Author Topic: flash worm ?  (Read 8461 times)

0 Members and 1 Guest are viewing this topic.

wchris

  • Guest
flash worm ?
« on: February 22, 2010, 08:30:56 AM »
if you're not an avast professionnal please DO NOT DOWNLOAD THIS FILE.

since 3 days i get spam that trick me into downloading a file here http://www.users.qwest.net/~ lorddaven/Links/FlashPlayer10.0.45.2.exe

i did NOT install it

i guess it's a malware but avast does not detect it, and kaspersky online file scanner fails too.

it can't be a true file, there's no reason to trick me into downloading it if it's not a troyan.

Please Avast detect this, don't wait for competitors

i also think the web page hosting this was hacked and his author is unaware of the problem.

can you check this file ?

thank you

« Last Edit: February 22, 2010, 09:49:42 AM by wchris »

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: flash worm ?
« Reply #1 on: February 22, 2010, 09:13:38 AM »
It looks as though it's an actual Adobe Flash player, the current version.
MBAM scans clean, as does Avast.
VirusTotal results 3/41, with Norman, K7, and Symantec identifying something suspicious.

It could easily be fake, it's not digitally signed.
I've uploaded it to Alwil for more checks.
Windows 10,Windows Firewall,Firefox w/Adblock.

wchris

  • Guest
Re: flash worm ?
« Reply #2 on: February 22, 2010, 09:51:21 AM »
It looks as though it's an actual Adobe Flash player, the current version.
MBAM scans clean, as does Avast.
VirusTotal results 3/41, with Norman, K7, and Symantec identifying something suspicious.

It could easily be fake, it's not digitally signed.
I've uploaded it to Alwil for more checks.

Ok thank you, i modified the link with a space after the ~ to avoid people downloading it

do you think you'll get feedback if they find a threat inside ? i would really like to know what 'gift' was included.

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: flash worm ?
« Reply #3 on: February 22, 2010, 10:00:55 AM »
It's possible I'd get a reply, it has happened before, but I wouldn't expect one.
The most likely thing is that if it is detected as containing malware, it will be added to a definitions file in the future.

The only way to know if this happens is to periodically scan it. I'll do that from time to time with the copy of it I've placed in the chest; I've deleted the original.

I'm not enough of an expert to try running it myself, and have no test computer. It may be alright- quite likely is, but who knows? Maybe someone more expert will have a look.

The downloading of the file itself is harmless enough; what happens if it is run is the unknown.

For yourself, it's always best to get such programs from the home page (Adobe/Macromedia in this case) rather than responding to a third party request to install them.
Windows 10,Windows Firewall,Firefox w/Adblock.

psw

  • Guest
Re: flash worm ?
« Reply #4 on: February 22, 2010, 10:25:47 AM »
do you think you'll get feedback if they find a threat inside ? i would really like to know what 'gift' was included.
I have launched this exe on my VM. Obvious effect - substitutes TaskManager by his own recycle.exe located at C:\RECYCLER\S-1-5-21-...
So definitely this is a fake.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: flash worm ?
« Reply #5 on: February 22, 2010, 02:01:53 PM »
Hi psw,

See: http://www.prevx.com/filenames/X732823755612345244-X1/RECYCLE.EXE.html
Component Name: RECYCLE.EXE

Description of : Silent Watcher allows third parties to take over your computer with full access rights. It uses TVicHW32 5.0 support routines and structures to allow a hacker read/write access to the ports and hard drives and SvCom to employ NT networking services.

Recommendation for :
It is highly recommended that this application be removed. Non-removal of this application will leave you defenseless against attackers who can take control of your computer,

polonus


Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

wchris

  • Guest
Re: flash worm ?
« Reply #6 on: February 22, 2010, 03:41:41 PM »
Hi psw,

See: http://www.prevx.com/filenames/X732823755612345244-X1/RECYCLE.EXE.html
Component Name: RECYCLE.EXE

Description of : Silent Watcher allows third parties to take over your computer with full access rights. It uses TVicHW32 5.0 support routines and structures to allow a hacker read/write access to the ports and hard drives and SvCom to employ NT networking services.

Recommendation for :
It is highly recommended that this application be removed. Non-removal of this application will leave you defenseless against attackers who can take control of your computer,

polonus

Thank you Polonus for the link.

i myself googled for "Silent Watcher" but did not get many hits.

woaw this "Silent watcher" is really an awfull thing, i'm sure getting rid of it once installed is a nightmare

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89145
  • No support PMs thanks
Re: flash worm ?
« Reply #7 on: February 22, 2010, 04:49:21 PM »
I hope you have learned a valuable lesson, don't click links (or open attachments) in unsolicited emails, no matter how legit they might appear.

For software updates always go to the source yourself rather than click a link provided for you.

If you downloaded the legit file to install flash player the file name wouldn't look anything like this with the multiple periods, FlashPlayer10.0.45.2.exe it would be something like this install_flash_player.exe (for firefox). When you hover over the file name it would show the Description, Company, Creation Date and version number; so there is no need for that version number to appear in the file name.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

wchris

  • Guest
Re: flash worm ?
« Reply #8 on: February 22, 2010, 07:23:31 PM »
I hope you have learned a valuable lesson, don't click links (or open attachments) in unsolicited emails, no matter how legit they might appear.

I did NOT open it, i just wanted to know what's inside.

Also i use a web mail client, and there is no need to open attachement or click a link, there's an image in the mail that directly launches the link to download the file without doing anything. The user just watches his mail and is redirected to a page and prompted to download the file with standard message (execute/download/cancel) ... i said cancel ... but posted the link to the file here to know how evil it is.

i got three times the same spam this week so i felt attacked, and wanted to know my ennemy's weapon better.

i think the installer is also evil, not only the final recycle.exe, like polonus shows the installer does plenty of nasty things and should also be stopped by antivirus if possible.

thank you

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: flash worm ?
« Reply #9 on: February 22, 2010, 08:23:09 PM »
Hi wchris,

This infection can be cleared using a program like MBAM. Download here:
http://www.malwarebytes.org/mbam-download.php

You could give a log after running it as an attached txt file,

polonus
« Last Edit: February 22, 2010, 09:33:06 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: flash worm ?
« Reply #10 on: February 22, 2010, 10:39:45 PM »
Norman is saying this detection (FlashPlayer10.0.45.2.exe) is real......no FP
« Last Edit: February 22, 2010, 10:41:34 PM by Pondus »

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: flash worm ?
« Reply #11 on: February 25, 2010, 10:45:38 AM »
I ran a routine MBAM scan today, and this was detected as "(Spyware.OnLineGames)" from within my recycle bin.
Still not detected by Avast.
Yet.
Windows 10,Windows Firewall,Firefox w/Adblock.

bong2x

  • Guest
Re: flash worm ?
« Reply #12 on: February 25, 2010, 11:25:31 AM »
spyware stay in your cookies that why you need anti spy ware avast is a resident police spyware is emigrant that you need emigration in your system(anti-spyware)
here something but i don't like to say to anyone
avast - resident police - enforce all data to maintain normal activities in your system
antimalware - catching rebellion on your system
antispyware - serve as emigration on your system
unlucker(not recommended to stupid) - human inter-phase for deleting some active element ( martial law) ;D
* please don't make this reference i'm just fooling around :) ;) ;D ::)*

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: flash worm ?
« Reply #13 on: February 25, 2010, 11:55:58 AM »
By all means, fool around. ::)
I'd appreciate it if you didn't fool around too much, though, this can be a fairly serious business. Especially in this sub-forum, where people who are infected often come for help.
Serious infections can cost people a lot of money.
By "don't fool around", an example is:
Quote from: bong2x
spyware stay in your cookies

This, frankly, is rubbish. >:(
The other aspects of the analogy you posted are somewhat creative, though not especially apropos, to my mind.
(BTW "unlucker" is spelled unlocker.)
Windows 10,Windows Firewall,Firefox w/Adblock.

bong2x

  • Guest
Re: flash worm ?
« Reply #14 on: February 25, 2010, 12:07:48 PM »
oh sorry! i say that for to investigate :'( i wrote unlucker cause if your not lucky to delete then you can scrap your computer ;D but please sorry again ;)