RE: Folder.htt & Desktop.ini Virus

RE: Folder.htt & Desktop.ini Virus

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
RE: Folder.htt & Desktop.ini Virus Subratam 07-05-2005
Posted by =?Utf-8?B?U3VicmF0YW0=?= on July 5, 2005, 12:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Is Folder.htt and Desktop.ini file is spreading in your computer? Try to
create a new folder and show hidden files and see if those two files are
created everytime you create a new folder. If that happens you have been
infected with Redlof . Do a download of Avast virus and run a complete scan
and that should clear Redlof. If there is the case otherwise then as said ,
leave those two files as they will be present in a computet but yes not in
each and every folders.

Regards

Posted by David H. Lipman on July 5, 2005, 3:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Is Folder.htt and Desktop.ini file is spreading in your computer? Try to
| create a new folder and show hidden files and see if those two files are
| created everytime you create a new folder. If that happens you have been
| infected with Redlof . Do a download of Avast virus and run a complete scan
| and that should clear Redlof. If there is the case otherwise then as said ,
| leave those two files as they will be present in a computet but yes not in
| each and every folders.
|
| Regards


NO....

VBS/Redlof@M -- http://vil.nai.com/vil/content/v_99476.htm
"This is a file infecting VBScript that sets a default, infected, stationary
file for the
Microsoft Outlook and Outlook Express email client programs. It exploits the
Microsoft VM
ActiveX Component Vulnerability." --
http://www.microsoft.com/technet/security/bulletin/MS00-075.mspx

"Symptoms
- Presence of KERNEL.DLL (11,160 bytes) in the SYSTEM directory
- Increase in file size of .HTM and .HTT documents "


It means 'paneerselvam' set folder options to show Hidden System files revealing
Folder.htt
& Desktop.ini which are used to show folders in a specific fashion.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?U3VicmF0YW0=?= on July 5, 2005, 9:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Yes ,
What I wanted to check if Redlof exists or not , as When VBS.Redlof.B runs,
it does the following:

1. Drops the following hidden files in multiple locations:

* Desktop.ini
* Folder.htt (viral code)

source :
http://securityresponse.symantec.com/avcenter/venc/data/vbs.redlof.b.html
Nothing more , but just a normal safety scan. :)

Regards

"David H. Lipman" wrote:

>
> | Is Folder.htt and Desktop.ini file is spreading in your computer? Try to
> | create a new folder and show hidden files and see if those two files are
> | created everytime you create a new folder. If that happens you have been
> | infected with Redlof . Do a download of Avast virus and run a complete scan
> | and that should clear Redlof. If there is the case otherwise then as said ,
> | leave those two files as they will be present in a computet but yes not in
> | each and every folders.
> |
> | Regards
>
>
> NO....
>
> VBS/Redlof@M -- http://vil.nai.com/vil/content/v_99476.htm
> "This is a file infecting VBScript that sets a default, infected, stationary
file for the
> Microsoft Outlook and Outlook Express email client programs. It exploits the
Microsoft VM
> ActiveX Component Vulnerability." --
> http://www.microsoft.com/technet/security/bulletin/MS00-075.mspx
>
> "Symptoms
> - Presence of KERNEL.DLL (11,160 bytes) in the SYSTEM directory
> - Increase in file size of .HTM and .HTT documents "
>
>
> It means 'paneerselvam' set folder options to show Hidden System files
revealing Folder.htt
> & Desktop.ini which are used to show folders in a specific fashion.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Posted by David H. Lipman on July 5, 2005, 10:12 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Yes ,
| What I wanted to check if Redlof exists or not , as When VBS.Redlof.B runs,
| it does the following:
|
| 1. Drops the following hidden files in multiple locations:
|
| * Desktop.ini
| * Folder.htt (viral code)
|
| source :
| http://securityresponse.symantec.com/avcenter/venc/data/vbs.redlof.b.html
| Nothing more , but just a normal safety scan. :)
|
| Regards


Thanx for that clarification. I was not aware of a new variant that was
detected as of
February of this year (2005).

It certainly makes modifications to the Registry that can easily be checked.

In addition, the easiest way to find out is to submit a copy of "Folder.htt"
with a recently
updated date to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against 18 different AV vendor's scanners in
cluding
Symantec.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
Re: Folder.htt & Desktop.ini Virus July 1, 2005, 11:11 am
Re: Folder.htt & Desktop.ini Virus March 29, 2006, 10:36 pm
recusive folder usb boot sector... virus March 14, 2008, 6:45 pm
Is this a virus or something else? Disappearing folder named "system", then can't delete the parent June 6, 2006, 6:28 pm
Folder sounds February 14, 2008, 3:13 pm
disappearing desktop May 12, 2007, 10:16 am
White Desktop April 23, 2008, 7:19 pm
Heard a sound when open a folder September 28, 2007, 8:06 am
Desktop wallpaper hijacked March 7, 2006, 8:20 am
Can't remove image in desktop October 6, 2006, 11:00 pm

The site map in XML format XML site map

Contact Us | Privacy Policy