Content

MSH/Danom

Type
Virus
SubType
Script
Discovery Date
08/04/2005
Length
Varies
Minimum DAT
4550 (08/04/2005)
Updated DAT
4552 (08/08/2005)
Minimum Engine
5.1.00
Description Added
08/04/2005
Description Modified
08/07/2005 11:19 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This detection covers several proof of concept viruses targeting the Microsoft Command Shell, which may be included in a future version of the Microsoft Windows operating system.  These viruses are not currently a threat to end users.

Symptoms

Modification of file size

Method of Infection

This virus requires MSH in order to replicate.

Removal

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Aliases

  • BAT/Monad
  • BAT_DANOM (Trend)
  • MSH/Danom
  • MSH/Danom (Panda)
  • MSH/Modan (Sophos)
  • Virus.MSH.Danom (AVP)

Characteristics

Characteristics -

This detection covers several proof of concept viruses targeting the Microsoft Command Shell, which may be included in a future version of the Microsoft Windows operating system.  These viruses are not currently a threat to end users.

Symptoms

Symptoms -

Modification of file size

Method of Infection

Method of Infection -

This virus requires MSH in order to replicate.

Removal -

Removal -

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A