I need help!!!!

Reply

Join Date: Oct 2009
Posts: 3
Reputation: Alex91 is an unknown quantity at this point 
Solved Threads: 0
Alex91 Alex91 is offline Offline
Newbie Poster

I need help!!!!

 
0
  #1
Oct 28th, 2009
Please, help me!! I need take information about a virus Trojan.Win32.Cosmu.
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 3
Reputation: Alex91 is an unknown quantity at this point 
Solved Threads: 0
Alex91 Alex91 is offline Offline
Newbie Poster
 
0
  #2
Oct 28th, 2009
Does anybody know smth about it??? Wright me here please!
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 1,001
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 48
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer
 
0
  #3
Oct 28th, 2009
Originally Posted by Alex91 View Post
Does anybody know smth about it??? Wright me here please!
Google it - see what the AV sites have to say about it.

Are you infected with it? If so, let us know and we can advise you further.

PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 3
Reputation: Alex91 is an unknown quantity at this point 
Solved Threads: 0
Alex91 Alex91 is offline Offline
Newbie Poster
 
0
  #4
Oct 28th, 2009
No, I must do my work. It is a home-task)) Google cant help me. I find there only tables with the viruses((
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 1,001
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 48
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer
 
0
  #5
Oct 28th, 2009
Originally Posted by Alex91 View Post
No, I must do my work. It is a home-task)
I do not know what that means.

If you need a sample of that particular malware, I can't help you.

Originally Posted by SOPHOS
Troj/Cosmu-A is a Trojan for the Windows platform.

Troj/Cosmu-A communicates via HTTP with the following locations:

kaderap . com


When Troj/Cosmu-A is installed the following files are created:

<User>\Local Settings\Application Data\Microsoft\mqtgsvc.exe
<System>\drivers\cisvc.exe
<System>\drivers\cmstp.exe
<Temp>\cisvc.exe

The following registry entries are created to run cisvc.exe and cmstp.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
CmSTP
<System>\drivers\cmstp.exe /waitservice

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Cisvc
<Temp>\cisvc.exe /waitservice

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<System>\drivers\cisvc.exe

The following registry entry is set:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
MqtgSVC
<Root>\DOCUME~1\support\LOCALS~1\APPLIC~1\MICROS~1\mqtgsvc.exe /waitservice
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Reply

Message:



Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC