Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

** New Virus **

Thread Tools
 
Search this Thread
 
Old 13 November 2002, 09:45 AM
  #1  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Red face

got a virus alert this morning for this:

Name: Tr/Mastaz
Alias: Troj/Maz.A
Type: Trojan Downloader
Discovered: November 11, 2002
Size: 4.096 KB
Platform: Microsoft Windows 95/98/Me/NT/2000/XP

Description:

Tr/Mastaz is a trojan downloader that downloads the file "Msrexe. exe (30.720KB)" from a specified website and installs it in the users \windows\system\ directory.

So that it gets run each time a user restart their computer the following registry key gets added:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run "System Service"="C:\\WINDOWS\\SYSTEM\\MSREXE. EXE"

It also adds the key:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\Swartax "ImagePath"="C:\\WINDOWS\\SYSTEM\\MSREXE. EXE"

worrying that Sophos & McAfee do not appear to have a listing of this one, is it a hoax, certainly doesn't appear to be.

Jack Clark, perhaps you could comment ??

found this: http://www.pccomputernotes.com/viruses/backdoorg2.htm

shunty
Old 13 November 2002, 10:04 AM
  #2  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Post

some other sites show the actual .exe as an older subseven virus.....
any ideas ???

www.centralcommand.com
has it listed as a new virus
shunty
Old 13 November 2002, 11:02 AM
  #3  
User 1421
Scooby Regular
 
User 1421's Avatar
 
Join Date: Jul 2001
Posts: 333
Likes: 0
Received 0 Likes on 0 Posts
Post

I think the payload looks a little small for the subseven virus IIRC..
Old 13 November 2002, 11:22 AM
  #4  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

I was right, it IS a new virus, Sophos have just released the ide file fo it:

http://www.sophos.com/virusinfo/analyses/trojbdooraml.html

edited to add the download link for sophos

http://www.sophos.com/downloads/ide/bdooraml.ide

shunty

[Edited by shunty - 11/13/2002 11:23:26 AM]
Old 13 November 2002, 11:31 AM
  #5  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

If you're a McAfee customer and you believe you're affected by this you can get a DAT file from Here

Further information
Old 13 November 2002, 11:39 AM
  #6  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Smile

Jack, just re-read my post, didn't mean to offend regarding the "maybe Jack Clark could comment" bit, just really busy this morning & didn't have time to phrase it better.
I have used mcafee for a few years btw. E-Policy suite.

Next time I get something like this do you want to mail you first ?

great for getting the link out to everyone, I'm sure you were aware of the virus.

shunty
Old 13 November 2002, 11:40 AM
  #7  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

There's more data being sent about this viruses than by it.

Messagelabs started the media avalanche this morning followed by Sophos. And here's me busy trying to sort out my Rally tickets

Trending Topics

Old 13 November 2002, 11:43 AM
  #8  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Smile

ok then, get yer tickets sorted & take an early lunch

shunty
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Big RS Dave
ScoobyNet General
5
14 April 2001 08:12 PM



Quick Reply: ** New Virus **



All times are GMT +1. The time now is 03:03 PM.