"mp3 Killer Worm"

JimmehJimmeh Join Date: 2003-08-24 Member: 20173Members, Constellation
<div class="IPBDescription">w32/nopir-b</div> <a href='http://www.siliconrepublic.com/news/news.nv?storyid=single4777' target='_blank'>Clicky</a>

<!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->The W32/Nopir-B worm spreads via peer-to-peer file-sharing systems and at first glance seems to be software that can be used to make copies of commercial DVDs. When opened, it shows its true colours, or rather its tricolour. When the user runs the file it shows an anti-piracy image complete with French flag and signed - for what that's worth - by someone purporting to be The French Hacker.

More importantly, once it infects the host PC the file tries to delete all MP3 music files as well as disabling various system utilities and wiping .com programs. According to data from Sophos, the worm also attempts to disable task manager, registry tools and access to the control panel. W32/Nopir-B will also check for debuggers and may attempt to disable any such software that it finds. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->

;<
«1

Comments

  • CplDavisCplDavis I hunt the arctic Snonos Join Date: 2003-01-09 Member: 12097Members
    hmmm good thing I dont d/l dvd copying software or use P2P programs (besides bittorent from known sources) <!--emo&:)--><img src='http://www.unknownworlds.com/forums/html/emoticons/smile-fix.gif' border='0' style='vertical-align:middle' alt='smile-fix.gif' /><!--endemo-->
  • coriscoris Join Date: 2003-07-08 Member: 18034Members, Constellation
    Wow getting that would suck.
  • OmegamanOmegaman Join Date: 2004-01-11 Member: 25239Members
    The French Hacker? <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html/emoticons/biggrin-fix.gif' border='0' style='vertical-align:middle' alt='biggrin-fix.gif' /><!--endemo-->
  • TresthTresth Join Date: 2002-11-03 Member: 5602Members, Constellation
    <!--QuoteBegin-Omegaman!+May 9 2005, 06:23 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Omegaman! @ May 9 2005, 06:23 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> The French Hacker? <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html/emoticons/biggrin-fix.gif' border='0' style='vertical-align:middle' alt='biggrin-fix.gif' /><!--endemo--> <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Yes. It begins.
  • Lt_PatchLt_Patch Join Date: 2005-02-07 Member: 40286Members
    Hmm, this one will be fun to deal with. I have to disinfect so many systems every week from viral infections, it will be nice to tell someone that they have been downloading illegal software, and have been infected with a virus for their troubles...

    <!--QuoteBegin-Sophos Corp.+--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Sophos Corp.)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> W32/Nopir-B is a worm for the Windows platform.

    W32/Nopir-B will display an anti-piracy image on the screen when run. The worm will then delete all COM and MP3 files from the computer. The worm will also disable taskmanager, registry tools, and access to the control panel. W32/Nopir-B will also check for debuggers and may attempt to disable any such software that it finds.

    W32/Nopir-B copies itself to <Program Files>\Projects Visual Studio.NET\Nctrup.exe, <Program Files>\Restore\<random name>.exe, <Program Files>\eMule\Incoming\AnyDVD 5.1.0.1 Crack+Keygen By Razor.exe. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->

    So, no downloading of AnyDVD 5.1.0.1 from the P2P networks.

    This will affect so many people it will be unbelievable. The amount of people who come in asking about copying original DVDs is getting stupid. Now I can say to them "Are you on <Random P2P Network>? Yes? Then download AnyDVD 5.1.0.1..." <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html/emoticons/biggrin-fix.gif' border='0' style='vertical-align:middle' alt='biggrin-fix.gif' /><!--endemo-->

    So evil.

    On a last note
    <!--QuoteBegin- Sophos Corp.+--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> ( Sophos Corp.)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->  W32/Nopir-B will create the following registry entries:
    ...
    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
    DisableRegistryTools
    1<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Hmm, disable access to regedit will you?

    It's as though all these virus creators have never used .reg files to delete registry entries... <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html/emoticons/biggrin-fix.gif' border='0' style='vertical-align:middle' alt='biggrin-fix.gif' /><!--endemo-->
  • OmegamanOmegaman Join Date: 2004-01-11 Member: 25239Members
    Lt Patch is a White Hat?
  • Lt_PatchLt_Patch Join Date: 2005-02-07 Member: 40286Members
    ¬_¬<!--emo&???--><img src='http://www.unknownworlds.com/forums/html/emoticons/confused-fix.gif' border='0' style='vertical-align:middle' alt='confused-fix.gif' /><!--endemo-->

    Explain...
  • OmegamanOmegaman Join Date: 2004-01-11 Member: 25239Members
    There are White Hats and Black Hats.

    Black Hats are hackers that do bad things.

    White Hats are hackers that get hired to perform awesome internet security, or do what you do, or whatever a good guy hacker would do.
  • Lt_PatchLt_Patch Join Date: 2005-02-07 Member: 40286Members
    edited May 2005
    <!--QuoteBegin-Omegaman!+May 9 2005, 06:00 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Omegaman! @ May 9 2005, 06:00 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> There are White Hats and Black Hats.

    Black Hats are hackers that do bad things.

    White Hats are hackers that get hired to perform awesome internet security, or do what you do, or whatever a good guy hacker would do. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Alrighty then...

    I'm a White Hat.

    But one that's employed in Tech Support.

    And one whos last hack was the college's Win2k server. Which was a piece of ****. Sub7, and self-written stuff, all the way...

    Gimme them passwords Mr. I-Know-About-Security-but-can't-recognise-a-false-RM-Netowrk-login-screen!
  • OmegamanOmegaman Join Date: 2004-01-11 Member: 25239Members
    There's also Gray Hats, but I forgot what they do.
  • theclamtheclam Join Date: 2004-08-01 Member: 30290Members
    <!--QuoteBegin-Omegaman!+May 9 2005, 01:11 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Omegaman! @ May 9 2005, 01:11 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> There's also Gray Hats, but I forgot what they do. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    An example of a grey hat would be someone who publicy publishes an exploit, in order to force a company to release a patch. They aren't malicious, but they aren't wholly benevolent.
  • BlackMageBlackMage [citation needed] Join Date: 2003-06-18 Member: 17474Members, Constellation
    telling people to go download virusses isn't very whitehattish.

    sir patch acts like a script kiddie
  • CommunistWithAGunCommunistWithAGun Local Propaganda Guy Join Date: 2003-04-30 Member: 15953Members
    <!--QuoteBegin-Jimmeh+May 9 2005, 11:33 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Jimmeh @ May 9 2005, 11:33 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <a href='http://www.siliconrepublic.com/news/news.nv?storyid=single4777' target='_blank'>Clicky</a>

    <!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->The W32/Nopir-B worm spreads via peer-to-peer file-sharing systems and at first glance seems to be software that can be used to make copies of commercial DVDs. When opened, it shows its true colours, or rather its tricolour. When the user runs the file it shows an anti-piracy image complete with French flag and signed - for what that's worth - by someone purporting to be The French Hacker.

    More importantly, once it infects the host PC the file tries to delete all MP3 music files as well as disabling various system utilities and wiping .com programs. According to data from Sophos, the worm also attempts to disable task manager, registry tools and access to the control panel. W32/Nopir-B will also check for debuggers and may attempt to disable any such software that it finds. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->

    ;< <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    <!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->"However this worm is easily detected by its snobbish attitude and love for cheese"<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
  • AlcapwnAlcapwn &quot;War is the science of destruction&quot; - John Abbot Join Date: 2003-06-21 Member: 17590Members
    The....french? Hacker?


    Little to Ballsy for a french guy. <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html/emoticons/biggrin-fix.gif' border='0' style='vertical-align:middle' alt='biggrin-fix.gif' /><!--endemo-->
  • JimmehJimmeh Join Date: 2003-08-24 Member: 20173Members, Constellation
    Doesn't matter if you're black or white.
  • CabooseCaboose title = name(self, handle) Join Date: 2003-02-15 Member: 13597Members, Constellation
    Hmm, I use Linux, god I love it. /me goes off to pirate DVD's (j/k btw mods)
  • LegionnairedLegionnaired Join Date: 2002-04-30 Member: 552Members, Constellation
    Five dollars says the RIAA paid someone to write this.

    Another 1.57 and some pocket lint says that the writer of the program isn't really French, just trying to humiliate people by making them think they were owned by a Frenchman.
  • TommyVercettiTommyVercetti Join Date: 2003-02-10 Member: 13390Members, Constellation, Reinforced - Shadow
    You know what would be funny? If they packed this in with anime fansubs. Oh wait, that would suck.



    And it's oh so illegal! Yep, I'm sure deleting random people's stuff and messing up their computers is a lot better than stealing music from the publisher.

    BTW I'm a little "MDKMDKMDKMDKMDK I WANT MY AK NOW" when it comes to publishers of popular music (a.k.a. "total crap").
  • theclamtheclam Join Date: 2004-08-01 Member: 30290Members
    I guess the lesson here is that you shouldn't run .exe files that you got from P2P.
  • TommyVercettiTommyVercetti Join Date: 2003-02-10 Member: 13390Members, Constellation, Reinforced - Shadow
    All the good groups put their stuff in .rar's and make you manually install.
  • LikuLiku I, am the Somberlain. Join Date: 2003-01-10 Member: 12128Members
    edited May 2005
    Gotta love the French. Wait...
  • theclamtheclam Join Date: 2004-08-01 Member: 30290Members
    <!--QuoteBegin-TommyVercetti+May 9 2005, 06:07 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (TommyVercetti @ May 9 2005, 06:07 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> All the good groups put their stuff in .rar's and make you manually install. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    You can rightclick to extract RARs without opening any exe.
  • TommyVercettiTommyVercetti Join Date: 2003-02-10 Member: 13390Members, Constellation, Reinforced - Shadow
    Yea, but the directory structure usually requires some work.
  • aonomusaonomus Dedicated NS Mastermind (no need for school) Join Date: 2003-11-26 Member: 23605Members, Constellation
    Im probably thinking that the RIAA made this, I doubt any 'hacker' would destroy the P2P networks that he probably downloads most of his music/stuff from (destroy the files, reduce the stuff on the network).
  • Status_QuoStatus_Quo Join Date: 2004-01-30 Member: 25749Members
    Wouldn't be surprised. From what I've seen RIAA doesn't give a damn about ethics and what is illegal, as long as it doesn't hurt their agenda. I suppose, in a way, that they are really no better than those who download the stuff to begin with. But at least those who download the stuff aren't hiding behind some righteous crusade.
  • OmegamanOmegaman Join Date: 2004-01-11 Member: 25239Members
    <!--QuoteBegin-Jimmeh+May 9 2005, 03:38 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Jimmeh @ May 9 2005, 03:38 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Doesn't matter if you're black or white. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Winner. Not winnar, but winner.
  • OrganoXOrganoX Join Date: 2004-03-21 Member: 27473Members
    lol, how come i recognize the file Nctrup.exe <!--emo&???--><img src='http://www.unknownworlds.com/forums/html/emoticons/confused-fix.gif' border='0' style='vertical-align:middle' alt='confused-fix.gif' /><!--endemo-->
    I dont use any visual studio programs.
    I think i have it blocked on my firewall, going to check it when i get home.
  • lolfighterlolfighter Snark, Dire Join Date: 2003-04-20 Member: 15693Members
    And once again we have random animosity towards the french. Ha ha, ain't we just hilarious? Stop insulting my neighbours, numbwits, or I'll stuff a broom handle into one of your more private places.

    It was bound to happen: People stealing from you, and you can't get to them through the legal system? Use an illegal one instead! Responding in kind has never been the best way of solving a conflict, but it's definitely one of the more popular ones.
    I'm going to suggest one of the more obvious ways of protecting yourself against this: Stop stealing software.
  • KillymageeKillymagee Join Date: 2002-11-01 Member: 3136Members
    Anyone with half a brain would just download DVD shrink a free program that is only a couple of megs and makes perfect dvd backups. <!--emo&;)--><img src='http://www.unknownworlds.com/forums/html/emoticons/wink-fix.gif' border='0' style='vertical-align:middle' alt='wink-fix.gif' /><!--endemo-->
  • Cereal_KillRCereal_KillR Join Date: 2002-10-31 Member: 1837Members
    <!--QuoteBegin-Omegaman!+May 9 2005, 08:11 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Omegaman! @ May 9 2005, 08:11 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> There's also Gray Hats, but I forgot what they do. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    They're black, only with bleach.
Sign In or Register to comment.