* name: iqykxi.exe
* size: 183063
* md5.: ee3a48d89399e3ad6b1576a28db4d30dAVG 7.5.0.516/20080226 found [SHeur.ATOO]
eSafe 7.0.15.0/20080221 found [Suspicious File]
F-Secure 6.70.13260.0/20080225 found [Backdoor.Win32.IRCBot.bol]
Fortinet 3.14.0.0/20080225 found [W32/IRCBot.BOL!tr.bdr]
Kaspersky 7.0.0.125/20080226 found [Backdoor.Win32.IRCBot.bol]
Microsoft 1.3204/20080226 found [Backdoor:Win32/Oderoor.gen!B]
NOD32v2 2901/20080225 found [Win32/Agent.NHE]
Panda 9.0.0.4/20080225 found [W32/MSNPhoto.AB.worm]
Prevx1 V2/20080226 found [SHeur.ATOO]
Webwasher-Gateway 6.6.2/20080225 found [Win32.Malware.gen (suspicious)]
Monday, February 25, 2008
iqykxi.exe - ee3a48d89399e3ad6b1576a28db4d30d
antivir.exe - 448ea9863debe13966a7f809e7f8f8ff
* name: antivir.exe
* size: 42358
* md5.: 448ea9863debe13966a7f809e7f8f8ff
AntiVir 7.6.0.67/20080218 found [TR/Crypt.XPACK.Gen]
BitDefender 7.2/20080218 found [Trojan.Spy.ZBot.V]
eSafe 7.0.15.0/20080217 found [Suspicious File]
Sophos 4.26.0/20080218 found [Sus/Behav-192]
Webwasher-Gateway 6.6.2/20080218 found [Trojan.Crypt.XPACK.Gen]
Sunday, February 17, 2008
Safe Strip Related Submissions (Rogue)
Earlier today we received these 4 files from a user at BleepingComputer.com
The detection is extremely low. I started to analyze these in my VM and figured it was worth mentioning these because very little information was available on Google.
The reason I titled this post "Safe Strip Related Submissions" is the url I found in each of these files that takes you to the "Safe Strip" download page.
After running for about 15 minutes I finally started to get the balloon tips:
Even some pretty error messages:
And of course I can't forget my pretty new desktop background:
Oh yeah and a popup for advanced cleaner:
Hijack This entries associated with these:O4 - HKLM\..\Run: [SMSERIALWORKSTARTER] "C:\WINDOWS\comsysobj.exe"Virustotal Scans:
O4 - HKLM\..\Run: [SMSERIALWORKERSTART] "C:\WINDOWS\shellexcon.exe"
O4 - HKLM\..\Run: [SMSERIALSTARTER] "C:\WINDOWS\win32st.exe"
O4 - HKLM\..\Run: [SMSERIALWORKERSTARTER] "C:\WINDOWS\winstrse.exe"* name: winstrse.exe
* size: 13899
* md5.: ed5db9136e502a87bdc20f36c787a977
Webwasher-Gateway 6.6.2/20080215 found [Virus.Win32.FileInfector.gen!90 (suspicious)]* name: comsysobj.exe
* size: 13477
* md5.: 17195c2104aee64b598aa815332bb6a4
Panda 9.0.0.4/20080217 found [Adware/SpyBurner]
Webwasher-Gateway 6.6.2/20080215 found [Virus.Win32.FileInfector.gen!90 (suspicious)]* name: shellexcon.exe
* size: 15479
* md5.: 3fe0e32201f34616edb7447e976df470
AntiVir 7.6.0.67/20080215 found [HEUR/Malware]
Webwasher-Gateway 6.6.2/20080215 found [Heuristic.Malware]* name: win32st.exe
* size: 36864 bytes
* md5.: 7dfb42300357f7b50ba763497e6c41c7
AntiVir 7.6.0.67/20080215 found [HEUR/Malware]
Webwasher-Gateway 6.6.2/20080215 found [Heuristic.Malware]
The files had the following URL's in the strings:http: //theonlybookmark.com/in.cgi
http: //safe-strip-download.com/soft/in.cgi
Once the files finally started doing their thing I finally got a new IE window that opened to a SystemErrorFixer webpage:http: //systemerrorfixer.com/clean/?cmpname=swpges31&eai=and to
swp_ges&eli=3948&eaf=pp_1685211491&eu=http%3A%2F%2F advancedcleaner.com%2F.cleaner%2Findex.php%3Ftmn%3 Dadctmp%26clone_name%3Dswpadcex %26led%3D3948%26afr% 3Dpp_1685211491&ed=0&ex=0&h=10&cmpname=null&mt_info= 4141_0_1556https ://www.anonymouschannel.com/home?pin=anzf3e
Which appears to be a fake Virtual Private Network manager.
Thanks to WlkingMan for submitting these files.
Surf Safe,
Dave
Saturday, February 16, 2008
svchost.exe - 9e3c13b6556d5636b745d3e466d47467
* name: svchost.exe-submit.zip
* size: 15783
* md5.: 9e3c13b6556d5636b745d3e466d47467AntiVir 7.6.0.67/20080215 found [W32/Hidrag.a]
Authentium 4.93.8/20080215 found [W32/Jeefo.A]
Avast 4.7.1098.0/20080215 found [Win32:Jeefo]
AVG 7.5.0.516/20080216 found [Win32/Hidrag.A]
BitDefender 7.2/20080216 found [Win32.Jeefo.A]
CAT-QuickHeal None/20080216 found [W32.Jeefo.A]
ClamAV 0.92.1/20080216 found [W32.Jeefo-3]
DrWeb 4.44.0.09170/20080216 found [Win32.HLLP.Jeefo.36352]
eSafe 7.0.15.0/20080214 found [Win32.Hidrag.a]
eTrust-Vet 31.3.5541/20080215 found [Win32/Jeefo.A]
Ewido 4.0/20080216 found [Worm.VB.dz]
F-Prot 4.4.2.54/20080215 found [W32/Jeefo.A]
F-Secure 6.70.13260.0/20080215 found [Virus.Win32.Hidrag.a]
Fortinet 3.14.0.0/20080216 found [W32/Jeefo.A]
Ikarus T3.1.1.20/20080216 found [Win32.Hidrag]
Kaspersky 7.0.0.125/20080216 found [Virus.Win32.Hidrag.a]
McAfee 5231/20080215 found [W32/Jeefo]
Microsoft 1.3204/20080216 found [Virus:Win32/Jeefo.A]
NOD32v2 2880/20080215 found [Win32/Jeefo.A]
Norman 5.80.02/20080215 found [W32/Hidrag.A]
Panda 9.0.0.4/20080216 found [W32/Jeefo.A.drp]
Prevx1 V2/20080216 found [Generic.Malware]
Rising 20.31.50.00/20080216 found [Win32.Hidrag]
Sophos 4.26.0/20080216 found [W32/Jeefo-A]
Sunbelt 2.2.907.0/20080216 found [Jeefo (v)]
Symantec 10/20080216 found [W32.Jeefo]
TheHacker 6.2.9.221/20080215 found [W32/Jeefo.gen]
VBA32 3.12.6.1/20080214 found [Win32.HLLP.Jeefo]
VirusBuster 4.3.26:9/20080215 found [Win32.Hidrag]
Webwasher-Gateway 6.6.2/20080215 found [Win32.Hidrag.a]
Ma72Pan.exe - 9b6a68204fa80c20d39ebd0da0024085
* name: Ma72Pan.exe-submit.zip
* size: 84508
* md5.: 9b6a68204fa80c20d39ebd0da0024085Ikarus T3.1.1.20/20080217 found [Backdoor.Win32.Rbot.c]
Thursday, February 14, 2008
rjmtjp.exe - d54d475125f7f6aa48d42f3f1122193a
* name: rjmtjp.exe
* size: 11910
* md5.: d54d475125f7f6aa48d42f3f1122193a
AVG 7.5.0.516/20080213 found [BackDoor.RBot.BI]
BitDefender 7.2/20080214 found [Backdoor.Irc.Sdbot.KC]
DrWeb 4.44.0.09170/20080213 found [BackDoor.IRC.Sdbot.945]
eSafe 7.0.15.0/20080213 found [Suspicious File]
F-Secure 6.70.13260.0/20080214 found [W32/Ircbot.dam]
Norman 5.80.02/20080213 found [W32/Ircbot.dam]
Panda 9.0.0.4/20080214 found [W32/Poebot.MW.worm]
Prevx1 V2/20080214 found [Worm.Ircbot.Gen]
Symantec 10/20080214 found [W32.IRCBot.Gen]
Webwasher-Gateway 6.6.2/20080214 found [Win32.Malware.dam (suspicious)]
packers: PE_Patch
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=AFC4ACC53825F0C930750061744E5E003D313D9A
Wednesday, February 13, 2008
Setup.exe - dd13a676ffee2688d9046c3084362feb
* name: Setup.exe
* size: 58794
* md5.: dd13a676ffee2688d9046c3084362feb
AntiVir 7.6.0.65/20080213 found [WORM/P2P.Kapucen.Gen]
Authentium 4.93.8/20080213 found [W32/Kapucen.gen1@p2p]
Avast 4.7.1098.0/20080213 found [Win32:Kapucen]
AVG 7.5.0.516/20080213 found [Win32/Puce.C]
BitDefender 7.2/20080213 found [Win32.Worm.P2P.Puce.G]
CAT-QuickHeal None/20080213 found [I-Worm.Kapucen.b]
ClamAV 0.92/20080213 found [Worm.Puce.E]
DrWeb 4.44.0.09170/20080213 found [Win32.HLLW.Puce]
eTrust-Vet 31.3.5532/20080212 found [Win32/Puce.D]
F-Prot 4.4.2.54/20080212 found [W32/Kapucen.gen1@p2p]
F-Secure 6.70.13260.0/20080213 found [P2P-Worm.Win32.Kapucen.b]
Fortinet 3.14.0.0/20080213 found [W32/Kapucen.B!worm.p2p]
Ikarus T3.1.1.20/20080213 found [P2P-Worm.Win32.Kapucen.b]
Kaspersky 7.0.0.125/20080213 found [P2P-Worm.Win32.Kapucen.b]
McAfee 5228/20080212 found [W32/Puce]
Microsoft 1.3204/20080213 found [Worm:Win32/Puce.Y]
NOD32v2 2872/20080213 found [Win32/Kapucen.B]
Norman 5.80.02/20080212 found [Kapucen.A]
Panda 9.0.0.4/20080213 found [W32/Puce.E.worm]
Prevx1 V2/20080213 found [TROJAN.MUDROP.DU]
Sophos 4.26.0/20080213 found [W32/Puce-H]
Symantec 10/20080213 found [W32.Ecup]
VirusBuster 4.3.26:9/20080213 found [Worm.Kapucen.A]
Webwasher-Gateway 6.6.2/20080213 found [Worm.P2P.Kapucen.Gen]
Subscribe to:
Posts (Atom)



