W32/LimpNet-A (orawin.exe)

Discussion in 'NOD32 version 2 Forum' started by blind486, Nov 28, 2006.

Thread Status:
Not open for further replies.
  1. blind486

    blind486 Registered Member

    Joined:
    Nov 10, 2006
    Posts:
    5
    resides in

    c:\$Windows$ \orawin.exe <-- virus/worm.
    c:\$Startup$\orawin.exe
    in registry run (startup applications) 'HP_spooler'


    Sad to say NOD32 didn't detect it at all. Even when i had it scanned specifically for that file only. Virus restarts your system when you hit CTRL+ALT+DEL when you try to terminate it, im not sure what damage it would do. File looks like an ordinary notepad which you would have thought a text file but instead it's an application. Author says '++'. Luckily you can remove it from safe mode and with the help of some info on the web. Didn't have much time to print screens and save a copy of the virus. Got dismayed and feel bad for NOD32 didn't catching this one. :doubt:
     
  2. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,410
    Did you send the file to samples @ eset.com? Remember that NO AV catches 100% of all threats, we have tons of samples detected only by NOD32 and missed by the others, but we are not here to bash anyone.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.