Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Dangerous Virus Question

Thread Tools
 
Search this Thread
 
Old 11 June 2002, 04:55 PM
  #1  
ozzy
Scooby Regular
Thread Starter
 
ozzy's Avatar
 
Join Date: Nov 1999
Location: Scotland, UK
Posts: 10,504
Likes: 0
Received 1 Like on 1 Post
Post

There's some info on the Symantec site.

More interestingly, going by the page update, they've know about it since the 9th October

Stefan

[Edited by ozzy - 11/6/2002 4:56:31 PM]
Old 05 November 2002, 08:22 PM
  #2  
BuRR
Scooby Regular
 
BuRR's Avatar
 
Join Date: Dec 2001
Location: Was Wakefield, now London
Posts: 5,210
Likes: 0
Received 0 Likes on 0 Posts
Post

As a few of you are no doubt aware of the problems I've been having lately, I'd like to attempt to satisfy my curiousity in relation to a virus-infected file. If you dare, and feel you ar4e qualified to deal with the potential consequences of downloading virus-infected files, please could someone tell me if the folling file is infected with a virus.

http://www.burratha.com/files/virus/n0tepad.zip

For your information, McAfee and Norton don't report anything untoward as far as I am aware. Kaspersky, however, reports it as the Backdoor.Hupigeon trojan.

Please don't open the zip, just scan it.

***DISCLAIMER***
I accept NO liability for any damage to any data that the use or misuse of the file may cause.

I'll take it down in about 24 hours.

Thanks in advance.
Old 05 November 2002, 08:28 PM
  #3  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Talking

My Norton see's it as clean.

I'd send it to an AV supplier if I were you, they are normally happy to assist.

Old 05 November 2002, 08:52 PM
  #4  
BuRR
Scooby Regular
 
BuRR's Avatar
 
Join Date: Dec 2001
Location: Was Wakefield, now London
Posts: 5,210
Likes: 0
Received 0 Likes on 0 Posts
Post

Just got this reply from Kaspersky's online virus scanner:

Current object: n0tepad.zip


n0tepad.zip Archive: ZIP
n0tepad.zip/n0tepad.exe Archive: Instyler
n0tepad.zip/n0tepad.exe/aliases.ini Ok
n0tepad.zip/n0tepad.exe/bluelab.dat Ok
n0tepad.zip/n0tepad.exe/cs.dat Ok
n0tepad.zip/n0tepad.exe/cscan4.mrc Ok
n0tepad.zip/n0tepad.exe/iserver.bat Ok
n0tepad.zip/n0tepad.exe/ltns.exe Ok
n0tepad.zip/n0tepad.exe/mirc.ini Ok
n0tepad.zip/n0tepad.exe/moo.dll Packed: UPX
n0tepad.zip/n0tepad.exe/moo.dll Ok
n0tepad.zip/n0tepad.exe/n.dat Ok
n0tepad.zip/n0tepad.exe/ntcmd.exe Ok
n0tepad.zip/n0tepad.exe/PipeCmd.exe Ok
n0tepad.zip/n0tepad.exe/recv/share.bat Infected: Backdoor.IRC.SdBot.p
n0tepad.zip/n0tepad.exe/s.dat Ok
n0tepad.zip/n0tepad.exe/share.bat Infected: Backdoor.IRC.SdBot.p
n0tepad.zip/n0tepad.exe/share.dat Ok
n0tepad.zip/n0tepad.exe/shr.vxd Ok
n0tepad.zip/n0tepad.exe/sysd.exe Packed: UPX
n0tepad.zip/n0tepad.exe/sysd.exe Ok
n0tepad.zip/n0tepad.exe/ws.exe Packed: FSG
n0tepad.zip/n0tepad.exe/ws.exe Infected: TrojanDownloader.Win32.Aphex.10.c


Old 05 November 2002, 09:14 PM
  #5  
IanW
Scooby Regular
 
IanW's Avatar
 
Join Date: Jul 2001
Posts: 21,865
Likes: 0
Received 0 Likes on 0 Posts
Post

NAI Virus Scan v4.5.1 with DAT 4.0.4231 and Scan Engine of 4.1.60 says its clean.

Send a copy to the guys at NAI, Jack posted the e-mail address to send it to earlier in the week.
Old 05 November 2002, 09:28 PM
  #6  
suba
Scooby Regular
 
suba's Avatar
 
Join Date: Mar 2000
Posts: 2,462
Likes: 0
Received 0 Likes on 0 Posts
Post

checked out OK on trend micro online scanner (housecall.antivirus.com).
Old 05 November 2002, 09:38 PM
  #7  
BuRR
Scooby Regular
 
BuRR's Avatar
 
Join Date: Dec 2001
Location: Was Wakefield, now London
Posts: 5,210
Likes: 0
Received 0 Likes on 0 Posts
Post

Things like this make you paranoid
Old 05 November 2002, 11:00 PM
  #8  
Figment©
Scooby Regular
 
Figment©'s Avatar
 
Join Date: Jun 2002
Posts: 133
Likes: 0
Received 0 Likes on 0 Posts
Post

Sophos reported it clean
Old 05 November 2002, 11:33 PM
  #9  
IWatkins
Scooby Regular
 
IWatkins's Avatar
 
Join Date: Mar 2000
Location: Gloucestershire, home of the lawnmower.
Posts: 4,531
Likes: 0
Received 0 Likes on 0 Posts
Post

Looks clean to my Sophos
Old 05 November 2002, 11:34 PM
  #10  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

In the labs now, should have a response soon.
Old 06 November 2002, 12:27 AM
  #11  
gregh
Scooby Regular
 
gregh's Avatar
 
Join Date: Dec 1999
Posts: 3,360
Likes: 0
Received 0 Likes on 0 Posts
Post

interesting, my norton doesn't come up with anything either, virus def file is 23/10/2002.

Will be interested to see what the lab finds Jack.

Greg
Old 06 November 2002, 09:23 AM
  #12  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

My NAI setup (same setup as Ian) reported all clean as well...
Old 06 November 2002, 04:27 PM
  #13  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

"This is a variant of IRC/Sdbot which drops a few folders and several files in C:\Windows\Temp. One of the files it drops is a Mirc client. BTW – Most of the malware which is dropped by the trojan is already detected by our scanners."

Not a great answer if I say so myself - most likely because it was me asking - but I'm guessing that if you ran it with our software you'd be fine. We just don't detect anything when it's packed.

I don't recommend testing the above by the way.
Old 06 November 2002, 05:00 PM
  #14  
ozzy
Scooby Regular
Thread Starter
 
ozzy's Avatar
 
Join Date: Nov 1999
Location: Scotland, UK
Posts: 10,504
Likes: 0
Received 1 Like on 1 Post
Post

Eh, why does my post say June

I didn't test the file BTW.

Stefan
Old 06 November 2002, 07:18 PM
  #15  
merlin
Scooby Regular
 
merlin's Avatar
 
Join Date: Jul 2000
Posts: 370
Likes: 0
Received 0 Likes on 0 Posts
Post

I work for McAfee but not directly with viruses. Out of curiousity I've had a look at this one on an old PC at home. As Jack says it drops some files to the windows temp folder. It then adds an entry to the Run key in the registry to run one of the dropped files, ltns.exe This appears to be a version of mIRC.

Running VirusScan against the dropped files gives the following files that contain viruses:

iserver.bat IRC/Flood.bc
ntcmd.exe Fluxay.gen
share.bat IRC/Flood.bc
sysd.exe IRC/Flood.e

The original filename for sysd.exe was hidewndw.exe. My guess is this hides the mIRC window. McAfee don't say what the Flood virus variants do exactly, but they appear to be for use in remote DOS attacks using IRC to start the attack.

If anyone is tempted to "play" with this virus, don't do it while connected to the net.
Old 06 November 2002, 07:22 PM
  #16  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

"I work for McAfee"

Really? Is that your P1 in the Slough car park?
Old 07 November 2002, 11:26 PM
  #17  
BuRR
Scooby Regular
 
BuRR's Avatar
 
Join Date: Dec 2001
Location: Was Wakefield, now London
Posts: 5,210
Likes: 0
Received 0 Likes on 0 Posts
Post

So - the file IS a virus then? and more importantly, all the software (apart from Kaspersky at this time) has missed it up until now - when hopefully the updated Virus definitions will cater for its removal.

I now feel like the 3 days grief its caused me hasn't been in vain
Old 07 November 2002, 11:54 PM
  #18  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

If you had run it we - McAfee - would have stopped it. Just didn't give as early a warning as Kapersky.
Old 08 November 2002, 12:18 AM
  #19  
BuRR
Scooby Regular
 
BuRR's Avatar
 
Join Date: Dec 2001
Location: Was Wakefield, now London
Posts: 5,210
Likes: 0
Received 0 Likes on 0 Posts
Post

Ok - but I would have liked McAfee to have spotted the archive as it landed on my PC, if you understand? or at least found it on a system scan.

....or am I asking too much?
Old 08 November 2002, 08:49 AM
  #20  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Fully agree, and due to your request if you scan that file next week it'll find it You'll also be to blame if adding detection causes a false alarm
Old 08 November 2002, 12:09 PM
  #21  
beemerboy
Scooby Regular
 
beemerboy's Avatar
 
Join Date: Sep 2002
Location: Essexville
Posts: 4,391
Likes: 0
Received 0 Likes on 0 Posts
Post

great, dont open up any files for a week, if your using mcafee folks!!!!

BB - (off for a 1 week holiday)

Old 08 November 2002, 12:28 PM
  #22  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

"great, dont open up any files for a week, if your using mcafee folks!!!!"

Beemerboy, where did you get that attitude from!! Opening the file would trigger VirusScan, scanning the file in it's unpacked form would not.

As you're such a huge Sophos fan, what are they doing to help their customers? You do your best and still get **** about it. TFI Friday!
Old 08 November 2002, 12:56 PM
  #23  
ozzy
Scooby Regular
Thread Starter
 
ozzy's Avatar
 
Join Date: Nov 1999
Location: Scotland, UK
Posts: 10,504
Likes: 0
Received 1 Like on 1 Post
Post

Jack,

I think BB was asking (in his sarcastic way) what at least I was thinking - why do we have to wait until the next DAT release next week?

What are the reasons for 4233 not being released immediately with the update? or is that irrelevant since it would be detected, cleaned (or deleted) by the current version when it's opened?

Stefan
Old 08 November 2002, 02:21 PM
  #24  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

If you double clicked that file, we'd detect the malicious components it contains. No need for an update.

To keep people happy I've had the whole file included in next weeks driver. If you'd like an extra driver to detect the file now I can get one sent to you. Chances are it's already in the hourly DAT files available from http://www.avertlabs.com
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
slimwiltaz
General Technical
20
09 October 2015 07:40 PM
IanG1983
Wheels, Tyres & Brakes
2
06 October 2015 03:08 PM
Brzoza
Engine Management and ECU Remapping
1
02 October 2015 05:26 PM
the shreksta
Other Marques
26
01 October 2015 02:30 PM



Quick Reply: Dangerous Virus Question



All times are GMT +1. The time now is 04:31 PM.