CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

MD5: 191f986fc7b646e7a95afa8711983035 isamonitor.exe ZLOB

 
Post new topic   Reply to topic       All -> FavForums -> Malware Listserv [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Sun Nov 19, 2006 5:49 pm    Post subject: MD5: 191f986fc7b646e7a95afa8711983035 isamonitor.exe ZLOB
Reply with quote

STATUS: FINISHEDComplete scanning result of "isamonitor.exe", received in VirusTotal at 11.19.2006, 18:18:17 (CET).

Antivirus Version Update Result
AntiVir 7.2.0.39 11.19.2006 no virus found
Authentium 4.93.8 11.17.2006 no virus found
Avast 4.7.892.0 11.18.2006 Win32:Zlob-QT
AVG 386 11.18.2006 no virus found
BitDefender 7.2 11.19.2006 no virus found
CAT-QuickHeal 8.00 11.18.2006 no virus found
ClamAV devel-20060426 11.18.2006 no virus found
DrWeb 4.33 11.19.2006 STPAGE.Trojan
eSafe 7.0.14.0 11.19.2006 no virus found
eTrust-InoculateIT 23.73.59 11.18.2006 no virus found
eTrust-Vet 30.3.3197 11.17.2006 no virus found
Ewido 4.0 11.19.2006 no virus found
Fortinet 2.82.0.0 11.19.2006 no virus found
F-Prot 3.16f 11.17.2006 no virus found
F-Prot4 4.2.1.29 11.17.2006 no virus found
Ikarus 0.2.65.0 11.17.2006 no virus found
Kaspersky 4.0.2.24 11.19.2006 no virus found
McAfee 4899 11.18.2006 no virus found
Microsoft 1.1609 11.19.2006 Getter
NOD32v2 1871 11.19.2006 no virus found
Norman 5.80.02 11.17.2006 W32/Malware
Panda 9.0.0.4 11.19.2006 Suspicious file
Prevx1 V2 11.19.2006 Trojan.eCodec
Sophos 4.11.0 11.16.2006 Troj/Zlobmi-Gen
TheHacker 6.0.3.122 11.18.2006 Trojan/Puper
UNA 1.83 11.17.2006 no virus found
VBA32 3.11.1 11.19.2006 MalwareScope.Downloader.Zlob.1
VirusBuster 4.3.15:9 11.18.2006 no virus found


Aditional Information
File size: 27648 bytes
MD5: 191f986fc7b646e7a95afa8711983035
SHA1: d9422f8b899792eeef5a9b9a7adb7ac4747b9016
norman sandbox: [ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Accesses executable file from resource section.
* File length: 27648 bytes.

[ Changes to filesystem ]
* Creates file C:isaddon.dll.

[ Changes to registry ]
* Creates key "HKLMSoftwareCLASSESCLSID{192c5b4a-3efd-40c7-9f99-c472deb8efc0}".
* Sets value ""="" in key "HKLMSoftwareCLASSESCLSID{192c5b4a-3efd-40c7-9f99-c472deb8efc0}".
* Creates key "HKLMSoftwareCLASSESCLSID{192c5b4a-3efd-40c7-9f99-c472deb8efc0}InprocServer32".
* Sets value ""="c:isaddon.dll" in key "HKLMSoftwareCLASSESCLSID{192c5b4a-3efd-40c7-9f99-c472deb8efc0}InprocServer32".
* Sets value "ThreadingModel"="Apartment" in key "HKLMSoftwareCLASSESCLSID{192c5b4a-3efd-40c7-9f99-c472deb8efc0}InprocServer32".
* Creates key "HKLMSoftwareCurrentVersionExplorerBrowser Helper Objects{192c5b4a-3efd-40c7-9f99-c472deb8efc0}".
* Sets value ""="" in key "HKLMSoftwareCurrentVersionExplorerBrowser Helper Objects{192c5b4a-3efd-40c7-9f99-c472deb8efc0}".
* Creates key "HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{192c5b4a-3efd-40c7-9f99-c472deb8efc0}".
* Sets value ""="" in key "HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{192c5b4a-3efd-40c7-9f99-c472deb8efc0}".

[ Process/window information ]
* Creates an event called __ISA_INSURANCE__.

Back to top
View users profile Send private message Send email
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Malware Listserv All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer