Author Topic: Virus alert: Runescapes "Popular" bot: Epicbot  (Read 13952 times)

0 Members and 4 Guests are viewing this topic.

Markeo

  • Guest
Virus alert: Runescapes "Popular" bot: Epicbot
« on: September 10, 2011, 09:38:37 PM »
If you havn't already downloaded this bot, don't, i know what you must be thinking, Runescape is for kids, blah blah, but it does contain a virus, my firewall, (Pctools) blocked Au_.exe, it was located in my local temp folder, if you don't know what Au_.exe is:

The Au_.exe executable file belongs to the rogue anti-spyware program, SpyFalcon.  This malicious program camouflages itself as an anti-spyware utility when in fact it is a Trojan. This malware has the capability to infiltrate your computer through security exploits and install itself along with other Trojans. What the file basically does is hijack the user’s desktop and changes user settings to make it function according to its own requirements.

Au_.exe is also linked to many other spyware, adware and cloaked malware groups. Where some say that the origin of this Trojan is unknown, some are of the opinion that the malicious software to which the file belongs can be downloaded easily from manufacturer’s website. The file is also said to be a part of the Arovax Anti-Spyware software. This may be probable, as the initial description says that this executable pretends to be an anti-spyware application.

How Au_.exe Infects your PC

The following are some of the ways au_.exe is known to affect the PC it infects:

    Deletes essential processes from the disk
    Executing harmful processes stored in temporary folders
    Creates other potentially dangerous processes on your system.
    Uses HTTP protocols to communicate with other computer systems for malicious purposes.
    Adds bad entries to the registry.
    Hijacks system processes to delete links in the Start Menu and can be a source of annoyance for many users.
    Looks at what’s inside the autoexec.bat file and invades your privacy by reading email addresses and phone book details.


IF you have downloaded this bot, and you are seeing decreases in PC performance, files disappearing, or anything else strange, open task manager, go to processes, Select: Show processes from all users, look for Au_.exe, and end it, then go to: C:\Users\User\AppData\Local\Temp, if you see a folder ~nsu.tmp open it, and see if there is a program with the Epicbot icon, if so, go back and delete the ~nsu.tmp and restart your computer.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Virus alert: Runescapes "Popular" bot: Epicbot
« Reply #1 on: September 10, 2011, 11:15:55 PM »
Prevx - AU_.EXE - Spyware
http://www.prevx.com/filenames/2090368270727727277-X1/AU_.EXE.html

do you have a sample ?  
can you upload it to www.virustotal.com and the post the scan link for us to see


from the info found on the net it seems to be very old ?
from the prevx link above it is first seen in 2007..
cleaning guide for SpyFalcon was posted at BleepingComputer 2006
« Last Edit: September 10, 2011, 11:24:02 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: Virus alert: Runescapes "Popular" bot: Epicbot
« Reply #2 on: September 10, 2011, 11:47:26 PM »
AU_EXE was last seen in Saudi Arabia on May 19 2010. Has been part of the Bagle malware, as such could it have been resurrected?

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Markeo

  • Guest
Re: Virus alert: Runescapes "Popular" bot: Epicbot
« Reply #3 on: September 11, 2011, 01:15:26 AM »
Prevx - AU_.EXE - Spyware
http://www.prevx.com/filenames/2090368270727727277-X1/AU_.EXE.html

do you have a sample ?  
can you upload it to www.virustotal.com and the post the scan link for us to see


from the info found on the net it seems to be very old ?
from the prevx link above it is first seen in 2007..
cleaning guide for SpyFalcon was posted at BleepingComputer 2006

A sample of the Au_.exe? no, i deleted it, i won't be redownloading epicbot either, and i C+P'ed from another site,  http://www.exe-error-fixes.com/remove-auexe-system/

Markeo

  • Guest
Re: Virus alert: Runescapes "Popular" bot: Epicbot
« Reply #4 on: September 11, 2011, 01:19:19 AM »
AU_EXE was last seen in Saudi Arabia on May 19 2010. Has been part of the Bagle malware, as such could it have been resurrected?

pol

2010 eh?, gives me another reason to believe epicbot contains this virus,

Epicbot was made back in 2010.

Markeo

  • Guest
Re: Virus alert: Runescapes "Popular" bot: Epicbot
« Reply #5 on: September 11, 2011, 01:20:42 AM »
AU_EXE was last seen in Saudi Arabia on May 19 2010. Has been part of the Bagle malware, as such could it have been resurrected?

pol

I also downloaded it again to see if it would work after i uninstalled it,

Guess what? it wouldn't start.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Virus alert: Runescapes "Popular" bot: Epicbot
« Reply #6 on: September 11, 2011, 03:07:26 AM »
upload suspicious file(s) to  www.virustotal.com  and test with 44 malware scanners
when you have the result, copy the url in the address bar and post it here for us to see


alternative
Jotti     http://virusscan.jotti.org/en
VirSCAN   http://virscan.org/

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: Virus alert: Runescapes "Popular" bot: Epicbot
« Reply #7 on: September 11, 2011, 03:58:22 PM »
Hi Markeo and Pondus,

Markeo, I remember year ago we had long postings here in the forums about Arovax.
About epicbot being malware and the link to mentioned malware:
Consider the info via this link: http://www.online-armor.com/oasis2/file/w3i__llc/installiq_installation_utility/epicbot_exe/3132880
Status not trusted
And this says malware from UAE from 2011 (that is not that far from Saudi Arabia):
considered to be cloaked malware: http://www.prevx.com/filenames/X498318420075365485-X1/EPICBOT.EXE.html
Do we find this malware described here? http://www.mpgh.net/forum/120-runescape-hacks-bots/323086-runescape-epicbot-better-than-rsbot.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: Virus alert: Runescapes "Popular" bot: Epicbot
« Reply #8 on: September 11, 2011, 10:42:50 PM »
Hi Markeo and Pondus,

Markeo, I remember year ago we had long postings here in the forums about Arovax.
About epicbot being malware and the link to mentioned malware:
Consider the info via this link: http://www.online-armor.com/oasis2/file/w3i__llc/installiq_installation_utility/epicbot_exe/3132880
Status not trusted
And this says malware from UAE from 2011 (that is not that far from Saudi Arabia):
considered to be cloaked malware: http://www.prevx.com/filenames/X498318420075365485-X1/EPICBOT.EXE.html
Do we find this malware described here? http://www.mpgh.net/forum/120-runescape-hacks-bots/323086-runescape-epicbot-better-than-rsbot.html

polonus


http://www.virustotal.com/file-scan/report.html?id=078989bdc50e00a4107451edb066313f064bbac5050986d8f29060e13fd695a6-1311623326

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: Virus alert: Runescapes "Popular" bot: Epicbot
« Reply #9 on: September 11, 2011, 11:18:05 PM »
Hi Dim@rik,

Thanks for the very practical scan to confirm detection,

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!