAV devel-20050501 07.14.2005 no virus found
DrWeb 4.32b 07.14.2005 Win32.Gael.3666
eTrust-Iris 7.1.194.0 07.13.2005 no virus found
eTrust-Vet 11.9.1.0 07.14.2005 no virus found
Fortinet 2.36.0.0 07.14.2005 suspicious
F-Prot 3.16c 07.14.2005 could be infected with an unknown virus
Ikarus 2.32 07.14.2005 no virus found
Kaspersky 4.0.2.24 07.14.2005 Virus.Win32.Tenga.a
McAfee 4535 07.14.2005 W32/Gael
NOD32v2 1.1168 07.14.2005 probably unknown WIN32 virus
Norman 5.70.10 07.14.2005 no virus found
Panda 8.02.00 07.14.2005 no virus found
Sybari 7.5.1314 07.14.2005 W32/Gael
Symantec 8.0 07.13.2005 no virus found
TheHacker 5.8.2.070 07.13.2005 no virus found
VBA32 3.10.4 07.14.2005 no virus found
  #2  
Old July 14th, 2005, 01:40 PM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: New virus - VERY DANGEROUS!

Well atleast NOD's heuristics stops it untill they add it to the signature db
If you can, send it to Eset for analysis.
  #3  
Old July 14th, 2005, 01:45 PM
Stan999 Stan999 is offline
Frequent Poster
 
Join Date: Sep 2002
Location: Fort Worth, TX USA
Posts: 566
Default Re: New virus - VERY DANGEROUS!

Quote:
Originally Posted by Brian N
Well atleast NOD's heuristics stops it untill they add it to the signature db
If you can, send it to Eset for analysis.

Good to have that zero-hour protection.
  #4  
Old July 14th, 2005, 02:08 PM
JimIT's Avatar
JimIT JimIT is offline
Very Frequent Poster
 
Join Date: Jan 2003
Location: Denton, Texas
Posts: 1,035
Default Re: New virus - VERY DANGEROUS!

I believe SARC is on this and have ID'd it as win32.licum.

At any rate, it appears they have a def:

Here
__________________
www.gremiss.com
  #5  
Old July 22nd, 2005, 07:18 AM
JoCool JoCool is offline
Infrequent Poster
 
Join Date: Jun 2005
Posts: 46
Default Does NOD detect Kirvo.B ?

Cannot nowhere find anything about that. Was this Version knwon by ESET ?
  #6  
Old July 22nd, 2005, 07:31 AM
Happy Bytes
 
Posts: n/a
Default Re: New virus - VERY DANGEROUS!

Here... Read this
Attached Files
File Type: zip Win32.Tenga.A-description.zip (123.5 KB, 174 views)
  #7  
Old July 22nd, 2005, 07:47 AM
JoCool JoCool is offline
Infrequent Poster
 
Join Date: Jun 2005
Posts: 46
Default Re: New virus - VERY DANGEROUS!

Quote:
Originally Posted by Happy Bytes
Here... Read this

Ok, thanks.

And you this http://www.zdnet.de/news/security/0,...9135132,00.htm

btw. It's called NEWS from the Yellows
  #8  
Old July 22nd, 2005, 07:52 AM
Happy Bytes
 
Posts: n/a
Default Re: New virus - VERY DANGEROUS!

Ich verstehe kein Wort was Du mir versuchst in Englisch zu erzaehlen
Also nochmal - was ist los?
  #9  
Old July 22nd, 2005, 09:07 AM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: New virus - VERY DANGEROUS!

Quote:
Originally Posted by Happy Bytes
Here... Read this
Very detailed description indeed
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #10  
Old July 22nd, 2005, 09:51 AM
Happy Bytes
 
Posts: n/a
Default Re: New virus - VERY DANGEROUS!

Quote:
Originally Posted by Brian N
Very detailed description indeed

Says who?
  #11  
Old July 22nd, 2005, 09:58 AM
Happy Bytes
 
Posts: n/a
Default Re: New virus - VERY DANGEROUS!

There's always some background information and "educational" stuff in my virus descriptions. So basicly you can read them even if you are not infected

Example here - a trojan downloader description spammed 2 days ago:
http://www.eset.com/msgs/vidloq.htm
  #12  
Old July 22nd, 2005, 10:00 AM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: New virus - VERY DANGEROUS!

Quote:
Originally Posted by Happy Bytes
Says who?
Says me. I didn't understand a word of it, so it must be detailed j/k
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #13  
Old July 23rd, 2005, 06:27 AM
hin123 hin123 is offline
Infrequent Poster
 
Join Date: Mar 2005
Posts: 12
Default Re: New virus - VERY DANGEROUS!

Quote:
Originally Posted by Happy Bytes
There's always some background information and "educational" stuff in my virus descriptions. So basicly you can read them even if you are not infected

Example here - a trojan downloader description spammed 2 days ago:
http://www.eset.com/msgs/vidloq.htm
The title of that page is "Win32/Mytob.DQ"
It is the same for Win32.Mydoom.BI, Win95/Tenrobot.B and Win32/Tenga.A
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:38 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums