This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Community Information

New Nasty

1 min read

This thread's last reply is from September 21, 2005, 9:37 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

First detected September 20 so of course I got one via email. Thankfully, Symantec had just done an auto def update. (of course, I wouldn't have tried to open it....it appeared to be from me to me with an attachment)

http://securityresponse.symantec.com/av ... oso.q.html

It targets the security programs:
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec
HKEY_LOCAL_MACHINE\SOFTWARE\McAfee
HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab
HKEY_LOCAL_MACHINE\SOFTWARE\Agnitum
HKEY_LOCAL_MACHINE\SOFTWARE\Panda Software
HKEY_LOCAL_MACHINE\SOFTWARE\Zone Labs


So far, Symantec only recommends scanning with updated defs

Ugly little piece of nastiness
Thanks Piney!

Wife got one of those last night as well... checked the source on it because it did look like she had sent it to herself... her email ends with @shaw.ca... this one came from @principal.com. The email account name was spelled differently too... my wifes is all lower case... this one had an upper case letter in it as well.

Payload in this case was named 06.exe... Norton took care of it.

Just checked the wifes machine again... was going to look a bit further into the source/return path as my brain was foggy last night(flu)... seems she has deleted it.

Will watch for others.
mine was @moxieinteractive.com and the 06 variety.

psssssssttttt I didn't remember all the above, I looked in the NIS log :oops: