beter nog..
zoek door heel je systeem.
dat bestand is de boosdoener..
tuurlijk kan norton wel iets .. maar als je 100% zeker wil zijn doe het handmatig..
heier heb je meer info..
Maar zoek wel naar dat bestand ook in onzichtbarer files en mappen via zoeken..
--
When W32.HLLP.Kindal@mm runs, it performs the following actions:
Copies itself as:
%Windir%\systask32l.exe
%Sysdir%\ln32k.exe
NOTES:
%Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
%System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
The attributes of these two files are set to Read-only, Hidden, and System.
Adds the value:
"SysService32"="%Windir%\systask32l.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
so that the worm runs when Windows starts.
Creates a file, %Windir%\ln32k.dll, whose attributes are set to Hidden and Archive. This file is a text file that contains the system date when the computer was infected.
NOTE: In32k.dll is not viral by itself, and therefore, Symantec antivirus products do not detect it. Manually delete it if this worm has infected your system.
Changes the value of "RegisteredOwner" in the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
to:
"RegisteredOwner" = "Not You, no longer"
Deletes the value:
"Advanced Tools Check"
from the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Deletes the following values:
"EnableAP"
"EnableEMI"
"EnableEMO"
"EnableSB"
from the registry key:
HKEY_LOCAL_MACHINE\Software\Symantec\Norton AntiVirus
Disables Windows File protection, if the computer runs Windows NT/2000/XP.
Creates a Hidden folder, %System%\kindlyback.
Locates the KaZaA shared folder through the registry key.
Copies itself to the following folders, if any of them exists:
%System%\kindlyback
KaZaA shared folder
%ProgramFiles%\Morpheus\My Shared Folder
%ProgramFiles%\LimeWire\Shared
%ProgramFiles%\Overnet\incoming
NOTE: %ProgramFiles% is a variable that refers to the path to the program files folder. By default, this is C:\Program Files.
The worm copies itself to the aforementioned folders as some of the following. It appends some random data to the end of its copy.
MyStuff Archive.exe
[eBook]The Hacker Zipped.exe
PornStar Pic.jpg.pif
Stacy Valentine.pif
Quake 3 Arena CD KeyGen.exe
[eBook] Sex And The City Zipped.exe
Warcraft 3 Crack.exe
[eBook] WebSite Design Zipped.exe
AGV Antivirus Pro.exe
WinZip 8.1 KeyGen.exe
Personal Firewall Pro.exe
Window Blinds + KeyGen.exe
Nero Burning Rom 5.5 KeyGen.exe
Eminem - 8 Mile Screensaver.scr
Adobe Photoshop 6 KeyGen.exe
HyperSnap-DX (Full + Crack).exe
Macromedia Flash MX 6.0 Crack.exe
SWiSH 2.0 KeyGen+Crack.exe
Kaspersky Anti-Virus Pro (KeyGen+Crack).exe
PC-Cillin 9.02 (Keygen+Crack).exe
GetRight 4.5e (KeyGen+Crack).exe
Age of Mythology (NoCD+Crack).exe
Easy CD Creator 5 Preview Crack.exe
Eminem 8 Mile Wallpaper.exe
WindowsXP SP KeyGen.exe
[eBook] The Black Art Of Hacking
ICQ Sniffer.exe
Lord Of The Rings Screensaver.scr
kaspersky Anti-Virus
Eminem Desktop.exe
Borland Delphi Trial Crack.exe
Civilization III (Latest Cracked Patch).exe
Old Games Collection I.exe
CuteFTP PRO (Serial included).exe
ACDSee 5.0 (Crack+Serial).exe
DivX Video Bundle
Diskeeper 7.0 (Trial Crack).exe
mIRC32 (Serial included).exe
ZoneAlarm Firewall.exe
Eminem 8 Mile Censored Scene.exe
Personal Web Server.exe
Paint Shop Pro 7 Crack.exe
Winzip 8.1 Full.exe
The Eminem Show (Full Album).exe
Porn Games Collection I.exe
MAME ROMS Archive I.exe
MAME ROMS Archive II.exe
Final Fantasy ROM collection I.exe
Nintendo64 Emulator (ROM included).exe
Castle Wolfstein Multiplayer KeyGen.exe
The Sims Online Crack.exe
The Sims Nude Patch.exe
XCOM 3 Apocalypse.exe
Leisure Suit Larry 6.exe
Virtual Valerie 2.exe
Queens Of The Stone Age (Complete Album).exe
DivX Codecs Pack (All Needed codecs).exe
Strip Poker 3.exe
Britney Spear (Nude Pics Pack).exe
Hacker Tools Pack.exe
[eBook] Visual Basic Programming Handlebook.exe
WinXP Themes Pack.exe
Unreal 2 0][0 3 (Official Crack).exe
Doom 3 Leaked Beta.exe
Lula The Sexy Empire (Full+Crack).exe
Paint Shop Pro7 KeyGen.exe
Randomly chooses the .exe or .scr files from the following folders:
KaZaA shared folder
%ProgramFiles%\Morpheus\My Shared Folder
%ProgramFiles%\LimeWire\Shared
%ProgramFiles%\Overnet\incoming
and copies the chosen file to %System%\kindlyback folder, using .exe, .zip, .mp3, or .lnb as the second extension filename.
Prepends its viral code to the host file. The size of the host file increases by 27,861 bytes.
Retrieves the SMTP Server name, SMTP Email Address, and SMTP Display Name from the registry.
Uses its own SMTP engine to send itself to all the contacts in the Windows Address Book.
The email has one of the following characteristics:
From: The SoftNet Security HQ
Mail From: d.mike@netsecurityhq.com
Subject: Free Net Security Bullettin Service: New security hole.
Attachment: CP_2OOAF3.exe
Message:
Cumulative Patch: (CP_2OOAF3)
Priority: Medium/High
Patch availability: Win9x/NT/XP
The problems could let an attacker run code on your machine,
read certain types of data files on an affected system, or misrepresent
the origin of a file offered for download.
Please, make sure your system is not affected by this problem by running
the attached Analyzer/Patch.
Regards,
The SoftNet Security HQ.
--
Mike Donovald
Softnet Security HQ