Not sure if this came up in the thread at U.Hall, but this trojan has now made its way onto ebay. I was bored tonight (or this morning, rather) and decided to see what things were selling on ebay. I go there and find these three programs:
*Links Removed by Admin*
I thought to myself, "These have got to be viruses." So I decided to download them (the seller so generously offers a seven day trial period

). The first sign of there being trouble was when all three programs had roughly the same file size (~498KB). So after completing the download (didn't take long) I ran them through some virus scanners. All three programs reported the same viruses.
http://virusscan.jotti.org/ reported the following which remained constant for all three programs:
Quote:
Status:
INFECTED/MALWARE
MD5 a5700e95fcd26f427eb6f53f70ac064b
Packers detected:
-
Scanner results
AntiVir
Found Heuristic/Trojan.Downloader (probable variant)
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found BehavesLike:Trojan.Downloader (probable variant)
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found Trojan-Downloader.Win32.Delf.abo
NOD32
Found probably unknown NewHeur_PE (probable variant)
Norman Virus Control
Found Sandbox: W32/Downloader; [ General information ]
* File length: 39936 bytes.
[ Changes to filesystem ]
* Creates file C:\WINDOWS\icq.exe.
[ Network services ]
* Downloads file from (This -> icq.doc <- was a virus that I removed the link for so as to hopefully avoid any accidental downloads. For more information on this file see my second post in this thread.) as C:\WINDOWS\icq.exe.
[ Security issues ]
* Starting downloaded file - potential security problem.
[ Process/window information ]
* Attemps to NULL C:\WINDOWS\icq.exe NULL.
UNA
Found nothing
VBA32
Found nothing
|
I really hope no one falls for this. It is bad enough to lose your account, but to unwillingly pay someone to take it from you?