Dimondsoft BBS
September 06, 2010, 11:18:22 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
 
   Home   Help Search Chat Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Avoid Sprites Inc.  (Read 165 times)
0 Members and 1 Guest are viewing this topic.
Strider
Resistance is Futile
Administrator
Sergeant
*
Offline Offline

Gender: Male
Posts: 549



View Profile
« on: December 13, 2009, 03:33:52 PM »

According to ACE Spark, the website has been infected with the HTML:iframe-inf virus (AKA: W32/Virut). The virus affects the following:

Quote
Overview -

W32/Virut.h is a polymorphic, entry point obscuring (EPO) file infector with IRC bot functionality. It can accept commands to download other malware on the compromised machine.

It appends to the end of the last section of executable (PE) files an encrypted copy of its code. The decryptor is polymorphic and can be located either:

    * Immediately before the encrypted code at the end of the last section
    * At the end of the code section of the infected host in 'slack-space' (assuming there is any)
    * At the original entry point of the host (overwriting the original host code)

The decryptor will either receive control directly or an API call within the host code body will be overwritten to point to it (EPO technique). In all cases where host code is overwritten by the virus the original bytes are stored within the encrypted virus body, and are restored before transfering control back to the host. This virus may also infect the files multiple times.
Aliases

    * W32.Virut.R (Symantec)

Characteristics -

When W32/Virut.h is executed it injects its code into running processes.


W32/Virut.h opens up backdoor on the compromised machine at port 80 (HTTP) but uses it for IRC communication.


This virus tries to connect to IRC server located at :

    * eircd.zief.pl

And joins the channel named: virtu


It can then receive commands to download and execute other malware on the infected machine. Though the download location in the commands can change, at the time of writing, the virus tried to download malware executables from:

    * http://85.114.[REMOVED]/~grander/[MALWARE].exe

 
Symptoms -

    * Modified executable files (increase in the size of exe files)
    * DNS queries to eircd.zief.pl and IRC related network traffic

Method of Infection -

W32/Virut.h is a file infecting virus. Infection starts with manual execution of the binary. Executables in network shares may also get infected if accessed by the compromised machine.

The virus has a number of bugs in its code, and as a result it may misinfect a proportion of executable files. In those cases of misinfection in which repair data is present within the virus body, and has not been miscalculated by it, the current DAT set will repair the virus as per the non-corrupted case. However, unfortunately, some W32/Virut.h infections are corrupted beyond repair.

ACE is currently working out the problem and should see a clean website by the end of next week.

(BTW, I know there's people on this board that don't give a hoot about SI, but this virus can infect this site as well.)

Marc, I recommend that all files be scanned with this.
Logged
Marc
Love Cook
Administrator
General
*
Offline Offline

Gender: Male
Posts: 3213


Well now...


View Profile
« Reply #1 on: December 13, 2009, 03:47:27 PM »

I noticed it earlier today on a Google image search. How the hell did he get that?

(Does this really need to be stickied? Tongue)
« Last Edit: December 13, 2009, 03:55:57 PM by Marc » Logged


_██_
(ಠ_ృ)
Speedy
Now, also in 'Suppeedi' flavor!
Major
****
Offline Offline

Gender: Male
Posts: 882


I should play Jump Ultimate Stars s'more.


View Profile WWW
« Reply #2 on: December 13, 2009, 05:22:38 PM »

Yeah it does. There's alot of people h..

Actually, there aren't alot of people here who actually go there, but it's still pretty important.
Logged


"C&C4 - The end of a decade of awesome, with a bad aftertaste."
Alex
Star Platinum
Administrator
General
*
Offline Offline

Gender: Male
Posts: 2615


Gimme a break.


View Profile
« Reply #3 on: December 13, 2009, 05:29:14 PM »

There are more reasons than this to stay away from Sprites Inc.
Logged
Serio
Game Staff
Private
*
Offline Offline

Posts: 292


i am disappoint


View Profile
« Reply #4 on: December 14, 2009, 08:50:26 AM »

http://www.avg-antivirus.com.au/avg_virus_removal.htm

the rmvirut part especially. it helped me kill that fucker permanently when i got it few months ago.
Logged

my grandfather was an electrician in the German army during WWII. he had two thunderbolts on the side of his helmet.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!