Alert ID : FrSIRT/ALRT-2006-07109
Aliases : N/A
Size : N/A
Rated as : Low Risk
Release Date : 2006-09-28
Description
W32/HLLP.Philis.ini are "_desktop.ini" files created by variants of W32/HLLP.Philis virus. These are created as a hidden system files and contain the date on which virus was executed to visit the folder in which the file resides.
References
http://vil.nai.com/vil/content/v_140656.htm
Credits
Reported by McAfee
ChangeLog
2006-09-28 - Initial Release
W32/HLLP.Philis.ini is a sub-set of the W32/HLLP.Philis virus. The *.ini variant is at this time ONLY detected by McAfee, and if you look at the description of the "virus" here:
http://vil.nai.com/vil/content/v_140656.htm
You'll see that it's not actually a virus that it's detecting, but an artifact of W32/HLLP.Philis. The _desktop.ini file can not contain the virus, it is merely potentially a record of the virus executing.
Looking at the _desktop.ini file included with the latest version of FROIS-01, there is a timestamp inidicating that Dexter2005 has been infected by the W32/HLLP.Philis virus, which prepends itself to .exe files.
The _desktop.ini file is NOT AN INFECTED FILE. It is only a sign that the system on which it was created is infected (and even then, only sometimes, there may be legit apps that create an _desktop.ini file). Since there are no .exes packed in a skin, this isn't even the beginnings of a concern.
However, any skin author that is told their skin is triggering this warning, they need to get their systems cleaned, because they might very well have the actual virus.
| However, any skin author that is told their skin is triggering this warning, they need to get their systems cleaned, because they might very well have the actual virus. |
Then why come off defensive like it's not a problem or "even the beginnings of a concern"? I'd think it would be a concern to the skin authors who likely have the virus on their systems even if it's not a big risk to users of their skins. Again, better safe than sorry.
Welcome Guest! Please take the time to register with us.
- Richer content, access to many features that are disabled for guests like commenting and posting on the forums.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!