W32/Induc

Discussion in 'Prevx Releases' started by Habakuck, Aug 21, 2009.

Thread Status:
Not open for further replies.
  1. Habakuck

    Habakuck Registered Member

    Joined:
    May 24, 2009
    Posts:
    544
    Hey PrevX Support.

    Is PrevX able to detect Induc in generally or only special infected files?

    What is about any patching virus? How is PrevX able to detect these files?

    I ask cause i didnt get any responds to the Induc sample i sent in...
     
  2. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We do detect a number of Induc samples but we saw only a small uptick in reports and then it has dropped down significantly. We're still monitoring the infection, however, but it looks like it was just seeded in a finite number of files.
     
  3. Habakuck

    Habakuck Registered Member

    Joined:
    May 24, 2009
    Posts:
    544
    Oh no!

    Induc is spreading widely.

    I would like to give just a few examples:

    QIP8095.exe:
    TidyFavorites:
    FinalUninstall_setup.exe:
    ANYTV_SETUP_2.4.1:
    Preispiraten 6:

    ~Multiple Virus Total links removed per Policy.~

    Glary Registry Repair:
    RegRepair:
    The GiveAwayOfTheDay Software is infected as well!
    http://de.giveawayoftheday.com/gold-audio-suite/
    http://www.soundeditingsoftware.net/

    And i could go on.

    There is no real damage caused by the virus but i think it should wake us all up!
    The infected files are ALL on the servers right now and they are infecting a lot of people!
    Thats an evidence of incapacity by companies like ComputerBild, Chip.de, GiveAway and many more.
    But also the AV companies should work on that problem.

    So my question was: Is PrevX only able to detect the flagt infected files or is it able to detect every zero-time file that is infected by Induc?
     
    Last edited by a moderator: Aug 22, 2009
  4. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We have a generic signature in place to block infected files but if you find anything which gets past us, please let us know :)
     
  5. Habakuck

    Habakuck Registered Member

    Joined:
    May 24, 2009
    Posts:
    544
    Ok. That aswers my question. :)

    I think the installers are quit difficult to detect but most of the unpacked infected files are beeing catched.
     
  6. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    The difficulty lies in the fact that the signature can appear anywhere within the program, thanks to the fact that the virus exists before the compilation happens :doubt:

    It is indeed a good technique (in a bad way) to use and I suspect we'll be seeing more like this in the future, possibly from the other high-level frameworks sooner because of their interdependency on linked runtimes.
     
  7. Habakuck

    Habakuck Registered Member

    Joined:
    May 24, 2009
    Posts:
    544
    The funniest story about Induc i found is that sophos has found Induc Code in other malicious files. So they consider that the malware authors got infected by induc too... ^^

    Bätsch... Serves them right! :D
     
  8. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    :D We see this a lot also - it's probably the purest form of real viruses when a virus and another virus combine to form a new one :)
     
  9. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    H1N1 to H1N2? Wish it was that easy to remove Human Viruses :ouch:

    TH
     
  10. Habakuck

    Habakuck Registered Member

    Joined:
    May 24, 2009
    Posts:
    544
    Oh yes!
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.