We got two variants of MSN worm today. We'll post details about these two variants.
1. picts-XXXX.zip (img0794-www.photoshare.com) [XXXX is random digitals, e.g. , picts-4270.zip,picts-7881.zip]
Size: 76,288 bytes
MD5: 2cd088793c854c6b3129e717e4a9dffc
Detection: Backdoor.Win32.IRCBot.aiu (Kaspersky)
Details: click here
2. imageXX.zip (imageXX.jpg-www.imageshack.com) [XX is random digitals, e.g. , image08.zip]
Size: 51,712 bytes
MD5: b858684251a28e9381a9920a389012df
Detection: Backdoor.Win32.IRCBot.ahw (Kaspersky)
Details: click here
Last modified by smallmo onSeptember 30, 2007 18:23
1. picts-XXXX.zip (img0794-www.photoshare.com) [XXXX is random digitals, e.g. , picts-4270.zip,picts-7881.zip]
Size: 76,288 bytes
MD5: 2cd088793c854c6b3129e717e4a9dffc
Detection: Backdoor.Win32.IRCBot.aiu (Kaspersky)
Details: click here
2. imageXX.zip (imageXX.jpg-www.imageshack.com) [XX is random digitals, e.g. , image08.zip]
Size: 51,712 bytes
MD5: b858684251a28e9381a9920a389012df
Detection: Backdoor.Win32.IRCBot.ahw (Kaspersky)
Details: click here
Last modified by smallmo onSeptember 30, 2007 18:23
I have tha same problem but all i found is mcagent_exe i dont what it is please help!!
vicentor Says :
January 21, 2008 10:09
I found a okzf addition in my reg. I dont know if it is a cause but it is basically attached to the system32 folder. i need help
Hello,
I have this virus, but after looking in:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Run
I could not find the virus or any of its variants. I am wondering if it is possible that I have a new variant. I have an entry with the name dla and under data it says "C:\WINDOWS\system32\dla\tfswctrl.exe Could this possibly be it?
I have this virus, but after looking in:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Run
I could not find the virus or any of its variants. I am wondering if it is possible that I have a new variant. I have an entry with the name dla and under data it says "C:\WINDOWS\system32\dla\tfswctrl.exe Could this possibly be it?
jord Says :
November 9, 2007 01:26
i got picts.xxxx but i cant delete the juchek? do u hav 2 b adminastra
frou14 Says :
November 6, 2007 13:15
I have the same problem. it freezes my mouse and sends files to my friends without me knowing and when i sign out it opens and closes conversations windows quickly.
i cannot find mdn.exe under the registry but i do have
mdesvc.exe and AGRSMMSG.exe
please advise.
i cannot find mdn.exe under the registry but i do have
mdesvc.exe and AGRSMMSG.exe
please advise.
mdesvc.exe is like the new variant, please look this post:
http://www.cisrt.org/enblog/read.php?191
http://www.cisrt.org/enblog/read.php?191
smallmo replied on November 7, 2007 12:26
Jacky Says :
October 30, 2007 10:26
i did not have the nvsvc64.exe file, but I had nvsvc32.exe file instead, I have not deleted the 32 one as it is part of nvidia driver helper service thing. I have the abgsvc.exe variant of the virus
Moonny replied on October 30, 2007 16:28
joo Says :
October 23, 2007 12:27
i don't remember getting/opening these, and i can't find any of the mentioned files, yet the symptoms are clear. what the heck should i do?
Tay Says :
October 22, 2007 02:43
I can not find mdn.exe anywhere, and I don't want to accidentally delete a wrong entry. Any help?
I got this virus through a file named "image12.zip" I have looked into my Registry Editor but i couldn't find the file I need to delete. Every variations so far that i have read requires you to delete a different file. I am afraid to delete the wrong file.
You may download this tool:
http://www.cisrt.org/tools/SREngPS.EXE
Save the report file "SREngLOG" generated by its "SmartScan" and send to me:
amezhs@cisrt.org
I'll help you to find the virus.
http://www.cisrt.org/tools/SREngPS.EXE
Save the report file "SREngLOG" generated by its "SmartScan" and send to me:
amezhs@cisrt.org
I'll help you to find the virus.
Moonny replied on October 21, 2007 00:32
ja Says :
October 20, 2007 21:36
hi i replied a few days ago regarding how i couldnt find "Machine Debug Mgr"="mdn.exe" in the right pane. hope that you can help me soon as this virus is driving me nuts! thanks so much.
You may download this tool:
http://www.cisrt.org/tools/SREngPS.EXE
Save the report file "SREngLOG" generated by its "SmartScan" and send to me:
amezhs@cisrt.org
I'll help you to find the virus.
http://www.cisrt.org/tools/SREngPS.EXE
Save the report file "SREngLOG" generated by its "SmartScan" and send to me:
amezhs@cisrt.org
I'll help you to find the virus.
Moonny replied on October 21, 2007 00:32
Hi I think that I got the same virus/spyware as "Cass" from below is there anything that i can do to stop it? it was those image ones and i've been sending countless files to my contacts and it completely freezed my computer, i've done the computer scans as well and i've found nothing too... help would be greatly appreciated!
nerd hunter Says :
October 14, 2007 20:12
fuck the sackface who creates this shit
ja Says :
October 13, 2007 20:31
thanks for the advice, Moonny! but i do not seem to have the "Machine Debug Mgr"="mdn.exe" on the right pane. i'm using windows 2000. what can i do? thanks.
ja Says :
October 9, 2007 22:09
hi i have this msn prpblem too... but i have no idea how to find the "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"Machine Debug Mgr" = "mdn.exe"" file you mention. please help me thanks!
"Machine Debug Mgr" = "mdn.exe"" file you mention. please help me thanks!
"Start" menu -> "Run", input "REGEDIT", "ENTER".
Open the registry editor...
left pane:
HKEY_LOCAL_MACHINE -> SOFTWARE -> Microsoft -> Windows -> CurrentVersion -> Run
right pane:
"Machine Debug Mgr"="mdn.exe"
Open the registry editor...
left pane:
HKEY_LOCAL_MACHINE -> SOFTWARE -> Microsoft -> Windows -> CurrentVersion -> Run
right pane:
"Machine Debug Mgr"="mdn.exe"
Moonny replied on October 10, 2007 09:56
eeled Says :
October 6, 2007 15:59
I (also stupidly) downloaded the zip file from my friend, and caught teh worm.
but for me, what the virus did was send out
"ZHE SHI WO DE LUOZHAO :O QING BU YAO FA GEI BIEREN !!." <ONLY this message to my friends
AND the zip file was called "pics4you.zip" <<or something like that...
i have no idea what to do T_T
msn keeps opening and reopening windows, sending multiple sends of those viruses to my friends. and also freezes my mouse, and disables me from doing anything other than "ctrl+alt+delete" and then closing the task for msn messenger.
I'm doomed T_T help anyone?
but for me, what the virus did was send out
"ZHE SHI WO DE LUOZHAO :O QING BU YAO FA GEI BIEREN !!." <ONLY this message to my friends
AND the zip file was called "pics4you.zip" <<or something like that...
i have no idea what to do T_T
msn keeps opening and reopening windows, sending multiple sends of those viruses to my friends. and also freezes my mouse, and disables me from doing anything other than "ctrl+alt+delete" and then closing the task for msn messenger.
I'm doomed T_T help anyone?
Could you send file "pics4you.zip" to us?
Please compress the file in .RAR or .ZIP fomat with the password "virus", thank you.
Email:
newvirus@cisrt.com
sample@cisrt.org
Please compress the file in .RAR or .ZIP fomat with the password "virus", thank you.
Email:
newvirus@cisrt.com
sample@cisrt.org
Moonny replied on October 6, 2007 23:09
Pages: 1/2
1 2
1 2
imageXX.zip, MSN worm variant
ARP attack to CISRT.org

Pages: [1] 




