The most recent variants of the RapidBlaster parasite ( http://www.doxdesk.com/parasite/RapidBlaster.html ) will "morph" themselves to evade detection. Periodically, RapidBlaster will download data from its controlling server that contains a new folder and filename. It will then copy itself to that folder, terminate the original process, delete the original file, and run the new file in the new location.
Since the folder and filenames that RapidBlaster uses are randomly sent from the server, and are not contained within the executable itself, it is very easy for the makers of RapidBlaster to simply update the list of folders/filenames that RapidBlaster uses. Thus, looking for the following folders/filenames should not be the only method of detection, and will not guarantee a RapidBlaster-free system.
The following is a incomplete list of RB file names that have been spotted so far:
rb32 lptt01 = rb32.exe (In a "RapidBlaster" folder in Program Files)
- realplay lptt01 = realplay.exe (In a "RealPlay" folder in Program Files)
- Notepad lptt01 = Notepad.exe (In a "Notepad" folder in Program Files)
- Bsoft lppt01 = Bsoft.exe (In a "BelmontSoft" folder in Program Files)
- Icon lptt01 = icon.exe (In a "Icon" folder in Program Files)
- msys lptt01 = msys.exe (In a "Msyss" folder in Program Files)
- aimaol lptt01 = aimaol.exe (In a "Aimaol" folder in Program Files)
- nvd32 lptt01 = nvd32.exe ( In a Program Files\NvidStar directory)
- syscon lptt01 = syscon.exe (In a "Syscon" folder in Program Files)
- winwan lptt01 = winwan.exe (In a "Winwan" folder in Program Files)
- taskmngr lptt01 = taskmngr.exe > (In a "Taskmngr" folder in Program Files)
- Microfinder lptt01 = mcf.exe (In a "MicroFinder" folder in Program Files)
- winsyslog lptt01 = winsyslog.exe (In a "Winsyslog" folder in Program Files)
- yahoo_toolbar lptt01 = yahoo_toolbar.exe (In a "yahoo_toolbar" folder in Program Files)
- Surfer lptt01 = surfer.exe (In a "mssurfer" folder in Program Files)
- Dkware lptt01 = dkware.exe (In a "DonkeySoft" folder in Program Files)
- Kazaa lptt01 = kazaa.exe (In a "kazaa" folder in Program Files)
- Explorer lptt01 = explorer.exe (In a "explorer" folder in Program Files)
- Newsgroup lptt01 = newsgroup.exe (In a "newsgroup" folder in Program Files)
- Spool lptt01 = spool.exe (In a "spool" folder in Program Files)
- Msconfig lptt01= msconfig.exe (In a "msconfig" folder in Program Files)
- Adaware lptt01 = adaware.exe (In a "adaware" folder in Program Files)
- iexplorer lptt01 = explorer.exe (In a "iexplorer" folder in Program Files)
- Syslog lptt01 = Syslog.exe (In a "Syslog" folder in Program Files)
- Spybott lptt01 - Spybott.exe (In a "Spybott" folder in Program Files)
- efaxs lptt01 = efaxs.exe > (In a "efaxs" folder in Program Files)
- win32_i lptt01 = win32_i.exe (In a "win32_i." folder in Program Files)
Javacool of
Javacoolsoftware fame has reacted with great speed, and issued a RapidBlaster killer, which will find any RapidBlaster variants on your system, will kill the process, and delete the Registry Run entry.
Once the process has been terminated, find the program's folder in Program Files, and simply delete it!
Read about it here:
http://www.wilderssecurity.net/specialinfo/rapidblaster.html