Prijava na forum:
Ime:
Lozinka:
Prijavi me trajno:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:

ConQUIZtador
Trenutno vreme je: 18. Maj 2024, 00:07:08
nazadnapred
Korisnici koji su trenutno na forumu 0 članova i 1 gost pregledaju ovu temu.

 Napomena: Za sva pitanja u vezi kupovine novog hardware-a ili procene vrednosti i preporuke koristite - ovu temu

Spyware,sta je,kako radi,kako se zastititi? :: Kako rade mreze :: Burek Anti-virus software review :: Index tema koje ne treba propustiti

Idi dole
Stranice:
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
Tema: speedy.pif  (Pročitano 754 puta)
15. Avg 2006, 16:14:51
Hronicar svakodnevice

Stigao mi je mail, eno kuce jale na POP-a....

Zodijak
Pol Muškarac
Poruke 748
Zastava Usa
OS
Windows 2000
Browser
Mozilla Firefox 1.5.0.5
mob
Samsung 6
[size=10pt][size=10pt][size=10pt]to je neki virus koji mi se nakacio na jednu masinu i ne znam sta cu sa njim.ima ga na par mesta ali ne  mogu skroz da izbrisem source fajl.zna li neko nesto vise o ovome/???


ovaj tekst sam pronasao na zone labs ali i kada sve izbrisem sto tamo pise opet se vrati.pomagajte
[/size][/size][/size]


Virus Information powered by Computer Associates
Virus Name: Opaserv.AG
Pervasiveness:         
   3 of 5
Destructiveness:         
   2 of 5
Wildness:         
   2 of 5
Type: Worm
Aliases: [W32/]Opaserv.worm.gen (McAfee); [W32.]Opaserv.AD.Worm (Symantec); [Win32.]Opaserv.AG; [W32/]Opaserv.AE (Wildlist); [Win32/]Opaserv.P.Worm (InoculateIT); [W32/]Opaserv.worm.ac (McAfee); [Worm.]Win32.Opasoft.p (Kaspersky);
 
Date Modified: 15-Jan-2004
Date Published: 24-Sep-2003
 
Description:

Win32.Opaserv.AG is a worm which spreads through shared Windows drives.
Method of Installation

When executed, Win32.Opaserv.AG attempts to create a mutex (Mutual Exclusion Object) called <SpeedyDoS3!> in order to check if it is already running on the target machine. If this fails, Opaserv.AG exits. If this succeeds, it then copies itself to C:\Windows\SPEEDY.PIF and adds the following value to the registry so that this copy is run each time Windows starts:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Spees3 = "C:\Windows\Speedy.pif"

It also creates the following registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SpeedLent = "<Location of the source file>"

This value is set to the file from which the worm was originally run.

Opaserv then deletes the file that it was originally run from and the associated registry entry (above).

Opaserv.AG also creates the following files for storing data
C:\Windows\banda! and C:\Windows\podre!!
Method of Distribution
Via Network Shares

It attempts to copy itself across Windows Networking (SMB) networks by exploiting a very old vulnerability in the way Windows 95, 98, 98SE and ME machines verify network share passwords. In short, unpatched versions of these Operating Systems can be fooled into accepting just a single character password, regardless of how long a password is actually set on the share (so long as a password has been set). Microsoft shipped a patch to fix this vulnerability in October 2000. A brief description of the problem with links to the patch download locations and installation instructions is available from this Microsoft security bulletin:

http://www.microsoft.com/technet/security/bulletin/ms00-072.asp

All users of Windows 95, 98, 98SE and ME machines that have file and print sharing enabled should obtain and install that patch, as despite the rather weak recommendation the security bulletin gives its installation, it really should be considered a critical update. Exploit code, allowing remote password discovery against share-level passwords, has been available s ince around the time the vulnerability was first disclosed, but Opaserv is the first malware known to have exploited this weakness.

The share-level password vulnerability only affects the non-NT versions of Windows. Further, it only affects shares available via share-level access permissions - Windows 9 x and ME machines that are part of a domain and only employ user-level (or domain) access controls are not vulnerable to this exploit. Microsoft recommends "... that user-level access permissions be granted to shares rather than share level permissions based on passwords ".

Earlier reports of Opaserv's operation suggested that it spread through open shares (i.e. ones with no passwords) or shares with only very short, or one character, passwords. This is incorrect. Opaserv spreads by exploiting the share-level password vulnerability mentioned above, specifically trying to attach to the 'C' share (the default name of a share based at the root of the C: drive) of randomly selected IP addresses. If it can attach to such a share, it attempts to copy itself to c:\windows\speedy.bat on the share, creates the file c:\Toma!!!, and adds the following line to Win.ini on Windows 9x machines (so that it will run at the next Windows start):

Run=c:\windows\speedy.bat

Note: Even though this particular vulnerability does not affect NT-based Windows operating systems, (NT, 2000, XP), Opaserv will still successfully copy itself to these systems if it finds a share that meets the above criteria.

Failure to patch this vulnerabilty in Windows means that disinfecting a machine is only a very temporary fix so long as it remains attached to the network(s) from which it was initially infected. If access to Microsoft Networking ports cannot be blocked or otherwise hardened with a firewall or similar means and a Windows 9x or ME machine must be left on a hostile network, the patch absolutely must be applied or the machine will likely be re-infected in short measure.
Additional Information

The worm attempts to update itself from particular websites. At the time of writing, these sites were no longer available.

Analysis by Paul Taylor

IP sačuvana
social share
Pogledaj profil GTalk Skype Facebook
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Veteran foruma
Superstar foruma


Life iz simple, make choices and don't look back

Zodijak
Pol
Poruke 50236
Zastava
OS
Windows XP
Browser
Mozilla Firefox 1.5.0.6
stavi neki drugi AV program pa skeniraj sa njime,ako ga ne ne ukloni ostavice putanju do zarazenog fajla kojeg slobodno obrisi rucno Wink
IP sačuvana
social share
Od kada su fenicani izmislili novac pitanje zahvalnosti je za mene reseno
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Svakodnevni prolaznik


Zodijak
Pol Muškarac
Poruke 260
OS
Windows XP
Browser
Mozilla Firefox 1.5.0.6
Idi u safe mod pa ondak skeniraj racunar!Uzmi neki bolji AV pa ga update-uj pa skeniraj mislim to je vec postala opste poznata stvarcica.Mislim da je bolje komp[ skenirati u safe modu zar ne?Belgarde
IP sačuvana
social share
Neću da se varam. Idem s ranom
u srcu još uvijek dosta čistom:
zašto mene zovu šarlatanom?
Zašto mene zovu skandalistom?

Nisam pljačkao po šumama ljude,
niti streljo apsenike jadne.
Samo sam vragolan ćudi lude,
spreman svakom svoj osmijeh da dadne.
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Veteran foruma
Superstar foruma


Life iz simple, make choices and don't look back

Zodijak
Pol
Poruke 50236
Zastava
OS
Windows XP
Browser
Mozilla Firefox 1.5.0.6
bolje skenirati u safe modu...hehe,pa pazi...i nije bas tako...safe mod se koristi vise kao radikalna metoda...
IP sačuvana
social share
Od kada su fenicani izmislili novac pitanje zahvalnosti je za mene reseno
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Hronicar svakodnevice

Stigao mi je mail, eno kuce jale na POP-a....

Zodijak
Pol Muškarac
Poruke 748
Zastava Usa
OS
Windows XP
Browser
Mozilla Firefox 1.5.0.6
mob
Samsung 6
sve sam pokusao, skenirao sam sa antivirom, avastom, pandom, kasperskiim, bitdefenderom, cak i on line scan svih njih.
ad-aware ga pronadje i kao izbrise ali ne moze ni jedan da izbrise source.i kada ga izbrisem ne vraca se odmah vec posle dva ili tri dana.taj racunar je kasa u prodavnici, nema vezu sa internetom pa mi nije jasno  Smile , cak nema ni cd-rom.
IP sačuvana
social share
Pogledaj profil GTalk Skype Facebook
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Zvezda u usponu


Baš sve, pa i ova izjava, je relativno...

Zodijak Cancer
Pol Muškarac
Poruke 1039
Zastava Cirih (CH)
OS
Windows XP
Browser
Mozilla Firefox 1.5.0.6
Okay, a da li si skenirao iz safe-moda? Pa čak i ako jesi, uradi to ponovo ali pre toga otvori Taskmanager i vidi koji procesi su aktivni. Onda jednostavno isključi sve one koji su ti sumnjivi, a ako neznaš koje napravi screenshot pa postuj.
U suštini nemožeš da pokvariš više nego što je sad - ja sam češće puta tako zatvarao proces po proces dok ne nađem koji mi blokira fajl. A kad nađem onda izbrišem i pif-fajl i proces i to direktno, bez nekog AV.
I što je isto važno - kad brišeš stisneš Shift i držiš ga stisnutog i onda Delete - tako fajlovi budu nepovratno izbrisani.
IP sačuvana
social share
There are two kinds of people in this world, and I am one of them.
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Idi gore
Stranice:
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
Trenutno vreme je: 18. Maj 2024, 00:07:08
nazadnapred
Prebaci se na:  

Poslednji odgovor u temi napisan je pre više od 6 meseci.  

Temu ne bi trebalo "iskopavati" osim u slučaju da imate nešto važno da dodate. Ako ipak želite napisati komentar, kliknite na dugme "Odgovori" u meniju iznad ove poruke. Postoje teme kod kojih su odgovori dobrodošli bez obzira na to koliko je vremena od prošlog prošlo. Npr. teme o određenom piscu, knjizi, muzičaru, glumcu i sl. Nemojte da vas ovaj spisak ograničava, ali nemojte ni pisati na teme koje su završena priča.

web design

Forum Info: Banneri Foruma :: Burek Toolbar :: Burek Prodavnica :: Burek Quiz :: Najcesca pitanja :: Tim Foruma :: Prijava zloupotrebe

Izvori vesti: Blic :: Wikipedia :: Mondo :: Press :: Naša mreža :: Sportska Centrala :: Glas Javnosti :: Kurir :: Mikro :: B92 Sport :: RTS :: Danas

Prijatelji foruma: Triviador :: Domaci :: Morazzia :: TotalCar :: FTW.rs :: MojaPijaca :: Pojacalo :: 011info :: Burgos :: Alfaprevod

Pravne Informacije: Pravilnik Foruma :: Politika privatnosti :: Uslovi koriscenja :: O nama :: Marketing :: Kontakt :: Sitemap

All content on this website is property of "Burek.com" and, as such, they may not be used on other websites without written permission.

Copyright © 2002- "Burek.com", all rights reserved. Performance: 0.078 sec za 16 q. Powered by: SMF. © 2005, Simple Machines LLC.