Ik kreeg vandaag op me werk een melding van een virus, na verder onderzoek bleek dit virus/worm open shares op een netwerk te zoeken, en in c:\windows\system32\ 2 files weg te schrijven, en iets aan te passen in het register, tot mijn grote verbazing betrof het DNETC.INI & DNETC.EXE
"
Virus Name
W32/Msinit
Date Added
9/28/00 2:12:35 PM
Virus Characteristics
This worm spreads through open network shares like the VBS/Netlog worm. It scans random IP address over NetBIOS for computers that have shares named "C" and a Windows folder called "Windows". When it finds one, it copies itself and the files "dnetc.exe" and "dnetc.ini" to the "c:\windows\system" folder of the remote computer. The file "dnetc.exe" is an encryption-cracking program from www.distributed.net, which is not the author of this worm. The samples received by AVERT are packed with the UPX file-compression utility.
"
zie meer op:
http://www.guardcentral.com/cgi-bin/frameit/FrameIt.cgi?Url=http://vil.mcafee.com/dispVirus.asp?virus_k=98844&&FooterSize=70&FooterLocation=2&FooterUrl=http://www.guardcentral.com/adbanners/FrameIt.custom.html&AllowResize=0
lekker lange url
"
Virus Name
W32/Msinit
Date Added
9/28/00 2:12:35 PM
Virus Characteristics
This worm spreads through open network shares like the VBS/Netlog worm. It scans random IP address over NetBIOS for computers that have shares named "C" and a Windows folder called "Windows". When it finds one, it copies itself and the files "dnetc.exe" and "dnetc.ini" to the "c:\windows\system" folder of the remote computer. The file "dnetc.exe" is an encryption-cracking program from www.distributed.net, which is not the author of this worm. The samples received by AVERT are packed with the UPX file-compression utility.
"
zie meer op:
http://www.guardcentral.com/cgi-bin/frameit/FrameIt.cgi?Url=http://vil.mcafee.com/dispVirus.asp?virus_k=98844&&FooterSize=70&FooterLocation=2&FooterUrl=http://www.guardcentral.com/adbanners/FrameIt.custom.html&AllowResize=0
lekker lange url