Win32.Virtob.Gen
SYMPTOMS: Increased size of some executable files with appreciatively 8K. Increased system activity (increased net traffic and processor usage) TECHNICAL DESCRIPTION: The virus is written in assembly language. The virus is continuously trying to connect to a IRC (proxima.irc[removed]) server on port 65520 and receives commands to download a file. It can interpret 2 different commands:
The default file witch is being downloaded from the IRC server is VT100.exe (witch moves itself in %windir%/system32 directory and acts as a backdoor program). Removal instructions: Please let BitDefender disinfect your files.ANALYZED BY: Suiu Andre, virus researcher Cimpoesu Mihai, virus researcher |