<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: i think i found a new virus in Security</title>
<link>http://www.dslreports.com/forum/r13422377</link>
<description></description>
<language>en</language>
<pubDate>Tue, 08 Dec 2009 17:20:03 EDT</pubDate>
<lastBuildDate>Tue, 08 Dec 2009 17:20:03 EDT</lastBuildDate>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13442043</link>
<description><![CDATA[<A HREF="/useremail/u/1161220"><b>LAB70</b></A> : even zonealarm w/av got it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13442043</guid>
<pubDate>Wed, 18 May 2005 22:40:13 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13433693</link>
<description><![CDATA[<A HREF="/useremail/u/191317"><b>bcool</b></A> : I'm happy to report that even NAV200<B>3</B> did its thing!<br><SMALL>--<br>"in flagrante delicto"</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13433693?c=826400&ret=L2ZvcnVtL3IxMzQyMjM3Ny54bWw%3D"><IMG TITLE="13788 bytes" BORDER=0 WIDTH=424 HEIGHT=255 SRC="/r0/download/826400~7642a263f685a6e15bc1350612963f79/virusalert.gif"></A><br>dusty ol' NAV2003</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13433693</guid>
<pubDate>Tue, 17 May 2005 23:05:43 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13432880</link>
<description><![CDATA[<A HREF="/useremail/u/927553"><b>RayMorris</b></A> : SAV Got it too.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13432880?c=826329&ret=L2ZvcnVtL3IxMzQyMjM3Ny54bWw%3D"><IMG TITLE="29443 bytes" BORDER=0 WIDTH=441 HEIGHT=261 SRC="/r0/download/826329~63f52a6bdc5c7293e1ad65c0360c4d15/untitled.JPG"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13432880</guid>
<pubDate>Tue, 17 May 2005 21:30:33 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13432509</link>
<description><![CDATA[<A HREF="/useremail/u/545873"><b>lawrence171</b></A> : AntiVir Personal Edition also have detected it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13432509</guid>
<pubDate>Tue, 17 May 2005 20:48:36 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13431083</link>
<description><![CDATA[<A HREF="/useremail/u/994849"><b>lol2004</b></A> :  [ General information ]<br>* File might be compressed.<br>* File length: 60053 bytes.<br><br>[ Changes to filesystem ]<br>* Creates file C:\WINDOWS\mgs.exe.<br>* Deletes file 1.<br><br>[ Changes to registry ]<br>* Creates key "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon".<br>* Sets value "Shell"="Explorer.exe C:\WINDOWS\MGS.EXE" in key "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon".<br>* Creates value "Windows Service Manager"="C:\WINDOWS\MGS.EXE" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".<br><br>[ Network services ]<br>* Connects to "ftpd.there3d.com" on port 4888 (TCP).<br>* Connects to IRC Server.<br>* Sends data stream (55 bytes) to remote address "ftpd.there3d.com", port 4888.<br><br>[ Process/window information ]<br>* Creates a mutex mgs.exe.<br>* Will automatically restart after boot (I'll be back...).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13431083</guid>
<pubDate>Tue, 17 May 2005 17:52:55 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13430267</link>
<description><![CDATA[<A HREF="/useremail/u/367939"><b>mboy</b></A> : Kav nail'd it as did Panda.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13430267</guid>
<pubDate>Tue, 17 May 2005 16:19:13 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13427016</link>
<description><![CDATA[<A HREF="/useremail/u/1006882"><b>HA Nut</b></A> : As of 8am CDT in the US, NOD32, PC-cillin and Vet still do not detect this virus. (These are the AV's we use at work.) Hopefully soon... :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13427016</guid>
<pubDate>Tue, 17 May 2005 09:19:15 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13425187</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : I tracked the virus using RegMon. It does a major traverse of the registry. I only found the following to be edited by the file (keep in mind this log was done under a limited account):<br><br>687&#9;4.64690685&#9;untitled.jpg.ex:1960&#9;SetValue&#9;HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed&#9;SUCCESS&#9;BD 44 69 7E 34 27 02 7E ...<br><br>I have no clue what that does, however.<br><br>Also, it created <I>up to</I> 3000 or more new files in the Windows directory. I am unable to find where exactly in the Windows folders these files are stored. If I find out then I will post. These files were not created when I ran it under a limited account.<br><SMALL>--<br>Asus A7N8X-X, Athlon XP 2400+ @ 2.0GHz, 1024MB DDR RAM (@ PC2100), GeForce FX 5600Ultra 128MB, Samsung SD-616T 16x DVD-ROM and Sony CRX215E1 48x24x48 CD-RW, 40GB & 120GB HDD. <A HREF="http://redxii.blogspot.com/">Windows Security Blog</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13425187</guid>
<pubDate>Mon, 16 May 2005 23:45:03 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13423631</link>
<description><![CDATA[<A HREF="/useremail/u/994849"><b>lol2004</b></A> : w32/sdbot.worm.gen.bh<br>it doesnt have write out yet  i  think]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13423631</guid>
<pubDate>Mon, 16 May 2005 20:47:41 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13423397</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : Does McAfee have a writeup of the virus? And the name too.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13423397</guid>
<pubDate>Mon, 16 May 2005 20:21:17 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13423248</link>
<description><![CDATA[<A HREF="/useremail/u/994849"><b>lol2004</b></A> : i did it mcafee send me this  file it worked  dat installed it scanning for that stupid virus]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13423248</guid>
<pubDate>Mon, 16 May 2005 20:03:13 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13423134</link>
<description><![CDATA[<A HREF="/useremail/u/994849"><b>lol2004</b></A> : what do i do with that stupid .dat<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap WIDTH=33%><A HREF="/r0/download/825671~aa105440cf89c54ec147774535ce9d8e/Extra.zip"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>Extra.zip</big></A> <small>2,647 bytes</small><br><small>(Extra.dat)</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13423134</guid>
<pubDate>Mon, 16 May 2005 19:49:40 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422984</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : <div class="bquote"><SMALL>said by  Quex <A HREF="/useremail/u/1163112"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>F-Prot nailed it, despite its failure to detect anything in the jotti screenshot.<br> </DIV>F-prot is detecting this worm heuristically; perhaps Jotti has heuristics turned off on F-prot.<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422984</guid>
<pubDate>Mon, 16 May 2005 19:30:12 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422849</link>
<description><![CDATA[<A HREF="/useremail/u/527502"><b>QS</b></A> : ya mcafee enterprise 8 with latest dat's doesn't detect it as a badee. Not like mcafee to be so slow]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422849</guid>
<pubDate>Mon, 16 May 2005 19:13:38 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422712</link>
<description><![CDATA[<A HREF="/useremail/u/994849"><b>lol2004</b></A> : im waiting for a new sandbox email......................]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422712</guid>
<pubDate>Mon, 16 May 2005 18:58:57 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422597</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : <div class="bquote"><SMALL>said by  lol2004 <A HREF="/useremail/u/994849"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>but mcafee doesnt detest this is diffent from  all of viruses andf it added a mgs.exe to the %systemroot%<br> </DIV>This tool is useful if Virustotal or Jotti didn't find anything, but you are still suspicious about a file. You pick a file to upload and the tool watches it run on a test (sandbox) system. Then the tool sends a report on what it saw. <br><br>&raquo;<A HREF="http://sandbox.norman.no/live_4.html" >sandbox.norman.no/live_4.html</A> (Norman AV's SandBox analysis tool)<br><br>Interpreting the report requires some expertise, so post the sandbox results in this thread.<br><br>If the sandbox analysis does find something the other tools missed, it will be something very new.<br><br>:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422597</guid>
<pubDate>Mon, 16 May 2005 18:45:26 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422520</link>
<description><![CDATA[<A HREF="/useremail/u/923463"><b>KyeU</b></A> : F-Prot also detects it ^_^<br><br>EDIT: Quex posted before me :D<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13422520?c=825637&ret=L2ZvcnVtL3IxMzQyMjM3Ny54bWw%3D"><IMG TITLE="122600 bytes" BORDER=0 WIDTH=456 HEIGHT=416 SRC="/r0/download/825637~a1aa9e3b7d80e6b2b600c208e0fb39a0/fprot.jpg"></A><br>F-Prot</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422520</guid>
<pubDate>Mon, 16 May 2005 18:36:58 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422494</link>
<description><![CDATA[<A HREF="/useremail/u/1163112"><b>Quex</b></A> : F-Prot nailed it, despite its failure to detect anything in the jotti screenshot.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422494</guid>
<pubDate>Mon, 16 May 2005 18:35:08 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422491</link>
<description><![CDATA[<A HREF="/useremail/u/994849"><b>lol2004</b></A> : but mcafee doesnt detest this is diffent from  all of viruses andf it added a mgs.exe to the %systemroot%]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422491</guid>
<pubDate>Mon, 16 May 2005 18:34:33 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422402</link>
<description><![CDATA[<A HREF="/useremail/u/994849"><b>lol2004</b></A> : i send it them all 30 antivirus maker thx you, you guys are the best]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422402</guid>
<pubDate>Mon, 16 May 2005 18:25:21 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422377</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : NAV detects it:<br><br>&raquo;<A HREF="http://securityresponse.symantec.com/avcenter/venc/data/w32.allim.a.html" >securityresponse.symantec.com/av&middot;&middot;&middot;m.a.html</A><br><br>W32.Allim.A is a worm that spreads a variant of the W32.Spybot.Worm through America Online Instant Messenger (AIM).<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13422377?c=825622&ret=L2ZvcnVtL3IxMzQyMjM3Ny54bWw%3D"><IMG TITLE="26203 bytes" BORDER=0 WIDTH=499 HEIGHT=274 SRC="/r0/download/825622~8362f4076e65f6f42dc6faf7073c7ee2/allim.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422377</guid>
<pubDate>Mon, 16 May 2005 18:22:39 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422294</link>
<description><![CDATA[<A HREF="/useremail/u/1193253"><b>SpannerITWks</b></A> : Hi, i just DW it from your link. It doesn't appear to to be unheard of, except by KAV/NOD and a few others at Jottis Online Scan ?<br><br>One of the interesting things is that my AVG picked it up Straightaway ! I'm well pleased with them.<br><br>Spanner<br><SMALL>--<br>I Only Know What I Know But I'm Learning all The Time - Stay Safe - Spanner intheWorks/SpannerITWks</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13422294?c=825614&ret=L2ZvcnVtL3IxMzQyMjM3Ny54bWw%3D"><IMG TITLE="70973 bytes" BORDER=0 WIDTH=517 HEIGHT=591 SRC="/r0/download/825614~b82362f9db938a8f82b3d4d5ea8891bd/VR1.png"></A><br>Virus-1</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422294</guid>
<pubDate>Mon, 16 May 2005 18:13:53 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422111</link>
<description><![CDATA[<A HREF="/useremail/u/818980"><b>habya</b></A> : Best to submit it to the AV vendors.  <br><br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428#submit">I think my computer is infected or hijacked. What should I do?</A><br><br>Edit: just saw the above post I was a little late in typing.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422111</guid>
<pubDate>Mon, 16 May 2005 17:53:53 EDT</pubDate>
</item>

<item>
<title>Re: i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422107</link>
<description><![CDATA[<A HREF="/useremail/u/607308"><b>Faram</b></A> : <A HREF="http://www.dslreports.com/faq/8428#submit">Submit suspected malware</A><br><br>It is only on the top of the forum.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422107</guid>
<pubDate>Mon, 16 May 2005 17:53:24 EDT</pubDate>
</item>

<item>
<title>i think i found a new virus</title>
<link>http://www.dslreports.com/forum/remark,13422077</link>
<description><![CDATA[<A HREF="/useremail/u/994849"><b>lol2004</b></A> : my freind sent me a exe file he said scan this with my antivirus and then no virus so i open this file and two reg line came added this %sytemroot%\mgs.exe %sytemroot%\expolorer.exe to the start up  and  here the link to this file h**p://myweb.cableone.net/jaross15/untitled%5B1%5D.jpg.exe<br>tt in the ** for protestion<br>i need help plz<br>srry for my bad english<br>and btw i use mcafee]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13422077</guid>
<pubDate>Mon, 16 May 2005 17:49:26 EDT</pubDate>
</item>

</channel>
</rss>
