|
Registered User
Join Date: Nov 2008
Posts: 8
OS: xp
|
Re: Virtumonde, malware, internet adware, popups, redirection
Thank you thank you again!
I disabled tea timer, and ran the teatimer.bat
Then, did the VirusTotal. Here is the scan results: (I don't know why the copy and paste header here says "not found stopped" etc., since the only words on the actual page just say "finished.", but here is the entire page from virustotal (long scan log)
File kwuishpf.exe received on 11.18.2008 21:26:18 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 10/34 (29.42%)
Loading server information...
Your file is queued in position: 5.
Estimated start time is between 70 and 100 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.
You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:
Antivirus Version Last Update Result
AhnLab-V3 2008.11.18.2 2008.11.18 Win-Trojan/FakeAv.126395
AntiVir 7.9.0.31 2008.11.18 TR/Fakealert.HO
Authentium 5.1.0.4 2008.11.18 -
Avast 4.8.1281.0 2008.11.18 -
AVG 8.0.0.199 2008.11.18 -
BitDefender 7.2 2008.11.18 -
CAT-QuickHeal 10.00 2008.11.18 -
ClamAV 0.94.1 2008.11.18 -
DrWeb 4.44.0.09170 2008.11.18 -
eSafe 7.0.17.0 2008.11.18 Suspicious File
eTrust-Vet 31.6.6210 2008.11.14 Win32/FakeAVDl.BG
Ewido 4.0 2008.11.18 -
F-Prot 4.4.4.56 2008.11.18 -
Fortinet 3.117.0.0 2008.11.18 -
GData 19 2008.11.18 -
Ikarus T3.1.1.45.0 2008.11.18 Trojan-Clicker.Win32.Klik
K7AntiVirus 7.10.527 2008.11.18 -
Kaspersky 7.0.0.125 2008.11.18 -
McAfee 5438 2008.11.18 Generic FakeAlert.d
Microsoft 1.4104 2008.11.17 Trojan:Win32/Wantvi.I
NOD32 3622 2008.11.18 -
Norman 5.80.02 2008.11.18 -
Panda 9.0.0.4 2008.11.18 -
PCTools 4.4.2.0 2008.11.18 -
Rising 21.04.12.00 2008.11.18 -
SecureWeb-Gateway 6.7.6 2008.11.18 Trojan.Fakealert.HO
Sophos 4.35.0 2008.11.18 -
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.18 -
TheHacker 6.3.1.1.157 2008.11.18 -
TrendMicro 8.700.0.1004 2008.11.18 -
VBA32 3.12.8.9 2008.11.18 Trojan-Downloader.Win32.Small.agdo
ViRobot 2008.11.18.1474 2008.11.18 Backdoor.Win32.UltimateDefender.250880.C
VirusBuster 4.5.11.0 2008.11.18 -
Additional information
File size: 35328 bytes
MD5...: 30e64013d44e1a04ba38b21c28897e02
SHA1..: 8602fe54cc6a544a2f2da16863768fdcd2d60c2a
SHA256: 221927fe805dfd9a0f76c401748af7eba645a5e74d86243ba805e82900a8d30c
SHA512: b132e0ad73c75c5e09bc884d39a843f0b0dd1539bb8167d19454890e40bd4d97
803ba30cc1b4ef71f61c0a2916c73e5ca08762fb7f26889815b3998baf2e3ef1
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x401008
timedatestamp.....: 0x0 (Thu Jan 01 00:00:00 1970)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.code 0x1000 0x1000 0x200 5.98 a737fee3b265faa47d600f88823a66ae
.data 0x2000 0x9000 0x8200 7.93 aa587318054020495408931131c3a8c8
.rdata 0xb000 0x6000 0x200 0.00 bf619eac0cdf3f68d496ea9344137e8b
( 3 imports )
> KERNEL32.DLL: AllocConsole, AreFileApisANSI, BuildCommDCBAndTimeoutsA, ClearCommBreak, DebugActiveProcess, EnumTimeFormatsW, ExitProcess, FlushInstructionCache, GenerateConsoleCtrlEvent, GetComputerNameW, GetConsoleScreenBufferInfo, GetCurrencyFormatA, GetCurrentThreadId, GetModuleHandleW, GetProcessTimes, GetTempPathA, GlobalAddAtomA, HeapWalk, LCMapStringW, MoveFileExA, OpenFileMappingA, PeekConsoleInputA, ReadConsoleOutputW, RemoveDirectoryA, SetLocaleInfoW, SetTimeZoneInformation, VerLanguageNameA, WriteConsoleOutputAttribute
> USER32.DLL: AlignRects, CreateIconFromResource, CreatePopupMenu, DdeImpersonateClient, DdeKeepStringHandle, DeferWindowPos, GetClassInfoExA, GetKeyNameTextW, GetSysColor, IsCharLowerA, IsChild, MapVirtualKeyA, MapVirtualKeyW, PackDDElParam, PostThreadMessageW, ScreenToClient, SetWindowLongA, ShowWindowAsync, UnregisterHotKey, wvsprintfA
> GDI32.DLL: Chord, CopyEnhMetaFileA, CreateBrushIndirect, CreateDIBitmap, CreateHatchBrush, DPtoLP, DeleteDC, DeviceCapabilitiesExW, EndDoc, EnumFontFamiliesA, GetCharABCWidthsW, GetGlyphOutlineA, GetLogColorSpaceA, GetObjectA, GetTextCharsetInfo, GetTextExtentPointW, PolyPolyline, RectInRegion, StartPage, StretchBlt, StrokePath, TextOutW
( 0 exports )
Please let me know what's next!
|