myITforum.com

Welcome to myITforum.com Sign in | Join | Help
in Search

Harry Waldron at myITforum.com

Sharing Security Developments, and Best Practices for corporate and home users

Storm Worm - Now infects PC with different file names

When cleaning Storm worm infections, the file names have changed for newer variants and the most up-to-date standalone cleaner should be used.

Storm Worm - Now infects PC with different file names
http://www.avertlabs.com/research/blog/index.php/2007/10/21/nuwar-new-file-names/

QUOTE: We all know that Nuwar aka Storm gang has been continuously changing their spam email text, download sites, executables, network traffic patterns etc in their efforts to penetrate through the security defenses at various layers, all throughout this year. I had a chance to briefly look at a ‘fresh’ Nuwar sample this weekend. It is interesting that they have now also changed the names of files Nuwar drops. It now drops noskrnl.exe, noskrnl.sys and noskrnl.config instead of Spooldr.exe, Spooldr.sys, and Spooldr.ini correspondingly. It also tried to actively propagate by coping itself on the floppy drive, which is new.

This site is one of my favorite links for locating malware cleaning facilities:

GREAT SITE FOR FREE VIRUS REMOVAL TOOLS
(see links on left top side -- "Free Protection and Removal Tools")
http://www.virusintel.com/tiki-index.php

Comments

No Comments
Powered by Community Server (Commercial Edition), by Telligent Systems