McAfee releases extraDAT for W32/Autorun.worm.aaeb-h

Published: 2012-11-28. Last Updated: 2012-11-28 22:46:20 UTC
by Mark Hofman (Version: 1)
5 comment(s)

McAfee released an extra dat this morning https://kc.mcafee.com/corporate/index?page=content&id=KB76807 for W32/Autorun.worm.aaeb-h

We've received a few emails relating to this, mainly because the formatting on some of the emails wasn't quite what people were expecting.  As far as I can tell it is legit.  I haven't found any evilness in the PDF linked to from the KB (at least there wasn't anything to find when I checked).

The KB also has an updated stinger file to remove the worm from the machine. 

If you have the issue at the moment you may want to apply the DAT, but otherwise you may wish to wait untill it rolls out as part of the normal update cycle.  In the mean time have a read of the KB and associated info and that will give you some info on determining if you have the issue in your network .

If you have been infected the malware guys and gals always enjoy plucking things apart so upload it via the contact form (zip file with a password of infected please).

 

Mark

 

5 comment(s)

Comments

This sound similar to the Win32/Changeup virus that Symantec updated their dat files for yesterday morning. And from what I hear, BHP was hit by this pretty hard.
Is there a virustotal link that we can have a look at, please?

Ta
I agree with Jeretmy. Win32.Changeup!gen32 was the first thought that came to mind. Across the board, I'm not seeing much information on this variant.
Symantec has confirmed W32/Autorun.worm.aaeb-h is what they are calling W32.changeup. Reference -- http://www.symantec.com/connect/forums/w32autorunwormaaeb-h#comment-8023911
- https://kc.mcafee.com/corporate/index?page=content&id=KB76807
Last Modified: November 30, 2012
.

Diary Archives