advertisement
Find Articles in:
All
Business
Reference
Technology
News
Lifestyle

Virus Alert: Global Hauri Issues Medium Warning for 'SMB Worm' Spreading Through MSN Messenger

Market Wire, September, 2003

Today, Global Hauri assigned a medium risk to Worm.Win32.Smbmsn.163840, which effects the systems win32. The new worm, discovered last night, comes through MSN Messenger as an SMB.EXE file attachment. Once the user accepts this file, the worm will send the SMB. EXE file to all contacts in MSN messenger contact list. If the user actually executes this file, a dos prompt will come up for about a second and then disappear. (See screenshot)

Global Hauri's CEO, Mr. Eric Kwon says, "After infection this virus tries to connect to some porno site and cause network traffic. To the user, it appears to be difficult to log in MSN Messenger. We are currently analyzing this worm for more details. However, when you get a message from MSN messenger 'Sending SMB.EXE file,' do not accept this file."

The worm unzips these files: Under C:\ drive - smb.exe, admagic.exe and test.txt and Under Windows directory - atl.dll, raw32x.dll, sm.dll and uz.exe, and Under Registry: KEY_LOCAL_MACHINE\SOFTWARE\Micorosoft\Windows\CurrentVersion\Run it will register svchost = admagic.exe.

How to Repair:

Go to www.globalhauri.com and download ViRobot latest definitions file of September 26, 2003 to detect/repair (removal of worm file).

How to repair manually

Go to task manager. (Ctrl+alt+del)
Select "process tab"
Click 'admagic.exe' then click End Process
Go to C drive and delete 'smb.exe' and 'admagic.exe'
Go to Windows directory and delete 'atl.dll,' 'raw32x.dll,' 'sm.dll' and
'uz.exe'
Go to registry (Start - > Run - > type "regedit" - > click ok then go to
HKEY_LOCAL_MACHINE\SOFTWARE\Micorosoft\Windows\CurrentVersion\Run and
delete svchost = admagic.exe string value.

When you get a message from MSN messenger "Sending SMB.EXE file," do NOT accept this file.

If you would like to speak to Global Hauri executives about the new announcements, or wish to review the Global Hauri ViRobot Expert virus killer software please contact Xenia at xvonwedel@terpin.com

Xenia von Wedel for Global Hauri
THE TERPIN GROUP
xvonwedel@terpin.com
(650) 563-
9130

 

BNET TalkbackShare your ideas and expertise on this topic

The following tags are supported in BNET comments:
<b></b> <i></i> <u></u> <pre></pre>

Leave a Reply

  1. You are currently a guest | Login?
advertisement
Go
advertisement
  • Click Here
  • Click Here
advertisement

Content provided in partnership with http://findarticles.com/source//