Re: strange software > winsupdater.exe

From: Nick FitzGerald (nick_at_virus-l.demon.co.uk)
Date: 03/16/05

  • Next message: Harlan Carvey: "RE: strange software > winsupdater.exe"
    Date: Wed, 16 Mar 2005 12:53:27 +1300
    To: incidents@securityfocus.com
    
    

    SDA wrote:

    > We are looking at an abnormal program named "winsupdater.exe" and we are
    > having trouble installing antispyware software on the infected computers,
    > and the antivirus is not detecting the malware.
    > We were able to disable it manual trough regedit, were it leaves a key entry
    > in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run named
    > "Microsoft Window Updater", but anyone knows if this is a new virus or
    > spyware?

    Filenames are all but totally useless for diagnosing malware, spyware
    _AND_ the normal operation of a system.

    If you suspect the file may be some (new) undesirable thing, send
    copies to your preferred antivirus (and possibly other "security")
    product developers asking them for an analysis and to add detection and
    removal if it turns out that it really is "undesirable" by their
    standard.

    To save you looking them up, here are the suspect file submission
    addresses for the better known antivirus engine developers:

       Authentium (Command Antivirus) <virus@authentium.com>
       Computer Associates (US) <virus@ca.com>
       Computer Associates (Vet/EZ) <ipevirus@vet.com.au>
       DialogueScience (Dr. Web) <Antivir@dials.ru>
       Eset (NOD32) <sample@nod32.com>
       F-Secure Corp. <vsamples@f-secure.com>
       Frisk Software (F-PROT) <viruslab@f-prot.com>
       Grisoft (AVG) <virus@grisoft.cz>
       H+BEDV (AntiVir, Vexira engine) <virus@antivir.de>
       Kaspersky Labs <newvirus@kaspersky.com>
       Network Associates (McAfee) <virus_research@nai.com>
         (use a ZIP file with the password 'infected' without the quotes)
       Norman (NVC) <analysis@norman.no>
       Panda Software <labs@pandasoftware.com>
       Sophos Plc. <samples@sophos.com>
       Symantec (Norton) <avsubmit@symantec.com>
       Trend Micro (PC-cillin) <virus_doctor@trendmicro.com>
         (Trend may only accept files from users of its products)

    -- 
    Nick FitzGerald
    Computer Virus Consulting Ltd.
    Ph/FAX: +64 3 3267092
    

  • Next message: Harlan Carvey: "RE: strange software > winsupdater.exe"

    Relevant Pages

    • strange software > winsupdater.exe
      ... having trouble installing antispyware software on the infected computers, ... and the antivirus is not detecting the malware. ...
      (Incidents)
    • Re: unable to open websites in browser(s)
      ... i use HijackThis to scan for BHOs and Malware. ... You are using a seriously obsolete antivirus. ... I would not recommend using that firewall. ...
      (microsoft.public.security.virus)
    • Re: new antivirus program
      ... Antivirus applications from Symantec, McAfee or Trend Micro -- the three leading AV vendors in 2005 -- are far less likely to detect new viruses and Trojans than the least popular brands. ... This has nothing to do with the quality of the software or how long it takes the respective firms to update their clients with signatures and other malware countermeasures. ... On Wednesday, the general manager of Australia's Computer Emergency Response Team, Graham Ingram, described how the threat landscape has changed -- along with the skill of malware authors. ... "We are getting code of a quality that is probably worthy of software engineers. ...
      (alt.comp.anti-virus)
    • Re: Do I have TOO MANY antivirus, antispyware, etc
      ... >>computer is retarted again and I ran the Windows Live Safety Center Scan, ... > antivirus, if the Service Pack level of XP is older than SP2. ... > all active malware. ... > that you know what "opening" a file can do in terms of risk. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Antivirus 2008/2009
      ... My firewall UTM even flagged your URL as malware. ... The un bias real truth about me and the quality of the tools I make can be found here Check my feedback and see what others have said about me and my tools. ... "Gregg Hill" ... I just ran into my third new client with "Antivirus 2008" or "Antivirus 2009" rogue malware infection on an XP computer. ...
      (microsoft.public.security.virus)