FAO Apd (Ant) (Was - Re: Win32/RAMNIT.A Anyone?)
David_B <[email protected]> Mon, 21 Dec 2020 17:09:54 +0000
| Newsgroups | alt.comp.virus,alt.comp.anti-virus,microsoft.public.security.virus |
|---|---|
| Organization | blocknews - www.blocknews.net |
| Message-ID | <[email protected]> |
On 31/07/2010 16:54, Ant wrote: > "David Kaye" wrote: > >> Thank you, Ant! This appears to be exactly the situation. There is the >> Microsoft directory (in this case it's under Program Files) and the executable >> is the same. The vbs was also there, which I found out about on a hunch when >> I disabled the vb scripting engine and watched error messages come up left and >> right. >> >> What a nasty nasty infection. > > Yes, nasty. It infects all candidate files on all drives with some > exceptions. However, it should be possible for a good AV to disinfect > files because it doesn't damage existing code. > > More info on the infection mechanism... > > It does NOT infect:- > > 1) Files in the windows directory and its subdirectories. > > 2) Any file or directory named "RMNetwork" (case sensitive). > > 3) Executables with a ".rmnet" section (this is the infection marker). > > 4) Executables which do not import the API functions "LoadLibraryA" > and "GetProcAddress". I don't know the reason for this but it means a > few will be left alone and all dot-net executables will be untouched. > Probably a larger percentage of DLLs will also be ok. > > Otherwise it infects all files with the extension "exe", "dll", "html" > and "htm". > > It creates hidden autorun.inf files on removeable drives only and > drops the infector (which autorun will launch) in a subdirectory of > RECYCLER. e.g, for a floppy drive: > > A:\RECYCLER\S-0-1-44-0561634483-2060570468-336017572-1221##\ycIeXQMt.exe > > The ## should probably be 2 random digits but in my test they were > invalid characters. > > If the registry key HKEY_LOCAL_MACHINE\Software\WASAntidot is present > and has a value named "disable" it will skip the infection process and > pop up a messagebox: "Antidot is activate". However, it will still try > to call home and possibly download stuff. > > A view of processes say, in Task Manager, on an infected system should > show an instance of your internet browser even if your browser is not > running. This is really the malicious code and injected DLL. The way > it achieves this is weird! It doesn't sound to me as if you think it's a 'False Positive', Ant! What makes you think that the version /I/ found WAS a false positive and not 'real'? If the virus DOES exist, why cannot it be downloaded alongside an installation of ClamXav? It could then be spread around the Internet with nobody having a clue from whence it came - nobody would be looking at an AV software being responsible - would they? (Follow-up set)