Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 15th, 2010, 05:59 PM
scitexia scitexia is offline
Infrequent Poster
 
Join Date: Apr 2010
Posts: 1
Default Shadow Defender Worm?

Had an interesting experience while installing Shadow Defender. Downloaded the file (32-bit) from their site (www.shadowdefender.com) and tried to install it. A-Squared AM told me that it was infected with a worm. Canceled the install and downloaded the file again. Same thing so I figured it was an FP and told it to install anyway.

After rebooting, Symantec Endpoint Security 12 (i have that installed too) immediately identified the trojan (presumably the same that A-Squared tried to warn me about earlier).

Sooo, after allowing SEP to quarantine it and uninstalling, I THEN went to cNet (www.download.com) and downloaded THEIR version and installed it. Guess what?? No worm and both A-Squared & SEP were quite happy.

Strange, huh?
  #2  
Old April 15th, 2010, 06:04 PM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Shadow Defender Worm?

what did each software tell you that was infected (file name(s)) and where was it/they located?
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #3  
Old April 15th, 2010, 08:34 PM
NoIos NoIos is offline
Frequent Poster
 
Join Date: Mar 2009
Posts: 607
Default Re: Shadow Defender Worm?

Compare the md5 hash of the files and tell us about the results.
  #4  
Old April 15th, 2010, 10:05 PM
Osaban's Avatar
Osaban Osaban is offline
Massive Poster
 
Join Date: Apr 2005
Posts: 3,093
Default Re: Shadow Defender Worm?

Quote:
Originally Posted by scitexia
Had an interesting experience while installing Shadow Defender. Downloaded the file (32-bit) from their site (www.shadowdefender.com) and tried to install it. A-Squared AM told me that it was infected with a worm. Canceled the install and downloaded the file again. Same thing so I figured it was an FP and told it to install anyway.

After rebooting, Symantec Endpoint Security 12 (i have that installed too) immediately identified the trojan (presumably the same that A-Squared tried to warn me about earlier).

Sooo, after allowing SEP to quarantine it and uninstalling, I THEN went to cNet (www.download.com) and downloaded THEIR version and installed it. Guess what?? No worm and both A-Squared & SEP were quite happy.

Strange, huh?

I've just scanned the Shadow Defender installer (from their website) with Avira Premium and found nothing. I agree it is strange.
__________________
Samsung Series 7 Chronos & Windows 8 (64bit)
“We are the cosmos made conscious and life is the means by which the universe understands itself.” Brian Cox
  #5  
Old April 15th, 2010, 10:42 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,614
Default Re: Shadow Defender Worm?

I tried to upload to VT and I keep getting errors so I tried Jotti and 2 scanners pick it as:

CP secure BackDoor.W32.Hupigon.jrud

Sophos Sus/Scribble-B

But that's it and the one from Download.com just Sophos Sus/Scribble-B

So that's strange! Mind you that jotti is outdated Feb 23 2010

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #6  
Old April 16th, 2010, 12:10 AM
Osaban's Avatar
Osaban Osaban is offline
Massive Poster
 
Join Date: Apr 2005
Posts: 3,093
Default Re: Shadow Defender Worm?

Quote:
Originally Posted by Triple Helix
I tried to upload to VT and I keep getting errors so I tried Jotti and 2 scanners pick it as:

CP secure BackDoor.W32.Hupigon.jrud

Sophos Sus/Scribble-B

But that's it and the one from Download.com just Sophos Sus/Scribble-B

So that's strange! Mind you that jotti is outdated Feb 23 2010

TH

I get the same results with Virus Total (errors) and same detections with Jotti. The MD5 and SHA1 are different though with the 2 installers.
__________________
Samsung Series 7 Chronos & Windows 8 (64bit)
“We are the cosmos made conscious and life is the means by which the universe understands itself.” Brian Cox
  #7  
Old April 16th, 2010, 12:36 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Shadow Defender Worm?

Hmmm, SD1.1.0.325_Setup.exe downloaded from authors site and SD1.1.0.325_Setup(2).exe downloaded from download.com?

Name:  SD.JPG
Views: 1262
Size:  19.1 KB
  #8  
Old April 16th, 2010, 02:09 PM
taleblou taleblou is offline
Frequent Poster
 
Join Date: Jan 2010
Posts: 302
Question Re: Shadow Defender Worm?

Hi:

I scanned it with a-squared and nothing detected. Also I managed to upload and scan it with virustotal the one from the shadow defender web site and virus total only found "1/40" (only Sophos detected). Here is the result of virus total. Must be a false positive.

~Virus Total results removed per Policy.~

( base data )
entrypointaddress.: 0x12226
timedatestamp.....: 0x4987F062 (Tue Feb 3 08:21:06 2009)
machinetype.......: 0x14C (Intel I386

Last edited by ronjor : April 16th, 2010 at 03:04 PM. Reason: VT results removed
  #9  
Old April 16th, 2010, 11:46 PM
LoneWolf's Avatar
LoneWolf LoneWolf is offline
Massive Poster
 
Join Date: Jan 2006
Posts: 3,133
Default Re: Shadow Defender Worm?

Quote:
Originally Posted by Franklin
Hmmm, SD1.1.0.325_Setup.exe downloaded from authors site and SD1.1.0.325_Setup(2).exe downloaded from download.com?

Attachment 217188

Waiting for confirmation on why over at SD forums........
http://www.shadowdefender.com/phpbb/....php?f=2&t=289
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness
  #10  
Old April 17th, 2010, 12:15 AM
Woody777 Woody777 is offline
Frequent Poster
 
Join Date: Aug 2006
Posts: 469
Default Re: Shadow Defender Worm?

I had exactly the same result when I downloaded the file previously. No alerts except with A2. Then I uninstalled. Immediately Threatfire indicated a worm a rootkit. Finally after sometime I got rid of it. I think there is a Worm in ShadowDefender but I can't say so for sure so it could be a FP.
  #11  
Old April 17th, 2010, 06:46 AM
Tony's Avatar
Tony Tony is offline
Frequent Poster
 
Join Date: Feb 2003
Location: Cumbria, England
Posts: 681
Default Re: Shadow Defender Worm?

No worm
http://www.shadowdefender.com/phpbb/...f=2&t=289#p997
__________________
Twister
ShadowDefender
SuperAntiSpyware Pro
Defensewall Personal Firewall
The legend that is FirstDefense-ISR

  #12  
Old September 1st, 2010, 10:50 AM
Smirs Smirs is offline
Infrequent Poster
 
Join Date: Mar 2007
Posts: 24
Default Re: Shadow Defender Worm?

Interesting how Prevx doesn't flag it as 'BackDoor.W32.Hupigon.jrud' or 'Sus/Scribble-B' but straight names it a ' Fraudulent Security Program '.
  #13  
Old September 1st, 2010, 12:00 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,614
Default Re: Shadow Defender Worm?

Quote:
Originally Posted by Smirs
Interesting how Prevx doesn't flag it as 'BackDoor.W32.Hupigon.jrud' or 'Sus/Scribble-B' but straight names it a ' Fraudulent Security Program '.

Prevx never pick this up as malware? Or are you saying it does for you?

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #14  
Old September 1st, 2010, 01:38 PM
Smirs Smirs is offline
Infrequent Poster
 
Join Date: Mar 2007
Posts: 24
Default Re: Shadow Defender Worm?

Quote:
Originally Posted by Triple Helix
Prevx never pick this up as malware? Or are you saying it does for you?

TH

Yes it picks up Shadow Defender (1.1.0.325) on my computer as malware;
Defender.exe MD5 69F211FC6E27F9AB715279E5FFC34F6E
  #15  
Old September 1st, 2010, 01:42 PM
Smirs Smirs is offline
Infrequent Poster
 
Join Date: Mar 2007
Posts: 24
Default Re: Shadow Defender Worm?

I uploaded the file to virus total, Prevx is the only one that flags it, ~ Virus Total Results Removed per Policy ~

Last edited by JRViejo : September 1st, 2010 at 02:32 PM. Reason: VirusTotal Results Removed - JRViejo
  #16  
Old September 1st, 2010, 06:48 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,614
Default Re: Shadow Defender Worm?

Quote:
Originally Posted by Smirs
I uploaded the file to virus total, Prevx is the only one that flags it, ~ Virus Total Results Removed per Policy ~

It doesn't on my machine and and VT still shows Sophos Sus/Scribble-B and my setup file is
SD1.1.0.325_Setup.exe MD5 : 4ed0f50233680ffc37fbe5cf8057c634 Also from my Prevx scan log: [u] (ACTIVE) c:\security programs folder\shadow defender folder\sd1.1.0.325_setup.exe [PX5: E443759160325FB96C54111D18404000A042BF29]
Name:  Capture01-09-2010-6.59.46 PM.jpg
Views: 594
Size:  51.0 KB Name:  Capture01-09-2010-7.01.55 PM.jpg
Views: 596
Size:  39.3 KB

So there could something with the setup file that you have because mine is fine! Do you have Prevx installed? If you do send a scan log and the setup file to Prevx as stated in this post: http://www.wilderssecurity.com/showthread.php?t=245129

TIA,

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.

Last edited by Triple Helix : September 1st, 2010 at 07:12 PM. Reason: added more info
  #17  
Old September 3rd, 2010, 10:27 AM
Smirs Smirs is offline
Infrequent Poster
 
Join Date: Mar 2007
Posts: 24
Default Re: Shadow Defender Worm?

Message sent. Thanks a lot for your support.
  #18  
Old September 3rd, 2010, 10:28 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: Shadow Defender Worm?

Quote:
Originally Posted by Smirs
I uploaded the file to virus total, Prevx is the only one that flags it

This was a false positive but we've corrected it now Shadow Defender is indeed legitimate, but the increasing number of rogues makes it hard for researchers to keep the line well defined
  #19  
Old September 3rd, 2010, 11:55 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,614
Default Re: Shadow Defender Worm?

Quote:
Originally Posted by PrevxHelp
This was a false positive but we've corrected it now Shadow Defender is indeed legitimate, but the increasing number of rogues makes it hard for researchers to keep the line well defined

Thanks for the confirmation!

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:37 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums