Notices
Non Scooby Related Anything Non-Scooby related

Nasty virus I cam across today...

Thread Tools
 
Search this Thread
 
Old 08 June 2001, 10:03 PM
  #1  
DazV
Scooby Regular
Thread Starter
 
DazV's Avatar
 
Join Date: Jun 2000
Posts: 3,783
Likes: 0
Received 0 Likes on 0 Posts
Post

Called BadTrans

Infects via an email attachment which can be any one of the following:
Card.pif
docs.scr
fun.pif
hamster.ZIP.scr
Humor.TXT.pif
images.pif
New_Napster_Site.DOC.scr
news_doc.scr
Me_nude.AVI.pif
Pics.ZIP.scr
README.TXT.pif
s3msong.MP3.pif
searchURL.scr
SETUP.pif
Sorry_about_yesterday.DOC.pif
YOU_are_FAT!.TXT.pif

Once triggered it splits intself into 3 parts.

One called INETD.EXE is triggered by the win.ini. (located in windows folder)

One called KERN32.exe which is a trojan. (located in windowssystem folder)

Last one is the worst, called HKSDLL.DLL - its a keylogger which is capable of recording keypresses (like credit card info) into a file. The file is then transmitted back to the author.

Nasty or what ?
More info at
Old 10 June 2001, 12:02 PM
  #2  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Clever little b'stard isn't it. Hope everyone here practices safe hex.

If anyone here needs Antivirus advice feel free to ask.

Jack Clark
McAfee/Dr Solomon's

<BLOCKQUOTE><font size="1" face="Verdana, Arial">quote:<HR>Originally posted by DazV:
<B>
Card.pif
docs.scr
fun.pif
hamster.ZIP.scr
Humor.TXT.pif
images.pif
New_Napster_Site.DOC.scr
news_doc.scr
Me_nude.AVI.pif
Pics.ZIP.scr
README.TXT.pif
s3msong.MP3.pif
searchURL.scr
SETUP.pif
Sorry_about_yesterday.DOC.pif
YOU_are_FAT!.TXT.pif[/quote]

Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
28 December 2015 11:07 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
18 November 2015 07:03 AM
Ganz1983
Subaru
5
02 October 2015 09:22 AM



Quick Reply: Nasty virus I cam across today...



All times are GMT +1. The time now is 08:17 PM.