Worm - Myphoto.zip .exe (question)

Started by TeaLeaf, May 31, 2007, 07:49:34 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

TeaLeaf

One of our own is currently having an issue with a worm that seems very similar to the W32/Dumaru worm from January 2004.  The 2004 variant was a keylogger worm with its own SMTP engine and arrived via an email attachement called:

Myphoto.zip [48 spaces] .exe

The new version (if it is at all related) appears to be spread via MSN and the worm repeatedly tries to send the above file to everyone in the infected machine's MSN address book.  The file name under MSN simply shows up as

Myphoto.zip (58KB)

I cannot find any information about this particular variant of W32/Dumaru or indeed if it is a brand new worm.

Does anyone have any information about this or can anyone help?


TL.
TL.
Wisdom doesn\'t necessarily come with age. Sometimes age just shows up all by itself.  (Tom Wilson)
Talent wins games, but teamwork and intelligence wins championships. (Michael Jordan)

TeaLeaf

Sounds very similar to the transmission of the W32/Bropia worm?

TL.
TL.
Wisdom doesn\'t necessarily come with age. Sometimes age just shows up all by itself.  (Tom Wilson)
Talent wins games, but teamwork and intelligence wins championships. (Michael Jordan)

BigFatCat

All the info is for the older variants, with a smaller payload size.
I'd submit a sample to the big AV names, though they won't update your product if you're not using theirs.
Will strip for badges

TeaLeaf

Yep, can do that, but I'd rather have that happen from the source machine (which is not mine) and not deliberately accept it onto my own systems.  Will pass that recommendation back to source.

TL.
TL.
Wisdom doesn\'t necessarily come with age. Sometimes age just shows up all by itself.  (Tom Wilson)
Talent wins games, but teamwork and intelligence wins championships. (Michael Jordan)

DuVeL

Seems it does 2 things Paul;
Port 2283 seems to be opend as a TCP-proxy, meanwhile through port 10.000 an ftp-server is up that gives acces to all the files on the harddrive from a PC.
 
Here is some info for Dumaru;
http://www.pchell.com/virus/dumaruy.shtml
 
http://antivirus.about.com/cs/allabout/a/dumaruy.htm
http://antivirus.about.com/cs/virusencyclopedia/p/dumaruz.htm
 
Will see if I can find some more interesting articles which might help out.
Survivor of LAN V, VI, VIII, IX, X, XII, XIV, XVI, XVIII, XX, XXIV, XXX, XXXII, XXXIV and XXXVI so far...
[QUOTE]Lionheart; Grolsch to DuVeL is like spinache to Popeye [/QUOTE]
[QUOTE]Cheesepuff...A cyborg is sent from the future on a deadly mission. He has to kill Ninja_Freak, a young Man whose life will have a great significance in years to come.Ninja has only one protector - DuVeL - also sent from the future. The Terminator uses his exceptional intelligence and strength to find Ninja_Freak & attempt to terminate him.
[/QUOTE]

TeaLeaf

Well a virus scan this morning discovered 'something' with a 'D' in the name, but the log was deleted so we'll never know what it was :doh:

Case closed.  Move along please, nothing to see here......

TL.
TL.
Wisdom doesn\'t necessarily come with age. Sometimes age just shows up all by itself.  (Tom Wilson)
Talent wins games, but teamwork and intelligence wins championships. (Michael Jordan)

Doorman

/Doorman puts hand up. Twas me. Scanned again, checked running processes, checked registry, startup folder er...that's it. No sign of any beasties. Good work TL and Duvel. Good links, top advice. :thumb:










     

Blunt

Quote from: TeaLeaf;191906...discovered 'something' with a 'D' in the name...
TL.

Quote from: Doorman;191924/Doorman puts hand up. Twas me.

:roflmao:
Regards
Blunt


People who blow things out of proportion are worse than Hitler.


Doorman

:roflmao:
Quote from: Blunt;191926

D, Doorman, I get it!:roflmao:










     

TeaLeaf

Small update.  Whilst one virus was found and removed, the original still appears to be there - so if you get any MSN file transfers at the moment do not accept!

From research it appears to be an English (badly translated) variant of the orignal Spanish W32/MsnPhoto.A.worm.  This was first picked up about 20th May so is a pretty new one.  None of the AV sites as yet carry any info about other variants.

Ron is currently installing a commercial AV package in the hope of finding the little bar steward.  When active and MSN is logged in then Ron does not get to control MSN and he cannot shut down MSN via task manager. It's a nasty little bugger :sad:

TL.
TL.
Wisdom doesn\'t necessarily come with age. Sometimes age just shows up all by itself.  (Tom Wilson)
Talent wins games, but teamwork and intelligence wins championships. (Michael Jordan)

Doorman

Another update: Scanned with McAfee (cheers BFC) and that found AOO14418.exe with which it took exception to. I then did a search for myphoto.zip and it was found in C:\RECYCLERS. I scanned it and it showed up clean. I've deleted it anyway. I'm now scared to start up MSN Messenger (Good thing, I hear some of you cry)
Point of order, Is not RECYCLERS the recycle bin? No? :getmecoat:










     

Anonymous

Quote from: Doorman;191968Another update: Scanned with McAfee (cheers BFC) and that found AOO14418.exe with which it took exception to. I then did a search for myphoto.zip and it was found in C:\RECYCLERS. I scanned it and it showed up clean. I've deleted it anyway. I'm now scared to start up MSN Messenger (Good thing, I hear some of you cry)
Point of order, Is not RECYCLERS the recycle bin? No? :getmecoat:

What AV package do you normally run Ron?

Doorman

Quote from: BlueBall;191973What AV package do you normally run Ron?
Avast 4 freebie type home deal.










     

TeaLeaf

Quote from: Doorman;191968Point of order, Is not RECYCLERS the recycle bin? No? :getmecoat:
I don't know where the recycle bin is, but I do not have that folder on my PC.

TL.
TL.
Wisdom doesn\'t necessarily come with age. Sometimes age just shows up all by itself.  (Tom Wilson)
Talent wins games, but teamwork and intelligence wins championships. (Michael Jordan)

Bob

Quote from: TeaLeaf;192003I don't know where the recycle bin is, but I do not have that folder on my PC.
You should have it - but it is a hidden system folder, so unless you have checked the options to show that kind of stuff, you won't see it.

But I saw that Ron wrote RECYCLERS, and not RECYCLER. If it's just a typo, that it's not a big deal - the latter is the recycle bin folder.
If it on the other hand weren't a typo, than something fishy might be going on...
[imga=right]http://77.108.135.49/fahtags/ms10.jpg[/imga]* Threbrilith the Nightelf, born and raised by the Silver Oak Guardians *
Proud member of Dead Men Walking