| View previous topic :: View next topic |
| Author |
Message |
CalamityJane
Security Expert Microsoft MVP
 Joined: Oct 05, 2002 Posts: 4004
|
Posted: Sat Oct 23, 2004 4:36 pm Post subject: New Virtumonde Variant wmslog.exe |
|
|
Appears in victim's log here:
http://forum.gladiator-antivirus.com/index.php?showtopic=19382
On HijackThis log as Startup items:
O4 - HKLM\..\Run: [*wmslog] C:\WINDOWS\addins\wmslog.exe
O4 - HKLM\..\RunOnce: [*wmslog] C:\WINDOWS\addins\wmslog.exe rerun
Jotti Scan results:
File: wmslog.exe
Status:
INFECTED/MALWARE
Packers detected: none
AntiVir
Heuristic/Backdoor.Generic (probable variant) (5.79 seconds taken)
Avast
No viruses found (12.42 seconds taken)
BitDefender
Application.Virtumond.B (2.84 seconds taken)
ClamAV
Trojan.Dropper.Virmo-1 (3.39 seconds taken)
Dr.Web
No viruses found (9.19 seconds taken)
F-Prot Antivirus
No viruses found (0.84 seconds taken)
Kaspersky Anti-Virus
No viruses found (7.70 seconds taken)
mks_vir
No viruses found (4.26 seconds taken)
NOD32
No viruses found (12.30 seconds taken)
Norman Virus Control
W32/Agent.BF (5.01 seconds taken)
.......................
I can attach a copy of the file if it is safe to do yet in this forum. Let me know
This is being submitted to various AT/AV/AS software developers today, but I could not find a writeup on it. It looks similar to the javaad variant in the HJT log with the asterisk in front of the run name _________________ Microsoft MVP/Windows Security 2003-2008
|
|
| Back to top |
|
 |
CalamityJane
Security Expert Microsoft MVP
 Joined: Oct 05, 2002 Posts: 4004
|
Posted: Sat Oct 23, 2004 4:56 pm Post subject: |
|
|
Going over that log again, it appears to have 1 or 2 BHOs associated with it as well (don't have those files).
O2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\Jeanne\LOCALS~1\Temp\wyek.dat (file missing)
O2 - BHO: CATLEvents Object - {6A06CDAD-9D2D-42A0-9C91-C0CF7CB9971B} - C:\DOCUME~1\Jack\LOCALS~1\Temp\golsmw.dat
As with the Javaad variant, it was running even in safe mode and had to use the Killbox to get rid of the exe using *delete on reboot* and then the victim was able to get rid of the BHOs _________________ Microsoft MVP/Windows Security 2003-2008
|
|
| Back to top |
|
 |
TonyKlein
Site Moderator Microsoft MVP
 Joined: Oct 15, 2002 Posts: 13120 Location: Netherlands
|
|
| Back to top |
|
 |
CalamityJane
Security Expert Microsoft MVP
 Joined: Oct 05, 2002 Posts: 4004
|
Posted: Sat Oct 23, 2004 9:30 pm Post subject: |
|
|
Ooops LOL, didn't realize that was a random exe. Sorry for the bother  _________________ Microsoft MVP/Windows Security 2003-2008
|
|
| Back to top |
|
 |
TonyKlein
Site Moderator Microsoft MVP
 Joined: Oct 15, 2002 Posts: 13120 Location: Netherlands
|
|
| Back to top |
|
 |
|
|