CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

Virtumonde hiding itself from AV scanners

 
Post new topic   Reply to topic       All -> FavForums -> Unknown Files [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
DeadMan3000

Cadet
Cadet


Joined: Jun 14, 2008
Posts: 1
Location: UK

PostPosted: Sat Jun 14, 2008 9:00 pm    Post subject: Virtumonde hiding itself from AV scanners
Reply with quote

Hi. New here. But I just had a brush with Virtumonde. Still trying to figure out if I have removed it all at present. However I think I caught it today from a dodgey warez file (I deserve what I get I guess).

It's on a public torrent site and comments reported it to have passed many AV scans (But you cannot trust people who make comments like that anyhow).

I was wondering about posting the link to the torrent so someone could take a look at it. Or would that be a rule violation?

Back to top
View users profile Send private message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6299
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Sat Jun 14, 2008 9:39 pm    Post subject:
Reply with quote

If you do , do it one of these ways :

http://www.virustotal.com/

http://www.virustotal.com/

hxxp://www.virustotal.com/

Anything like this will make it so it cant be directly clicked .

Back to top
View users profile Send private message Send email
IP: 87.74.*.*

Guest






PostPosted: Sat Jun 14, 2008 11:54 pm    Post subject:
Reply with quote

I'm thinking that vundo was in the setup.exe file which is autoexecuted via the rar self executing file. If you rename the file to rar or zip and open it it shows the setup.exe file and the file that installs the application. You can install the application without setup.exe so that is why I believe that is the culprit. To prevent spreading 'warez' I am going to upload the setup.exe only to rapidshare renamed as vundo.vir and leave it to whomever wishes to look at it to rename it if they need to.

I'd be interested to know if this really is where I caught the trojan or not. Otherwise it is in the warezed application itself which I would prefer not to infringe further by distributing (Suddenly I have an attack of morals).

hxxp://rapidshare.de/files/39721981/vundo.vir.html

Back to top
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5774

MIRT Premium

PostPosted: Sun Jun 15, 2008 12:34 am    Post subject:
Reply with quote

The file you uploaded is malware. I've added it to the malware listserv.

CastleCops Link/p1098585-MD5_ede8de02b67e988a7a7218a210645664.html


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
hjtuser

Cadet
Cadet


Joined: Jun 23, 2008
Posts: 1
Location: USA

PostPosted: Mon Jun 23, 2008 9:50 pm    Post subject: vundo
Reply with quote

It can become disguised in practically any warez. I just got it embedded in ACAD 08.

Pesky little critter, although norton "cough" it, browser still fires up random pages -the notoriously fake security pages- so at least it's half there.

Oh btw, MS updates are fried too, can't get the Service to run but it could be unrelated to Vundo.
Confused

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5774

MIRT Premium

PostPosted: Mon Jun 23, 2008 10:46 pm    Post subject:
Reply with quote

You could try removing the rest of the malware with this http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en

Have you had any luck getting Windows Update to work? If not it's worth spending some time trying to fix it.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Unknown Files All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer