Nyxem.E virus delete files payload



F-secure has some details on a dangerous payload for the Nyxem.E virus. (The Nyxem.E virus is very similar to the Email-Worm.Win32.VB.bi that was talked about earlier in the week.) In fact, this virus seems to be spreading fairly well (not the blockbuster spread of older email viruses, but it is spreading.) Anyway, according to f-secure it will on the 3rd of the month, delete all files matching the following patterns. *.doc *.xls *.mdb *.mde *.ppt *.pps *.zip *.rar *.pdf *.psd *.dmp *(on all accessible drives.)


What this means is that IF you have this virus and it’s the third of the month it will delete most all Microsoft Office formatted documents + rar’s, zips, pdf and a few other file formats. Nasty. Technically it doesn’t delete them, but overwrite their data with… “The files’ contens get replaced with a text string “DATA Error [47 0F 94 93 F4 K5]“.”

Through the process of infection it also deletes the following files…..

DAP*.dll
BearShare*.dll
SymantecLiveUpdate*.*
SymantecCommon FilesSymantec Shared*.*
Norton AntiVirus*.exe
Alwil SoftwareAvast4*.exe
McAfee.comVSO*.exe
McAfee.comAgent*.*
McAfee.comshared*.*
Trend MicroPC-cillin 2002*.exe
Trend MicroPC-cillin 2003*.exe
Trend MicroInternet Security*.exe
NavNT*.exe
Kaspersky LabKaspersky Anti-Virus Personal*.ppl
Kaspersky LabKaspersky Anti-Virus Personal*.exe
GrisoftAVG7*.dll
TREND MICROOfficeScan*.dll
Trend MicroOfficeScan Client*.exe
LimeWireLimeWire 4.2.6LimeWire.jar
Morpheus*.dll

( The * matches anything for those that don’t know…., so deleting *.dll in a folder deletes this.dll that.dll and the other.dll, without having to explicitly give a delete command for each. Think of it as “delete everything that ends with .dll” to delete *.dll)

Related Posts

Blog Traffic Exchange Related Posts
  • How to Remove BlockProtector | Removal Guide So... the tail end of last week saw another new variant in the Wini family of rogue antivirus: blockprotector. It's the successor to..... Blockscanner (blockscanner removal guide) as well as the long list of prior variants that you can find on that page. (Sorry... it's just getting to be ridiculously......
  • Hiding malware may evade antivirus Sans had an interesting malware analysis this morning about a blob that appeared to be ascii text (gibberish) that was retrieved by a piece of malware. It turns out that the ascii text was a cleverly encoded exe file (windows executable or program file.) It took several iterations of their......
  • How to Remove Cyber Protection Center | Removal Guide Cyber Protection Center is related to Cyber Security (see how to remove cyber security). These are rogue antivirus applications that will generate many warnings and error messages on your system claiming (falsely) that your system is infected with countless virus and trojan infected files. In reality, Cyber Protection Center may......
Blog Traffic Exchange Related Websites
  • Turn Any File into an EXE with Convert to EXE If you're a geek like me, you may on occasion have run into a situation where you had a file that you needed to convert to exe. I had read a few forum posts and tutorials on how to do this with self-extracting installers, and I even managed to do......
  • Women's Fragrance Trend – Bakery Fresh Scents Have you ever walked into a local bakery and been overcome with the wonderful aromatics? Imagine standing in line while looking at all the baked goods that line the shelves just waiting to be tasted. Now think about these same scents only used as women's fragrance. Yummy and decadent! Bakery......
  • Micro-Trend Trading for Daily Income: Using Intra-Day Trading Tactics to Harness the Power of Today's Volatile Markets Reviews Micro-Trend Trading for Daily Income: Using Intra-Day Trading Tactics to Harness the Power of Today's Volatile Markets ISBN13: 9780071752879Condition: NewNotes: BRAND NEW FROM PUBLISHER! BUY WITH CONFIDENCE, Over one million books sold! 98% Positive feedback. Compare our books, prices and service to the competition. 100% Satisfaction Guaranteed Profit every day......
PDF24    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site