Re: Kernels32.exe

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 09/26/05


Date: Sun, 25 Sep 2005 18:09:09 -0400

From: "Phil Weldon" <notdiscosed@example.com>

| 'David H. Lipman' wrote, in part:
|> That is NOT a legitimate OS file and could be associated with a Downloader
| Trojan.
| _____
|
| Oops, that went right past me. I guess that's why the malcoders pick file
| names that are close to legitimate ones B^(
|
| Phil Weldon

Yepper.

Not only do VX'ers mask their file names as being similar to legitimate file names, they
often USE the name of legitimate files. The difference is the location of where they are
executed.

for example; take SVCHOST.EXE
It should be executed from; %windir%\system32\svchost.exe

However if it is found running in; %windir%\svchost.exe
there is a high probability it is an infector.

If SVCHOST.EXE is found running on any Win9x/ME PC you are almost guaranteed it is an
infector.

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Relevant Pages

  • Re: Cycle.exe pinning cpu at 100%, what is it? Help
    ... and it is to the infector's benefit to mask itself by using the name of a legitimate file. ... I am glad it turns out it is NOT an infector. ... |> 3) If you are using WinME or WinXP, disable System Restore ... |> | cycle.exe and one executes svchost.exe. ...
    (microsoft.public.win2000.general)
  • Re: What is a sxe*.tmp File
    ... indication of a backdoor IRC Trojan. ... I would scan *all* files with an up to date virus ... That's why a virus scanner is necessary. ... these Trojans kits are installed by packaging legitimate ...
    (microsoft.public.windowsxp.security_admin)
  • Re: TrojanSpy.Goldun --- Format=Cure?
    ... If I save Favorites, Mail Settings, Mail, Address ... Names of malware files often use names similar to or ... the actual names of legitimate files to obfuscate their malicious intent. ...
    (microsoft.public.security.virus)
  • [Full-Disclosure] Re: MS-02-052
    ... (I am the original poster of this thread) ... I still have no idea whether the unsigned control of 2 days ago was legitimate or a trojan, and presumably MS isn't going to tell us. ...
    (Full-Disclosure)