WORM/Bube.1.m
Geizhals » Forum » Security & Viren » WORM/Bube.1.m (3 Beiträge, 259 Mal gelesen) Top-100 | Fresh-100
Du bist nicht angemeldet. [ Login/Registrieren ]
WORM/Bube.1.m
20.09.2005, 21:01:29
Hi

Hat wer von euch den Wurm schon mal gehabt?
Im Google finde ich nichts, nur andere Bube.X.X Wuermer

-----------------------------------
We are currently seeing an increase in cases which involve file infecting AdWare.
These new viruses are more sophisticated than the one we previously reported and append malicious code to Windows' explorer.exe. The viruses belong to the Virus.Win32.Bube family.

For example, Virus.Win32.Bube.d downloads AdWare and Trojans, including: AdWare.ISearch.d, Trojan-Clicker.Win32.Agent.bn, Trojan.Win32.LowZones.ai and PornWare.Dialer.Salc.

Disinfection in this case is tricky, as explorer.exe is an important Windows process. Additionally, the malware tries to prevent removal by disabling system restore, infecting the explorer.exe residing in %sysdir%\dllcache and lowering overall system security.

Things can get extra complicated as an AV can block access to the infected explorer.exe. This is why we provide the following removal instructions.

Please note that this removal guide does not apply to KAV 5 series. KAV 5 can disinfect explorer.exe in normal mode. However a full system scan is still required to delete or disinfect other malicious files.

* Boot into safe mode.
* Start a full system scan
* While the scan is running, kill the explorer.exe process via taskmanager.
* Disinfect all files detected as Virus.Win32.Bube.
* Reboot.
* The system is now clean of Virus.Win32.Bube.

Notes:
* Make sure to use the extended bases to remove the AdWare that Virus.Win32.Bube. may have downloaded..
* Security related system settings may have been altered by Virus.Win32.Bube, so check your settings after disinfection.
-----------------------------------
This short removal guide is meant for AVs which can disinfect Bube infected files.
Please make sure explorer.exe has been shutdown when attempting to disinfect(not delete or quarantine!!)the infected explorer.exe.
-----------------------------------

ich hab AV personal, funktioniert leider nicht so wie beschrieben

Hat ihn schon wer gehabt u weggebracht?

---------------------------------
WoW Guild Pugnax on Alleria
---------------------------------

Antworten PM Alle Chronologisch
 
Melden nicht möglich
.  Re: WORM/Bube.1.m  (hurt am 21.09.2005, 14:41:05)
.  Re: WORM/Bube.1.m  (shambler am 02.10.2005, 14:02:44)
 

Dieses Forum ist eine frei zugängliche Diskussionsplattform.
Der Betreiber übernimmt keine Verantwortung für den Inhalt der Beiträge und behält sich das Recht vor, Beiträge mit rechtswidrigem oder anstößigem Inhalt zu löschen.
Datenschutzerklärung