Author Topic: Win32.Worm.Zimuse  (Read 5019 times)

0 Members and 1 Guest are viewing this topic.

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Win32.Worm.Zimuse
« on: January 27, 2010, 08:31:05 AM »
Dear All,

Do you guys know or analyze about this variant malware?

As i got this variant able to destroy Master Boot Record of Hardware.

Please visit : http://www.youtube.com/watch?v=KgjX4LQrkgI



Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Win32.Worm.Zimuse
« Reply #1 on: January 27, 2010, 10:26:36 PM »
Hi Yanto.Chiang,

BitDefender today identified a new e-threat that combines the destructive behavior of a virus with the spreading mechanisms of a worm. Two variants are known to this day.

Called Win32.Worm.Zimuse.A, this malicious piece is extremely dangerous; unlike average worms, it would lead to severe data loss as it overwrites the first 50 KB of the Master Boot Record, a key zone of the hard disk drive.

Win32.Worm.Zimuse.A enters the computer disguised as an apparently harmless IQ Test. Once executed, the worm creates between seven and eleven copies of itself (depending on the variant) in critical areas of the Windows system.

In order to execute itself on each Windows boot-up, the worm sets the following registry entry: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]"Dump"="%programfiles%DumpDump.exe", and also creates two driver files, namely %system%driversMstart.sys and %system%driversMseu.sys. Since 64-bit versions of Windows Vista and Windows 7 require digitally-signed drivers, the worm would fail installing these files.

Analysis here: http://news.bitdefender.com/NW1318-en--Virus-Writers-Produce-Hardware-Damaging-Code-with-Win32.Worm.Zimuse.html

Removal-tool here: http://www.malwarecity.com/blog/zimuse-removal-tool-739.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Re: Win32.Worm.Zimuse
« Reply #2 on: January 28, 2010, 03:19:53 AM »
Hi Polonus,

Thanks for details summary about this worm,

Anyway, do you ever met this before with avast?

Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya