![]() |
|
Register | FAQ | The Twelve Commandments | Members List | Calendar | Arcade | Find the Best VPN | Today's Posts | Search |
Open Discussion topics Discuss the time of day, whatever you want to. This is the hangout area. If you have LimeWire problems, post them here too. |
![]() |
| LinkBack | Thread Tools | Display Modes |
| |||
![]() [COLOR=firebrick][B][I][SIZE=1][FONT=arial] Found on the program (T-42832-)hacking tools 2002.exe W32.HLLW.Purol Type: Worm Infection Length: 38,225 bytes Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me Systems Not Affected: Windows 3.x, Microsoft IIS, Macintosh, OS/2, UNIX, Linux Virus Definitions (Intelligent Updater) April 11, 2003 Damage - Payload ![]() Distribution - Shared drives: Attempts to spread through various file-sharing networks. When W32.HLLW.Purol runs, it does the following: Attempts to delete all the files from the following folders: C:\Progra~1\eSafe\Protect C:\Progra~1\McAfee VirusScan C:\Progra~1\NORTON~1 C:\Progra~1\Acceleration Software\Anti-Virus C:\Progra~1\F-prot C:\Progra~1\Mcafee C:\Progra~1\Kasper~1 C:\Progra~1\Avpersonal C:\Progra~1\Bullguard Adds the value: "Winstart"="c:\windows\winstart32.exe" to the following registry keys: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\ RunServices HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run Checks the following folders: C:\Windows\Myshares C:\Program Files\Icq\Shared Files C:\Program Files\Bearshare\Shared C:\Program Files\Morpheus\My Shared Folder C:\Program Files\Edonkey2000\Incoming C:\Program Files\Gnucleus\Downloads C:\Program Files\Gnucleus\Downloads\Incoming C:\Program Files\Kazaa\My Shared Folder C:\Program Files\Kazaa Lite\My Shared Folder C:\Program Files\Limewire\Shared Then, the worm copies itself to any of the folders that it finds. It also adds registry values to all of the above, then happily sets about procreating. More details, plus how to remove it manually can be found at the Symantec site (among others). 2 viruses (virii?) in 2 days. Geez, I feel like one of those bomb-sniffing dogs! |
| |||
![]() pfft! Norton Antivirus caught this in mid-download, so it never completed. However, I have been caught once by spamware which flew below Norton's radar, and later was caught by Ad Aware (not AA's fault, I thought that permission was being asked for something legit & granted it). Now, it's no more decisions on the sleep-deprivation diet ![]() ![]() Quote:
|
| |||
![]() Kazaa pfft. one of the worst filing sharing apps out there no wonder why some of you noobs have no clue how to download from Gnutella. ![]() You might want to run only one file sharing app, its any wonder how you computer isnt totally infested with spyware by now. and I know its an old thread. ![]() |
| ||||
![]() Every P2P network has a lot of spyware/adware/malware. Get used to it. Use some common sense and it shouldn't be a problem. deepblue |
![]() |
| |
![]() | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Virus problem (everything but music has a virus in it) | krazynoklahoma | Download/Upload Problems | 1 | April 14th, 2007 01:05 PM |
Virus here, virus there, virus everywhere ... so beware ! | luckysizes | Open Discussion topics | 4 | January 25th, 2006 05:55 PM |
I Got A Virus!!!!! | deacon72 | Open Discussion topics | 1 | December 24th, 2005 06:36 AM |
Virus | scrottocks | Download/Upload Problems | 3 | December 23rd, 2005 01:49 AM |
Worm - W32.HLLW.Purol | mhbweb | Tips & Tricks | 0 | July 3rd, 2004 09:53 AM |