WORM_FUNNER.A ESET NOD32 ????

Discussion in 'NOD32 version 2 Forum' started by Spyro, Oct 15, 2004.

Thread Status:
Not open for further replies.
  1. Spyro

    Spyro Registered Member

    Joined:
    Oct 15, 2004
    Posts:
    6
    Location:
    Italy
    #1 - TREND MICRO

    WORM_FUNNER.A Severity:
    1/3 File Size:
    -

    Reported:
    2004-10-10 22:36 Last Update:
    2004-10-12 14:42

    Description:
    This worm propagates by sending a copy of itself to all contacts found in the MSN Messenger application. Its code also suggests that it may attempt to propagate via QQ Instant Messaging Application by sending a copy of itself as the file FUNNY.EXE.

    Full Report From Vendor View/Hide ChangeLog

    ChangeLog:


    Changes are listed in chronological order with the latest changes first.





    2004-10-12 14:42 Description was changed.

    New:
    "This worm propagates by sending a copy of
    itself to all contacts found in the MSN
    Messenger application. Its code also suggests
    that it may attempt to propagate via QQ
    Instant Messaging Application by sending a
    copy of itself as the file FUNNY.EXE."

    Old:
    "This worm propagates by sending a copy of
    itself to all contacts found in the MSN
    Messenger application."





    2004-10-11 16:02 Description was changed.

    New:
    "This worm propagates by sending a copy of
    itself to all contacts found in the MSN
    Messenger application."

    Old:
    "Upon execution, this worm drops several
    copies of itself in the Windows and Windows
    system folders. It creates autostart entries
    in the registry in order to ensure its
    automatic execution at every system startup.
    On Windows 98 and ME, it also modifies the
    file SYSTEM.INI."







    #2 - NETWORK ASSOCIATES

    W32/Funner.worm Severity:
    2/7 File Size:
    56,320

    Reported:
    2004-10-11 15:02 Last Update:
    2004-10-11 15:47

    Description:
    This worm is packed using ASPACK packer software and written in MSVB.

    Full Report From Vendor



    #3 - SYMANTEC

    W32.Funner Severity:
    2/5 File Size:
    56,320 bytes, 312,832 bytes (unpacked)

    Reported:
    2004-10-11 15:10 Last Update:
    2004-10-14 01:44

    Description:
    W32.Funner is a worm that spreads using Microsoft's MSN Messenger instant message program and modifies the hosts file.

    Full Report From Vendor View/Hide ChangeLog

    ChangeLog:


    Changes are listed in chronological order with the latest changes first.





    2004-10-14 01:44 Description was changed.

    New:
    "W32.Funner is a worm that spreads using
    Microsoft's MSN Messenger instant message
    program and modifies the hosts file."

    Old:
    "W32.Funner is a worm that spreads using
    Microsoft's Windows Messenger instant message
    program and modifies the hosts file."





    2004-10-12 20:44 File size was changed.

    New:
    "56,320 bytes, 312,832 bytes (unpacked)"

    Old:
    "56320, 312,832"







    #4 - COMPUTER ASSOCIATES

    Win32.Funner.A Severity:
    2/5 File Size:
    -

    Reported:
    2004-10-12 01:21 Last Update:
    2004-10-12 11:02

    Description:
    Win32.Funner is a worm that spreads via MSN Messenger and overwrites the host file on an affected machine. When executed, Win32.Funner creates several copies of itself on the affected system:

    Full Report From Vendor View/Hide ChangeLog

    ChangeLog:


    Changes are listed in chronological order with the latest changes first.





    2004-10-12 03:22 Description was changed.

    New:
    "Win32.Funner is a worm that spreads via MSN
    Messenger and overwrites the host file on an
    affected machine. When executed, Win32.Funner
    creates several copies of itself on the
    affected system:"

    Old:
    "Win32.Funny is a worm that spreads via MSN
    Messenger and overwrites the host file on an
    affected machine. When executed, Win32.Funner
    creates several copies of itself on the
    affected system:"





    2004-10-12 03:11 Severity was raised from N/A to 2/5.





    2004-10-12 03:11 Description was changed.

    New:
    "Win32.Funny is a worm that spreads via MSN
    Messenger and overwrites the host file on an
    affected machine. When executed, Win32.Funner
    creates several copies of itself on the
    affected system:"

    Old:
    "N/A"







    #5 - F-SECURE

    Funner.A Severity:
    - File Size:
    -

    Reported:
    2004-10-12 22:40 Last Update:
    2004-10-13 02:01

    Description:
    Funner is a MSN worm that spreads by sending itself to the contacts listed in Microsoft's Windows Messenger.

    Full Report From Vendor



    #6 - SOPHOS

    W32/Funner-A Severity:
    2/5 File Size:
    -

    Reported:
    2004-10-12 22:53 Last Update:
    -

    Description:


    Full Report From Vendor



    #7 - PANDA ANTIVIRUS

    Funner.A Severity:
    1/4 File Size:
    -

    Reported:
    2004-10-13 16:18 Last Update:
    2004-10-14 10:33

    Description:
    It modifies the HOSTS file, so that certain websites cannot be accessed.
     
  2. rumpstah

    rumpstah Registered Member

    Joined:
    Mar 19, 2003
    Posts:
    486
    NOD32 - v.1.892 (20041012)
    Virus signature database updates:
    Win32/Funner.A
     
Thread Status:
Not open for further replies.