CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

Executable malware on itsa.ir

 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Spockish

Captain
Captain


Joined: May 19, 2006
Posts: 328


PostPosted: Mon Jun 30, 2008 9:50 am    Post subject: Executable malware on itsa.ir
Reply with quote

Code:
http://www.itsa.ir/images/?Intimacao_.php?143b3986360b0da35ce212c17c198358

Back to top
View users profile Send private message
0vermind

Cadet
Cadet


Joined: Oct 15, 2007
Posts: 9
Location: USA

PostPosted: Tue Jul 01, 2008 7:09 pm    Post subject:
Reply with quote

This malware when executed immedietly opens a connection to a remote computer then downloads a fake msnmsgr.exe and winlogon.exe (winlogon.exe is in java). At that point it seems to open a netsh.exe to take control of the computer. Then it downloads and opens GvbSvm.exe, that processes opens 2 processes of GvbSvk.exe.

These two processes (GvbSvm.exe and GvbSvk.exe) from the looks of the decompiled strings.. do something with days and times and the internet aswell as file streams. Not sure exactly what this could accomplish.

-Mike

Edit: The msnmsgr.exe and winlogon.exe are infected replacements of the real files. Meaning the original system versions were deleted and replaced with this infected ones.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer