Universa Application

C

CJE Culver

My apologies if this is the wrong newsgroup for this enquiry.

Recently, I've managed to pick up a virus/malware which I've been unable
to locate any information on. I'm calling it "Universa" because Kerio PF
identifies it as "Universa Application".

It modus operandum is essentially this:

At odd times (I haven't figured out yet what the trigger is), it will
create two files in %WINDOWS%\TEMP, a REG file and an EXE file, both
randomly named (the EXE is named WIN*.TMP.EXE where the * is a random
four-digit hex number). First, it tries to run the REG file, which wants
to create a key in
HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\,
then it launches WIN*.TMP.EXE, which attempts to connect to two internet
sites, usually at reverse.theplanet.com, though most recently it seems
has switched to bones.vg.

I have all the detailed log reports if anyone's interested, but someone
must be able to identify this thing for me, and how to get rid of it.

CJE Culver
 
A

Art

My apologies if this is the wrong newsgroup for this enquiry.

Recently, I've managed to pick up a virus/malware which I've been unable
to locate any information on. I'm calling it "Universa" because Kerio PF
identifies it as "Universa Application".

It modus operandum is essentially this:

At odd times (I haven't figured out yet what the trigger is), it will
create two files in %WINDOWS%\TEMP, a REG file and an EXE file, both
randomly named (the EXE is named WIN*.TMP.EXE where the * is a random
four-digit hex number). First, it tries to run the REG file, which wants
to create a key in
HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\,
then it launches WIN*.TMP.EXE, which attempts to connect to two internet
sites, usually at reverse.theplanet.com, though most recently it seems
has switched to bones.vg.

I have all the detailed log reports if anyone's interested, but someone
must be able to identify this thing for me, and how to get rid of it.

If Ewido, Spybot S&D, AdAware, and Kaspersky av all find nothing it's
likely you have some new and "unknown" malware. I wonder if you can
copy a sample of one of the offending files so that it can be sent to
av vendors for analysis.

Art

http://home.epix.net/~artnpeg
 
C

CJE Culver

Recently, I've managed to pick up a virus/malware which I've been unable
If Ewido, Spybot S&D, AdAware, and Kaspersky av all find nothing it's
likely you have some new and "unknown" malware. I wonder if you can
copy a sample of one of the offending files so that it can be sent to
av vendors for analysis.

I've haven't run all of the above against it, but NAV (2006), A-Squared
and Ad-Aware all miss it. Kerio is the only thing that stopped it. I
have saved copies of the REG and WIN*.TMP.EXE files, as well as Kerio's
log information.
 
A

Art

I've haven't run all of the above against it, but NAV (2006), A-Squared
and Ad-Aware all miss it. Kerio is the only thing that stopped it. I
have saved copies of the REG and WIN*.TMP.EXE files, as well as Kerio's
log information.

Ok, start by uploading the suspect files here:

http://www.virustotal.com/flash/index_en.html

Let us know the results. While samples are submitted to the av vendors
from this site, you will get a much faster analysis if you zip the
samples and send them to (e-mail address removed) and in the message
body explain what happened.

Art


http://home.epix.net/~artnpeg
 
D

David H. Lipman

From: "CJE Culver" <[email protected]>

| My apologies if this is the wrong newsgroup for this enquiry.
|
| Recently, I've managed to pick up a virus/malware which I've been unable
| to locate any information on. I'm calling it "Universa" because Kerio PF
| identifies it as "Universa Application".
|
| It modus operandum is essentially this:
|
| At odd times (I haven't figured out yet what the trigger is), it will
| create two files in %WINDOWS%\TEMP, a REG file and an EXE file, both
| randomly named (the EXE is named WIN*.TMP.EXE where the * is a random
| four-digit hex number). First, it tries to run the REG file, which wants
| to create a key in
| HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\,
| then it launches WIN*.TMP.EXE, which attempts to connect to two internet
| sites, usually at reverse.theplanet.com, though most recently it seems
| has switched to bones.vg.
|
| I have all the detailed log reports if anyone's interested, but someone
| must be able to identify this thing for me, and how to get rid of it.
|
| CJE Culver


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://harrisonrj.home.comcast.net/step_by_step_pc_cleaning_process.htm#Step_3_%96_Getting_Help


* * * Please report back your results * * *
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top