Geo Posted August 19, 2006 Report Posted August 19, 2006 SIMPTOME: - Prezenta fisierului C:sysnet- Prezenta urmatorului fisier in fisierul C:sysnet:Ruby31.exe (30,720 bytes)- Prezenta mai multor copii ale Ruby31.exe (30,720 bytes) in fisierul C:sysnet sub diferite nume - Prezenta urmatoarelor chei de registrii sau intrari: [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]"Ruby13"="c:sysnetRuby13.exe"unde %WINDOWS% indica spre fisierul Windows (sau WinNT in sistemele bazate pe Windows NT)%SYSTEM% indica spre fisierul "System" pe sistemele Windows 9x si fisierul "System32" in sistemele WinNT.DESCRIERE TEHNICA: Virusul se imprastie prin e-mail si, de asemenea, prin retelele Kazaa si Imesh.De obicei ajunge la destinatar prin intermediul e-mailului. Formatul mailului este urmatorul: De la: (adresa ascunsa)Pentru: (adresa “recoltata”)Subiect: EBAY InformationCorp: EBAY Installer...Atasament: EBAY.exeSubiect: VISA InformationCorp: Security Tool...Atasament: VISA.EXESubiect: Provider InformationCorp: New account data...Atasament: PROVIDER.EXESubiect: Your CrackCorp: Here is your crack!Atasament: (one of the copies of the virus)Subiect: Internet InformationCorp: New account data...Atasament: INTERNET.EXECand este rulat, virusul face urmatoarele: 1. Afiseaza urmatorul mesaj:Ruby V1.3Serial: %random%File crack...Nota: %random% este un numar luat la intamplare (ex: Numarul serial: 41365345)2. Creeaza fisierul C:sysnet unde isi face copii sub urmatoarele nume: A+ Certification Test.exeBorland KeyGens.exeBurnDvds.exeCisco Certification Test.exeCounter-Strike, Condition Zero - Activation Key.exeCounterstrike aim hack.exeCounterstrike hacks.exeCrack McAfee 7.exeCrack Norton 3000.exeDiablo 2 map hack.exeDiablo 2 no-cd hack.exeDvd Ripper.exeDvd To Vcd.exeEasy Dvd Ripper.exeEZ Dvd Ripper.exeicqbomber.exeInformation.exeMP3 encoder decoder V1.8.exeMSCE Certification Test.exeNero Burning ROM v6.3 Ultra - Enterprise edition key.exeNimo Codec Pack Updater.exePANDA.AVers.lusers.exePANDA.lusers.exes Diablo 2 hero editor.exeSophosCrackAllVersion.exeStarcraft + Broodwar 1.10 map hack.exeStarcraft + Broodwar 1.10 no-cd hack.exeThe Frozen Throne map hack.exeWarcraft 3 Frozen Throne cd-cd hack.exeWarcraft 3 Frozen Throne map hack.exeWarcraft 3 map hack.exeWarcraft 3 no-cd hack.exeWarcraft 3 stat hack.exeWindows Nt Certification Test.exeXBOX X-Fer Ripper and Transfer.exeXvid Codec Installer.exeSi de asemenea isi creeaza copii prin adaugarea Keygen.exeSerial.exeNoCD.exeCrack.exela urmatoarele nume:Adobe Photoshop CS and ImageReady CS 8.0Airport Tycoon II -All Adobe ProductsAll Macromedia ProductsAll Microsoft ProductsAmerican Conquest -Apache AH-64 Air Assault -Battlefield 1942 The Road to Rome -Battlefield Vietnam -BitDefenderBridge Baron 13Command and Conquer GeneralsDeus Ex -Divx Pro 5.1Doom 3 -Dvd PlusDvd Wizard ProDvd XcopyDvdCopyOneDvdToVcdEasy Dvd creatorEonix Realm Of Hepmia -Fetish Fighters -Forbidden Siren -Freelancer -Grom -Harry Potter and the Prisoner of Azkaban KeyGen andHarry Potter und der Gefangene von AskabanI Was An Atomic Mutant -IGI-2 Covert Strike -Impossible Creatures -Ipswich Town Official Management Game -JamellaKazaa allMicrosoft Windows XP ProfessionalNascar Racing 2003 SeasonNero Burning RomNod32Norton AntiVirus 2004 Pro Activation Key &Norton AntiVirus 2005Norton Internet Security 2004 Keygen &Norton Internet Security 2004 ProNorton Internet Security 2005 ProOffice XP UniversalPrivate Nurse -Robot Arena Design And Destroy -Serious Sam - Gold Edition -Shadow of Memories -Shrek 2Sim City 4 -Slot City 3Spellforce - Breath of WinterSpider-Man 2Symantec Antivirus 2005Symantec Internet Secutiy 2005Test Drive -The Campaigns of La Grande Armee -The Emperors Mahjong -Tom Clancys Splinter Cell -Tombstone 1882 -Unreal II The Awakening -WinACE Windows Server 2003WinRAR 3WinZIP 9World Of Outlaws Sprint Car Racing 2002 -Zone Alarm 5.0 pro(exemplu: Zone Alarm 5.0 pro Crack.exe, BitDefender Keygen.exe)3. Seteaza folderul de descarcare/sheruit default Kazaa si Imesh pe c:sysnet4. Creeaza intrarea de registrii: [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]"Ruby13"="c:sysnetRuby13.exe"pentru a rula la startup.5. Incepe sa recolteze adrese de e-mail in fisiere care au terminatia: *.wab*.dbx*.htm*.sht*.txt*.doc*.rtfDar evitand adresele de e-mail continand:suppwebmvirunewvkaspmicrrootadmihostsi se trimite la fiecare adresa de e-mail gasita in formatul de e-mail descris mai sus folosind propriile motoare smtp. 6. Poate sa afiseze un mesaj:Ruby V1.3, ©BI 16.08.2004Fight against MICROSOFT and make a virus!INSTRUCTIUNI DE DEZINFECTIE: - Folositi utilitarul de dezinfectie gratuit pus la dispozitie de BitDefender- Dezinfectie automata: lasati BitDefender sa stearga/dezinfecteze fisierele gasite infectate.ANALIZAT DE: Patrik Vicol BitDefender Virus Researcher Quote
Trane22_India Posted April 22, 2008 Report Posted April 22, 2008 Ciudat sau nu dar o porcarie deasta am eu.Am vrut sa iau un crack al un program.Am download o arhiva am deschiso si a inceput sami apara pe desktop file ciudate.Le-am sters si am dat Ctrl Alt Del si "Command removed by administrator".Am intrat in registry si am activat din nou am inchis fisierul crack.exe si deatuncea imi merge calculatorul ca o caruta, si tot imi spune sa downloadeze programe de remove la care cauti 2 ore ptr un serial si nu le gasesti.Acuma ma chinui sal scot fara sa dau format[dak se pote:D] k am dat 4 formaturi saptamana asta>sper k asta sa ma ajute.Windows-ul imi vede virusul ca Win32NetBooster ceva de gen asta. Quote
loki Posted April 22, 2008 Report Posted April 22, 2008 pune-ti antivirusuita-te la astahttp://rstcenter.com/forum/ce-te-faci-fara-antivirus-t10746.rstsi eventual la asta (dar mai greu)http://rstcenter.com/forum/viewtopic.php?t=10919Daca il gasesti sterge-l in safe mode si creeaza un folder cu acelasi nume si extensie. Asa il fortezi sa nu se instalezeCauta numele spamului (banuiesc) pe google si gasesti informatii si removal tools. Aici gasesti unul postat de mine si alte informatii:http://rstcenter.com/forum/viewtopic.php?t=10685 Quote