A New Virus?

A

Alan

Hi Steve,

I'm crossposting this to the microsoft.private.security.spyware.general,
microsoft.private.security.spyware.announcements and the
microsoft.public.security.virus newsgroups.

Maybe someone in one of those groups will have some ideas as to cleaning
this.

At least they will be on the alert that a new virus seems to be making its
way through the 'Net.

Alan


Wife got a fake blue mountain ecard yesterday and it looks like when
she clicked through we picked up a virus of some sorts. So far
neither AVG nor Panda detect it - which is worrysome. Here are the
indications.

running in taskmon was winverr.exe, which was located in \system32\
and time stamped with the correct time for the infection. fport
showed it active on 1029 and 1031 tcp.

I killed the process, removed the startup reg key in HKLM\Software\MS
\Windows\CurrentVersion\Run and rebooted.

Upon reboot, my Firefox.exe file was replaced (same size - 7,455) with
upload.exe and all shortcuts to firefox.exe were updated to
upload.exe. Deleted that reinstalled firefox, rebooted, and same
thing - a new upload.exe and firefox.exe is gone.

Look back in taskmon and now it's cdrwrr.exe running on 1029 and
1031. Netstat showed the processes connecting to 209.51.196.244:80.
Both winverr.exe and cdrwrr.exe were small - about 71k in size.

Other files that have the same timestamp in \system32 are:

default_user_class.dat.LOG
looking at that in textpad shows:
s y s t e m 3 2 \ d e f a u l t _ u s e r _ c l a s s . d a t
^DIRTÿ

and a file called: ulvrsao with the only content displayable in
notepad being: Y2RydnY&

As I mentioned both AVG and Panda report the system clean. The other
suspicious factor is that it seems to be adding a 2nd duplicate letter
at the end of the running process in an attempt to hide itself -
winver.exe to winverr.exe etc.

In Eventviewer under System, I see a couple of these:


Windows Defender Real-Time Protection agent has detected changes.
Microsoft recommends you analyze the software that made these changes
for potential risks. You can use information about how these programs
operate to choose whether to allow them to run or remove them from
your computer. Allow changes only if you trust the program or the
software publisher. Windows Defender can't undo changes that you
allow.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=74409
Scan ID: {6198A5F8-4071-4F4B-9F15-4C5D78034F76}
User: STEVE-QPGWKTW1R\Steve
Name: Unknown
ID:
Severity: Not Yet Classified
Category: Not Yet Classified
Path Found: clsid:HKLM\SOFTWARE\CLASSES\CLSID\{9A9307A0-7DA4-4DAF-
B042-5009F29E09E1};regkey:HKLM\Software\Microsoft\Code Store Database
\Distribution Units\{9A9307A0-7DA4-4DAF-B042-5009F29E09E1}\CONTAINS
\FILES\\C:\WINDOWS\Downloaded Program Files\asinst.dll;regkey:HKLM
\Software\Microsoft\Code Store Database\Distribution Units
\{9A9307A0-7DA4-4DAF-B042-5009F29E09E1};regkey:HKLM\SOFTWARE\CLASSES
\TYPELIB\{4387D200-E98E-4194-9684-44783E8EB4EE}\1.0;regkey:HKLM
\SOFTWARE\CLASSES\CLSID\{9A9307A0-7DA4-4DAF-
B042-5009F29E09E1};activex:HKLM\Software\Microsoft\Code Store Database
\Distribution Units\{9A9307A0-7DA4-4DAF-
B042-5009F29E09E1};typelibversion:HKLM\SOFTWARE\CLASSES\TYPELIB
\{4387D200-E98E-4194-9684-44783E8EB4EE}\1.0;typelib:HKLM\SOFTWARE
\CLASSES\TYPELIB\{4387D200-E98E-4194-9684-44783E8EB4EE};file:C:\WINDOWS
\Downloaded Program Files\asinst.dll
Alert Type: Unclassified software
Detection Type:

2nd:

Scan ID: {F1BE1670-344B-4D4F-AAB6-A2FD5D9E186C}
User: STEVE-QPGWKTW1R\Steve
Name: Unknown
ID:
Severity: Not Yet Classified
Category: Not Yet Classified
Path Found: driver:RkPavProc
Alert Type: Unclassified software
Detection Type:

3rd:

Scan ID: {A942A6AB-FD6D-405E-B44B-F043E2ACDCC8}
User: STEVE-QPGWKTW1R\Steve
Name: Unknown
ID:
Severity: Not Yet Classified
Category: Not Yet Classified
Path Found:
regkey:HKCU@S-1-5-21-1454471165-1708537768-839522115-1003\Software
\Microsoft\Windows\CurrentVersion\Run\
\SPOLSV;runkey:HKCU@S-1-5-21-1454471165-1708537768-839522115-1003\Software
\Microsoft\Windows\CurrentVersion\Run\\SPOLSV;file:C:\WINDOWS
\system32\tracerts.exe
Alert Type: Unclassified software
Detection Type:
 
P

Paul Wilson

Hi gang,

I got bit by this. Windows Live One Care scan didn't find it but it did
alert me that winverr.exe was attempting to access the internet and gave me
the opportunity to allow or refuse the connection. That's what alerted me to
the problem.

AVG 7.5 Anti-Malware identified it as Logger.Banker.Bum and removed it. The
files removed were tracerts.exe and winverr.exe in Windows\System32;
rfc2attach20[1].exe in the user's temporary internet files folder; and a
cookie - user@trafficmp[1].txt.

I have not yet reinstalled Firefox but I experienced the same situation as
Steve - Firefox.exe was replaced with upload.exe.

I have a feeling One Care DID warn before it was installed but I wasn't the
operator at the time. I'm running Vista 32-bit.

Please note that winver.exe (ONE R) is a legitimate process, but the
spyware/malware is spelled with two Rs.

Paul
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top