<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-166393339978616430</atom:id><lastBuildDate>Tue, 19 Jun 2012 09:47:00 +0000</lastBuildDate><category>arbor networks</category><category>bots</category><category>malware</category><category>asert</category><category>submitted</category><category>rogue</category><category>general</category><category>exploit</category><category>storm</category><category>dnschanger</category><title>UploadMalware.com's Malware Blog</title><description /><link>http://uploadmalware.blogspot.com/</link><managingEditor>noreply@blogger.com (UploadMalware.com)</managingEditor><generator>Blogger</generator><openSearch:totalResults>29</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/UploadmalwarecomsMalwareBlog" /><feedburner:info uri="uploadmalwarecomsmalwareblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-6360289382060679760</guid><pubDate>Sat, 24 May 2008 01:32:00 +0000</pubDate><atom:updated>2008-05-23T20:35:41.758-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">general</category><title>Will summer break bring the normal malware influx?</title><description>&lt;p class="MsoNormal"&gt;Summer break is just around the corner and I started to ask myself if we would notice the normal influx of malware we used to see from students out on break in the not too distant past. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;With &lt;span style=""&gt; &lt;/span&gt;large crime-ware groups operating most of the malware we see and hear about daily, it seems like we forgot about the so called “script kiddies” who used to bring so much burden to the anti-malware world at this time of year.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Last summer it seems like the script kiddies had dropped off the face of the planet, but maybe they were just over shadowed by all the hype and media attention that the RBN and Storm were drawing last year. &lt;span style=""&gt; &lt;/span&gt;I personally think that this was the case, they weren’t gone we just didn’t hear anything about them because they weren’t the huge impact they had been in the past. With thousands of new malwares being seen daily would the few extra hundred a week (or month) be really that noticeable in the overall picture.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I guess only time will tell, but look out for new malware to come out this summer!&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/dTCE8a52L8g" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/dTCE8a52L8g/will-summer-break-bring-normal-malware.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>5</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/05/will-summer-break-bring-normal-malware.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-7524392406428990002</guid><pubDate>Mon, 12 May 2008 01:06:00 +0000</pubDate><atom:updated>2008-05-11T21:04:16.482-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">dnschanger</category><category domain="http://www.blogger.com/atom/ns#">exploit</category><title>Mass File Injection - Redirecting to DNSChanger Download</title><description>Mike from UploadMalware.com's team has discovered a mass file injection attack going around injecting the 2 urls below into sites running any version of phpbb forum software&lt;br /&gt;&lt;br /&gt;hxxp://free.hostpinoy.info/f.js&lt;br /&gt;hxxp://xprmn4u.info/f.js&lt;br /&gt;&lt;br /&gt;The 2 urls point to a  javascript redirect script that automatically redirect visitors to a fake codec download site. These fake codecs are known as DNSChanger. Anyone running phpbb should check out their servers.&lt;br /&gt;&lt;br /&gt;At the time of this writing over 400,000 hits are shown in Google when you search for the urls.&lt;br /&gt;&lt;br /&gt;If anyone has any information as to how the scripts are being injected or which exploit is being used please contact me at dnelson(shift+2)uploadmalware.com&lt;br /&gt;&lt;pre id="tabulado"&gt;&lt;blockquote&gt;Antivirus Version Last Update Result&lt;br /&gt;AntiVir 7.8.0.17 2008.05.11 DR/Dldr.DNSChanger.Gen&lt;br /&gt;AVG 7.5.0.516 2008.05.11 DNSChanger.AE&lt;br /&gt;ClamAV 0.92.1 2008.05.11 Trojan.Dropper-6806&lt;br /&gt;F-Secure 6.70.13260.0 2008.05.12&lt;br /&gt; Trojan.Win32.DNSChanger.clm&lt;br /&gt;Ikarus T3.1.1.26.0 2008.05.12&lt;br /&gt;  Virus.Trojan.Win32.DNSChanger.chg&lt;br /&gt;Kaspersky 7.0.0.125 2008.05.12&lt;br /&gt;  Trojan.Win32.DNSChanger.clm&lt;br /&gt;Norman 5.80.02 2008.05.09 Vundo.gen171.dropper&lt;br /&gt;Prevx1 V2 2008.05.12 Cloaked Malware&lt;br /&gt;Sophos 4.29.0 2008.05.11 Troj/Zlobar-Fam&lt;br /&gt;TheHacker 6.2.92.307 2008.05.11 Trojan/DNSChanger.chg&lt;br /&gt;Webwasher-Gateway 6.6.2 2008.05.11&lt;br /&gt;  Trojan.Dropper.Dldr.DNSChanger.Gen&lt;/blockquote&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/8eVgeTkgp-M" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/8eVgeTkgp-M/mass-file-injection-redirecting-to-zlob.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>3</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/05/mass-file-injection-redirecting-to-zlob.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-7959538337922764123</guid><pubDate>Sun, 04 May 2008 15:45:00 +0000</pubDate><atom:updated>2008-05-04T15:02:30.292-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">storm</category><category domain="http://www.blogger.com/atom/ns#">bots</category><title>New Storm Moving In – Presumably for Mother’s Day</title><description>&lt;p class="MsoNormal"&gt;One of our researchers at UploadMalware.com has found indications of a new storm worm variant moving in. &lt;span style=""&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;At the time of this posting we have not had any reports of spam from the botnet using the 3 domains that were found in the research, but the files are definitely there and the domains are fast fluxing as per the normal method. We can only presume they are gearing up for a mother’s day storm campaign to raise their numbers.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The three domains we have found to this point are: (visit at your own risk)&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;blockquote&gt;stateandfed.cn, apartment-mall.cn and centerprop.cn&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The file load.exe on execution copies itself to %windir%\libor.exe and drops the standard peers.ini as gogora.config. Libor.exe is then added to the run key in the registry to allow execution every reboot.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;So not to add to the problem I personally only ran the exe with an internet connection for about 1 minute and it contacted ~1700 other infected boxes. &lt;span style=""&gt; &lt;/span&gt;Other research done by members of UploadMalware.com indicates approximately 100,000 or more which are still infected (number was taken by methods other than running the file).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;This proves contrary to &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9079653"&gt;computerword.com’s&lt;/a&gt; article that Microsoft had killed the storm worm.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The article had already been strongly disputed by &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9080261&amp;amp;intsrc=hm_list"&gt;researchers&lt;/a&gt;. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;Storm worm is alive and well, it may be smaller then when it first came onto the scene, but it seems when their numbers dwindle they come back with another holiday targeted mail campaign and boost the numbers back up. &lt;span style=""&gt; &lt;/span&gt;The storm group isn’t going anywhere as far as I can tell.&lt;/p&gt;&lt;p class="MsoNormal"&gt;Jeremy over at sudosecure.net has posted some more info &lt;a href="http://www.sudosecure.net/archives/61"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/anpNhEzxvpg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/anpNhEzxvpg/new-storm-moving-in-presumably-for.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/05/new-storm-moving-in-presumably-for.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-3682214757289483860</guid><pubDate>Tue, 26 Feb 2008 04:21:00 +0000</pubDate><atom:updated>2008-02-25T22:26:56.187-06:00</atom:updated><title>postcard.gif.exe - 63e8fe1363431d2e56f38141a35278d3</title><description>* name: postcard.gif.exe&lt;br /&gt;* size: 878374&lt;br /&gt;* md5.: 63e8fe1363431d2e56f38141a35278d3&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;AntiVir    7.6.0.67/20080225    found [HIDDENEXT/Worm.Gen]&lt;br /&gt;Authentium    4.93.8/20080226    found [could be infected with an unknown virus]&lt;br /&gt;Avast    4.7.1098.0/20080225    found [IRC:Zapchast-D]&lt;br /&gt;AVG    7.5.0.516/20080226    found [IRC/BackDoor.Flood]&lt;br /&gt;BitDefender    7.2/20080226    found [Backdoor.Zapchast.Z]&lt;br /&gt;ClamAV    0.92.1/20080226    found [Trojan.IRCBot-96]&lt;br /&gt;DrWeb    4.44.0.09170/20080225    found [Win32.Parite.2]&lt;br /&gt;eSafe    7.0.15.0/20080226    found [Win32.IRC.Zapchast]&lt;br /&gt;Ewido    4.0/20080225    found [Backdoor.Zapchast.z]&lt;br /&gt;F-Prot    4.4.2.54/20080225    found [W32/Heuristic-300!Eldorado]&lt;br /&gt;F-Secure    6.70.13260.0/20080226    found [Backdoor.IRC.Zapchast]&lt;br /&gt;Fortinet    3.14.0.0/20080225    found [REG/Zapchast.4D53!tr.bdr]&lt;br /&gt;Ikarus    T3.1.1.20/20080226    found [Backdoor.IRC.Zapchast]&lt;br /&gt;Kaspersky    7.0.0.125/20080226    found [Backdoor.IRC.Zapchast]&lt;br /&gt;McAfee    5237/20080225    found [IRC/Generic Flooder]&lt;br /&gt;Microsoft    1.3204/20080226    found [Backdoor:IRC/Zapchast.AN]&lt;br /&gt;NOD32v2    2901/20080225    found [IRC/Zapchast.Z]&lt;br /&gt;Norman    5.80.02/20080225    found [Pinfi.A.dropper]&lt;br /&gt;Rising    20.33.02.00/20080225    found [Win32.Parite.b]&lt;br /&gt;Sophos    4.27.0/20080226    found [Mal/Zapchas-C]&lt;br /&gt;Sunbelt    3.0.893.0/20080223    found [Trojan.Zapchas.F]&lt;br /&gt;Symantec    10/20080226    found [IRC Trojan]&lt;br /&gt;TheHacker    6.2.9.229/20080225    found [Adware/2Search]&lt;br /&gt;VBA32    3.12.6.2/20080226    found [Trojan.IRC.Zapchast.H]&lt;br /&gt;VirusBuster    4.3.26:9/20080225    found [IRC.Zapchast.AQ]&lt;br /&gt;Webwasher-Gateway    6.6.2/20080225    found [Virus.HIDDENEXT/Worm.Gen]&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/u9giRlNuFhw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/u9giRlNuFhw/postcardgifexe-63e8fe1363431d2e56f38141.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>1</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/postcardgifexe-63e8fe1363431d2e56f38141.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-4562232733401563627</guid><pubDate>Tue, 26 Feb 2008 04:06:00 +0000</pubDate><atom:updated>2008-02-25T22:11:23.564-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>ekvgsnw.dll - 39bfebf001bfdd44830076e378958c4a</title><description>&lt;pre wrap=""&gt;* name: ekvgsnw.dll&lt;br /&gt;* size: 84451&lt;br /&gt;* md5.: 39bfebf001bfdd44830076e378958c4a&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;a href="http://www.free-av.com/"&gt;AntiVir&lt;/a&gt; 7.6.0.67/20080225 found [ADSPY/AdSpy.Gen]&lt;br /&gt;&lt;a href="http://free.grisoft.com/"&gt;AVG&lt;/a&gt; 7.5.0.516/20080226 found [Downloader.Zlob.SE]&lt;br /&gt;&lt;a href="http://www.microsoft.com/athome/security/spyware/software/default.mspx"&gt;Microsoft&lt;/a&gt; 1.3204/20080226 found [Adware:Win32/Vapsup]&lt;br /&gt;&lt;a href="http://www.prevx.com/"&gt;Prevx1&lt;/a&gt; V2/20080226 found [KAVKOP:Trojan-A]&lt;br /&gt;&lt;a href="http://www.sophos.com/"&gt;Sophos&lt;/a&gt; 4.27.0/20080226 found [Mal/Zlob-I]&lt;br /&gt;&lt;a href="http://www.securecomputing.com/"&gt;Webwasher-Gateway&lt;/a&gt; 6.6.2/20080225 found [Ad-Spyware.AdSpy.Gen]&lt;/blockquote&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/mgCXFlHfyLw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/mgCXFlHfyLw/ekvgsnwdll-39bfebf001bfdd44830076e37895.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/ekvgsnwdll-39bfebf001bfdd44830076e37895.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-2602517590587009789</guid><pubDate>Tue, 26 Feb 2008 04:01:00 +0000</pubDate><atom:updated>2008-02-25T22:05:17.541-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>dgtxrdfrmw.dll - 9432a1b6b11bf5247291e68763b25938</title><description>* name: dgtxrdfrmw.dll&lt;br /&gt;* size: 108190&lt;br /&gt;* md5.: 9432a1b6b11bf5247291e68763b25938&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;a href="http://free.grisoft.com"&gt;AVG&lt;/a&gt;    7.5.0.516/20080226    found [Downloader.Zlob.AAQ]&lt;br /&gt;&lt;a href="http://www.microsoft.com/athome/security/spyware/software/default.mspx"&gt;Microsoft&lt;/a&gt;    1.3204/20080226    found [Trojan:Win32/Zlob.ZWY]&lt;br /&gt;&lt;a href="http://www.prevx.com/"&gt;Prevx1&lt;/a&gt;    V2/20080226    found [Downloader.Zlob]&lt;br /&gt;&lt;a href="http://www.anti-virus.by/en/"&gt;VBA32&lt;/a&gt;    3.12.6.2/20080226    found [suspected of Downloader.Zlob.8]&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/6gBaJlaeswI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/6gBaJlaeswI/dgtxrdfrmwdll-9432a1b6b11bf5247291e6876.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/dgtxrdfrmwdll-9432a1b6b11bf5247291e6876.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-6767985141749678575</guid><pubDate>Tue, 26 Feb 2008 03:55:00 +0000</pubDate><atom:updated>2008-02-25T22:00:02.815-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>bxlrvps.dll - 8120d45ce090c65fd864ac8f48cf87cf</title><description>* name: bxlrvps.dll&lt;br /&gt;* size: 108451&lt;br /&gt;* md5.: 8120d45ce090c65fd864ac8f48cf87cf&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;a href="http://www.free-av.com/"&gt;AntiVir&lt;/a&gt;    7.6.0.67/20080225    found [ADSPY/Agent.PB]&lt;br /&gt;&lt;a href="http://www.avast.com/"&gt;Avast &lt;/a&gt;  4.7.1098.0/20080225    found [Win32:Agent-LTS]&lt;br /&gt;&lt;a href="http://free.grisoft.com/"&gt;AVG&lt;/a&gt;    7.5.0.516/20080226    found [Downloader.Zlob.AAS]&lt;br /&gt;&lt;a href="http://www.prevx.com/"&gt;Prevx1&lt;/a&gt;    V2/20080226    found [Generic.Malware]&lt;br /&gt;&lt;a href="http://www.anti-virus.by/en/"&gt;VBA32&lt;/a&gt;    3.12.6.2/20080226    found [suspected of Downloader.Zlob.5]&lt;br /&gt;&lt;a href="http://www.securecomputing.com"&gt;Webwasher-Gateway&lt;/a&gt;    6.6.2/20080225    found [Ad-Spyware.Agent.PB]&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/38dHbKpr3Dg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/38dHbKpr3Dg/bxlrvpsdll-8120d45ce090c65fd864ac8f48cf.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/bxlrvpsdll-8120d45ce090c65fd864ac8f48cf.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-4341049272424829414</guid><pubDate>Tue, 26 Feb 2008 03:48:00 +0000</pubDate><atom:updated>2008-02-25T21:53:49.513-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>alofkmn.dll - 0e962ef1d4eb86162cd02b72c4689d86</title><description>* name: alofkmn.dll&lt;br /&gt;* size: 86422&lt;br /&gt;* md5.: 0e962ef1d4eb86162cd02b72c4689d86&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;a href="http://free.grisoft.com/"&gt;AVG &lt;/a&gt; 7.5.0.516/20080226    found [Downloader.Zlob.AAM]&lt;br /&gt;&lt;a href="http://www.f-prot.com/"&gt;F-Prot&lt;/a&gt;  4.4.2.54/20080225    found [W32/FakeAlert.E.gen!Eldorado]&lt;br /&gt;&lt;a href="http://www.ikarus.at/"&gt;Ikarus&lt;/a&gt;  T3.1.1.20/20080226    found [Virus.Win32.Agent.LTS]&lt;br /&gt;&lt;a href="http://www.prevx.com/"&gt;Prevx1&lt;/a&gt; V2/20080226    found [Downloader.Zlob]&lt;br /&gt;&lt;a href="http://www.anti-virus.by/en/"&gt;VBA32&lt;/a&gt;  3.12.6.2/20080226    found [suspected of Downloader.Zlob.5]&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/JX0thSs_kqU" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/JX0thSs_kqU/alofkmndll-0e962ef1d4eb86162cd02b72c468.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/alofkmndll-0e962ef1d4eb86162cd02b72c468.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-964704816602318777</guid><pubDate>Tue, 26 Feb 2008 03:37:00 +0000</pubDate><atom:updated>2008-02-25T21:45:37.961-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>AlrtDrv.dll - 24326ce4cd6569dbc965c318c4c49d61</title><description>&lt;pre wrap=""&gt;* name: AlrtDrv.dll&lt;br /&gt;* size: 14326&lt;br /&gt;* md5.: 24326ce4cd6569dbc965c318c4c49d61&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;a href="http://www.free-av.com/"&gt;AntiVir&lt;/a&gt; 7.6.0.67/20080225 found [TR/Crypt.XPACK.Gen]&lt;br /&gt;&lt;a href="http://www.ikarus.at/"&gt;Ikarus&lt;/a&gt; T3.1.1.20/20080226 found [BehavesLikeTrojan.ShellObject]&lt;br /&gt;&lt;a href="http://www.kaspersky.com/"&gt;Kaspersky&lt;/a&gt; 7.0.0.125/20080226 found [Heur.Trojan.Generic]&lt;br /&gt;&lt;a href="http://www.norman.com/"&gt;Norman&lt;/a&gt; 5.80.02/20080225 found [W32/Smalltroj.CWNE]&lt;br /&gt;&lt;a href="http://www.prevx.com/"&gt;Prevx1&lt;/a&gt; V2/20080226 found [Downloader.Zlob]&lt;br /&gt;&lt;a href="http://www.securecomputing.com"&gt;Webwasher-Gateway&lt;/a&gt; 6.6.2/20080225 found [Trojan.Crypt.XPACK.Gen]&lt;/blockquote&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/haExTwGPFxA" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/haExTwGPFxA/alrtdrvdll-24326ce4cd6569dbc965c318c4c4.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/alrtdrvdll-24326ce4cd6569dbc965c318c4c4.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-3669915781133507653</guid><pubDate>Tue, 26 Feb 2008 03:30:00 +0000</pubDate><atom:updated>2008-02-25T21:32:03.892-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>JavaCore.exe -</title><description>&lt;pre wrap=""&gt;* name: JavaCore.exe&lt;br /&gt;* size: 79801&lt;br /&gt;* md5.: 780913add22a55b787f3eb9934e8207f&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;BitDefender 7.2/20080225 found [Adware.JCore.A]&lt;br /&gt;DrWeb 4.44.0.09170/20080224 found [Trojan.Insider.origin]&lt;br /&gt;Fortinet 3.14.0.0/20080224 found [Adware/Insider]&lt;br /&gt;Kaspersky 7.0.0.125/20080225 found [not-a-virus:AdWare.Win32.Insider.b]&lt;br /&gt;Prevx1 V2/20080225 found [Generic.Malware]&lt;br /&gt;TheHacker 6.2.9.228/20080223 found [Adware/Insider.b]&lt;/blockquote&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/Q3-WB7SKn4s" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/Q3-WB7SKn4s/javacoreexe.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/javacoreexe.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-1840340013562118495</guid><pubDate>Tue, 26 Feb 2008 03:23:00 +0000</pubDate><atom:updated>2008-02-25T21:29:54.859-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>iqykxi.exe - ee3a48d89399e3ad6b1576a28db4d30d</title><description>&lt;pre wrap=""&gt;* name: iqykxi.exe&lt;br /&gt;* size: 183063&lt;br /&gt;* md5.: ee3a48d89399e3ad6b1576a28db4d30d&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;AVG 7.5.0.516/20080226 found [SHeur.ATOO]&lt;br /&gt;eSafe 7.0.15.0/20080221 found [Suspicious File]&lt;br /&gt;F-Secure 6.70.13260.0/20080225 found [Backdoor.Win32.IRCBot.bol]&lt;br /&gt;Fortinet 3.14.0.0/20080225 found [W32/IRCBot.BOL!tr.bdr]&lt;br /&gt;Kaspersky 7.0.0.125/20080226 found [Backdoor.Win32.IRCBot.bol]&lt;br /&gt;Microsoft 1.3204/20080226 found [Backdoor:Win32/Oderoor.gen!B]&lt;br /&gt;NOD32v2 2901/20080225 found [Win32/Agent.NHE]&lt;br /&gt;Panda 9.0.0.4/20080225 found [W32/MSNPhoto.AB.worm]&lt;br /&gt;Prevx1 V2/20080226 found [SHeur.ATOO]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080225 found [Win32.Malware.gen (suspicious)]&lt;/blockquote&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/T0-kW2zozVg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/T0-kW2zozVg/iqykxiexe-ee3a48d89399e3ad6b1576a28db4d.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/iqykxiexe-ee3a48d89399e3ad6b1576a28db4d.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-5281679978182851119</guid><pubDate>Tue, 26 Feb 2008 03:19:00 +0000</pubDate><atom:updated>2008-02-25T21:22:56.685-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>antivir.exe - 448ea9863debe13966a7f809e7f8f8ff</title><description>&lt;pre wrap=""&gt;* name: antivir.exe&lt;br /&gt;* size: 42358&lt;br /&gt;* md5.: 448ea9863debe13966a7f809e7f8f8ff&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;AntiVir 7.6.0.67/20080218 found [TR/Crypt.XPACK.Gen]&lt;br /&gt;BitDefender 7.2/20080218 found [Trojan.Spy.ZBot.V]&lt;br /&gt;eSafe 7.0.15.0/20080217 found [Suspicious File]&lt;br /&gt;Sophos 4.26.0/20080218 found [Sus/Behav-192]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080218 found [Trojan.Crypt.XPACK.Gen]&lt;/blockquote&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/vgNTJIMIUcc" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/vgNTJIMIUcc/antivirexe-448ea9863debe13966a7f809e7f8.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/antivirexe-448ea9863debe13966a7f809e7f8.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-4723276436310482158</guid><pubDate>Mon, 18 Feb 2008 02:07:00 +0000</pubDate><atom:updated>2008-02-17T22:14:52.799-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rogue</category><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>Safe Strip Related Submissions (Rogue)</title><description>&lt;pre wrap=""&gt;Earlier today we received these 4 files from a user at &lt;a href="http://www.bleepingcomputer.com/"&gt;BleepingComputer.com&lt;/a&gt;&lt;br /&gt;The detection is extremely low. I started to analyze these in my VM and figured it was worth mentioning these because very little information was available on Google.&lt;br /&gt;&lt;br /&gt;The reason I titled this post "Safe Strip Related Submissions" is the url I found in each of these files that takes you to the "Safe Strip" download page.&lt;br /&gt;&lt;br /&gt;After running for about 15 minutes I finally started to get the balloon tips:&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_6YaiYD4nLk4/R7j1GE5PlrI/AAAAAAAAABQ/kJP2MiB06mQ/s1600-h/wlkingman3b.png"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_6YaiYD4nLk4/R7j1GE5PlrI/AAAAAAAAABQ/kJP2MiB06mQ/s320/wlkingman3b.png" alt="" id="BLOGGER_PHOTO_ID_5168150057149503154" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre wrap=""&gt; Even some pretty error messages:&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_6YaiYD4nLk4/R7j1Xk5PlsI/AAAAAAAAABY/0zkGXag2548/s1600-h/wlkingman3.png"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_6YaiYD4nLk4/R7j1Xk5PlsI/AAAAAAAAABY/0zkGXag2548/s320/wlkingman3.png" alt="" id="BLOGGER_PHOTO_ID_5168150357797213890" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre wrap=""&gt;&lt;br /&gt;And of course I can't forget my pretty new desktop background:&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_6YaiYD4nLk4/R7jzk05PlqI/AAAAAAAAABI/OUsVvEguBmk/s1600-h/wlkingman.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_6YaiYD4nLk4/R7jzk05PlqI/AAAAAAAAABI/OUsVvEguBmk/s320/wlkingman.png" alt="" id="BLOGGER_PHOTO_ID_5168148386407224994" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre wrap=""&gt;Oh yeah and a popup for advanced cleaner:&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_6YaiYD4nLk4/R7j_yU5PltI/AAAAAAAAABg/xFOTly2DTgo/s1600-h/wlkingman4.png"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_6YaiYD4nLk4/R7j_yU5PltI/AAAAAAAAABg/xFOTly2DTgo/s320/wlkingman4.png" alt="" id="BLOGGER_PHOTO_ID_5168161812474992338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre wrap=""&gt;Hijack This entries associated with these:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;O4 - HKLM\..\Run: [SMSERIALWORKSTARTER] "C:\WINDOWS\comsysobj.exe"&lt;br /&gt;O4 - HKLM\..\Run: [SMSERIALWORKERSTART] "C:\WINDOWS\shellexcon.exe"&lt;br /&gt;O4 - HKLM\..\Run: [SMSERIALSTARTER] "C:\WINDOWS\win32st.exe"&lt;br /&gt;O4 - HKLM\..\Run: [SMSERIALWORKERSTARTER] "C:\WINDOWS\winstrse.exe"&lt;/blockquote&gt;Virustotal Scans:&lt;br /&gt;&lt;blockquote&gt;* name: winstrse.exe&lt;br /&gt;* size: 13899&lt;br /&gt;* md5.: ed5db9136e502a87bdc20f36c787a977&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Webwasher-Gateway 6.6.2/20080215 found [Virus.Win32.FileInfector.gen!90 (suspicious)]&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;* name: comsysobj.exe&lt;br /&gt;* size: 13477&lt;br /&gt;* md5.: 17195c2104aee64b598aa815332bb6a4&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Panda 9.0.0.4/20080217 found [Adware/SpyBurner]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080215 found [Virus.Win32.FileInfector.gen!90 (suspicious)]&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote&gt;* name: shellexcon.exe&lt;br /&gt;* size: 15479&lt;br /&gt;* md5.: 3fe0e32201f34616edb7447e976df470&lt;br /&gt;&lt;br /&gt;AntiVir 7.6.0.67/20080215 found [HEUR/Malware]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080215 found [Heuristic.Malware]&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;* name: win32st.exe&lt;br /&gt;* size: 36864 bytes&lt;br /&gt;* md5.: 7dfb42300357f7b50ba763497e6c41c7&lt;br /&gt;&lt;br /&gt;AntiVir 7.6.0.67/20080215 found [HEUR/Malware]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080215 found [Heuristic.Malware]&lt;/blockquote&gt;&lt;/pre&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre wrap=""&gt;&lt;br /&gt;The files had the following URL's in the strings:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;http: //theonlybookmark.com/in.cgi&lt;br /&gt;http: //safe-strip-download.com/soft/in.cgi&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Once the files finally started doing their thing I finally got a new IE window that opened to a SystemErrorFixer webpage:&lt;br /&gt;&lt;blockquote&gt;http: //systemerrorfixer.com/clean/?cmpname=swpges31&amp;amp;eai=&lt;br /&gt;swp_ges&amp;amp;eli=3948&amp;amp;eaf=pp_1685211491&amp;amp;eu=http%3A%2F%2F advancedcleaner.com%2F.cleaner%2Findex.php%3Ftmn%3 Dadctmp%26clone_name%3Dswpadcex %26led%3D3948%26afr% 3Dpp_1685211491&amp;amp;ed=0&amp;amp;ex=0&amp;amp;h=10&amp;amp;cmpname=null&amp;amp;mt_info= 4141_0_1556&lt;/blockquote&gt; and to&lt;blockquote&gt;https ://www.anonymouschannel.com/home?pin=anzf3e&lt;/blockquote&gt;&lt;br /&gt;Which appears to be a fake Virtual Private Network manager.&lt;br /&gt;&lt;br /&gt;Thanks to WlkingMan for submitting these files.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Surf Safe,&lt;br /&gt;Dave&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/7dLA_M835TE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/7dLA_M835TE/safe-strip-related-submissions.html</link><author>noreply@blogger.com (UploadMalware.com)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_6YaiYD4nLk4/R7j1GE5PlrI/AAAAAAAAABQ/kJP2MiB06mQ/s72-c/wlkingman3b.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/safe-strip-related-submissions.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-7966337969085957328</guid><pubDate>Sun, 17 Feb 2008 05:09:00 +0000</pubDate><atom:updated>2008-02-16T23:11:19.317-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>svchost.exe - 9e3c13b6556d5636b745d3e466d47467</title><description>&lt;pre wrap=""&gt;* name: svchost.exe-submit.zip&lt;br /&gt;* size: 15783&lt;br /&gt;* md5.: 9e3c13b6556d5636b745d3e466d47467&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;AntiVir 7.6.0.67/20080215 found [W32/Hidrag.a]&lt;br /&gt;Authentium 4.93.8/20080215 found [W32/Jeefo.A]&lt;br /&gt;Avast 4.7.1098.0/20080215 found [Win32:Jeefo]&lt;br /&gt;AVG 7.5.0.516/20080216 found [Win32/Hidrag.A]&lt;br /&gt;BitDefender 7.2/20080216 found [Win32.Jeefo.A]&lt;br /&gt;CAT-QuickHeal None/20080216 found [W32.Jeefo.A]&lt;br /&gt;ClamAV 0.92.1/20080216 found [W32.Jeefo-3]&lt;br /&gt;DrWeb 4.44.0.09170/20080216 found [Win32.HLLP.Jeefo.36352]&lt;br /&gt;eSafe 7.0.15.0/20080214 found [Win32.Hidrag.a]&lt;br /&gt;eTrust-Vet 31.3.5541/20080215 found [Win32/Jeefo.A]&lt;br /&gt;Ewido 4.0/20080216 found [Worm.VB.dz]&lt;br /&gt;F-Prot 4.4.2.54/20080215 found [W32/Jeefo.A]&lt;br /&gt;F-Secure 6.70.13260.0/20080215 found [Virus.Win32.Hidrag.a]&lt;br /&gt;Fortinet 3.14.0.0/20080216 found [W32/Jeefo.A]&lt;br /&gt;Ikarus T3.1.1.20/20080216 found [Win32.Hidrag]&lt;br /&gt;Kaspersky 7.0.0.125/20080216 found [Virus.Win32.Hidrag.a]&lt;br /&gt;McAfee 5231/20080215 found [W32/Jeefo]&lt;br /&gt;Microsoft 1.3204/20080216 found [Virus:Win32/Jeefo.A]&lt;br /&gt;NOD32v2 2880/20080215 found [Win32/Jeefo.A]&lt;br /&gt;Norman 5.80.02/20080215 found [W32/Hidrag.A]&lt;br /&gt;Panda 9.0.0.4/20080216 found [W32/Jeefo.A.drp]&lt;br /&gt;Prevx1 V2/20080216 found [Generic.Malware]&lt;br /&gt;Rising 20.31.50.00/20080216 found [Win32.Hidrag]&lt;br /&gt;Sophos 4.26.0/20080216 found [W32/Jeefo-A]&lt;br /&gt;Sunbelt 2.2.907.0/20080216 found [Jeefo (v)]&lt;br /&gt;Symantec 10/20080216 found [W32.Jeefo]&lt;br /&gt;TheHacker 6.2.9.221/20080215 found [W32/Jeefo.gen]&lt;br /&gt;VBA32 3.12.6.1/20080214 found [Win32.HLLP.Jeefo]&lt;br /&gt;VirusBuster 4.3.26:9/20080215 found [Win32.Hidrag]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080215 found [Win32.Hidrag.a]&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/90dUSLl23e0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/90dUSLl23e0/svchostexe-9e3c13b6556d5636b745d3e466d4.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/svchostexe-9e3c13b6556d5636b745d3e466d4.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-4783010341958977295</guid><pubDate>Sun, 17 Feb 2008 04:54:00 +0000</pubDate><atom:updated>2008-02-16T22:59:34.049-06:00</atom:updated><title>Ma72Pan.exe - 9b6a68204fa80c20d39ebd0da0024085</title><description>&lt;pre wrap=""&gt;* name: Ma72Pan.exe-submit.zip&lt;br /&gt;* size: 84508&lt;br /&gt;* md5.: 9b6a68204fa80c20d39ebd0da0024085&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Ikarus T3.1.1.20/20080217 found [Backdoor.Win32.Rbot.c]&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/rGUX_GI15WI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/rGUX_GI15WI/ma72panexe-9b6a68204fa80c20d39ebd0da002.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/ma72panexe-9b6a68204fa80c20d39ebd0da002.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-3951408480574349608</guid><pubDate>Thu, 14 Feb 2008 15:17:00 +0000</pubDate><atom:updated>2008-02-14T09:20:20.488-06:00</atom:updated><title>rjmtjp.exe - d54d475125f7f6aa48d42f3f1122193a</title><description>&lt;pre wrap=""&gt;&lt;br /&gt;* name: rjmtjp.exe&lt;br /&gt;* size: 11910&lt;br /&gt;* md5.: d54d475125f7f6aa48d42f3f1122193a&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;AVG 7.5.0.516/20080213 found [BackDoor.RBot.BI]&lt;br /&gt;BitDefender 7.2/20080214 found [Backdoor.Irc.Sdbot.KC]&lt;br /&gt;DrWeb 4.44.0.09170/20080213 found [BackDoor.IRC.Sdbot.945]&lt;br /&gt;eSafe 7.0.15.0/20080213 found [Suspicious File]&lt;br /&gt;F-Secure 6.70.13260.0/20080214 found [W32/Ircbot.dam]&lt;br /&gt;Norman 5.80.02/20080213 found [W32/Ircbot.dam]&lt;br /&gt;Panda 9.0.0.4/20080214 found [W32/Poebot.MW.worm]&lt;br /&gt;Prevx1 V2/20080214 found [Worm.Ircbot.Gen]&lt;br /&gt;Symantec 10/20080214 found [W32.IRCBot.Gen]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080214 found [Win32.Malware.dam (suspicious)]&lt;br /&gt;&lt;br /&gt;packers: PE_Patch&lt;br /&gt;Prevx info: &lt;a class="moz-txt-link-freetext" href="http://info.prevx.com/aboutprogramtext.asp?PX5=AFC4ACC53825F0C930750061744E5E003D313D9A"&gt;http://info.prevx.com/aboutprogramtext.asp?PX5=AFC4ACC53825F0C930750061744E5E003D313D9A&lt;/a&gt;&lt;/blockquote&gt;&lt;a class="moz-txt-link-freetext" href="http://info.prevx.com/aboutprogramtext.asp?PX5=AFC4ACC53825F0C930750061744E5E003D313D9A"&gt;&lt;/a&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/_Caib4Z3bhg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/_Caib4Z3bhg/rjmtjpexe-d54d475125f7f6aa48d42f3f11221.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/rjmtjpexe-d54d475125f7f6aa48d42f3f11221.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-2149463294423189617</guid><pubDate>Wed, 13 Feb 2008 15:56:00 +0000</pubDate><atom:updated>2008-02-13T21:23:29.166-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>Setup.exe - dd13a676ffee2688d9046c3084362feb</title><description>&lt;pre wrap=""&gt;&lt;br /&gt;* name: Setup.exe&lt;br /&gt;* size: 58794&lt;br /&gt;* md5.: dd13a676ffee2688d9046c3084362feb&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;AntiVir 7.6.0.65/20080213 found [WORM/P2P.Kapucen.Gen]&lt;br /&gt;Authentium 4.93.8/20080213 found [W32/Kapucen.gen1@p2p]&lt;br /&gt;Avast 4.7.1098.0/20080213 found [Win32:Kapucen]&lt;br /&gt;AVG 7.5.0.516/20080213 found [Win32/Puce.C]&lt;br /&gt;BitDefender 7.2/20080213 found [Win32.Worm.P2P.Puce.G]&lt;br /&gt;CAT-QuickHeal None/20080213 found [I-Worm.Kapucen.b]&lt;br /&gt;ClamAV 0.92/20080213 found [Worm.Puce.E]&lt;br /&gt;DrWeb 4.44.0.09170/20080213 found [Win32.HLLW.Puce]&lt;br /&gt;eTrust-Vet 31.3.5532/20080212 found [Win32/Puce.D]&lt;br /&gt;F-Prot 4.4.2.54/20080212 found [W32/Kapucen.gen1@p2p]&lt;br /&gt;F-Secure 6.70.13260.0/20080213 found [P2P-Worm.Win32.Kapucen.b]&lt;br /&gt;Fortinet 3.14.0.0/20080213 found [W32/Kapucen.B!worm.p2p]&lt;br /&gt;Ikarus T3.1.1.20/20080213 found [P2P-Worm.Win32.Kapucen.b]&lt;br /&gt;Kaspersky 7.0.0.125/20080213 found [P2P-Worm.Win32.Kapucen.b]&lt;br /&gt;McAfee 5228/20080212 found [W32/Puce]&lt;br /&gt;Microsoft 1.3204/20080213 found [Worm:Win32/Puce.Y]&lt;br /&gt;NOD32v2 2872/20080213 found [Win32/Kapucen.B]&lt;br /&gt;Norman 5.80.02/20080212 found [Kapucen.A]&lt;br /&gt;Panda 9.0.0.4/20080213 found [W32/Puce.E.worm]&lt;br /&gt;Prevx1 V2/20080213 found [TROJAN.MUDROP.DU]&lt;br /&gt;Sophos 4.26.0/20080213 found [W32/Puce-H]&lt;br /&gt;Symantec 10/20080213 found [W32.Ecup]&lt;br /&gt;VirusBuster 4.3.26:9/20080213 found [Worm.Kapucen.A]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080213 found [Worm.P2P.Kapucen.Gen]&lt;/blockquote&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/csVjwrpnEiM" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/csVjwrpnEiM/setupexe-dd13a676ffee2688d9046c3084362f.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/setupexe-dd13a676ffee2688d9046c3084362f.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-3728256379027600851</guid><pubDate>Tue, 12 Feb 2008 13:23:00 +0000</pubDate><atom:updated>2008-02-12T07:28:17.934-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>AcroIEHelper.dll - 32929bace82a07c26c1d3877176cb2a9</title><description>&lt;pre wrap=""&gt;&lt;blockquote&gt;* submitter: Milkdad&lt;br /&gt;* name: AcroIEHelper.dll&lt;br /&gt;* size: 227894&lt;br /&gt;* md5.: 32929bace82a07c26c1d3877176cb2a9&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;AntiVir 7.6.0.62/20080212 found [TR/Dldr.Delf.eqb.1]&lt;br /&gt;AVG 7.5.0.516/20080211 found [Downloader.Generic6.AICW]&lt;br /&gt;BitDefender 7.2/20080212 found [Trojan.Downloader.Codec.E]&lt;br /&gt;CAT-QuickHeal None/20080211 found [TrojanDownloader.Delf.eqb]&lt;br /&gt;F-Prot 4.4.2.54/20080211 found [W32/Banload.E.gen!Eldorado]&lt;br /&gt;F-Secure 6.70.13260.0/20080212 found [Trojan-Downloader.Win32.Delf.eqb]&lt;br /&gt;Fortinet 3.14.0.0/20080212 found [W32/Delf.EQB!tr.dldr]&lt;br /&gt;Ikarus T3.1.1.20/20080212 found [Trojan-Downloader.Delf.OGX]&lt;br /&gt;Kaspersky 7.0.0.125/20080212 found [Trojan-Downloader.Win32.Delf.eqb]&lt;br /&gt;Microsoft 1.3204/20080211 found [Trojan:Win32/Delflob.I]&lt;br /&gt;Prevx1 V2/20080212 found [Generic.Malware]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080212 found [Trojan.Dldr.Delf.eqb.1]&lt;br /&gt;&lt;br /&gt;packers: ASPack&lt;/blockquote&gt;Av's that added because of your submission:&lt;br /&gt;&lt;br /&gt;Avira: &lt;span&gt;TR/Dldr.Delf.eqb.1&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/uaZh5udGAfM" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/uaZh5udGAfM/acroiehelperdll-32929bace82a07c26c1d387.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/acroiehelperdll-32929bace82a07c26c1d387.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-1261525220147635907</guid><pubDate>Tue, 12 Feb 2008 03:12:00 +0000</pubDate><atom:updated>2008-02-12T07:03:27.577-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">arbor networks</category><category domain="http://www.blogger.com/atom/ns#">storm</category><category domain="http://www.blogger.com/atom/ns#">bots</category><title>And so it begins.....</title><description>The new wave of storm is flowing just in time for Valentines.  At the time of this post I've only recieved 3 emails for it and I imagine a lot more to come.&lt;br /&gt;&lt;br /&gt;The first with the subject  "Phone Love" and  a body that simply contained the following:&lt;blockquote&gt; Love Machine http:// 24.131.212.16/&lt;/blockquote&gt;&lt;br /&gt;I of course went to the page to get the newest version and this was the image I found              &lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_6YaiYD4nLk4/R7ERaE5PljI/AAAAAAAAAAQ/_IkhkzSFJFQ/s1600-h/storm-val3.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_6YaiYD4nLk4/R7ERaE5PljI/AAAAAAAAAAQ/_IkhkzSFJFQ/s320/storm-val3.gif" alt="" id="BLOGGER_PHOTO_ID_5165929387258779186" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_6YaiYD4nLk4/R7EUOk5PlkI/AAAAAAAAAAY/BaRhZOKsMKk/s1600-h/storm-val2.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_6YaiYD4nLk4/R7EUOk5PlkI/AAAAAAAAAAY/BaRhZOKsMKk/s320/storm-val2.gif" alt="" id="BLOGGER_PHOTO_ID_5165932488225166914" border="0" /&gt;&lt;/a&gt;&lt;/div&gt; Onto the next one I received:&lt;br /&gt;Subject: Valentine Invitation&lt;br /&gt;Body:    &lt;div style="text-align: left;"&gt;&lt;blockquote&gt;Happy Valentine's Day! http://  200.75.106.166  &lt;/blockquote&gt;&lt;br /&gt;&lt;---And yet another pretty pic            Now for the third: &lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_6YaiYD4nLk4/R7EVBU5PllI/AAAAAAAAAAg/AleQW_L_eME/s1600-h/storm-val.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_6YaiYD4nLk4/R7EVBU5PllI/AAAAAAAAAAg/AleQW_L_eME/s320/storm-val.gif" alt="" id="BLOGGER_PHOTO_ID_5165933360103528018" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;Subject: Be My Valentine&lt;br /&gt;Body:  &lt;blockquote&gt;Valentine Friends http:// 59.92.53.16/&lt;/blockquote&gt;&lt;br /&gt;Ahh another pretty pic, reminds me a elementary school.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;The ones thing all of the files have in common is no detection at the time of the post!&lt;br /&gt;Be very careful opening any valentines emails that you receive they could be more trouble than you ever wanted.&lt;br /&gt;&lt;br /&gt;http:// 24.131.212.16/    - valentine.exe MD5: d1789d5bbc74bcf4def368f9b9db303e&lt;br /&gt;http://  200.75.106.166/ - valentine.exe MD5: 8ef7be6c05aca940b1e9cf677d471a41&lt;br /&gt;http:// 59.92.53.16/        - valentine.exe MD5: 74ca598169f8fdee49d04e22c8ac7514&lt;br /&gt;&lt;br /&gt;While I was writing this I received another one but it seems to be dead already. Here is the info from it.&lt;br /&gt;&lt;br /&gt;Subject: You're Super Sweet&lt;br /&gt;Body: &lt;blockquote&gt;Love Rose http:// 203.128.211.219/ &lt;/blockquote&gt;&lt;br /&gt;I've stayed away from the technical details here at least for now. Our friends over at asert.arbornetworks.com have posted some details check it out at:&lt;br /&gt;&lt;a href="http://asert.arbornetworks.com/2008/02/new-storm-valentines-day-campaign/"&gt;http://asert.arbornetworks.com/2008/02/new-storm-valentines-day-campaign/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Edit:&lt;br /&gt;&lt;br /&gt;Here's some more if the images:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_6YaiYD4nLk4/R7GXmk5PlmI/AAAAAAAAAAo/bfGaHUwA6N4/s1600-h/storm-val4.gif"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_6YaiYD4nLk4/R7GXmk5PlmI/AAAAAAAAAAo/bfGaHUwA6N4/s320/storm-val4.gif" alt="" id="BLOGGER_PHOTO_ID_5166076936565266018" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_6YaiYD4nLk4/R7GX305PlnI/AAAAAAAAAAw/Q21WTtRCRSA/s1600-h/storm-val6.gif"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_6YaiYD4nLk4/R7GX305PlnI/AAAAAAAAAAw/Q21WTtRCRSA/s320/storm-val6.gif" alt="" id="BLOGGER_PHOTO_ID_5166077232918009458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_6YaiYD4nLk4/R7GYD05PloI/AAAAAAAAAA4/L0OVHeuCC8U/s1600-h/storm-val9.gif"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_6YaiYD4nLk4/R7GYD05PloI/AAAAAAAAAA4/L0OVHeuCC8U/s320/storm-val9.gif" alt="" id="BLOGGER_PHOTO_ID_5166077439076439682" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_6YaiYD4nLk4/R7GYKU5PlpI/AAAAAAAAABA/yPF48g3kPtg/s1600-h/storm-val11.gif"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_6YaiYD4nLk4/R7GYKU5PlpI/AAAAAAAAABA/yPF48g3kPtg/s320/storm-val11.gif" alt="" id="BLOGGER_PHOTO_ID_5166077550745589394" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;More subject lines and bodies:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Just you: Rockin' Valentine http:// 71.156.93.100/&lt;br /&gt;Rockin' Valentine: My Love http:// 65.34.217.24/&lt;br /&gt;Rockin' Valentine: Powerful Love http:// 58.63.155.16/&lt;br /&gt;My Heart: World Love http:// 76.68.144.52/ &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Safe surfing!&lt;br /&gt;Uploadmalware.com&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/skvp9ua2NYk" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/skvp9ua2NYk/and-so-it-begins.html</link><author>noreply@blogger.com (UploadMalware.com)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_6YaiYD4nLk4/R7ERaE5PljI/AAAAAAAAAAQ/_IkhkzSFJFQ/s72-c/storm-val3.gif" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/and-so-it-begins.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-4851185121591932729</guid><pubDate>Tue, 12 Feb 2008 03:02:00 +0000</pubDate><atom:updated>2008-02-11T21:07:39.119-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">asert</category><category domain="http://www.blogger.com/atom/ns#">arbor networks</category><category domain="http://www.blogger.com/atom/ns#">bots</category><title /><description>The Mega-D botnet that everyone was led to believe was so huge apparently isn't according to a recent blog post at asert.arbornetworks.com&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;&lt;a href="http://asert.arbornetworks.com/2008/02/secureworks-ozdokmega-d-trojan-analysis/" rel="bookmark" title="Permanent Link: SecureWorks: Ozdok/Mega-D Trojan Analysis"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;blockquote&gt;&lt;h2&gt;&lt;a href="http://asert.arbornetworks.com/2008/02/secureworks-ozdokmega-d-trojan-analysis/" rel="bookmark" title="Permanent Link: SecureWorks: Ozdok/Mega-D Trojan Analysis"&gt;SecureWorks: Ozdok/Mega-D Trojan Analysis&lt;/a&gt;&lt;/h2&gt;    &lt;small&gt;by Danny McPherson &lt;/small&gt;           &lt;p&gt;Enabled by some spam samples &lt;a onclick="javascript:urchinTracker ('/outgoing/www.marshal.com/');" href="http://www.marshal.com/" title="Marshal"&gt;Marshal&lt;/a&gt; provided, Joe Stewart and the good folks &lt;a onclick="javascript:urchinTracker ('/outgoing/www.secureworks.com/research/blog/');" href="http://www.secureworks.com/research/blog/" title="SecureWorks Research"&gt;@SecureWorks&lt;/a&gt;, with an assist from &lt;a onclick="javascript:urchinTracker ('/outgoing/www.cymru.com');" href="http://www.cymru.com/" title="Team Cymru"&gt;Team Cymru&lt;/a&gt; and &lt;a onclick="javascript:urchinTracker ('/outgoing/www.mynetwatchman.com/');" href="http://www.mynetwatchman.com/" title="my|NetWatchman"&gt;my|NetWatchman&lt;/a&gt;, have identified the malware and botnet referred to as Mega-D.&lt;/p&gt; &lt;p&gt;It turns out Mega-D is composed of bots from the little-known Ozdok malware family.  Joe provides &lt;a onclick="javascript:urchinTracker ('/outgoing/www.secureworks.com/research/threats/ozdok/?threat=ozdok');" href="http://www.secureworks.com/research/threats/ozdok/?threat=ozdok" title="SecureWorks Ozdok Trojan Analysis"&gt;some analysis on scale and distribution of the botnet here&lt;/a&gt;, as well as some detailed bits on behaviors of the Trojan itself.&lt;/p&gt; &lt;p&gt;Based solely on the hostnames provided in the analysis we (Jose, actually) was able to find three samples in our database, with dates all well over a year old:&lt;/p&gt;&lt;/blockquote&gt;&lt;br /&gt;Read the full story at the link below.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://asert.arbornetworks.com/2008/02/secureworks-ozdokmega-d-trojan-analysis/"&gt;http://asert.arbornetworks.com/2008/02/secureworks-ozdokmega-d-trojan-analysis/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/RbH9uX69zgw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/RbH9uX69zgw/mega-d-botnet-that-everyone-was-led-to.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/mega-d-botnet-that-everyone-was-led-to.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-3988004953857744058</guid><pubDate>Tue, 12 Feb 2008 02:10:00 +0000</pubDate><atom:updated>2008-02-11T20:18:43.202-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>video.exe - 9f36a92add503d6c08a97d5dc0d5eb8c</title><description>&lt;pre wrap=""&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;* name: video.exe&lt;br /&gt;* size: 91831&lt;br /&gt;* md5.: 9f36a92add503d6c08a97d5dc0d5eb8c&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;AntiVir 7.6.0.62/20080208 found [TR/Dropper.Gen]&lt;br /&gt;eSafe 7.0.15.0/20080128 found [suspicious Trojan/Worm]&lt;br /&gt;Ikarus T3.1.1.20/20080210 found [Trojan-Spy.Win32.Banker.caw]&lt;br /&gt;Panda 9.0.0.4/20080209 found [Suspicious file]&lt;br /&gt;VBA32 3.12.6.0/20080209 found [suspected of Trojan-IM.VB.1 (paranoid heuristics)]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080209 found [Trojan.Dropper.Gen]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;packers: UPX_LZMA&lt;/blockquote&gt;AV's that added because of your submission:&lt;br /&gt;&lt;br /&gt;Trojan-Downloader.Win32.Banload.hjl&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/kT78fS-uDHY" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/kT78fS-uDHY/videoexe-9f36a92add503d6c08a97d5dc0d5eb.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/videoexe-9f36a92add503d6c08a97d5dc0d5eb.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-2255672847951340325</guid><pubDate>Tue, 12 Feb 2008 02:00:00 +0000</pubDate><atom:updated>2008-02-11T20:19:26.578-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>album_leticia.exe - 532c3c5674bb03464d4d990c291d8a14</title><description>&lt;pre wrap=""&gt;&lt;br /&gt;&lt;blockquote&gt;* name: album_leticia.exe&lt;br /&gt;* size: 14794&lt;br /&gt;* md5.: 532c3c5674bb03464d4d990c291d8a14&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;ClamAV 0.92/20080210 found [Trojan.Downloader-13210]&lt;br /&gt;Rising 20.29.22.00/20080130 found [Trojan.DL.Win32.Agent.ejs]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080210 found [Virus.Win32.FileInfector.gen!90 (suspicious)]&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;AV's that added based on your submission:&lt;br /&gt;&lt;br /&gt;Avira Lab: &lt;span&gt;TR/Dldr.Agent.iwf&lt;/span&gt;&lt;br /&gt;Kaspersky: Trojan-Downloader.Win32.Agent.iwf&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/XvwsDU0B99c" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/XvwsDU0B99c/albumleticiaexe-532c3c5674bb03464d4d990.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/albumleticiaexe-532c3c5674bb03464d4d990.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-430714518456561881</guid><pubDate>Tue, 12 Feb 2008 01:45:00 +0000</pubDate><atom:updated>2008-02-11T20:19:58.436-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>elxxfghg.dll- 227f6af6fb4ae8063b5f7348fd9694ee</title><description>&lt;pre wrap=""&gt;&lt;br /&gt;* name: elxxfghg.dll&lt;br /&gt;* size: 80084 bytes&lt;br /&gt;* md5.: 227f6af6fb4ae8063b5f7348fd9694ee&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;AntiVir 7.6.0.62/20080210 found [TR/Dldr.ConHook.Gen]&lt;br /&gt;Avast 4.7.1098.0/20080210 found [Win32:TratBHO]&lt;br /&gt;AVG 7.5.0.516/20080210 found [Lop]&lt;br /&gt;BitDefender 7.2/20080210 found [Trojan.Vundo.DYM]&lt;br /&gt;DrWeb 4.44.0.09170/20080210 found [Trojan.Virtumod.272]&lt;br /&gt;eTrust-Vet 31.3.5522/20080208 found [Win32/Vundo.MO]&lt;br /&gt;F-Prot 4.4.2.54/20080210 found [W32/Virtumonde.G.gen!Eldorado]&lt;br /&gt;Ikarus T3.1.1.20/20080210 found [not-a-virus:AdWare.Win32.Virtumonde]&lt;br /&gt;Kaspersky 7.0.0.125/20080210 found [not-a-virus:AdWare.Win32.Virtumonde.gen]&lt;br /&gt;Microsoft 1.3204/20080210 found [Trojan:Win32/Vundo.gen!A]&lt;br /&gt;Norman 5.80.02/20080208 found [W32/Virtumonde.KYQ]&lt;br /&gt;Panda 9.0.0.4/20080210 found [Suspicious file]&lt;br /&gt;Sophos 4.26.0/20080210 found [Troj/Virtum-Gen]&lt;br /&gt;Symantec 10/20080210 found [Trojan.Adclicker]&lt;br /&gt;TheHacker 6.2.9.215/20080209 found [Adware/Virtumonde.gen]&lt;br /&gt;VirusBuster 4.3.26:9/20080210 found [Adware.Vundo.V.Gen]&lt;br /&gt;Webwasher-Gateway 6.6.2/20080210 found [Trojan.Dldr.ConHook.Gen]&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/_2TlxspQjs0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/_2TlxspQjs0/elxxfghgdll-227f6af6fb4ae8063b5f7348fd9.html</link><author>noreply@blogger.com (UploadMalware.com)</author><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/elxxfghgdll-227f6af6fb4ae8063b5f7348fd9.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-998126536543068874</guid><pubDate>Tue, 12 Feb 2008 01:38:00 +0000</pubDate><atom:updated>2008-02-12T09:54:48.955-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">submitted</category><title>sbsm.exe - ead7b53b7a67d39dfe74ff6fe981d389</title><description>&lt;pre wrap=""&gt;* size: 2759 bytes&lt;br /&gt;* md5.: ead7b53b7a67d39dfe74ff6fe981d389&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;AVG 7.5.0.516/20080211 found [Downloader.Zlob]&lt;br /&gt;F-Secure 6.70.13260.0/20080211 found [Trojan-Downloader.Win32.Zlob.hku]&lt;br /&gt;Kaspersky 7.0.0.125/20080211 found [Trojan-Downloader.Win32.Zlob.hku]&lt;br /&gt;NOD32v2 2865/20080211 found [Win32/TrojanDownloader.Zlob.BPH]&lt;br /&gt;Prevx1 V2/20080211 found [Downloader.Zlob]&lt;br /&gt;Symantec 10/20080211 found [Trojan.Startpage]&lt;br /&gt;VirusBuster 4.3.26:9/20080211 found [Trojan.DL.Zlob.Gen.34]&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Edit 1: Added by Ikarus as Virus.Win32.Zlob.AJV&lt;br /&gt;Edit 2: Added by Avira as &lt;span&gt;TR/Dldr.Zlob.hku&lt;/span&gt;&lt;br /&gt;Edit 3: Added by DrWeb as Virus: Trojan.Popuper&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/wW50fDxEySY" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/wW50fDxEySY/sbsmexe-ead7b53b7a67d39dfe74ff6fe981d38.html</link><author>noreply@blogger.com (UploadMalware.com)</author><feedburner:origLink>http://uploadmalware.blogspot.com/2008/02/sbsmexe-ead7b53b7a67d39dfe74ff6fe981d38.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-166393339978616430.post-5959374792645557593</guid><pubDate>Mon, 09 Jul 2007 00:16:00 +0000</pubDate><atom:updated>2007-07-09T15:47:07.433-05:00</atom:updated><title>New Nuwar</title><description>Yet another new set of Nuwar (storm worm) spam mails are coming out. Be on the look out for emails like the following:&lt;br /&gt;&lt;blockquote&gt;   Dear Customer,&lt;br /&gt;&lt;br /&gt;Our robot has detected an abnormal activity from your IP adress&lt;br /&gt;on sending e-mails. Probably it is connected with the last epidemic&lt;br /&gt;of a worm which does not have official patches at the moment.&lt;br /&gt;&lt;br /&gt;We recommend you &lt;a href="http://link-removed-for-security/"&gt;to install this patch&lt;/a&gt; to remove worm files&lt;br /&gt;and stop email sending, otherwise your account will be blocked.&lt;br /&gt;&lt;br /&gt;Customer Support Robot&lt;/blockquote&gt;&lt;blockquote&gt;&lt;/blockquote&gt;The downloaded executable is named "patch.exe"&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;****URLS BELOW ARE POSTED FOR RESEARCH PURPOSES ONLY VISIT AT YOUR OWN RISK****&lt;br /&gt;&lt;/div&gt;Worm Detected!&lt;br /&gt;Customer Support Center&lt;br /&gt;nrp @  eyou.com&lt;br /&gt;http://  74.227.240.152/  ?a3b01bdad81d9b848ca9a8&lt;br /&gt;&lt;br /&gt;Worm Activity Detected!&lt;br /&gt;Customer Support&lt;br /&gt;qof @ calgarypolice.ca&lt;br /&gt;http://  66.31.89.82/  ?2989907cd64e28cae3d7703a3b01bdad81d9b&lt;br /&gt;&lt;br /&gt;Spyware Alert!&lt;br /&gt;Customer Support Robot&lt;br /&gt;vyjig @ kbhr933.com&lt;br /&gt;http://  203.192.225.72/  ?b161d496d2989907cd64e28cae3d7703a3b01bd&lt;br /&gt;&lt;br /&gt;Spyware Detected!&lt;br /&gt;Customer Support Robot&lt;br /&gt;vyjig @ kbhr933.com&lt;br /&gt;http://  76.24.0.216/  ?8ee7c634591933434671c1&lt;br /&gt;&lt;br /&gt;Trojan Alert!&lt;br /&gt;Administrator&lt;br /&gt;aupl @ nyc.rr.com&lt;br /&gt;http://  69.177.200.82/  ?1c8a8aa50bb1c20bb5790c08a823e9627257&lt;br /&gt;&lt;br /&gt;Malware Alert!&lt;br /&gt;Customer Support Robot&lt;br /&gt;xas @ evercell.com&lt;br /&gt;http://  81.48.51.112/  ?8a823e96272575cbc68911e6c36a4bc9&lt;br /&gt;&lt;br /&gt;Virus Activity Detected!&lt;br /&gt;Mailer-Deamon&lt;br /&gt;bij @ fibertel.com.ar&lt;br /&gt;http://  76.83.102.143/  ?8088aea28abd4d55393e4dd7ae5b23933&lt;br /&gt;&lt;br /&gt;ATTN!&lt;br /&gt;Customer Support Center Robot&lt;br /&gt;gal @ madbrands.com&lt;br /&gt;http://  66.68.92.35/  ?e7c634591933434671c16a2e59b1283bd17061a&lt;br /&gt;&lt;br /&gt;Worm Alert!&lt;br /&gt;Administrator&lt;br /&gt;djn @ lge.com&lt;br /&gt;http://  81.236.145.163/  ?58e47d14c775ed2175ee0c2a4c1c8a8aa50&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;div style="text-align: center;"&gt;****URLS ABOVE ARE POSTED FOR RESEARCH PURPOSES ONLY VISIT AT YOUR OWN RISK****&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;script expr:src='"http://feeds.feedburner.com/~s/UploadmalwarecomsMalwareBlog?i=" + data:post.url' type="text/javascript" charset="utf-8"&gt;&lt;/script&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/UploadmalwarecomsMalwareBlog/~4/iJC1YE3U9HI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/UploadmalwarecomsMalwareBlog/~3/iJC1YE3U9HI/new-nuwar.html</link><author>noreply@blogger.com (UploadMalware.com)</author><thr:total>0</thr:total><feedburner:origLink>http://uploadmalware.blogspot.com/2007/07/new-nuwar.html</feedburner:origLink></item></channel></rss>
