NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Security

Security


New Trojan Prevents XP from Booting and Shutting Down

Trojan:Win32/Daonol

By Marius Oiaga, Technology News Editor

4th of November 2009, 09:21 GMT

Adjust text size:


Windows XP
Enlarge picture
Developers will agree that code is never perfect as opposed to being always perfectible. This holds true for mammoth software products like the Windows platform, but also for smaller applications designed to run on top of the OS, and even for malicious code targeting the operating system. Microsoft has warned users that a new Trojan horse actively spreading in the wild, particularly on computers running Windows XP, will cause additional problems on top of the infection. Specifically, due to bugs contained by some versions of Trojan:Win32/Daonol, the malware can prevent XP machines from booting and from shutting down.

“Several recent versions of this malware are buggy and prevent computers from successfully shutting down or (more importantly) starting up. If you have (or someone you know has) a Windows XP system which won’t boot completely (ie, shows the ‘Windows XP’ splash-screen with the progress bar, but then the screen turns black and the system never starts up completely), it’s likely a Daonol infection,” explained Aaron Putnam, researcher with the Microsoft Malware Protection Center.

Daonol is by no means designed to prevent users from shutting down or starting up their computers. Such malicious behavior is a direct result of poorly written code, and nothing more. The malware’s authors built network traffic monitoring capabilities into Daonol, with the malware being geared towards stealing FTP credentials. Daonol will deliver additional clues to end users with compromised computers, including the fact that navigation to the websites of security companies is not possible, access to system programs is disabled, and web searches are redirected to malicious sites hosting malware.

“Another obvious symptom of infection is that regedit.exe and cmd.exe will not launch properly. To see if this is the case, navigate to Start->Run and enter regedit.exe. If nothing happens after a few seconds, most likely you are infected with Daonol. If you launch cmd.exe in the same way, you will see a command-prompt window but no text will appear in the window itself. Daonol allows the regedit and cmd processes to launch, but it forces them into a suspended state and doesn’t allow them to do anything,” Putnam added.

TAGS:

Trojan:Win32/Daonol | Daonol | Windows XP
Read by 1,223 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (4.7/5) 4 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows 7 Gets Free Internet TV via Windows Media Center

Download Google Chrome 4.0 Beta - 400% More Performance over v1.0

Windows 7 Security Built on Vista’s Superiority over XP

Windows 7 Whoppers, 10,000 Burgers Sold in Just a Week

OfficeDesktop Embraces Exchange ActiveSync

Forefront Products Tailored to Windows Server 2008 R2

Vista SP2 Failed Installations Fix Tool Available

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM