1. Welcome! Please take a few seconds to create your free account to post threads, make some friends, remove a few ads while surfing and much more. ClutchFans has been bringing fans together to talk Houston Sports since 1996. Join us!

  2. ROCKETS GAMEDAY
    Dave and Bryson (@RedNationBlogga) hop on for the late-night recap after the Rockets take on Nikola Jokic and the Nuggets in Denver. Come join us!

    LIVE! ClutchFans on YouTube

Plexus B virus hit us today

Discussion in 'BBS Hangout' started by DaDakota, Jun 8, 2004.

Tags:
  1. DaDakota

    DaDakota Arrest all Pedophiles
    Supporting Member

    Joined:
    Mar 14, 1999
    Messages:
    132,707
    Likes Received:
    44,169
    Anyone else get this critter, it shut down about 50% of our computers.

    If you have dealt with it, any advice?

    Thanks,

    DD
     
  2. Dr of Dunk

    Dr of Dunk Clutch Crew

    Joined:
    Aug 27, 1999
    Messages:
    47,198
    Likes Received:
    34,553
  3. DaDakota

    DaDakota Arrest all Pedophiles
    Supporting Member

    Joined:
    Mar 14, 1999
    Messages:
    132,707
    Likes Received:
    44,169
    Yeah,

    I did that, we have lost a lot of our machines, but mine is uninfected !!

    It is a nasty bugger....did I mention I hate people who do this crap.

    DD
     
  4. macalu

    macalu Member

    Joined:
    May 19, 2002
    Messages:
    16,950
    Likes Received:
    846
    how do you get it?
     
  5. Stack24

    Stack24 Member

    Joined:
    Jul 15, 2003
    Messages:
    11,766
    Likes Received:
    1,737
  6. KingCheetah

    KingCheetah Atomic Playboy

    Joined:
    Jun 3, 2002
    Messages:
    60,176
    Likes Received:
    54,586
    Attachment i've received 4 today or

    I-Worm.Plexus.b spreads via local networks and the Internet as an attachment to infected messages. It also spreads via file-sharing networks, and exploits a vulnerability in MS Windows LSASS. It is very similar to I-Worm.Plexus.a, with a few insignificant differences.

    On launching, Plexus.b copies itself to the Windows\System32 folder under the upu.exe. It then installs a file named setupex.exe to the Windows\System32 folder, and a file named svchost.exe to the Windows root directory.

    Setupex.exe is TrojanProxy.Win32.Webber.h, a Trojan proxy program. The program is writtten in Microsoft Visual C++, and is 47779 bytes in size. svchost.exe is the main module of Plexus.b. It is written in Microsoft Visual C++ and compressed using FSG. The compressed file is 16224 bytes in size and 57857 bytes when decompressed. The text inside this file is encrypted, and contains the line:

    "-== KAV I'm Expletus !!!. Made in China. ==-"
    The worm registers this file in the system register auto-run key:

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    InternetServ=path to executable file
    It also creates the mutex Expletus.b, to flag its presence in the system, ensuring that only one copy of the worm can be executed.

    Propagation via local and file sharing networks.
    The worm copies itself to the file-sharing folder and to all accessible network resources under the following names:

    AVP5.xcrack.exe
    InternetOptimizer1.05b.exe
    Shrek_2.exe
    ICQ04noimageCrk.exe
    UnNukeit9xNT.exe
    YahooDBMails.exe
    hx00def.exe
    ICQBomber.exe
    The worm is otherwise identical to I-Worm.Plexus.a

     

Share This Page