W32/LimpNet-A (orawin.exe)

Discussion in 'NOD32 version 2 Forum' started by blind486, Nov 28, 2006.

Thread Status:
Not open for further replies.
  1. blind486

    blind486 Registered Member

    Joined:
    Nov 10, 2006
    Posts:
    5
    resides in

    c:\$Windows$ \orawin.exe <-- virus/worm.
    c:\$Startup$\orawin.exe
    in registry run (startup applications) 'HP_spooler'


    Sad to say NOD32 didn't detect it at all. Even when i had it scanned specifically for that file only. Virus restarts your system when you hit CTRL+ALT+DEL when you try to terminate it, im not sure what damage it would do. File looks like an ordinary notepad which you would have thought a text file but instead it's an application. Author says '++'. Luckily you can remove it from safe mode and with the help of some info on the web. Didn't have much time to print screens and save a copy of the virus. Got dismayed and feel bad for NOD32 didn't catching this one. :doubt:
     
  2. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,374
    Did you send the file to samples @ eset.com? Remember that NO AV catches 100% of all threats, we have tons of samples detected only by NOD32 and missed by the others, but we are not here to bash anyone.
     
Thread Status:
Not open for further replies.