
May 31st, 2008
|
 | Possum | | Join Date: May 18th, 2008
Posts: 4
| |
Virus warning G'day. I have made a search of the forums, however I can find no reference to the below mentioned item. So it appears that I have to be the idiot who posts this warning for what it is worth.
Over the past couple of days I have found files (.mp3's) which contain a virus. These files disguise them as legitimate audio files in that they have the format : (Name of legitimate artist - Name of legitimate song). These files are 5611Kb in size. They do not contain any audio information. I have found that if a file of this size is downloaded and then another files is attempted to be downloaded, of a different name, a popup appears indicating that one has already downloaded this file under the name of the previous download. This file was submitted to virustotal.com with the following results :
[ scan result ]
AhnLab-V3 2008.5.30.1/20080530 found nothing
AntiVir 7.8.0.25/20080530 found [TR/Dldr.WMA.Wimad.N]
Authentium 5.1.0.4/20080531 found nothing
Avast 4.8.1195.0/20080530 found nothing
AVG 7.5.0.516/20080530 found [Downloader.Wimad.E]
BitDefender 7.2/20080531 found nothing
CAT-QuickHeal 9.50/20080530 found nothing
ClamAV 0.92.1/20080531 found nothing
DrWeb 4.44.0.09170/20080530 found [Trojan.Click.18899]
eSafe 7.0.15.0/20080529 found nothing
eTrust-Vet 31.4.5837/20080530 found nothing
Ewido 4.0/20080530 found nothing
F-Prot 4.4.4.56/20080531 found nothing
F-Secure 6.70.13260.0/20080531 found [Trojan-Downloader.WMA.Wimad.n]
Fortinet 3.14.0.0/20080530 found nothing
GData 2.0.7306.1023/20080531 found [Trojan-Downloader.WMA.Wimad.n]
Ikarus T3.1.1.26.0/20080531 found nothing
Kaspersky 7.0.0.125/20080531 found [Trojan-Downloader.WMA.Wimad.n]
McAfee 5307/20080530 found [Downloader-UA]
Microsoft None/20080531 found nothing
NOD32v2 3148/20080530 found nothing
Norman 5.80.02/20080530 found nothing
Panda 9.0.0.4/20080531 found nothing
Prevx1 V2/20080531 found nothing
Rising 20.46.50.00/20080531 found nothing
Sophos 4.29.0/20080531 found nothing
Sunbelt 3.0.1139.1/20080529 found nothing
Symantec 10/20080531 found nothing
VBA32 3.12.6.6/20080531 found nothing
VirusBuster 4.3.26:9/20080530 found nothing
Webwasher-Gateway 6.6.2/20080530 found [Trojan.Dldr.WMA.Wimad.N]
I have attempted to block the various hosts without much success however I have been able to maintain the 'Junk' filter in respect to these files. Anyway I have submitted this post in the event that somebody out there may be interested. Regards. |