- Information & Protection database
- Website Hyperlinks
- Comparative tests of antivirus programs
- Antivirus software tutorials
- Tutorials for previous versions
- A-Squared Freeware 4.0.0.46
- AdAware Free Edition 8.0.4
- AntiVir Free Edition 9.0.0.387
- Avast Free Edition 4.8.1335
- AVG Free Edition 8.5.285
- BitDefender Free Edition 10
- ClamWin Freeware 0.95.1
- DriveSentry Freeware 3.3
- MalwareBytes Antimalware Free Edition 1.36
- Spybot Search & Destroy Freeware 1.5
- SuperAntispyware Free Edition 4.15.1000
- ThreatFire Freeware 4.1.0.25
- Polls
- Other polls
- Would you like us to include guides/presentations of freeware antivirus software?
- What do you use in order to protect your computer?
- What is the OS of your computer?
- Where do you store backups of the files in your hard disk?
- Have you upgraded your Windows Vista to 7?
- What type of Internet connection do you have?
- Various freeware software
- Virus Collecting: How To's
- Press releases
- Latest Virus Alerts: Articles and Statistics
BitDefender - Virus Writers Produce Hardware Damaging Code with Win32.Worm.Zimuse
Submitted by virusp on Sat, 01/30/2010 - 10:50.

Disguised IQ test combines virus, rootkit and worm -- malicious code for one fatal formula
BitDefender®,
an award-winning provider of innovative anti-malware security
solutions, today identified a new e-threat that combines the
destructive behavior of a virus with the spreading mechanisms of a
worm. There are two known variants of this virus, which enters the
computer as a harmless IQ test.
Once executed, the worm creates between seven and eleven copies of
itself (depending on the variant) in critical areas of the Windows
system.
Win32.Worm.Zimuse.A is an extremely dangerous piece of malware. Unlike
average worms, Win32.Worm.Zimuse.A could lead to severe data loss as it
overwrites the first 50 KB of the Master Boot Record - a key zone of
the hard disk drive.
In order to execute on each Windows boot-up, the worm sets the following registry entry:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Dump"="%programfiles%\Dump\Dump.exe
It also creates two driver files, namely:
%system%\drivers\Mstart.sys and %system%\drivers\Mseu.sys
Since 64-bit versions of Windows Vista and Windows 7 require digitally
signed drivers, the worm would fail installing these files.
Unfortunately, in its early stages, this worm makes it nearly
impossible for users to know their system has fallen victim to the
e-threat. If a certain number of days have elapsed since the infection
(40 days for variant A and 20 days for variant B), the computer user
receives an error message stating that a problem has occurred due to
malicious content in IP packets from a peculiar-looking web address. It
then asks the user to recover the system by pressing “OK.” After this
message, the next restart causes the computer’s hard disk to become
damaged due to the compromised boot sector. To view a video detailing
what occurs during an attack by Win32.Worm.Zimuse.A, please click here.
In order to stay safe, BitDefender recommends downloading, installing
and updating a complete antimalware suite with antivirus, antispam,
antiphishing and firewall protection. Users should also employ extra
caution when prompted to open files from unfamiliar locations.
Related articles
- BitDefender - Peer-to-Peer Platforms Lead in the Spread of Malware in BitDefender’s January Top Ten E-Threat Report
- BitDefender - Critical Zero-Day Exploits Hit Internet Explorer and Adobe Reader
- BitDefender Malware and Spam Survey Finds E-Threats Shifting with International Current Events and the Rising Popularity of Web
- BitDefender Malware and Spam Survey Finds E-Threats Shifting with International Current Events and the Rising Popularity of Web
- BitDefender Highlights Top Security Predictions for 2010
- BitDefender - Autorun-Based Malware Tops BitDefender’s November Top Ten Threat Report
- BitDefender - Trojans Continue to Dominate BitDefender’s Top Ten E-Threats for October
- BitDefender - Halloween Doesn’t Have to Be a Scary Time for Internet Users
- Trend Micro - Spammers Fake Responses from Google Job Applications
- Symantec - Phishing Using Pornographic Content as Bait
- Symantec - iPad SEO Poisoning Leads To Rogue Security Software
- Symantec - Trojan.Hydraq's Backdoor Capabilities
- Symantec - A Brilliant Proposal: Stay Away from Valentine’s Day Spam!
- F-Secure Internet Security 2010 blocked “Operation Aurora” before it happened
- Trend Micro - Haiti: Earthquake Unearths Malware


