Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251
Question(s) about VBS/Petik-V & boot.ini
Question(s) about VBS/Petik-V & boot.ini

Question(s) about VBS/Petik-V & boot.ini

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Question(s) about VBS/Petik-V & boot.ini AS 12-14-2005
Posted by =?Utf-8?B?QVM=?= on December 14, 2005, 3:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options
After runnning scan at:

http://safety.live.com/site/en-US/default.htm

I was told that 6 files containing VBS/Petik-V virus were deleted. (without
asking)

All of these files were Firefox related. (<user-dir>\Applicaton Data\...)

Google-ing "VBS/Petik-V" lead to:

http://www.sophos.com/virusinfo/analyses/vbspetikv.html

Now, aside from the fact that this doesn't seem to have to ANYTHING to do
with Firefox and I couldn't find any of the keys in the registry, I was
wondering about this line from the "Recovery" tab:

"and delete 'c:\boot.ini'."

Wouldn't THAT really screw things up?!

Posted by David H. Lipman on December 14, 2005, 9:25 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| After runnning scan at:
|
| http://safety.live.com/site/en-US/default.htm
|
| I was told that 6 files containing VBS/Petik-V virus were deleted. (without
| asking)
|
| All of these files were Firefox related. (<user-dir>\Applicaton Data\...)
|
| Google-ing "VBS/Petik-V" lead to:
|
| http://www.sophos.com/virusinfo/analyses/vbspetikv.html
|
| Now, aside from the fact that this doesn't seem to have to ANYTHING to do
| with Firefox and I couldn't find any of the keys in the registry, I was
| wondering about this line from the "Recovery" tab:
|
| "and delete 'c:\boot.ini'."
|
| Wouldn't THAT really screw things up?!

Realize that it is still a Beta.

Having said that, you didn't post the fully qualified path
(<user-dir>\Applicaton Data\...)
is insufficient.

If it is something to the effect of...
%HOMEPATH%\Applicaton Data\Mozilla\Firefox\Profiles\< variable>\default\Cache

The the VBS source code of this Trojan was found in the Browser cache and could
very well be
a valid detection.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?QVM=?= on December 14, 2005, 5:41 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
OK, fair enough. But, what about deleting boot.ini?

"David H. Lipman" wrote:

>
> | After runnning scan at:
> |
> | http://safety.live.com/site/en-US/default.htm
> |
> | I was told that 6 files containing VBS/Petik-V virus were deleted. (without
> | asking)
> |
> | All of these files were Firefox related. (<user-dir>\Applicaton Data\...)
> |
> | Google-ing "VBS/Petik-V" lead to:
> |
> | http://www.sophos.com/virusinfo/analyses/vbspetikv.html
> |
> | Now, aside from the fact that this doesn't seem to have to ANYTHING to do
> | with Firefox and I couldn't find any of the keys in the registry, I was
> | wondering about this line from the "Recovery" tab:
> |
> | "and delete 'c:\boot.ini'."
> |
> | Wouldn't THAT really screw things up?!
>
> Realize that it is still a Beta.
>
> Having said that, you didn't post the fully qualified path
(<user-dir>\Applicaton Data\...)
> is insufficient.
>
> If it is something to the effect of...
> %HOMEPATH%\Applicaton Data\Mozilla\Firefox\Profiles\< variable>\default\Cache
>
> The the VBS source code of this Trojan was found in the Browser cache and
could very well be
> a valid detection.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Posted by David H. Lipman on December 14, 2005, 7:05 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| OK, fair enough. But, what about deleting boot.ini?
|

It actually deleted C:\BOOT.INI ?

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
Boot Malmo on my USB Mem!! Help October 20, 2005, 9:18 am
Boot Virus Help June 22, 2006, 12:50 pm
boot problem November 24, 2007, 12:59 pm
Please help!! Boot Virus?? May 10, 2008, 11:46 am
Boot. Malmo threat May 11, 2006, 5:20 am
Boot Sector virus September 22, 2006, 6:38 pm
Can't boot to safe mode June 3, 2007, 5:33 pm
Boot Malmo removal from a USB Mem Stick??? September 28, 2005, 3:56 pm
Anti Virus Solutions That Use Their Own Boot CD? July 2, 2008, 1:47 pm
Unknown exploit - Boot.ini/Windows shares February 20, 2006, 5:05 am

The site map in XML format XML site map

Contact Us | Privacy Policy