A
Adam Piggott
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hiya,
Found a pair of viral files on a client's Windows XP Home (RTM) computer
recently that seemed to be scanning the WAN IP range (couldn't tell what as
ethereal wouldn't listen on the interface type). This was causing the PC to
hang after a short while.
I removed the files which were in C:\WINDOWS\system32, with system and
hidden attributes set. They were both sitting in the HKCU Windows\Run
registry key and when the entries were removed, they were replaced.
winrarx.exe
138,721 bytes
SHA1: daf47331caf439fbaad74332e4507f37f77f83af
wumgrd32.exe
78,622 bytes
SHA1: 16e7c2958abb7042e8492b8fdea71e968f1b8afb
Virustotal.com's results are all heuristic detection and I'd like to know
what exactly these files were doing so I can consider a plan of action on
the infected PC.
Any further information appreciated!
Cheers,
Adam Piggott,
Proprietor,
Proactive Services (Computing).
- --
Please replace dot invalid with dot uk to email me.
Apply personally for PGP public key.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (MingW32)
iD8DBQFCcOVi7uRVdtPsXDkRAmgjAKCceDXF3TzBMFkmdWw2WZLwhEc1QACfcBPN
DTYPLJRhMld4PLLvOcjPjkI=
=xxWI
-----END PGP SIGNATURE-----
Hash: SHA1
Hiya,
Found a pair of viral files on a client's Windows XP Home (RTM) computer
recently that seemed to be scanning the WAN IP range (couldn't tell what as
ethereal wouldn't listen on the interface type). This was causing the PC to
hang after a short while.
I removed the files which were in C:\WINDOWS\system32, with system and
hidden attributes set. They were both sitting in the HKCU Windows\Run
registry key and when the entries were removed, they were replaced.
winrarx.exe
138,721 bytes
SHA1: daf47331caf439fbaad74332e4507f37f77f83af
wumgrd32.exe
78,622 bytes
SHA1: 16e7c2958abb7042e8492b8fdea71e968f1b8afb
Virustotal.com's results are all heuristic detection and I'd like to know
what exactly these files were doing so I can consider a plan of action on
the infected PC.
Any further information appreciated!
Cheers,
Adam Piggott,
Proprietor,
Proactive Services (Computing).
- --
Please replace dot invalid with dot uk to email me.
Apply personally for PGP public key.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (MingW32)
iD8DBQFCcOVi7uRVdtPsXDkRAmgjAKCceDXF3TzBMFkmdWw2WZLwhEc1QACfcBPN
DTYPLJRhMld4PLLvOcjPjkI=
=xxWI
-----END PGP SIGNATURE-----