Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Virut on the rise  (Read 17279 times)

0 Members and 1 Guest are viewing this topic.

Wefro_froyas



    Hopeful

    Thanked: 2
    Re: Virut on the rise
    « Reply #15 on: February 21, 2009, 07:41:10 PM »
    bye any chance evil fantasy is it possible to contract the virus bye going to IRC channel?

    evilfantasy

      Topic Starter
    • Malware Removal Specialist


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Virut on the rise
    « Reply #16 on: February 21, 2009, 07:59:40 PM »
    Possibly. If you visit a page which injects code through your browser then it's completely possible.

    See here: Under the Hood: Virut. I love the first line. "Virut is a weird freak amongst malware."

    Oh and an update from the first post. This new version is also infecting every mp3, doc, dll and on and on... :-\

    Wefro_froyas



      Hopeful

      Thanked: 2
      Re: Virut on the rise
      « Reply #17 on: February 21, 2009, 08:04:00 PM »
      should No script stop that?

      evilfantasy

        Topic Starter
      • Malware Removal Specialist


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Virut on the rise
      « Reply #18 on: February 21, 2009, 08:07:48 PM »
      That would be a good start as far as the browser is concerned.

      BC_Programmer


        Mastermind
      • Typing is no substitute for thinking.
      • Thanked: 1140
        • Yes
        • Yes
        • BC-Programming.com
      • Certifications: List
      • Computer: Specs
      • Experience: Beginner
      • OS: Windows 11
      Re: Virut on the rise
      « Reply #19 on: February 21, 2009, 08:46:28 PM »
      "Virut is a weird freak amongst malware."

      That actually isn't 100% true- there have been a few file infecting viruses with IRC and networking capabilities built in- in fact the author of a book studying viruses and how they work had one as an example.

      Interestingly enough, he submitted all his virus code to anti-malware authors/companies, in the hopes that they would add his virus signatures to prevent anybody doing anything malicious with them- it took most vendors over a year after publication before the AVs were catching them  :o

      Obviously none have been as widespread.
      I was trying to dereference Null Pointers before it was cool.

      evilfantasy

        Topic Starter
      • Malware Removal Specialist


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Virut on the rise
      « Reply #20 on: February 21, 2009, 09:05:08 PM »
      The explosion of p2p use has a lot to do with how rapid and widespread virus are now. People and antivirus vendors caught on to email/chat attachments pretty fast so many are able to avoid the malware spread through such means. With p2p all it takes is uploading the latest cracked version of a hot game, movie or CD to a single host site and it takes off like wild fire throughout the rest of the torrent sites and ultimately to the user.

      patio

      • Moderator


      • Genius
      • Maud' Dib
      • Thanked: 1769
        • Yes
      • Experience: Beginner
      • OS: Windows 7
      Re: Virut on the rise
      « Reply #21 on: February 21, 2009, 11:52:51 PM »
      IM is the new horizon for infections.
      " Anyone who goes to a psychiatrist should have his head examined. "

      BC_Programmer


        Mastermind
      • Typing is no substitute for thinking.
      • Thanked: 1140
        • Yes
        • Yes
        • BC-Programming.com
      • Certifications: List
      • Computer: Specs
      • Experience: Beginner
      • OS: Windows 11
      Re: Virut on the rise
      « Reply #22 on: February 22, 2009, 09:29:05 AM »
      IM is the new horizon for infections.

      which brings up an interesting story.

      yesterday somebody added me to MSN, so I figured, alright, I'll give them a chance.

      Immediately they sign in and ask for "help with VB" or something, and attach a zip.

      So I transfer it, unzip it... and it's an EXE file.

      they claimed it was their visual basic program. Can't remember exactly what they said was "wrong" with it, but I found a few things interesting when I opened the file with dependency viewer.

      In that is wasn't dependent on any vb runtime. This was a very strange VB program indeed! additionally viewing the resources revealed some untyped date that looked to be some sort of executable (in that it started with MZ.)

      but I decided to play along with them(I didn't run the program I'm just messing with them. great fun)...
      <Names are changed to protect the innocent>

      Them:"Did you open it?"

      Me:"Yeah. It just opened a command window, and then closed."

      Me:"hmm. looks like I got infected somehow."

      Them:"PWNED"

      Me:"how?"

      Them:"It was my trojan >:)"

      Me:"Oh, it's a good thing I didn't run it then. I kind of figured out it wasn't a VB program like you claimed."

      Them:"I'm kidding I really need help with C++. Can you run it and check for me"

      Me:F---- off.


      (deletes contact)


      So, all in all, I got some entertainment for a few minutes anyway.
      I was trying to dereference Null Pointers before it was cool.

      Wefro_froyas



        Hopeful

        Thanked: 2
        Re: Virut on the rise
        « Reply #23 on: February 22, 2009, 11:12:52 AM »
        IM is the new horizon for infections.

        which brings up an interesting story.

        yesterday somebody added me to MSN, so I figured, alright, I'll give them a chance.

        Immediately they sign in and ask for "help with VB" or something, and attach a zip.

        So I transfer it, unzip it... and it's an EXE file.

        they claimed it was their visual basic program. Can't remember exactly what they said was "wrong" with it, but I found a few things interesting when I opened the file with dependency viewer.

        In that is wasn't dependent on any vb runtime. This was a very strange VB program indeed! additionally viewing the resources revealed some untyped date that looked to be some sort of executable (in that it started with MZ.)

        but I decided to play along with them(I didn't run the program I'm just messing with them. great fun)...
        <Names are changed to protect the innocent>

        Them:"Did you open it?"

        Me:"Yeah. It just opened a command window, and then closed."

        Me:"hmm. looks like I got infected somehow."

        Them:"PWNED"

        Me:"how?"

        Them:"It was my trojan >:)"

        Me:"Oh, it's a good thing I didn't run it then. I kind of figured out it wasn't a VB program like you claimed."

        Them:"I'm kidding I really need help with C++. Can you run it and check for me"

        Me:F---- off.


        (deletes contact)


        So, all in all, I got some entertainment for a few minutes anyway.

        Lol nice I wish that kind of stuff would happen to me.

        kizza1645

        • Guest
        Re: Virut on the rise
        « Reply #24 on: February 25, 2009, 02:05:19 AM »
        How do i get a copy of this so called virut?

        Just want to test one out on my virtual pc.
        See if i can stop it.

        BC_Programmer


          Mastermind
        • Typing is no substitute for thinking.
        • Thanked: 1140
          • Yes
          • Yes
          • BC-Programming.com
        • Certifications: List
        • Computer: Specs
        • Experience: Beginner
        • OS: Windows 11
        Re: Virut on the rise
        « Reply #25 on: February 25, 2009, 03:06:48 AM »
        How do i get a copy of this so called virut?

        Just want to test one out on my virtual pc.
        See if i can stop it.


         ::)

        see if you can stop it. yeah using your "hacker skills" which probably pretty much end at being able to show hidden files/folders.

        How would you stop it? There is no feasible attack vector to stop it.

        If EvilFantasy says a reformat/reinstall is required- your wasting your time.
        I was trying to dereference Null Pointers before it was cool.

        kizza1645

        • Guest
        Re: Virut on the rise
        « Reply #26 on: February 25, 2009, 11:51:52 PM »
        How do i get a copy of this so called virut?

        Just want to test one out on my virtual pc.
        See if i can stop it.


         ::)

        see if you can stop it. yeah using your "hacker skills" which probably pretty much end at being able to show hidden files/folders.

        How would you stop it? There is no feasible attack vector to stop it.

        If EvilFantasy says a reformat/reinstall is required- your wasting your time.

        well i at least want to watch what happens.....

        evilfantasy

          Topic Starter
        • Malware Removal Specialist


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Virut on the rise
        « Reply #27 on: February 26, 2009, 09:32:11 AM »

        well i at least want to watch what happens.....

        See here: Under the Hood: Virut.