Author Topic: Undetected virus  (Read 4307 times)

0 Members and 1 Guest are viewing this topic.

pranaysharma94

  • Guest
Undetected virus
« on: May 02, 2009, 04:12:57 PM »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89218
  • No support PMs thanks
Re: Undetected virus
« Reply #1 on: May 02, 2009, 04:54:31 PM »
Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help, plus the VT results link and undetected malware in the subject.
 
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.
 
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Omid Farhang

  • Frontend Developer
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1660
  • I wish I could write longer personal text!!
    • Homepage
Re: Undetected virus
« Reply #2 on: May 02, 2009, 04:57:54 PM »
Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help, plus the VT results link and undetected malware in the subject.
 
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.
 
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.
Thanks for the info ;D ;D ;D ;D ;D
Twitter: OmidFarhangEn - OS: Manjaro KDE

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89218
  • No support PMs thanks
Re: Undetected virus
« Reply #3 on: May 02, 2009, 05:09:31 PM »
You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

pranaysharma94

  • Guest
Re: Undetected virus
« Reply #4 on: May 02, 2009, 07:47:22 PM »
Actually its a keygen..... you know that xp and other av programs are not fond of keygens.... so it might not actually be a virus ::) ::) ::)

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Undetected virus
« Reply #5 on: May 02, 2009, 07:58:41 PM »
Hi Pranay,

We treated this malcode here: http://forum.avast.com/index.php?topic=37513.0
Was yours also related to BBOX Trial Client DLL : http://www.processlibrary.com/directory/files/vboxs430/  obviously this threat was covered by a Packer which were usually used by hacker

System Changes

These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files

The following registry elements have been created:

# HKEY_CURRENT_USER\_reg\

    * shell = "c:\windows\system32\rundll32.exe" "c:\windows\system32
      \shell32.dll",control_rundll "c:\docume~1\admini~1\locals~1\temp
      \dat15.tmp"

# HKEY_LOCAL_MACHINE\software\classes\clsid\{e25c29ab-12b9-4523-a53c-324b5fba648c}\inprocserver32\

    * (default) = c:\docume~1\admini~1\locals~1\temp\dat15.tmp
    * threadingmodel = apartment

The following registry elements have been changed:

# HKEY_CURRENT_USER\sessioninformation\

    * programcount = 2

# HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\desktop\

    * mrulist = [binary data]
    * rxmru = [binary data]

# HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\desktop\

    * mrulist = [binary data]
    * rxmru = [binary data]
    * sysfile = c:\documents and settings\administrator\local settings\temp
      \2.exe

The following registry elements have been deleted:

# HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\desktop\

    * sysfile = c:\documents and settings\administrator\local settings\temp
      \2.exe

Symptoms
Symptoms -

This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.

Considerations there may be variants,

     polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

pranaysharma94

  • Guest
Re: Undetected virus
« Reply #6 on: May 02, 2009, 08:20:49 PM »
Hi Pranay,

We treated this malcode here: http://forum.avast.com/index.php?topic=37513.0
Was yours also related to BBOX Trial Client DLL : http://www.processlibrary.com/directory/files/vboxs430/  obviously this threat was covered by a Packer which were usually used by hacker

System Changes

These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files

The following registry elements have been created:

# HKEY_CURRENT_USER\_reg\

    * shell = "c:\windows\system32\rundll32.exe" "c:\windows\system32
      \shell32.dll",control_rundll "c:\docume~1\admini~1\locals~1\temp
      \dat15.tmp"

# HKEY_LOCAL_MACHINE\software\classes\clsid\{e25c29ab-12b9-4523-a53c-324b5fba648c}\inprocserver32\

    * (default) = c:\docume~1\admini~1\locals~1\temp\dat15.tmp
    * threadingmodel = apartment

The following registry elements have been changed:

# HKEY_CURRENT_USER\sessioninformation\

    * programcount = 2

# HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\desktop\

    * mrulist = [binary data]
    * rxmru = [binary data]

# HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\desktop\

    * mrulist = [binary data]
    * rxmru = [binary data]
    * sysfile = c:\documents and settings\administrator\local settings\temp
      \2.exe

The following registry elements have been deleted:

# HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\desktop\

    * sysfile = c:\documents and settings\administrator\local settings\temp
      \2.exe

Symptoms
Symptoms -

This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.

Considerations there may be variants,

     polonus




hmmmm actually i scanned my registry myself(manually) and found out that none of the changes above have taken place......

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Undetected virus
« Reply #7 on: May 02, 2009, 08:30:18 PM »
Hi Pranay,

I do not doubt your words, as this info was the official info on the malware for which you gave the names, as it was a generic name it might have been similarity in the packer used that made the flag come down for this one. There are more dogs to answer the same name when called. I just wanted to present the information as it was previously discussed in this here forum.
Thanks for reporting and the attention for it that was renewed.
The general motto here is: "Stay vigilant and trust nothing and no-one on the Internet, and stay away from things that look to good to be true, in more than one case they are not golden rimmed but come with some darker clouds attached, something we cal malcode!"

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

pranaysharma94

  • Guest
Re: Undetected virus
« Reply #8 on: May 02, 2009, 08:37:56 PM »
So.... is this a virus?????
« Last Edit: May 03, 2009, 06:40:55 PM by Pranay »