Wilders Security Forums  

Go Back   Wilders Security Forums > Official BrightFort Forum > SpywareBlaster & Other Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 29th, 2012, 09:24 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,854
Thumbs up CLSID's for the sKyWIper infection

Be nice if someone could provide them for the following OCX's to manually include in SB

advnetcfg.ocx - bb5441af1e1741fca600e9c433cb1550
msglu32.ocx - d53b39fb50841ff163f6e9cfd8b52c2e
mssecmgr.ocx - bdc9e04388bda8527b398a8c34667e18
nteps32.ocx - c9e00c9d94d1a790d5923b050b0bd741
soapr32.ocx - 296e04abb00ea5f18ba021c34e486746

And others that appear
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #2  
Old May 31st, 2012, 06:32 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,854
Lightbulb Re: CLSID's for the sKyWIper infection

I managed to find 2 to include

CLSID (6994AD04-93EF-11D0-A3CC-00A0C9223196)

CLSID (6994AD04-93EF-11D0-A3CC-00A0C9223196)

Courtesy of - http://blog.fireeye.com/research/201...-analysis.html
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #3  
Old June 1st, 2012, 02:30 AM
redwolfe_98's Avatar
redwolfe_98 redwolfe_98 is offline
Frequent Poster
 
Join Date: Feb 2002
Location: South Carolina, USA
Posts: 518
Default Re: CLSID's for the sKyWIper infection

cloneranger, adding activex-killbits for the activex controls that are used by "skywiper" is a good idea.. however, as far as the two CLSID's that you associated with "skywiper", first, the two CLSID's that you listed actually are the same CLSID, so you actually only have one CLSID listed.. second, the CLSID that you cited appears to be a legitimate CLSID that shouldn't be blocked..

here is what google pulled up for the CLSID:

http://www.google.com/search?num=20&...6}&btnG=Search
__________________
win xpsp3, "windows firewall", avira 12 premium, SSM, RegDefend

Last edited by redwolfe_98 : June 1st, 2012 at 05:33 AM.
  #4  
Old June 1st, 2012, 11:58 AM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,854
Default Re: CLSID's for the sKyWIper infection

@ redwolfe_98

Quote:
adding activex-killbits for the activex controls that are used by "skywiper" is a good idea..


Thanks

Quote:
however, as far as the two CLSID's that you associated with "skywiper", first, the two CLSID's that you listed actually are the same CLSID, so you actually only have one CLSID listed..

Oops, my bad so it is ! Thanks

Quote:
second, the CLSID that you cited appears to be a legitimate CLSID that shouldn't be blocked..

In the - http://blog.fireeye - link i posted, it says this,

Quote:
CLSID (6994AD04-93EF-11D0-A3CC-00A0C9223196) appears to be the Audio GUID for the KS Media sound card driver, as published by ReactOS, which is supposed to be binary compatible with Microsoft Windows. The malware performs these registry key additions as part of its ability to record audio from the compromised system's microphone.

So as it's a ReactOS .DRV i wouldn't have expected many people, if at all, to have it. In which case my thinking was, blocking it via the CLSID trick wouldn't be a problem ! If this isn't the case ? i'm sorry for any inconvenience. Just thought these CLSID's tricks "might" help. Anyway, if the CLSID (6994AD04-93EF-11D0-A3CC-00A0C9223196) "is" a no go, the CLSID's for other ActiveX controls, if obtainable, would block the nasties, i'm sure.
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #5  
Old June 1st, 2012, 02:25 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,854
Lightbulb Re: CLSID's for the sKyWIper infection

Here's another which you "might" be able to make use of {0AFACED1-E828-11D1-9187-B532F1E9575D}

Quote:
Flamer uses some special tricks to bypass this behavior. Three CLSID entries are added to the ShellClassInfo section with a specially chosen CLSID.

http://www.symantec.com/connect/blog...s-and-exploits
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #6  
Old June 5th, 2012, 04:33 AM
redwolfe_98's Avatar
redwolfe_98 redwolfe_98 is offline
Frequent Poster
 
Join Date: Feb 2002
Location: South Carolina, USA
Posts: 518
Default Re: CLSID's for the sKyWIper infection

Quote:
Originally Posted by CloneRanger
Here's another which you "might" be able to make use of {0AFACED1-E828-11D1-9187-B532F1E9575D}

nope.. that CLSID, too, is legitimate and shouldn't be blocked..

i did a google-search for "{0AFACED1-E828-11D1-9187-B532F1E9575D}" and pulled up some information about it:

http://www.google.com/search?num=20&...=Google+Search

i also searched my computer's "registry" and found a couple of instances of the CLSID.. (i am running windows xp)..

sometimes, legitimate regkeys (or, in this case, a "CLSID") are associated with malware but are used for legitimate purposes, as well.. just because a regkey (or CLSID) was used by malware, that doesn't necessarily mean that the regkey, or CLSID, is malicious..
__________________
win xpsp3, "windows firewall", avira 12 premium, SSM, RegDefend

Last edited by redwolfe_98 : June 5th, 2012 at 11:29 AM.
  #7  
Old June 9th, 2012, 03:22 AM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,854
Default Re: CLSID's for the sKyWIper infection

@ redwolfe_98

Hi, ok thanks for the info No other CLSID's appearing for this ? Anyway the danger is probably over now, as most Anti's detect it one way or another. Plus it's started to delete itself

I guess it won't be the last we see of it though, in some form or another !
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
 

Wilders Security Forums > Official BrightFort Forum > SpywareBlaster & Other Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:55 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums