CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

malwarecrush

 
Post new topic   Reply to topic       All -> FavForums -> Unknown Files [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
securitynut

Sergeant
Sergeant


Joined: Jul 11, 2007
Posts: 95
Location: USA

PostPosted: Mon Dec 24, 2007 2:23 am    Post subject: malwarecrush
Reply with quote

Attached is a sample of a new rogue (I believe).

Someone wanna confirm this?
I've sent this file to Avira for them to check but with the holiday it might be a day or two. I'll post back with their results.


hxxp://malwarecrush.com/

File mc-installer.exe received on 12.24.2007 03:02:10 (CET)


Antivirus;Version;Last Update;Result
AhnLab-V3;2007.12.22.10;2007.12.21;-
AntiVir;7.6.0.46;2007.12.23;-
Authentium;4.93.8;2007.12.23;-
Avast;4.7.1098.0;2007.12.23;-
AVG;7.5.0.516;2007.12.23;-
BitDefender;7.2;2007.12.24;-
CAT-QuickHeal;9.00;2007.12.22;-
ClamAV;0.91.2;2007.12.24;-
DrWeb;4.44.0.09170;2007.12.23;-
eSafe;7.0.15.0;2007.12.23;-
eTrust-Vet;31.3.5395;2007.12.21;-
Ewido;4.0;2007.12.23;-
FileAdvisor;1;2007.12.24;-
Fortinet;3.14.0.0;2007.12.23;-
F-Prot;4.4.2.54;2007.12.23;-
F-Secure;6.70.13030.0;2007.12.24;-
Ikarus;T3.1.1.15;2007.12.24;-
Kaspersky;7.0.0.125;2007.12.24;-
McAfee;5191;2007.12.21;-
Microsoft;1.3109;2007.12.24;-
NOD32v2;2744;2007.12.23;Win32/Adware.SpywareQuake
Norman;5.80.02;2007.12.21;-
Panda;9.0.0.4;2007.12.23;-
Prevx1;V2;2007.12.24;-
Rising;20.23.62.00;2007.12.23;-
Sophos;4.24.0;2007.12.23;-
Sunbelt;2.2.907.0;2007.12.21;-
Symantec;10;2007.12.24;-
TheHacker;6.2.9.168;2007.12.22;-
VBA32;3.12.2.5;2007.12.22;-
VirusBuster;4.3.26:9;2007.12.23;-
Webwasher-Gateway;6.6.2;2007.12.24;-

Additional information
File size: 5656371 bytes
MD5: 925a9f07451375d229d431c103a1df18
SHA1: 249f24dbfdcfa017d382348b8e4445c904b00b4f
PEiD: -
packers: Armadillo

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Mon Dec 24, 2007 4:32 pm    Post subject:
Reply with quote

I've sent the file to AntiVir and Kaspersky. If they confirm that this file is malware I'll add it to the malware listserv.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
tetonbob

1st Responder
Premium Member

Joined: Jul 15, 2004
Posts: 24
Location: USA
1st Responders Premium

PostPosted: Wed Dec 26, 2007 8:57 pm    Post subject:
Reply with quote

See some related information here, if you've not already:

http://www.threatexpert.com/report.aspx?uid=cbea8c6c-8030-4f98-99b0-a1ae99621fea

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Thu Dec 27, 2007 4:21 pm    Post subject:
Reply with quote

AntiVir and Kaspersky have confirmed that this is malware.

not-a-virus:FraudTool.Win32.MalwareCrush (Kaspersky)


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Unknown Files All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer