Author Topic: win32 trojan gen {other} on my jpg files, pls help!!  (Read 5761 times)

0 Members and 1 Guest are viewing this topic.

FRANZCIS

  • Guest
win32 trojan gen {other} on my jpg files, pls help!!
« on: November 10, 2008, 08:44:45 AM »
AVAST found win32 trojan gen {other} on my jpg files, i need the files, help me...

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: win32 trojan gen {other} on my jpg files, pls help!!
« Reply #1 on: November 10, 2008, 09:05:08 AM »
Please upload one of the files to VirusTotal for analysis. Post the results here.

You will need to temporarily disable avast! Be careful and start avast! again after you have uploaded the file.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

FRANZCIS

  • Guest
Re: win32 trojan gen {other} on my jpg files, pls help!!
« Reply #2 on: November 10, 2008, 09:52:22 AM »
here are the result of the analysys.. which antivirus should i use to heal the file. thanx for the time

Antivirus Version Last Update Result
AhnLab-V3 2008.11.7.1 2008.11.10 Win-Trojan/Xema.variant
AntiVir 7.9.0.29 2008.11.10 TR/Dropper.Gen
Authentium 5.1.0.4 2008.11.09 W32/VB-Wird-based!Maximus
Avast 4.8.1248.0 2008.11.10 Win32:Trojan-gen {Other}
AVG 8.0.0.161 2008.11.09 Exploit.BOO
BitDefender 7.2 2008.11.10 Trojan.Agent.AILQ
CAT-QuickHeal 9.50 2008.11.10 Exploit.MS04-028.g (Not a Virus)
ClamAV 0.94.1 2008.11.10 -
DrWeb 4.44.0.09170 2008.11.10 -
eSafe 7.0.17.0 2008.11.09 Suspicious File
eTrust-Vet 31.6.6200 2008.11.09 -
Ewido 4.0 2008.11.09 Not-A-Virus.Exploit.Win32.MS04028.g
F-Prot 4.4.4.56 2008.11.09 W32/VB-Wird-based!Maximus
F-Secure 8.0.14332.0 2008.11.10 Exploit.Win32.MS04-028.g
Fortinet 3.117.0.0 2008.11.09 -
GData 19 2008.11.10 Trojan.Agent.AILQ
Ikarus T3.1.1.45.0 2008.11.10 Trojan-Downloader.Win32.Banload
K7AntiVirus 7.10.520 2008.11.08 Exploit.Win32.MS04-028.g
Kaspersky 7.0.0.125 2008.11.10 Exploit.Win32.MS04-028.g
McAfee 5429 2008.11.10 -
Microsoft 1.4104 2008.11.10 Trojan:Win32/Greener.A
NOD32 3598 2008.11.10 -
Norman 5.80.02 2008.11.07 W32/Smalltroj.EHZK
Panda 9.0.0.4 2008.11.09 Suspicious file
PCTools 4.4.2.0 2008.11.09 Worm.Kilada.A
Prevx1 V2 2008.11.10 -
Rising 21.03.01.00 2008.11.10 -
SecureWeb-Gateway 6.7.6 2008.11.10 Trojan.Dropper.Gen
Sophos 4.35.0 2008.11.10 Mal/VB-G
Sunbelt 3.1.1785.2 2008.11.08 -
Symantec 10 2008.11.10 Trojan Horse
TheHacker 6.3.1.1.147 2008.11.10 Trojan/Exploit.MS04-028.g
TrendMicro 8.700.0.1004 2008.11.10 Mal_Banker
VBA32 None 2008.11.10 -
ViRobot 2008.11.10.1458 2008.11.10 -
VirusBuster 4.5.11.0 2008.11.09 Worm.Kilada.A
Additional information
File size: 322686 bytes
MD5...: f360315f062fa792f89ee2dc93864c85
SHA1..: 831f2d8421e13f4b0de80c4f5c236855d77b04f1
SHA256: 82bec3a9153e24eaab156a0bdea6697e9059e6a39396216410904938385b3e58
SHA512: d80ab43d52cba47a39d2064f988bf1935978964edb78976d26cc38b3616e4d5c
5d7bd9b697dca9fa77ee8ab3a0cf0b3442ed4673c9afa35480d39f6996e2cb29
PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
TrID..: File type identification
UPX compressed Win32 Executable (43.8%)
Win32 EXE Yoda's Crypter (38.1%)
Win32 Executable Generic (12.2%)
Generic Win/DOS Executable (2.8%)
DOS Executable Generic (2.8%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x41eb50
timedatestamp.....: 0x48219792 (Wed May 07 11:50:42 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x17000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x18000 0x7000 0x6e00 7.86 c4555d6633f070e45d17b00347fba11e
.rsrc 0x1f000 0x6000 0x6000 5.77 126bd1bb5e884690a2c0844dd80c5339

( 2 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> MSVBVM60.DLL: -

( 0 exports )
 
packers (F-Prot): UPX
packers (Kaspersky): PE_Patch.UPX, UPX
packers (Authentium): UPX

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: win32 trojan gen {other} on my jpg files, pls help!!
« Reply #3 on: November 10, 2008, 10:18:41 AM »
When were the photos taken? With what camera?
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

FRANZCIS

  • Guest
Re: win32 trojan gen {other} on my jpg files, pls help!!
« Reply #4 on: November 10, 2008, 10:31:54 AM »
cannon and sony camera, it think it was taken by august or september 2008.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: win32 trojan gen {other} on my jpg files, pls help!!
« Reply #5 on: November 10, 2008, 10:48:17 AM »
Although a lot of AV's detected the file, as I understand it the detection of this exploit is prone to false positives due to specific makes of cameras or to file corruption.

I would suggest submitting a few of the files to avast! for analysis via the procedure described here:

http://forum.avast.com/index.php?board=2;action=display;threadid=7779

Put a link to this thread in the email.

You could also do the same for a few other AV companies:

http://analysis.avira.com/samples/index.php

newvirus[at]kaspersky.com/virus_submission[at]bitdefender.com (subject "possible false positive")

     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: win32 trojan gen {other} on my jpg files, pls help!!
« Reply #6 on: November 10, 2008, 10:49:24 AM »
Of course, if they all say it's a genuine detection, you'll need to look for a file infector on your computer.  ;)
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34062
  • malware fighter
Re: win32 trojan gen {other} on my jpg files, pls help!!
« Reply #7 on: November 10, 2008, 07:06:08 PM »
Hi FwF,

Sounds like a vundo file infector. If it is a problem of a virus using shares, here is another elegant solution, I give it from the author, as I did not experience it:

The virus scanners we all use do a pretty good job. The problem is that this virus looks for shared folders. If you keep getting infected, I ask you, are your drives shared? Thats how it kept getting me. My first problem was that I used "share" as the name for a shared folder, a likely guess for an attacker. Anyways here's what you have to do to make your shared folders off-limits to this virus.

First of all, if you're using simple file sharing, you're asking for trouble. Turn it off as follows:
1. Double click "My Computer"
2. Tools -> Folder Options
3. Click the view tab
4. Scroll to the very bottom
5. Make sure that "use simple file sharing (recommended)" is UNCHECKED

You now can configure what people can do to your shared folder. Go to the directory that keeps having infected files pop up. If its icon has the hand under it, right click on it and select properties. If is not shared, check its parent directory.


click sharing
Click permissions
click on "everyone"
make sure "Change" is not checked

Click ok
Click the security tab
Click "Everyone"
Uncheck everything but "Read" and "List Folder Contents"

If you had to uncheck any boxes particularly "write", you probably just fixed your problem.

This will make it much harder to map to your shared folder, since the virus would have to know a username and password of someone that can log into your computer in order to connect. As soon as I realized I was giving write privileges to everyone I was kicking myself. I had been wondering why this thing kept popping up, since I never had time to run the EXE. Scanners always got it the second it overwrote a file. Well it only overwrote files in my shared folder (of course I didn't share c:), and that is because the virus was never on my machine at all (not for more than a few seconds anyway). It was on somebody's computer who was too cheap to buy a virus scanner and it was getting to me through my shared folder. That is why every virus scanner said my drive was clean. But problem solved. I haven't seen a virus alert since i changed the permissions to read only. I bet it'll work for you too

If you want another computer to have full access to the shared folder, you need to map the share using an existing username and password, or you need to create a windows user on the computer with the shared drive (The new user need not be an administrator). Use the procedure just given but check the "full controll" boxes for this user. Then when you map the share use "connect using a different username and password" to specify the windows user you just added,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

FRANZCIS

  • Guest
Re: win32 trojan gen {other} on my jpg files, pls help!!
« Reply #8 on: November 12, 2008, 09:42:39 AM »
thank you polonus, but the virus is still there. i still cant open any of my jpg files.. i even try some AV hoping to cure it but they failed.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: win32 trojan gen {other} on my jpg files, pls help!!
« Reply #9 on: November 12, 2008, 10:06:09 AM »
Although a lot of AV's detected the file, as I understand it the detection of this exploit is prone to false positives due to specific makes of cameras or to file corruption.

I would suggest submitting a few of the files to avast! for analysis via the procedure described here:

http://forum.avast.com/index.php?board=2;action=display;threadid=7779

Put a link to this thread in the email.

You could also do the same for a few other AV companies:

http://analysis.avira.com/samples/index.php

newvirus[at]kaspersky.com/virus_submission[at]bitdefender.com (subject "possible false positive")



Have you followed this advice?
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog