Svchelper.exe...probably unknown NewHeur_PE virus

Discussion in 'NOD32 version 2 Forum' started by hispanico, Jul 9, 2005.

Thread Status:
Not open for further replies.
  1. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
    Thanks! :)

    That would appear to be the case. It also creates this startup:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SYSTEM service helper"
    Type: REG_SZ
    Data: E:\Documents and Settings\Ton\My Documents\Baddies\svchelper.exe

    Traffic:

    10/07/2005 21:03:27pm OPEN TCP 0.0.0.0:0 0.0.0.0:0 Success 0 E:\Documents and Settings\Ton\My Documents\Baddies\svchelper.exe:1652
    10/07/2005 21:03:27pm CONNECT TCP 0.0.0.0:1036 62.211.69.7:6667 Success E:\Documents and Settings\Ton\My Documents\Baddies\svchelper.exe:1652 Italy
    10/07/2005 21:03:27pm SEND TCP 192.168.1.11:1036 62.211.69.7:6667 Success 361 E:\Documents and Settings\Ton\My Documents\Baddies\svchelper.exe:1652 Italy
    10/07/2005 21:03:27pm SEND TCP 192.168.1.11:1036 62.211.69.7:6667 Success 161 E:\Documents and Settings\Ton\My Documents\Baddies\svchelper.exe:1652 Italy
    10/07/2005 21:03:28pm RECEIVE TCP 192.168.1.11:1036 62.211.69.7:6667 Success 67 E:\Documents and Settings\Ton\My Documents\Baddies\svchelper.exe:1652 Italy
    10/07/2005 21:03:39pm RECEIVE TCP 192.168.1.11:1036 62.211.69.7:6667 Success 82 E:\Documents and Settings\Ton\My Documents\Baddies\svchelper.exe:1652 Italy
    10/07/2005 21:04:27pm CLOSE TCP 192.168.1.11:1036 62.211.69.7:6667 Success E:\Documents and Settings\Ton\My Documents\Baddies\svchelper.exe:1652 Italy
    1

    irc1.tin.it = [ 62.211.69.7 ]

    domain: tin.it
    org: TI MEDIA SpA
    descr: TI MEDIA SpA
    admin-c: MMM134-ITNIC
    tech-c: STT2-ITNIC
    postmaster: SPT1-ITNIC
    zone-c: SZT1-ITNIC
    nserver: 194.243.154.62 dns.tin.it
    nserver: 195.31.190.31 dnsca.tin.it
    remarks: Delegated-To tin.it
    mnt-by: TIN-MNT
    created: 19961003
    expire: 20060531
    source: IT-NIC
    person: MAURIZIO MARIA MONTI
    address: Via C.Colombo 142
    address: ROMA 00144
    nic-hdl: MMM134-ITNIC
    New size: 3.452 bytes
     
  2. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
    OK, Kaspersky just came back to me (fast as always...):

    Detection added as Backdoor.Win32.RBot.uj
     
  3. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    Good job ESET!!! :D
     
  4. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
  5. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
  6. Firecat

    Firecat Registered Member

    Joined:
    Jan 2, 2005
    Posts:
    8,251
    Location:
    The land of no identity :D
    Does NOD32 now detect it with signatures as well? :)
     
  7. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
    Yes they do:

    Sophos have it here: http://www.sophos.com/virusinfo/analyses/w32monkbda.html

    Wouldn't it be nice if everyone would agree... LOL
     
  8. Firecat

    Firecat Registered Member

    Joined:
    Jan 2, 2005
    Posts:
    8,251
    Location:
    The land of no identity :D
  9. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508

    Agreed. :D
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.