Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 
1101
3122 posts

Uber Geek


  #1199274 17-Dec-2014 15:59
Send private message

https://www.virustotal.com/en/file/661385e050dcb4791856608819266a989061e026941182c08f8eb63f39e8448a/analysis/1418784214/



1101
3122 posts

Uber Geek


  #1199281 17-Dec-2014 16:03
Send private message

Thats the actual file from an infected PC, different to the attachment. The email attatchment is a downloader Id guess


Nothing will be in the sent items...
but you will have a random jibberish file in C:\windows folder
and you'll be getting bounced emails
Most AV still cant detect the actual virus once infected. The email attachment seems to now be detected though.

Cameron24
2 posts

Wannabe Geek


  #1199307 17-Dec-2014 16:27
Send private message

Still waiting on Eset to pick up on the exe (https://www.virustotal.com/en/file/661385e050dcb4791856608819266a989061e026941182c08f8eb63f39e8448a/analysis/)

But also noticed in services there was a new "Google update service" pointing to the exe.



Paul1977

5058 posts

Uber Geek


  #1199332 17-Dec-2014 16:44
Send private message

Still can't find any info on if it does anything other than just send copies of itself out.

1101
3122 posts

Uber Geek


  #1199339 17-Dec-2014 16:47
Send private message


But also noticed in services there was a new "Google update service" pointing to the exe.


Malwarebytes detected & removed that "Google update service" . I initially though it that part may have been a false positive . Good to get some more info.

Not good when the freeware is on the ball-detecting & removing from this morning, payware still not detecting .


Edit:
PC's still infected , after running 5 different AV, malware programs
I just tried Sophos free scanner, it found more exe's and reg entries all the others missed. Makes me wonder if
its just re-infecting itself .

I'll have to wait till Thurs when all the virus definitions get updated

andrewNZ
2487 posts

Uber Geek
Inactive user


  #1199385 17-Dec-2014 18:03
Send private message

I'm no expert, but my firm opinion is that once a PC is infected it can't reliably be cleaned. Nuke it and (if you have one) restore a backup. It really isn't worth the risk.

1101
3122 posts

Uber Geek


  #1199702 18-Dec-2014 09:46
Send private message

It does some nasty stuff. Change passwords on infected PC's
If any internet banking was done that day, change bank pass as well.

 

http://www.virusradar.com/en/Win32_Battdil.F/description

 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Free setup code: R587125ERQ6VE. Note that to use Quic Broadband you must be comfortable with configuring your own router.
myopinion
938 posts

Ultimate Geek


  #1199738 18-Dec-2014 10:14
Send private message

We where getting them yesterday via O365 exchange for a couple of hours. 6 people opened the zip file but Trend WFB zapped it.

1 | 2 
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Gen Threat Report Reveals Rise in Crypto, Sextortion and Tech Support Scams
Posted 7-Aug-2025 13:09


Logitech G and McLaren Racing Sign New, Expanded Multi-Year Partnership
Posted 7-Aug-2025 13:00


A Third of New Zealanders Fall for Online Scams Says Trend Micro
Posted 7-Aug-2025 12:43


OPPO Releases Its Most Stylish and Compact Smartwatch Yet, the Watch X2 Mini.
Posted 7-Aug-2025 12:37


Epson Launches New High-End EH-LS9000B Home Theatre Laser Projector
Posted 7-Aug-2025 12:34


Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.