Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Strange virus/trojan not detected

 
   Security Forums (Home) -> General Discussions RSS
Next:  Virus: Firewall and antivirus, trojan scanners, ...  
Author Message
Zantafio

External


Since: Oct 22, 2003
Posts: 9



(Msg. 1) Posted: Tue Oct 28, 2003 9:23 pm
Post subject: Strange virus/trojan not detected
Archived from groups: alt>comp>anti-virus (more info?)

I didn't get any answer to this message nor it appeared within my message
list.
Probably lost.

I'd appreciate to get additional information.
Sorry for the length!

After the first post I performed Internet scans with TrojanScan and
Symantec.
They didn't ring on the infected files.
____________________________________________________

I finally restored my computer defences. At least I hope so ! The
virus-trojan-worm (?) is probably still present but doesn't appear active
anylonger.


Its actions:
It disabled Zone Alarm, VirusScan when launched, TC-Active and T-C Monitor,
The Cleaner (scaning machine on demand), The Windows System File Compare
(SFC), every attempt done with scan engines.

It didn't stop the functioning of "Ad-Aware 6" (free), dedicated virus
removers as "fixSbigF;exe, "stinger.exe", "The cleaner" launched from the
network server, even under normal sessions of Windows. I didn't try
VirusScan from the server.


Its activity/detection:
It wasn't active under the safe mode (probably because it was loaded by the
run keys).
Neither detected by "The cleaner", nor "stinger", "fixSbigF", "VirusScan"
unless the heuristics scanning was selected. In that case only the
"image023.pif" was recognized to contain "NewBackdoor1".
Later on I applied VirusScan to the other files without positive result,
even in heuristics mode.


Its system installation:
There were three "Com Service = "Wins98\command\" " entries in the registry
Run keys (HKCU, HKLM, and HKUD\Software\Microsoft\Windows\Current
version\Run) pointinh to E:\Win98\command\mshxbh.com.


This NewsGroup gave me the idea to look for strange file names with the same
date as the two known files (image023.pif and mshxbh.com).
I found two other occurrences: Win98\services.exe and
Win98\System\msulwy.com. They've exactly the same date (05.05.99 22:22)
identical to the Windows file's date and the same length (54 048bytes) and
the same contents (with Quick view). These characteristics also apply to
"image023.pif".
The characteristics of the four infected files follow here-below in case
this could bring some information more.
The three files have the attributes "system" & "hidden"


The disabling:
I went again in safe mode, (off then boot) and renamed "mshxbh.com",
"msulwy.com" and "Services.exe". I edited the registry searching for these
filenames as well as for "Com Service" and deleted the run keys launching
"mshxbh.com". I found a new one:
HKLM\Software\Microsoft\Active Setup\Installed
Components\{42AC0312-EE51-A3CC-EA32-40AA12E6115C}
containing "StubPath=E:\Win98\System\msulwy.com". I renamed its name &
value. It will be deleted later on if necessary.
Nothing concerning "Services.exe". This looks rather strange for me because
it's never called by any key or something else.

Should I mention that I also used "HiJackThis" after the cleaning was
manually done ? It didn't reveal anything more.



Rather satisfied I turned the computer Off and rebooted in normal mode. All
the protections were SUCCESSFULLY restored.
I tested ZoneAlarm attachment filters with fake files. The ".pif" is
correctly filtered. I'll give a complete try but I lost the Internet site
address allowing to do that. I'd appreciate to get this address. I still
don't understand why this attachment went through the protection.

I'm conscious the virus is still here. I still don't know what's its name
and what its activity is.
The ways to follow:
To find the free search engines and scan again the computer
To send a copy of the infected files to some antivirus manufacturers'
sites.
To compare the dates and the CRCs of the dll files called by the virus
in order to know if they were garbaged. But where to find the correct CRCs ?
Any other proposals ?

This post was rather long. I hope it is in the policy of this group. I
really thank everybody who answered and those who will bring some help more.

Bye



This is the information of the infected files Quick View provided:

WINDOWS EXECUTABLE
32bit for Windows 95 and Windows NT

Technical File Information:

Image File Header

Signature: 00004550
Machine: Intel 386
Number of Sections: 0003
Time Date Stamp: 2a425e19
Symbols Pointer: 00000000
Number of Symbols: 00000000
Size of Optional Header 00e0
Characteristics: Relocation info stripped from file.
File is executable (i.e. no unresolved external references).
Line numbers stripped from file.
Local symbols stripped from file.
Low bytes of machine word are reversed.
32 bit word machine.
High bytes of machine word are reversed.



Image Optional Header

Magic: 010b
Linker Version: 2.25
Size of Code: 0000c000
Size of Initialized Data: 00001000
Size of Uninitialized Data: 0001b000
Address of Entry Point: 0002794f
Base of Code: 0001c000
Base of Data: 00028000
Image Base: 00400000
Section Alignment: 00001000
File Alignment: 00000200
Operating System Version: 4.00
Image Version: 0.00
Subsystem Version: 4.00
Reserved1: 00000000
Size of Image: 00029000
Size of Headers: 00001000
Checksum: 00000000
Subsystem: Image runs in the Windows GUI subsystem.
DLL Characteristics: 0000
Size of Stack Reserve: 00100000
Size of Stack Commit: 00004000
Size of Heap Reserve: 00100000
Size of Heap Commit: 00001000
Loader Flags: 00000000
Size of Data Directory: 00000010
Import Directory Virtual Address: 0002849c
Import Directory Size: 00000264
Resource Directory
Virtual Address: 00028000
Resource Directory Size: 0000049c
TLS Directory Virtual Address: 00027aa4
TLS Directory Size: 00000018




Import Table

KERNEL32.DLL
Ordinal Function Name

0000 LoadLibraryA
0000 GetProcAddress
0000 ExitProcess


advapi32.dll
Ordinal Function Name

0000 RegEnumKeyA


AVICAP32.DLL
Ordinal Function Name

0000 capCreateCaptureWindowA


gdi32.dll
Ordinal Function Name

0000 BitBlt


oleaut32.dll
Ordinal Function Name

0000 SysFreeString


URLMON.DLL
Ordinal Function Name

0000 URLDownloadToFileA


user32.dll
Ordinal Function Name

0000 GetDC


wininet.dll
Ordinal Function Name

0000 InternetCheckConnectionA


winmm.dll
Ordinal Function Name

0000 mciSendStringA


wsock32.dll
Ordinal Function Name

0000 send


Section Table

Section name: code
Virtual Size: 0001b000
Virtual Address: 00001000
Size of raw data: 00000000
Pointer to Raw Data: 00000200
Pointer to Relocations: 00000000
Pointer to Line Numbers: 00000000
Number of Relocations: 0000
Number of Line Numbers: 0000
Characteristics: Section contains initialized data
Section is readable
Section is writeable



Section name: text
Virtual Size: 0000c000
Virtual Address: 0001c000
Size of raw data: 0000bc00
Pointer to Raw Data: 00000200
Pointer to Relocations: 00000000
Pointer to Line Numbers: 00000000
Number of Relocations: 0000
Number of Line Numbers: 0000
Characteristics: Section contains initialized data
Section is readable
Section is writeable



Section name: .rsrc
Virtual Size: 00001000
Virtual Address: 00028000
Size of raw data: 00000800
Pointer to Raw Data: 0000be00
Pointer to Relocations: 00000000
Pointer to Line Numbers: 00000000
Number of Relocations: 0000
Number of Line Numbers: 0000
Characteristics: Section contains initialized data
Section is readable
Section is writeable


Header Information

Signature: 5a4d
Last Page Size: 0050
Total Pages in File: 0002
Relocation Items: 0000
Paragraphs in Header: 0004
Minimum Extra Paragraphs: 000f
Maximum Extra Paragraphs: ffff
Initial Stack Segment: 0000
Initial Stack Pointer: 00b8
Complemented Checksum: 0000
Initial Instruction Pointer: 0000
Initial Code Segment: 0000
Relocation Table Offset: 0040
Overlay Number: 001a
Reserved: 0000 0000 0000 0000
0000 0000 0000 0000
0000 0000 0000 0000
0000 0000 0000 0000
Offset to New Header: 00000080
Memory Needed: 1K

 >> Stay informed about: Strange virus/trojan not detected 
Back to top
Login to vote
Nick FitzGerald

External


Since: Jul 03, 2003
Posts: 179



(Msg. 2) Posted: Wed Oct 29, 2003 10:59 am
Post subject: Re: Strange virus/trojan not detected [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Zantafio" <zzz DeleteThis @zorglub.net> wrote:

> I'd appreciate to get additional information.
> Sorry for the length!
<<snip>>

Sounds like you have done a great job so far.

Could I suggest that, to get detection of this added to virus scanners as
quickly as possible you should send all the suspect files, and a copy of
your description from your post, to your preferred antivirus developers
from the following list? I recommend that you send the samples to several
(if not all) vendors rather than just those whose product(s) you use.

Command Software <virus DeleteThis @commandcom.com>
Computer Associates (US) <virus DeleteThis @ca.com>
Computer Associates (Vet/EZ) <ipevirus DeleteThis @vet.com.au>
DialogueScience (Dr. Web) <Antivir DeleteThis @dials.ru>
Eset (NOD32) <sample DeleteThis @nod32.com>
F-Secure Corp. <samples DeleteThis @f-secure.com>
Frisk Software (F-PROT) <viruslab DeleteThis @f-prot.com>
Grisoft (AVG) <virus DeleteThis @grisoft.cz>
H+BEDV (AntiVir): <virus DeleteThis @antivir.de>
Kaspersky Labs <newvirus DeleteThis @kaspersky.com>
Network Associates (McAfee) <virus_research DeleteThis @nai.com>
Norman (NVC) <analysis DeleteThis @norman.no>
Sophos Plc. <support DeleteThis @sophos.com>
Symantec (Norton) <avsubmit DeleteThis @symantec.com>
Trend Micro (PC-cillin) <virus_doctor DeleteThis @trendmicro.com>
(Trend may only accept files from users of its products)


--
Nick FitzGerald

 >> Stay informed about: Strange virus/trojan not detected 
Back to top
Login to vote
Zantafio

External


Since: Oct 22, 2003
Posts: 9



(Msg. 3) Posted: Wed Oct 29, 2003 10:59 am
Post subject: Re: Strange virus/trojan not detected [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thanks for your answer. I did sent the information to the companies you
mention.
Concerning the files, I'll send them only upon their request. I'm not so
familiar with this kind of stuff!
Thanks again


"Nick FitzGerald" <nick.TakeThisOut@virus-l.demon.co.uk> a écrit dans le message news:
3f9ee6c5.TakeThisOut@clear.net.nz...
> "Zantafio" <zzz.TakeThisOut@zorglub.net> wrote:
>
> > I'd appreciate to get additional information.
> > Sorry for the length!
> <<snip>>
>
> Sounds like you have done a great job so far.
>
> Could I suggest that, to get detection of this added to virus scanners as
> quickly as possible you should send all the suspect files, and a copy of
> your description from your post, to your preferred antivirus developers
> from the following list? I recommend that you send the samples to several
> (if not all) vendors rather than just those whose product(s) you use.
>
> Command Software <virus.TakeThisOut@commandcom.com>
> Computer Associates (US) <virus.TakeThisOut@ca.com>
> Computer Associates (Vet/EZ) <ipevirus.TakeThisOut@vet.com.au>
> DialogueScience (Dr. Web) <Antivir.TakeThisOut@dials.ru>
> Eset (NOD32) <sample.TakeThisOut@nod32.com>
> F-Secure Corp. <samples.TakeThisOut@f-secure.com>
> Frisk Software (F-PROT) <viruslab.TakeThisOut@f-prot.com>
> Grisoft (AVG) <virus.TakeThisOut@grisoft.cz>
> H+BEDV (AntiVir): <virus.TakeThisOut@antivir.de>
> Kaspersky Labs <newvirus.TakeThisOut@kaspersky.com>
> Network Associates (McAfee) <virus_research.TakeThisOut@nai.com>
> Norman (NVC) <analysis.TakeThisOut@norman.no>
> Sophos Plc. <support.TakeThisOut@sophos.com>
> Symantec (Norton) <avsubmit.TakeThisOut@symantec.com>
> Trend Micro (PC-cillin) <virus_doctor.TakeThisOut@trendmicro.com>
> (Trend may only accept files from users of its products)
>
>
> --
> Nick FitzGerald
>
>
 >> Stay informed about: Strange virus/trojan not detected 
Back to top
Login to vote
Nick FitzGerald

External


Since: Jul 03, 2003
Posts: 179



(Msg. 4) Posted: Wed Oct 29, 2003 4:42 pm
Post subject: Re: Strange virus/trojan not detected [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Zantafio" <zzz.DeleteThis@zorglub.net> wrote:

> Thanks for your answer. I did sent the information to the companies you
> mention.
> Concerning the files, I'll send them only upon their request. I'm not so
> familiar with this kind of stuff!

Realistically, they may not request them.

Sending them is quite OK -- that's how most AV companies get much of the
"new stuff" they add detection for anyway. You will not get in trouble
for sending malware or suspected malware to the addresses I listed --
that is primarily what those addresses are for and the folk who handle
the Email that arrives to those addresses are well trained in doing so
"safely" (in fact, most of those addresses probably have automated
processes screening incoming messages for any attachments and do at least
some of the required processing automatically).

I strongly commend you to send the files to the sample submission
addresses of the AV developers you trust.


--
Nick FitzGerald
 >> Stay informed about: Strange virus/trojan not detected 
Back to top
Login to vote
Zantafio

External


Since: Oct 22, 2003
Posts: 9



(Msg. 5) Posted: Thu Oct 30, 2003 12:00 am
Post subject: Re: Strange virus/trojan not detected [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

I did it today.


"Nick FitzGerald" <nick RemoveThis @virus-l.demon.co.uk> a écrit dans le message news:
3f9f3748 RemoveThis @clear.net.nz...
> "Zantafio" <zzz RemoveThis @zorglub.net> wrote:
>
>
> I strongly commend you to send the files to the sample submission
> addresses of the AV developers you trust.
>
>
> --
> Nick FitzGerald
>
>
 >> Stay informed about: Strange virus/trojan not detected 
Back to top
Login to vote
Buffalo

External


Since: Jul 01, 2004
Posts: 195



(Msg. 6) Posted: Thu Oct 30, 2003 4:39 am
Post subject: Re: Strange virus/trojan not detected [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Great move. Good for you and probably it will be good for me also.
Smile

"Zantafio" <zzz.RemoveThis@zorglub.net> wrote in message
news:bnphcq$ub4$1@news-reader4.wanadoo.fr...
> I did it today.
>
>
> "Nick FitzGerald" <nick.RemoveThis@virus-l.demon.co.uk> a écrit dans le message news:
> 3f9f3748.RemoveThis@clear.net.nz...
> > "Zantafio" <zzz.RemoveThis@zorglub.net> wrote:
> >
> >
> > I strongly commend you to send the files to the sample submission
> > addresses of the AV developers you trust.
> >
> >
> > --
> > Nick FitzGerald
> >
> >
>
>
 >> Stay informed about: Strange virus/trojan not detected 
Back to top
Login to vote
Ka Khiong Kwok

External


Since: Oct 25, 2003
Posts: 26



(Msg. 7) Posted: Thu Oct 30, 2003 7:31 am
Post subject: Re: Strange virus/trojan not detected [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Sorry to tag onto your Nick. With VET, there's an automated feature that
let's you submit files. It turns it around quick smart. I think Symantec's
got one too but haven't bothered with it yet.

Gonna have to start getting back into this stuff.

Regards,

Ka.

"Nick FitzGerald" <nick.RemoveThis@virus-l.demon.co.uk> wrote in message
news:3f9f3748@clear.net.nz...
> "Zantafio" <zzz.RemoveThis@zorglub.net> wrote:
>
> > Thanks for your answer. I did sent the information to the companies you
> > mention.
> > Concerning the files, I'll send them only upon their request. I'm not so
> > familiar with this kind of stuff!
>
> Realistically, they may not request them.
>
> Sending them is quite OK -- that's how most AV companies get much of the
> "new stuff" they add detection for anyway. You will not get in trouble
> for sending malware or suspected malware to the addresses I listed --
> that is primarily what those addresses are for and the folk who handle
> the Email that arrives to those addresses are well trained in doing so
> "safely" (in fact, most of those addresses probably have automated
> processes screening incoming messages for any attachments and do at least
> some of the required processing automatically).
>
> I strongly commend you to send the files to the sample submission
> addresses of the AV developers you trust.
>
>
> --
> Nick FitzGerald
>
>
 >> Stay informed about: Strange virus/trojan not detected 
Back to top
Login to vote
Nick FitzGerald

External


Since: Jul 03, 2003
Posts: 179



(Msg. 8) Posted: Thu Oct 30, 2003 7:09 pm
Post subject: Re: Strange virus/trojan not detected [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Buffalo" <eric(nospam)@nada.com.invalid> replied to "Zantafio":

> > I did it today.
> >
> Great move. Good for you and probably it will be good for me also.
> Smile

Yep -- as I hinted earlier in teh thread, to an "outsider" it may be quite
surprising how much stuff has detection added because of initial "from the
field" sample submissions such as this. The sooner a user who suspects
something gets it to the vendors the better for _all_.


--
Nick FitzGerald
 >> Stay informed about: Strange virus/trojan not detected 
Back to top
Login to vote
Zantafio

External


Since: Oct 22, 2003
Posts: 9



(Msg. 9) Posted: Thu Oct 30, 2003 11:00 pm
Post subject: Re: Strange virus/trojan not detected [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi,
Following the different responses, I got from the sites you directed me,
The backdoor is
"Backdoor.beasty.Fami" or "Backdoor.beastdoor.202" aka "Backdoor-AMQ"
The library informations don't give exactly the same infection profile as I
had. The filenames are different and the mode the virus modified the
registry is slightly different as well.
I have probably a variant of one of above. The antivirus aren't yet updated
and I'm proposed beta signatures.

However my evening readings led me to find another file:
Windows\system\ulwy.blf. I think it's the log the virus wrote in prevision
to send it to the remote site.

Your recommendations have been widely helpful. Thanks again to all who
answered.


Now begins another story: Why didn't ZoneAlarm rename the PIF file ?



"Nick FitzGerald" <nick.TakeThisOut@virus-l.demon.co.uk> a écrit dans le message news:
3fa0ab20.TakeThisOut@clear.net.nz...
> "Buffalo" <eric(nospam)@nada.com.invalid> replied to "Zantafio":
>
> > > I did it today.
> > >
> > Great move. Good for you and probably it will be good for me also.
> > Smile
>
> Yep -- as I hinted earlier in teh thread, to an "outsider" it may be quite
> surprising how much stuff has detection added because of initial "from the
> field" sample submissions such as this. The sooner a user who suspects
> something gets it to the vendors the better for _all_.
>
>
> --
> Nick FitzGerald
>
>
 >> Stay informed about: Strange virus/trojan not detected 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Trojan Virus? - Hi, a friend of mine has booked a ticket for a concert and a few minutes later it was booked again. When he complained to the ticket-company and said that he only ordered one ticket and asked why they charged him two, they said that it was booked twice....

Possible virus/trojan? - found in alt.binaries.images.suntan: Subject: Hillary Duff nude Message-ID: <nR7yc.24058$wH4.1199379@twister.southeast.rr.com> .... Content-Disposition: attachment; filename="Hillary_Duff.scr" Found similar attachment last week...

Trojan Virus..need help - My friend has 2 viruses..Using AVG free with windows 95..She says it affects the start page and windows file pup.exe..avg has found it but she still has probems and is afraid to delete the virus from the vault.when she opens IE avg pops up and says..

trojan virus - I am running Avast on my computer. It has picked up 2 viruses. win32:trojan-gen and win32:abusable system utility. What are these and do I get rid of them? I have instructed Avast to delete them, but it continues to give me warnings of a virus found.....

do I have a virus ,trojan or what? - Hi Guys Im running a p4 with xpsp1 also running Nortons Anti virus2005 and Nortons Firewall 2005 which have just been put on also adware and spybot as well. Now the problem Im having is that nearly every time I turn on the pc I keep getting a (suppose i....
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]