Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 27th, 2002, 08:03 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,719
Default mswin.exe

Someone sent me a file called mswin.exe.
On his computer it tried to gain internet access at startup.
The file name and the registry-entry HKCU\Software\Microsoft\WindowsNT\CurrentVersion\Windows\Run\mswin seem to indicate Backdoor.Dumba but NAV didnīt find it, although it should be in their definitions.

Any ideas on this one?

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #2  
Old October 27th, 2002, 08:33 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:mswin.exe

Pieter,

NAV certainly should cover both backdoor.Dumba and Trojan.Dumba.

I suggest putting up the file for a (free) check on both KAV/AVP and Dr.Web; links available on our free services page. The person infected could run a free system check (Panda, Trend) over there as well.

Apart from that, NAV is an antivirus. I would recommend installing a trial version from TDS, update de signatures (radius) by grabbing the latest radius file here, overwriting the existing ones, and perform a full system scan.

Keep us posted!

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #3  
Old October 27th, 2002, 08:33 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,719
Default Re:mswin.exe

A little more info about this one: the file was offered for download as DIVX 2003 from BBShareware.com

Paul, I missed your post
The person I got it from had removed DIVX 2003 some time ago. On my advise he deleted the registry entry, the file has been quarantained and submitted to SARC
I certainly will keep you posted.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #4  
Old October 27th, 2002, 08:43 AM
anders anders is offline
Eset Moderator
 
Join Date: Oct 2002
Posts: 410
Default Re:mswin.exe

Feel free to send me the file via email to support@ eurosecure.com and I'll check it out.

Regards,
Anders
__________________
Best regards,
Anders
nod32 antivirus
  #5  
Old October 27th, 2002, 08:45 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:mswin.exe

Quote:
quoting: anders link=board=30;threadid=4464;start=0#29146 date=1035726228]
Feel free to send me the file via email to support@ eurosecure.com and I'll check it out.

Regards,
Anders

Talking about service...

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #6  
Old October 27th, 2002, 08:56 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,719
Default Re:mswin.exe

Itīs on itīs way Anders. Thnx for the offer.

I submitted them to the scans Paul suggested.
On DrWeb it came up suspicious, KAV could not find anything wrong with it.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #7  
Old October 27th, 2002, 09:50 AM
anders anders is offline
Eset Moderator
 
Join Date: Oct 2002
Posts: 410
Default Re:mswin.exe

Seems to be a dropper for an IRC-backdoor. I didn't check it THAT throughly. It will be further analyzed and if needed added to the NOD32 database.

If you ever get any other suspicious files, don't hesitate to send them...

Regards,
Anders
EuroSecure
__________________
Best regards,
Anders
nod32 antivirus
  #8  
Old October 27th, 2002, 09:58 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,719
Default Re:mswin.exe

Quote:
quoting: anders link=board=30;threadid=4464;start=0#29155 date=1035730218]
If you ever get any other suspicious files, don't hesitate to send them...
With this kind of service? Iīd be a fool not to send them.

Thnx again,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #9  
Old October 27th, 2002, 10:52 AM
Caspar107's Avatar
Caspar107 Caspar107 is offline
Infrequent Poster
 
Join Date: Oct 2002
Location: Apeldoorn, Netherlands
Posts: 25
Default Re:mswin.exe

Thanks guys, I'm the person with the mswin.exe firewall alert, so I'll keep an eye on this topic.
  #10  
Old October 27th, 2002, 12:38 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:mswin.exe

Quote:
quoting: Caspar107 link=board=30;threadid=4464;start=0#29168 date=1035733972]
Thanks guys, I'm the person with the mswin.exe firewall alert, so I'll keep an eye on this topic.

Well Caspar, you ended up on the right place here! . Welcome.

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #11  
Old October 28th, 2002, 11:30 AM
anders anders is offline
Eset Moderator
 
Join Date: Oct 2002
Posts: 410
Default Re:mswin.exe

FYI, that file is now detected by NOD32 as Win32/IRC.Dix.A.

And, I can't stress it enough, don't hesitate to send me any suspicious files.

Regards,
Anders
EuroSecure
__________________
Best regards,
Anders
nod32 antivirus
  #12  
Old October 28th, 2002, 11:36 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,719
Default Re:mswin.exe

Quote:
quoting: anders link=board=30;threadid=4464;start=0#29345 date=1035822607]
FYI, that file is now detected by NOD32 as Win32/IRC.Dix.A.

And, I can't stress it enough, don't hesitate to send me any suspicious files.

Thanks again anders and what I don't trust is all yours

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #13  
Old October 29th, 2002, 09:25 AM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re:mswin.exe

Please let me have a copy just in case, submit@diamondcs.com.au

thx
  #14  
Old October 29th, 2002, 09:28 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,719
Default Re:mswin.exe

Quote:
quoting: Gavin / DiamondCS link=board=30;threadid=4464;start=0#29515 date=1035901501]
Please let me have a copy just in case, submit@diamondcs.com.au

thx

I'll do that tonight Gavin, if that's OK. (in about 5 hours, keep forgetting time- zones )

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #15  
Old October 29th, 2002, 02:34 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,719
Default Re:mswin.exe

Gavin,

Iīm sorry to tell you that I canīt send you the file. Iīm pretty sure I copied the file from my attachments folder to a safe place before I sent it to Anders and SARC. But the copy in the attachments folders is gone which was to be expected, since I put it in quarantaine before I sent it to SARC.
But unfortunately the copy is gone as well

BTW This is the answer from SARC:

quote

resultaat: Dit bestand is geïnfecteerd met Trojan.Dumba
This file is infected with Trojan.Dumba
opmerkingen van Symantec Security Response-medewerker:
remarks by SSR-employee
C:\Program Files\IncrediMail\Data\Identities\{50AE2311-B53A-4AED-84F7-43F56DA0449F}\Message Store\Attachments\mswin.exe is a non-repairable threat. It is detected by NAV after an update using the attached definition updater. Please delete this file and replace it if neccessary.

unquote

Well at least I got the 29-10 update by e-mail
Maybe Anders would be so kind to send you his copy?

Sorry,

Pieter

__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #16  
Old October 29th, 2002, 02:46 PM
Caspar107's Avatar
Caspar107 Caspar107 is offline
Infrequent Poster
 
Join Date: Oct 2002
Location: Apeldoorn, Netherlands
Posts: 25
Default Re:mswin.exe

So now it's detected by NAV? I can have a look on the site where I downloaded the file, it's on a so called warez site
I'll check it out
  #17  
Old October 29th, 2002, 02:52 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,719
Default Re:mswin.exe

Caspar107,

Please be carefull in doing so. Symantec claimed it to be Trojan.Dumba which was in their definitions al along.
Besides that: they e-mailed me the update for the 29th which is not available for download yet.
[EDIT] Is available now [/EDIT]

Take care,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #18  
Old October 29th, 2002, 02:56 PM
Caspar107's Avatar
Caspar107 Caspar107 is offline
Infrequent Poster
 
Join Date: Oct 2002
Location: Apeldoorn, Netherlands
Posts: 25
Default Re:mswin.exe

It's a zipped file, but I looked on the site and............ it's not there anymore , that's better!

But it's detected now with the latest ref of NAV? LiveUpdate? Because mine stands at 28-10, and no more updates available
  #19  
Old October 29th, 2002, 02:59 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,719
Default Re:mswin.exe

Direct download link:

http://www.symantec.com/avcenter/download/us-files/20021029-003-i32.exe

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #20  
Old October 29th, 2002, 03:04 PM
Caspar107's Avatar
Caspar107 Caspar107 is offline
Infrequent Poster
 
Join Date: Oct 2002
Location: Apeldoorn, Netherlands
Posts: 25
Default Re:mswin.exe

Got it from the Helpmij NAV update topic, recieve automatic email

But I still don't get it why NAV did not detect it while it was a known trojan? Or is the difference now that it was a so called "dropper" wich is not detected as a part of it?
  #21  
Old October 29th, 2002, 03:08 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,719
Default Re:mswin.exe

Not quite sure about that. Maybe Anders can answer that. Heīs the one that took it apart to see what made it tick

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #22  
Old October 29th, 2002, 07:18 PM
anders anders is offline
Eset Moderator
 
Join Date: Oct 2002
Posts: 410
Default Re:mswin.exe

Symantecs Dumba description somewhat matches this file. I assume this is another variant of the file they detected already, and, as they received the sample, they added detection for it.

Regards,
Anders
EuroSecure
__________________
Best regards,
Anders
nod32 antivirus
  #23  
Old October 30th, 2002, 01:04 AM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re:mswin.exe

Got a copy, thanks everyone - don't hesitate to send me suspicious samples either
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:08 AM.


Powered by vBulletinŪ Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright Đ2002 - 2013, Wilders Security Forums