C
CJE Culver
My apologies if this is the wrong newsgroup for this enquiry.
Recently, I've managed to pick up a virus/malware which I've been unable
to locate any information on. I'm calling it "Universa" because Kerio PF
identifies it as "Universa Application".
It modus operandum is essentially this:
At odd times (I haven't figured out yet what the trigger is), it will
create two files in %WINDOWS%\TEMP, a REG file and an EXE file, both
randomly named (the EXE is named WIN*.TMP.EXE where the * is a random
four-digit hex number). First, it tries to run the REG file, which wants
to create a key in
HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\,
then it launches WIN*.TMP.EXE, which attempts to connect to two internet
sites, usually at reverse.theplanet.com, though most recently it seems
has switched to bones.vg.
I have all the detailed log reports if anyone's interested, but someone
must be able to identify this thing for me, and how to get rid of it.
CJE Culver
Recently, I've managed to pick up a virus/malware which I've been unable
to locate any information on. I'm calling it "Universa" because Kerio PF
identifies it as "Universa Application".
It modus operandum is essentially this:
At odd times (I haven't figured out yet what the trigger is), it will
create two files in %WINDOWS%\TEMP, a REG file and an EXE file, both
randomly named (the EXE is named WIN*.TMP.EXE where the * is a random
four-digit hex number). First, it tries to run the REG file, which wants
to create a key in
HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\,
then it launches WIN*.TMP.EXE, which attempts to connect to two internet
sites, usually at reverse.theplanet.com, though most recently it seems
has switched to bones.vg.
I have all the detailed log reports if anyone's interested, but someone
must be able to identify this thing for me, and how to get rid of it.
CJE Culver