Author Topic: Potential Malware!! :- MediaPluginInstall from game play labs is a spyware!!!  (Read 32691 times)

0 Members and 1 Guest are viewing this topic.

Offline Zyndstoff (aka Steven Gail)

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2604
  • I can resist anything except temptation.
    • tex62
What do you want Avast to notice?

There's 38 scanners out of 40 that say it's clean.  ???

And one of the others is VIPRE... not known for good results anyway.
« Last Edit: April 14, 2011, 07:01:14 PM by Zyndstoff »
7 x64 SP1, FF 8a Aurora, TB6, 6.0.1203 Free
Free MBAM Clear

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user

Offline Zyndstoff (aka Steven Gail)

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2604
  • I can resist anything except temptation.
    • tex62
@Zyndstoff  see the Vipre detection name

http://www.virustotal.com/file-scan/report.html?id=1d86690a7f0959533649b31898efa07b91d8a141bf468d39557a3ddb6b5a2018-1302798056

Then look on reply #24

I'm aware of that.
Didn't know you can distinguish malware by reading the EULA... most of every software would be malware in one way or the other if you take their respective EULA literally.
7 x64 SP1, FF 8a Aurora, TB6, 6.0.1203 Free
Free MBAM Clear

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Quote
Didn't know you can distinguish malware by reading the EULA
they did more then just read the EULA

Quote
Just looking at the file briefly will not tell you this information but more indepth research will

Offline Zyndstoff (aka Steven Gail)

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2604
  • I can resist anything except temptation.
    • tex62
So, if that is so, then a new scan today, which is significantly later, should bring up 36 or more scanners showing positiv results?
7 x64 SP1, FF 8a Aurora, TB6, 6.0.1203 Free
Free MBAM Clear

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Hi Pondus,

Two flags are more than one as searched the malware hash...
VirusTotal.com     2/40 (5%) detected malware

ThreatExpert.com   New/Nothing Found

Team-CYMRU.org     New/Nothing Found

Now lets use the common google search query "MediaPluginSetup.exe BHO.C" and what do we get...e.g.:
This report for WOT: http://www.mywot.com/en/forum/11086-fake-media-player-spreading-through-facebook

This with another added flag: http://virscan.org/report/36f7a8ba55a616e274915fa4a3e3c4b1.html
CP Secure finding: Troj.Downloader.W32.Aphex.020

So what you think?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
So, if that is so, then a new scan today, which is significantly later, should bring up 36 or more scanners showing positiv results?
Is it the exact same sample ?  same MD5 ?

Offline Zyndstoff (aka Steven Gail)

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2604
  • I can resist anything except temptation.
    • tex62
So, if that is so, then a new scan today, which is significantly later, should bring up 36 or more scanners showing positiv results?
Is it the exact same sample ?  same MD5 ?

Sorry, I don't have that file. I would just like to see more scanners jumping on it.
7 x64 SP1, FF 8a Aurora, TB6, 6.0.1203 Free
Free MBAM Clear

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Quote
Sorry, I don't have that file. I would just like to see more scanners jumping on it.
Working on it   ;)

Offline Zyndstoff (aka Steven Gail)

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2604
  • I can resist anything except temptation.
    • tex62
Quote
Sorry, I don't have that file. I would just like to see more scanners jumping on it.
Working on it   ;)

 ;D waiting
7 x64 SP1, FF 8a Aurora, TB6, 6.0.1203 Free
Free MBAM Clear

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
« Last Edit: April 14, 2011, 10:06:17 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
yep seems to be the same type, but different MD5...
looks as they do the same as with FakeAV....new MD5 on every sample...
so i was hoping @nounzein should respond so i could get his sample to be 100% sure


here is one more, and again new MD5
http://www.virustotal.com/file-scan/report.html?id=1ffb8c2870f5913928817d64ae361f0a26c20085b64b8336709aa48ee8ce5690-1302812934


Malwarebytes detect as - Spyware.GamePlayLabs


« Last Edit: April 14, 2011, 11:42:26 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Hi Pondus,

So the morphing goes on like in "neverending story", good we have you to track them down (and some others as well),
ThreatExpert does not have that one yet. Question is this an older one:
htxp://d.gameplaylabs.com/ce9237be57719933386c8a88b67bf7a5/install.xml?pid=4
poor rep scan: http://www.mywot.com/en/scorecard/d.gameplaylabs.com

Scanned without results here: http://wepawet.iseclab.org/domain.php?hash=a8445223b1364b1b8a9a9bc4f7180d42&type=js

Check the MD5 hashes at virus check, I think not reported yet,

polonus
« Last Edit: April 14, 2011, 11:54:51 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Hi Pondus,

So the morphing goes on like in "neverending story", good we have you to track them down (and some others as well),
ThreatExpert does not have that one yet,

polonus
I will upload the sample to them  ;)

Offline DraKuL

  • Sr. Member
  • ****
  • Posts: 392
I'd like to say that Malwarebytes' definitions are spot on! The way they make users to download and install that plugin, and the fact that you dont actually need it to play videos on facebook is very suspicious.. (As shown in the link polonus posted)

Hope Avast adds it to their definitions as it would help so many users..
ASUS ROG Mobo - AMD Ryzen 7 3700X| RAM 32.00GB | 4TB HDD +1TB SSD | ATI Radeon RX 5700 XT 8GB
Windows 10 Pro 64bit |Avast One Individual | MBAM PRO - RealTime | SUPERAntiSpyware PRO |CC Cleaner | Chrome | Firefox |(The Latest Release of all the Software)