31-03-2005, 10:15
|
#1
|
|
Google it!!
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL
BT Telephone
Posts: 14,954
|
Herustic.Adwaredropper.A
Another day, another new virus rears it's head. Not the most dangerous or widest spread but just a heads up in case
Quote:
Security Threat: Herustic.Adwaredropper.A
At this time, protection for this virus is NOT provided by Symantec and/or McAfee. This product will undergo further submissions to other antivirus companies on March 31st, 2005. All findings below are subject to change and are based on an analysis completed by Messenger Plus! Zone.
WARNING: This security alert was submitted to and processed by Dane Smith on 3/24/05 at 8:45PM Central Standard Time. The information contained herein is preliminary and should NOT be considered a final product. Special thanks to Dash for submitting this sample!
Viral Name: None Assigned Yet - Please see Herustic Name
Herustic Name: Herustic.AdwareDropper.A
Infection Length: 214,137 Bytes
Threat Level: Undetermined - Preliminary Level set at 5 due to evasion of major antivirus detections.
Protection Date: Currently, Symantec and McAfee do not provide protection against this threat. When further information is discovered, We will rush it to you. This threat will be submitted to other AntiViral labs on March 31st, 2005. Messenger Plus! Zone AntiVirus 2005 Beta will have protection from this threat.
Threat Details:
This threat creates C:\WINDOWS\systray.exe and drops the virus Adware.WinTaskAd, additionally, the virus downloads and installs more adware from internet websites. The virus is disguised as an MSN Messenger Hack Tool. The virus displays an error message when executed, although there is no real error with the software.
Removal Tool: Download Now!
Additional Notes:
This threat attempts to spread by a fake "Hack tool" that transmits by the name of "MSN Fun Maker" or MsnFunMaker204.exe. It uses the generic Windows Installer icon, while the "Installer" is actually the virus. McAfee has responded by adding this file to there "Potentially Unwanted Programs (PUP)" list, however, Messenger Plus! Zone feels strongly that it should be added to there latest virus definition.
|
|
|
|