Thumbs up for the latest in automated analysis

January 2, 2008

ThreatExpert looking good today !

In comes a new virus undetected by everything on VirusTotal. Just had a quick look and immediately thought it looks like a VIRUT .. this is the only detection

Note the automated analysis thinks certain system files are deleted, this is another sign that they were infected by the virus or hidden by the rootkit, or both.

Please note: While TrojanHunter doesn’t deal with viruses in most cases, detection for the sample will be added very shortly since it was scanning 100% clean and analysis will take some time. The computer systems analysing the malware took over 3 minutes, an eternity when talking trillions of operations a second.


More Zhelatin/Storm worm spam

December 24, 2007

An interesting new spam, slight twist on the usual social engineering:

Mrs. Clause Is Out Tonight!

Dude,

I know you hate these kind of emails but this one is different. Hey what
can 1 min from your day hurt. You wont regret it for sure. ;-)
<malicious URL removed>

Obviously, users should avoid such emails and immediately delete them. If you can’t spot this sort of email as being a spammed virus, give us an email with any questions!


Sneak Preview: Trojan Information Library

October 15, 2007

We’ve started working on our new Trojan Information Library, and there are already a few sample entries online. Read about how to remove some of the most common trojans manually, and get additional technical insight into how the trojans work. We’re also adding aliases so you can cross-reference the trojan names with those from other virus and malware scanners.


Another wave of Zhelatin spam

October 12, 2007

Another new variant of Worm.Zhelatin is currently being spammed by infected hosts. The new variants use the filenames SuperLaugh.exe and ArcadeWorldGame.exe. The latest trick the controller of this worm has up his sleeve is making the landing page simulate a “free games download” site to get users to install the trojan. We’ve added generic detection for these latest variants to our trojan remover. As always, never run program files attached to emails, or linked to in sites from unknown emails.


TrojanHunter 5.0 Released!

September 10, 2007

I am proud to announce the release of TrojanHunter 5.0. We’ve worked hard to make this the best TrojanHunter version ever. The scan engine has been substantially enhanced to handle new threats, and LiveUpdate can now upgrade the TrojanHunter program files. In addition, the user interface has been enhanced and there’s now a scheduling option for the scanner and LiveUpdate available within the scanner.

The release also includes the TrojanHunter Command Line Scanner (thcl.exe), that can be used to scan for trojans from the command line, or from batch files. For a full list of new features and changes, see below.

Download:

http://www.misec.net/products/TrojanHunterSetup.exe

Screenshots:

TrojanHunter 5
TrojanHunter 5

How do I upgrade?

1. Uninstall your current version of TrojanHunter via Control Panel - Add or Remove Programs

2. Download the setup file from the link above

3. Run the setup file, and complete the installation

4. If you are a licensed user, copy the License.tlf file from your old TrojanHunter folder to the TrojanHunter 5.0 folder. Alternatively, use your authorization code to install the license.

_________________________________
TrojanHunter 5.0.950 (2007-09-09)

New features:

* Redesigned, polished user interface

* Schedule page allows scheduling of LiveUpdate and TrojanHunter scans

* LiveUpdate is able to perform program upgrades

* Optional automatic cleaning of trojans found during scheduled scans

* During a scheduled scan, TrojanHunter Scanner runs invisibly so as to not get in the user’s way. If trojans are found, however, a message box alert is displayed, and optional automatic cleaning initiated. This happens even if no user is logged in to the computer when the scan is run.

* New file analyzer in engine ensures all files are scanned correctly according to content, no matter what extension they have

* TrojanHunter now scans inside RARSFX archives

* Scanning inside resources embedded in Windows PE executables


Zango Loses Law Suit

September 1, 2007

A Washington District Court ruling has adware maker Zango’s suit against Kaspersky Lab Inc thrown out, ruling that has Kaspersky has immunity from liability under the Communications Decency Act:

“No provider or user of an interactive computer service shall be held liable on account of … any action taken to enable or make available … the technical means to restrict access to the material described [i.e. material that the provider or user considers to be obscene, lewd, lascivious, ... or otherwise objectionable].”

I agree with Alex Eckelberry at Sunbelt’s Blog when he says “This is very big news folks. Big news. This decision may have far-reaching consequences for security companies in the inclusion of malicious and/or potentially unwanted software in their software.”


TrojanHunter 5.0 Beta 1 Released!

August 29, 2007

The first beta version of TrojanHunter 5 is now ready for testing! Featuring an improved user interface and some exciting scan engine changes under the hood, this version of TrojanHunter is the best ever.

Download:

http://www.misec.net/beta/TrojanHunterSetup.exe

TrojanHunter 5

TrojanHunter 5

Please report any and all bugs here or by email (support@misec.net). Note that using the beta will start your trial period. However, we will provide an additional 30-day trial period upon request to any beta tester who wishes to test out the final version.

What’s new in TrojanHunter 5.0?

  • Redesigned, polished user interface
  • Schedule page allows scheduling of LiveUpdate and TrojanHunter scans
  • Optional automatic cleaning of trojans found during scheduled scans
  • During a scheduled scan, TrojanHunter Scanner runs invisibly so as to not get in the user’s way. If trojans are found, however, a message box alert is displayed, and optional automatic cleaning initiated. This happens even if no user is logged in to the computer when the scan is run.
  • New file analyzer in engine ensures all files are scanned correctly according to content, no matter what extension they have
  • TrojanHunter now scans inside RARSFX archives
  • Scanning inside resources embedded in Windows PE executables, as well as numerous other scan engine improvements.

Why compound scanning is important..

August 29, 2007

Doing some housecleaning, and going through a whole bunch of malware files with the new scanner (as you do..)

This one brings a smile.. TrojanHunter now includes SFX detection among other things in the 5.0 beta, here’s an “installer”…

Found trojan file: C:\TESTING\2005107\2005107.exe/3721.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/ad1.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/ad2.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/ad3.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/ad4.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/ad5.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/ad6.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/ad7.exe (TrojanClicker.VB.166)
Found adware file: C:\TESTING\2005107\2005107.exe/bind_8432.exe (Adware.AdHelper.107)
Found adware file: C:\TESTING\2005107\2005107.exe/dmshell.dll/Upxlpbqnauj (Adware.Dm.100)
Found trojan file: C:\TESTING\2005107\2005107.exe/s45337.exe (Agent.629)
Found adware file: C:\TESTING\2005107\2005107.exe/setup_110013.exe (Adware.WSearch.121)
Found trojan file: C:\TESTING\2005107\2005107.exe/system.exe (TrojanClicker.VB.167)
Found trojan file: C:\TESTING\2005107\2005107.exe/system2.exe (TrojanClicker.VB.167)
Found trojan file: C:\TESTING\2005107\2005107.exe/system3.exe (TrojanClicker.VB.167)
Found adware file: C:\TESTING\2005107\2005107.exe/WIS174.exe (Adware.AllSum.105)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/3721.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/ad1.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/ad2.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/ad3.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/ad4.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/ad5.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/ad6.exe (TrojanClicker.VB.166)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/ad7.exe (TrojanClicker.VB.166)
Found adware file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/bind_8432.exe (Adware.AdHelper.107)
Found adware file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/dmshell.dll/Upxtgyxoryw (Adware.Dm.100)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/s45337.exe (Agent.629)
Found adware file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/setup_110013.exe (Adware.WSearch.121)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/system.exe (TrojanClicker.VB.167)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/system2.exe (TrojanClicker.VB.167)
Found trojan file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/system3.exe (TrojanClicker.VB.167)
Found adware file: C:\TESTING\2005107\2005107.exe/Upxeeorvkdi/WIS174.exe (Adware.AllSum.105)

We detect supsicious droppers too, simply because a normal SFX should be well, normal. Lets just say I wouldn’t want to execute the above on MY system…


How a Mobile Phone Network in Greece was Compromised

August 25, 2007

In a fascinating online article, IEEE spectrum reports of the extremely sophisticated rootkitting of several Vodafone Greece mobile phone switches.

Reading like a regular high-tech crime novel, it includes a mysterious suicide, and possible NSA involvement. Only it happened for real in the run-up to the Athens 2004 olympics. Highly recommended reading.


Latest Zhelatin Emails

August 21, 2007

A new wave of Zhelatin emails is currently going out. A typical example is this email:

Greetings,

Are you ready to have fun at Web Joker.

Account Number: 775152935455
Temp Login ID: user1160
Your Password ID: px259

Please keep your account secure by logging in and changing your login info.

Use this link to change your Login info: http://74.64.28.xx/

Enjoy,
Confirmation Dept.
Web Joker

The page linked to in the email advises the user to install a “Secure Login Applet” to view the page, which of course is an executable trojan file — a typical name is applet.exe. Below is a brief analysis.

The applet.exe file, when run, performs the standard Zhelatin actions: Copying itself to C:\Windows\spooldr.exe, and extracting a driver file to C:\Windows\system32\spooldr.sys. It also adds a rename entry for a .tmp file:

HKLM\System\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations = C:\Windows\system32\drivers\OLD3.tmp"

This entry will simply delete the file on reboot. Interestingly enough, the variants we’ve examined so far haven’t patched the tcpip.sys file to make themselves autostart. This makes removal easier since tcpip.sys does not need to be restored from backup. (Check that the digital signature on tcpip.sys is valid though, in case you are infected with this and it is a different variant!)

The OLD3.tmp file is actually a patched version of the legitimate Microsoft kbdclass.sys driver file. The trojan version has an extra 15 KB of data appended to it. The entry point of the patched driver file has been modified to point to the start of this extra block of data. Once loaded, the OLD3.tmp file loads the spooldr.sys trojan driver using the native Windows API function ZWSetSystemInformation.

The spooldr.sys driver will as usual disable most common firewalls, including the built-in Windows firewall.

Manual removal steps

  1. Reboot computer in Safe Mode without networking
  2. Delete the following files: C:\Windows\spooldr.exe, C:\Windows\system32\spooldr.sys
  3. Restart computer normally