Author Topic: trojan spread via www.onlinehelptool.com  (Read 3369 times)

0 Members and 1 Guest are viewing this topic.

MarkSnoswell

  • Guest
trojan spread via www.onlinehelptool.com
« on: January 12, 2008, 02:33:51 PM »
Hi,
   A few hours ago my sons computer was infected with a trojan that installs tools that point to www.onlinehelptool.com
That URL appears not to exist and the trojan prevents avast from removing it -- it crashes avast.

Starting in safe mode we were able to run avast and tell it to do a boot scan -- which it is now doing.

In the meantime I have failed to find any reports anywhere on a trojen associated with www.onlinehelptool.com   ... and so I went to alexa to see if there were any traffic stats for that URL -- and there are... http://www.alexa.com/data/details/traffic_details/onlinehelptool.com

This URL fist appeared 9 days ago on Jan 4th. It's traffic is increacing exponentially!!!!

I am reporting this here as no one seems to have noticed yet!!!!

cheers

mark.


MarkSnoswell

  • Guest
Re: trojan spread via www.onlinehelptool.com
« Reply #1 on: January 12, 2008, 02:49:43 PM »
THe payload of this web site appears to be:

win32:renos-BI and zlob-AIK  trojans

Infected fiels were:

c:\Program Files\Video Add-on\icmntr.exe\[UPX]      infected with win32:renos-BI
c:\Program Files\Video Add-on\isfmm.exe                infected with zlob-AIK

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67185
Re: trojan spread via www.onlinehelptool.com
« Reply #2 on: January 12, 2008, 07:16:43 PM »
To know if a file is a false positive, please submit it to VirusTotal and let us know the result. If it is indeed a false positive, send it in a password protected zip to virus@avast.com
Please, mention in the body of the message why you think it is a false positive and the password used. Thanks.
Other possibility is JOTTI. VirusTotal and Jotti both have file size limits 10 and 15MB each.

You'll be helping avast improving detection or correcting false positives. Thanks.
The best things in life are free.

MarkSnoswell

  • Guest
Re: trojan spread via www.onlinehelptool.com
« Reply #3 on: January 13, 2008, 12:57:17 AM »
@tech

Thanks.  How about the domain being used to spread the trojans -- any idea where I can report that?  I cant find any reference to the domain or anyehrer to report it. This seems to be an oversite in net security.
It's only Alexa that had any confirmation that the domain is real -- clearly because Alexa toolbar users are being infected at an exponentially increacing rate. As I said the traffic tracked by Alexa indicates that this domain initated the current campain of attack on Jan 4th and that it's still rising exponentially -- where do I report this?

Mark.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67185
Re: trojan spread via www.onlinehelptool.com
« Reply #4 on: January 13, 2008, 05:32:34 PM »
How about the domain being used to spread the trojans -- any idea where I can report that?
Post here an edited link (not live to click).

Edited: Are you talking about www.onlinehelptool.com?
The best things in life are free.