Computer Knowledge. Gadget. Anime. Design. Dance. Hong Kong Life. Stuff like that.

12.23.2006

Damage control: After the virus attack at my workplace

The client I worked with (a department in Hong Kong government) got virus infection on their machine, and seemingly spreading like wildfire since then. As of yesterday, things seem to be under control, and the machine under my control are all pretty safe now. It's time to apply the same scanning on my home machine and discs.

Using NOD32, I found out that the following items, among millions of files that I have, has virus in it:

- Hacking - 45 eBooks\Fighting Malicious Code (From the office laptop)
- Storm Codec 5.0.7 , Codec 6.x (From the shared server on 19th Floor)
- Reveal XP Product ID\keyfinder.exe

Among the three, the hacking ebook thing has been deleted form my disc set long time ago. The keyfinder ... well ... I don't use it at all. It was the Storm Codec that suprised me the most since, I actually used the codec pack in A LOT OF PLACES, and the system that has storm codec installed all worked out fine without any virus. It seems like the problem is on the installer, as it tried to download more stuff to the system while installing. Well, I will stop using StormCodec, and find another better codec pack form download.com instead. Gee, no wonder I cannot find StormCodec at Download.com.


The following is jsut for my own reference:



APPS_060321
Virus Detected by NOD32 (2006-12-23)
V:\Storm Codec 6.01.28\StormCodec6.01.28.exe »NSIS »StormSet.exe »NSIS »mms.exe - Win32/TrojanDownloader.Small.CHQ trojan

APPS_051125
Virus Detected by NOD32 (2006-12-23)
W:\_ Apps\Storm Codec 5.0.7\StormCodec5.07.exe »NSIS »yisou_sc.exe »NSIS »aclayer.exe »NSIS »aclayer.dll - Win32/TrojanDownloader.Agent.RS trojan


APPS_051114
Virus Detected by NOD32 (2006-12-23)
W:\_ Apps\Reveal XP Product ID\keyfinder.exe »RAR »xpkey.exe - Win32/PSWTool.RAS.A application
W:\_ Apps\Storm Codec 5.07\StormCodec5.07.exe »NSIS »yisou_sc.exe »NSIS »aclayer.exe »NSIS »aclayer.dll - Win32/TrojanDownloader.Agent.RS trojan


MOV_050828
Virus Detected by NOD32 (2006-12-23)
W:\喇叭書院.Swing.Girls.2004.DVDRip.x264.AC3.5.1CH-JJH繁體中文字幕\Swing.Girls.2004.DVDRip.x264.AC3.5.1CH-JJH\播放軟件\Storm Codec\StormCodec5.07.exe »NSIS »yisou_sc.exe »NSIS »aclayer.exe »NSIS »aclayer.dll - Win32/TrojanDownloader.Agent.RS trojan


MOV_050405
Virus Detected by NOD32 (2006-12-23)
R:\Million.Dollar.Baby.LiMITED.DVD.SCREENER.XViD-MPAA\播放軟件\Storm Codec\StormCodec5.00.-29.exe »NSIS »quiet.exe - probably unknown NewHeur_PE virus [7]
R:\Ray.2004.DVDRiP.XViD-KJS\播放軟件\Storm Codec\StormCodec5.00.-29.exe »NSIS »quiet.exe - probably unknown NewHeur_PE virus [7]
R:\...Phantom of the Opera ...