Dr Web Anti-virus protects peer-to-peer networks from a dangers polymorphic Win32Polipos

Softarea51.com is your source for all the latest computer technology and software related press releases.
Browse our archive for more press releases!

Released on: 20, April 2006
, Author: Doctor Web, Ltd.
, Audience: Computers related

Before you download:
Clean your PC from errors


Virus monitoring service of Doctor Web, Ltd. warns users of peer-to-peer networks ona dangerous polymorphic virus named Win32.Polipos which emerged around a months agoand is actively propagating in different file sharing networks.

The propagation of Win32.Polipos began in March. It was added to Dr.Web virus baseon March 20, 2006 and since that time it is no more a danger for users of Dr.WebAnti-virus.

Apart from the complicated polymorphic technique used by the virus writer, the virusalso has a dangerous function of Â"neutralizing" certain antivirus and securityprograms. Fluently spreading across P2Ps, the virus infiltrates computers connectedto these networks and, being run, secretly makes them accessible to public ofP2P-networks.

The virus infected Windows executables by writing the code of the polymorphicdecoder into unused spaces of code sections, as if Â"covering the body of the victimwith own spotsÂ". When doing this, the virus creates a new section and places thereits main encoded code, moving the resource section, if any exists, below. Whenimplanting into a file it does not modify the original entry point, but replacesaddresses of calls of API, selected at random, with the start address of the virus.

When the virus is launched, it implants its code into all run processes, except forthe following:

savedump, dumprep, dwwin, drwtsn32, drwatson, kernel32.dllsmss, csrss, spoolsv, ctfmon, temp

Thus, several copies of the virus stay in the computer memory, each of them isresponsible for a definite activity, for example search for files for infection,infection of files, interaction with P2Ps based on Gnutella networks, etc. Infectedfiles become open for members of this network. Resident copies of Win32.Polipos intercept the following API functions -ExitProcess, CreateProcess, CreateFileA, LoadLibraryExA, SearchPathA,CreateProcessW, CreateFileW, LoadLibraryExW, SearchPathW. When any of thesefunctions is called, new files get infected. When the control is passed to avictimized file with overlays (sfx-archives, installation files , etc.) the virustries to create the original copy of file in the temporary directory with the nameptf*.tmp and runs it. This is done to evade the integrity check used by certaininstallers.

The spread of such virus undoubtly caused the anxiety of users of P2Ps and it isstrange enough that though the presence in networks of Win32.Polipos is not a secretfor any body for a whole month, Dr.Web Anti-virus long remained the only anti-virusto detect it.

At the beginning of the epidemics the technical support service of Doctor Web, Ltd.received usersÂ' requests about false alarms to Â"clean filesÂ". But Dr.Web analystsproved the existence of a new virus. Dr.Web Anti-virus successfully detectsdifferent modifications of this complicated polymorphic virus due to the hightechnological level of the Dr.Web engine.

At present, Virus monitoring service of Doctor Web, Ltd. designed the curingprocedure for files infected with Win32.Polipos. It was done for users whoseanti-virus programs still do not detect this virus and whose computers, thoughprotected by other anti-virus programs, are infected with the virus and let itinfect other computers. The curing technique is rather difficult, as it requiresprocessing of a complicated crypt algorithm XTEA, and the decoding of the virus codecan take much time. You should not download any additional curing utilities to curethe infected files, just use Dr.Web Anti-virus and update the virus bases on time.


Source: Express-Press-Release.com
Related downloads


Comodo EasyVPN allows users to easily group multiple computers into a secure, peer-to-peer network over the Internet. Access your PC remotely, share files, printers, and music, even set up multi-player gaming sessions.

Shareaza is a file sharing system that can harness the power of up to four separate peer-to-peer (P2P) networks, including EDonkey2000, Gnutella, BitTorrent and Shareaza's native network, Gnutella2 (G2).

PIPL is not only a lean and quick MP3 player and playlist editor, it also has built in peer-to-peer networking and ID3 tag editing. New in this version is the ability to print your MP3 collection.

It is the real-time messaging system specifically designed for business Intranets. Using a peer-to-peer architecture, it delivers text messages from workstation to workstation at real-time, without the typical delay associated with e-mail.

Zeus is a free peer to peer, or P2P file sharing program that allows users to download unlimited free files from other Zeus users. Zeus contains NO adware and NO spyware at all. It's very user friendly and allows you to download files anonymously.

Manolito is a file-sharing program that uses a peer-to-peer network and works without a central server. Search and get free music downloads from the entire network of users. Also offers buddy list, integrated chat, firewall support and CD burner.

BearShare MP3 Downloader is an excellent tool for users who desire maximum peer to peer download speed. Delivering advanced search algorithm will help you find the most hidden media around.

BitComet Turbo is a clean and free peer to peer file sharing program that offers you the opportunity to download any kind of media files and enables users to share any digital file including MOVIES, images, audio, video, software,documents, etc.

Use MsgConnect to exchange information between parts of your application that work on the same or on different computers. MsgConnect is a cross-platform message-oriented middleware that can be used in both client-server and peer-to-peer modes.

BitPump is a Bittorrent client that provides easy download management via .torrent files. Rather than coming from a single server, files are transferred in bits via a p2p network of other .torrent users/clients, allowing for high-speed downloads.
Softarea51.com RSS Feed

Get RSS updates on latest computer technology and software related press releases Subscribe to Latest Press Releases RSS feed    Subscribe



You are welcome to include these headlines in your own pages. If you want to find out how to parse this RSS file please read our tutorial How to parse RSS feeds with PHP.