Author Topic: i need help  (Read 4373 times)

0 Members and 1 Guest are viewing this topic.

smoothy

  • Guest
i need help
« on: April 28, 2006, 09:41:10 AM »
i have this virus, and my avast is not stopping it getting through
Win32:Busan-E [Wrm]

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: i need help
« Reply #1 on: April 28, 2006, 10:25:57 AM »
Hello smoothy,

This worm spreads by copying itself to all accessible network resources. The worm is Windows application (C++ PE EXE-file). It's packed by UPX and is around 14kB large.

When executed, the worm sends a message through ICQ to the author of the worm, then copies itself to Windows directory with name "files32.sys", and also copies a file "mh32.dll" there. This is a keyboard hooker. Then the worm tries to copy itself with name "auto.exe" to following directory:

 C:\WINDOWS\All Users\Start Menu\Program Files\StartUp\

Because of a bug, this fails. Next the worm copies itself to all accessible network shares.

After that the worm registers itself in the system register in a key:

 [HKEY_CLASSES_ROOT\exefile\shell\open\command]
 @="files32.sys \"%1\" %*"

This means that when executing any EXE-file the worm will be started.

The worm collects information from the local system and tries to send them to the worm writer. This includes addresses, passwords and results of the keyboard snooper.

The worm tries download a file "worm31.bmp" from a web-site in the Internet, but this page has been removed and the download fails.

Here is the technical information and removal instructions:
http://www.sophos.com/virusinfo/analyses/w32busanc.html

Did you manage to move the virus to the chest, there it can do no harm for the moment.

polonus
« Last Edit: April 28, 2006, 10:33:50 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

smoothy

  • Guest
Re: i need help
« Reply #2 on: April 28, 2006, 11:05:51 AM »
thanks for your help.
i am on it as we speak.
these people just piss you right of .

smoothy

  • Guest
Re: i need help
« Reply #3 on: April 28, 2006, 02:03:29 PM »
this bloody thing just keeps coming back
every time i re-start the pc.

i have looked in the reg files and cant find it  :(

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: i need help
« Reply #4 on: April 28, 2006, 04:10:22 PM »
this bloody thing just keeps coming back
Can't you schedule a boot-time scanning?
Start avast! > Right click the skin > Schedule a boot-time scanning.
Select for scanning archives.
Boot.
The best things in life are free.

smoothy

  • Guest
Re: i need help
« Reply #5 on: April 28, 2006, 04:41:48 PM »
yes i have done that .
twice. it still keeps coming back.

also my pc is opening with the my documents  page.
i cant understand this ..

maybe i need to unplug the broadband to stop it connecting
while i do this ??

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: i need help
« Reply #6 on: April 28, 2006, 05:27:45 PM »
Clean your temporary files (maybe using CCleaner).
Schedule a boot time scanning (do not boot yet).
Disable your system restore feature. Boot.
Run the boot time scanning.

What is the name (and path) of the infected file being detected?
« Last Edit: April 28, 2006, 05:32:39 PM by Tech »
The best things in life are free.

smoothy

  • Guest
Re: i need help
« Reply #7 on: April 29, 2006, 08:53:53 AM »
it always comes in 2`s
first i get
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5

then another right after it.


\M81JBE9J\udps[1].exe\[Upack]C:\Documents and Settings\Administrator\1.exe\[Upack]

i still have not fixed it yet. ??


Spiritsongs

  • Guest
Re: i need help
« Reply #8 on: April 29, 2006, 09:13:52 AM »
 :)  Hi Smoothy :

      Since you have a "worm", have you tried using "Ewido"
      from www.ewido.net/en ( assuming your OS is either
      Win XP or Win 2000 ) !? This good & FREE program
      "specializes" in detecting & removing worms, trojans, etc .
      There's a tutorial at :
      www.greyknight17.com/spy/Tutorials/ewidoQuickGuide.pdf