Новая версия Bagle: Trojan-Proxy.Win32.Mitglieder.ee
Пошел новый вал писем с троянскими программами. Отправитель "Вика", текст "В архиве фото с нудисткого пляжа. Там я и Ленка.". Пока детектируют так:
Antivirus Version Update Result
AntiVir 6.35.0.21 07.08.2006 HEUR/Trojan.Downloader
Authentium 4.93.8 07.07.2006 could be infected with an unknown virus
Avast 4.7.844.0 07.07.2006 no virus found
AVG 386 07.07.2006 no virus found
BitDefender 7.2 07.09.2006 Trojan.Proxy.Mitglieder.B
CAT-QuickHeal 8.00 07.07.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 07.07.2006 Trojan.Bagle.BH
DrWeb 4.33 07.07.2006 DLOADER.Trojan
eTrust-InoculateIT 23.72.63 07.08.2006 no virus found
eTrust-Vet 12.6.2291 07.07.2006 no virus found
Ewido 3.5 07.08.2006 no virus found
Fortinet 2.77.0.0 07.09.2006 suspicious
F-Prot 3.16f 07.07.2006 could be infected with an unknown virus
F-Prot4 4.2.1.29 07.07.2006 Possibly a new unknown PE_Virus!Maximus
Ikarus 0.2.65.0 07.07.2006 no virus found
Kaspersky 4.0.2.24 07.09.2006 Trojan-Proxy.Win32.Mitglieder.ee
McAfee 4802 07.07.2006 Proxy-Mitglieder
Microsoft 1.1481 07.08.2006 no virus found
NOD32v2 1.1651 07.08.2006 a variant of Win32/TrojanProxy.Mitglieder
Norman 5.90.23 07.07.2006 W32/Malware
Panda 9.0.0.4 07.08.2006 Suspicious file
Sophos 4.07.0 07.08.2006 W32/Bagle-Gen
Symantec 8.0 07.09.2006 no virus found
TheHacker 5.9.8.170 07.07.2006 no virus found
UNA 1.83 07.08.2006 no virus found
VBA32 3.11.0 07.08.2006 suspected of Email-Worm.Bagle.1
VirusBuster 4.3.7:9 07.08.2006 no virus found
Aditional Information
File size: 8752 bytes
MD5: 1871312991b02e5ccab7e7fb793b0920
SHA1: f671893cf86db74281813aa46439dd470ff55be9
packers: FSG
packers: FSG
Norman SandBox:
[ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: [email][email protected][/email] - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* File might be compressed.
* Decompressing FSG.
* File length: 8752 bytes.
[ Changes to filesystem ]
* Creates file C:WINDOWSSYSTEM32winhost.exe.
[ Changes to registry ]
* Creates key "HKCUSoftwareTimeout".
* Sets value "uid"="238131497" in key "HKCUSoftwareTimeout".
* Sets value "port"="" in key "HKCUSoftwareTimeout".
* Sets value "pid"="" in key "HKCUSoftwareTimeout".
* Creates value "winhost.exe"="C:WINDOWSSYSTEM32winhost.exe" in key "HKCUSoftwareMicrosoftWindowsCurrentVersionRun".
* Creates key "HKLMSystemCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList".
* Creates key "HKLMSystemControlSet001ServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList".
* Creates key "HKLMSystemControlSet002ServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList".
* Sets value "%"="" in key "HKLMSystemControlSet002ServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList".
* Creates key "HKLMSystemControlSet003ServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList".
* Sets value "%"="" in key "HKLMSystemControlSet003ServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList".
* Sets value "%"="" in key "HKLMSystemCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList".
* Sets value "%"="" in key "HKLMSystemControlSet001ServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList".
[ Network services ]
* Looks for an Internet connection.
* Opens URL: [url]http://thehiphops.com?p=0&dhgdhf=238131497[/url]