RE: New Virus?

From: Ragnar Harper (ragnar_at_harper.no)
Date: 08/15/05

  • Next message: Harlan Carvey: "RE: New Virus?"
    Date: Mon, 15 Aug 2005 23:35:44 +0200
    To: "Alex Arndt" <aarndt@rogers.com>
    
    

    I find http://sandbox.norman.no/live.html very useful for determining
    unknown files. It gives you quite nice information about it.

    Here is an example of output you will get with this:

    Report created: 15.08.2005 23:38:35

    Automatic Sandbox analysis of unknown malware (W32/Downloader)
    [ General information ]
    * Creating several executable files on hard-drive.
    * File length: 38982 bytes.

    [ Changes to filesystem ]
    * Deletes file autorun.inf.
    * Creates file C:\WINDOWS\System\CSRSS.EXE.
    * Creates file C:\TEMP\upd_0001.exe.

    [ Changes to registry ]
    * Creates value ".svchost"="C:\WINDOWS\System\CSRSS.EXE" in key
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".

    [ Network services ]
    * Opens URL: http://medabop.com/u/upd_0001.exe.

    [ Security issues ]
    * Starting downloaded file - potential security problem.

    [ Process/window information ]
    * Creates a mutex 3676C64A-W454-122E-BFC6-083C2BF4S551.
    * Will automatically restart after boot (I'll be back...).

    Best regards,

    Ragnar Harper

    -----Original Message-----
    From: Alex Arndt [mailto:aarndt@rogers.com]
    Sent: 15. august 2005 21:50
    To: incidents@security-focus.com; focus-virus@security-focus.com
    Subject: New Virus?

    Good day,

    I just received an e-mail (subject: test) with a ZIP archive attachment
    that
    claims to be from "MAILER-DAEMON@rogers.com", but it in reality from IP
    66.31.78.168 (c-66-31-78-168.hsd1.nh.comcast.net).

    ZIP Attachment, when opened contains an .EXE file that is attempting to
    look
    like a .DOC file by using a number of spaces in it. Filename in the
    e-mail I
    received is "aarndt@rogers.com.doc
    .exe"

    This is likely a Trojan or other backdoor program. The interesting thing
    is
    that my AV software (which is the free CA anti-virus provided by Rogers
    Yahoo) is not picking it up, nor is the Symantec-based AV scanning that
    Rogers uses on inbound e-mail.

    I will be forwarding the e-mail to AV vendors as a sample. Just figured
    I'd
    give everyone a heads-up just in case...

    FYI, a quick Google search of the .EXE filename came up with nothing. In
    fact, I got this error message when I tried to search for
    "rogers.com.doc
    .exe":

    <SAMPLE WEB PAGE>
    403 Forbidden

    We're sorry...
    ... but we can't process your request right now. A computer virus or
    spyware
    application is sending us automated requests, and it appears that your
    computer or network has been infected.

    We'll restore your access as quickly as possible, so try again soon. In
    the
    meantime, you might want to run a virus checker or spyware remover to
    make
    sure that your computer is free of viruses and other spurious software.

    We apologize for the inconvenience, and hope we'll see you again on
    Google.
    </SAMPLE WEB PAGE>

    I hope this information proves useful,

    Alex Arndt
    CISSP, GCIA, GCIH

    "Within all order is the potential for chaos..."


  • Next message: Harlan Carvey: "RE: New Virus?"

    Relevant Pages

    • Re: registry? virus? help!
      ... I found it interesting that you mentioned Itunes. ... launch anti-virus software which returned no results that indicate a virus. ... then whenever i open any .EXE files, ... but i cant use any of them cuz they are all EXE files.. ...
      (microsoft.public.windowsxp.general)
    • RE: registry? virus? help!
      ... I found it interesting that you mentioned Itunes. ... launch anti-virus software which returned no results that indicate a virus. ... then whenever i open any .EXE files, ... but i cant use any of them cuz they are all EXE files.. ...
      (microsoft.public.windowsxp.general)
    • Re: registry? virus? help!
      ... I found it interesting that you mentioned Itunes. ... then whenever i open any .EXE files, ... therefore i've looked around the internet and i came across this virus ... but i cant use any of them cuz they are all EXE files.. ...
      (microsoft.public.windowsxp.general)
    • backdoor.trojan
      ... I do get virus alert windows popped up once in awhile saying a .exe ... But I do not see anything was registered in my registry, win.ini, and ... I've Symantec Antivirus installed in my computer and the real-time scan ...
      (microsoft.public.security.virus)
    • Re: getting to msconfig or regedit
      ... Possibly check the date/ time stamp on the file may reveal something. ... number of virus are responsible for unknown files. ... Dave Patrick ....Please no email replies - reply in newsgroup. ...
      (microsoft.public.win2000.general)