Author Topic: Avast does not detect TR/Dldr.Agent.uur.2  (Read 3091 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: Avast does not detect TR/Dldr.Agent.uur.2
« Reply #1 on: August 14, 2012, 04:36:13 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Avast does not detect TR/Dldr.Agent.uur.2
« Reply #2 on: August 14, 2012, 10:10:30 PM »
Not detected by SuperAntiSpyware   :-\

Malwarebytes detect as Worm.Agent   :)

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: Avast does not detect TR/Dldr.Agent.uur.2
« Reply #3 on: August 14, 2012, 11:32:09 PM »
Hi Pondus,

Thanks for checking this one out, but there is also more interesting info on the packers used.
VT lists:
TrID
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
PEiD packer identifier
UPX 2.93 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
DrWeb finds:

Checking: htxp://gjgt.sk/%7Efuller/dotakeys1.3/autoupdate.exe?fakeParam=3D3D%26%26amp%2F%26%2F%2F/
Engine version: 7.0.3.7130
Total virus-finding records: 3086527
File size: 209.84 KB
File MD5: e22b03decb36b26ee2c7b83becf02ec3

htxp://gjgt.sk/%7Efuller/dotakeys1.3/autoupdate.exe?fakeParam=3D3D%26%26amp%2F%26%2F%2F/ packed by UPX
>htxp://gjgt.sk/%7Efuller/dotakeys1.3/autoupdate.exe?fakeParam=3D3D%26%26amp%2F%26%2F%2F/ - archive AUTOIT
>>htxp://gjgt.sk/%7Efuller/dotakeys1.3/autoupdate.exe?fakeParam=3D3D%26%26amp%2F%26%2F%2F//_ahk\warpath\dotakeys1.3\pokusy\upd\update_checking.gif - Ok
>>htxp://gjgt.sk/%7Efuller/dotakeys1.3/autoupdate.exe?fakeParam=3D3D%26%26amp%2F%26%2F%2F//_ahk\warpath\dotakeys1.3\pokusy\upd\update_downloading.gif - Ok (Nebezpečné pokusy)
>>htxp://gjgt.sk/%7Efuller/dotakeys1.3/autoupdate.exe?fakeParam=3D3D%26%26amp%2F%26%2F%2F//_ahk\warpath\dotakeys1.3\pokusy\upd\update_available.gif - Ok (Nebezpečné pokusy)
>>htxp://gjgt.sk/%7Efuller/dotakeys1.3/autoupdate.exe?fakeParam=3D3D%26%26amp%2F%26%2F%2F//_ahk\warpath\dotakeys1.3\pokusy\upd\update_notfound.gif - Ok (Nebezpečné pokusy)
>>htxp://gjgt.sk/%7Efuller/dotakeys1.3/autoupdate.exe?fakeParam=3D3D%26%26amp%2F%26%2F%2F//_ahk\warpath\dotakeys1.3\pokusy\upd\line.gif - Ok
>>htxp://gjgt.sk/%7Efuller/dotakeys1.3/autoupdate.exe?fakeParam=3D3D%26%26amp%2F%26%2F%2F//DOCUME~1\Fucko\LOCALS~1\Temp\ahk1E7.tmp - Ok (hidden files an folders!)
>htxp://gjgt.sk/%7Efuller/dotakeys1.3/autoupdate.exe?fakeParam=3D3D%26%26amp%2F%26%2F%2F/ - Ok

compare the encoding heuristics to those given here: http://www.malwareblacklist.com/searchClearingHouse.php?search=soft.youxi123.com/download/comsc/setup_7.exe?

DotaKeys, the program that allows you to remap keys in Warcraft 3 map DotA:Allstars # see: http://www.mywot.com/en/scorecard/gjgt.sk?utm_source=addon&utm_content=popup-donuts    url also flagged by Bitdefender's TrafficLight as unsafe...

Above you see the update files haven't been found - fakeParam ddbeug parameter etc...

polonus


« Last Edit: August 14, 2012, 11:35:31 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Avast does not detect TR/Dldr.Agent.uur.2
« Reply #4 on: August 15, 2012, 12:39:48 AM »
Quote
htxp://gjgt.sk/%7Efuller/dotakeys1.3/autoupdate.exe?fakeParam=3D3D%26%26amp%2F%26%2F%2F//DOCUME~1\Fucko\LOCALS~1\Temp\ahk1E7.tmp

not detected
https://www.virustotal.com/file/09402c2230605db072d3fad621afbb1cdcbb6c798ef61e8808a53a9a7b5766dc/analysis/1344983914/


sendt avast lab   ;)


« Last Edit: August 15, 2012, 12:46:22 AM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: Avast does not detect TR/Dldr.Agent.uur.2
« Reply #5 on: August 15, 2012, 01:31:58 AM »
Hi Pondus,

Thank you very much for checking and reporting. Very attentive of you  (hidden files and folders gave away the clue apparently), but the additional scanning produced this detection...Well let us hope avast adds this to detection soon,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!