A forum for reverse engineering, OS internals and malware analysis 

 #19245  by mikeinhouston
 Fri May 10, 2013 8:58 am
I'm looking for a USB/file share malware from 2011 named malas / bindo / linkfars. I have searched these names here on the board and don't find it.
File name may be userinit.exe or svchost.exe or some other.

The following are names AV products use for this malware.

Win32/Agent.worm.155648.C (AhnLab) Trojan horse SHeur.AKKW (AVG)
Win32.Worm.P2p.Agent.AL (BitDefender)
Win32/Malas (ESET)
P2P-Worm.Win32.Malas.f (Kaspersky)
W32/Bindo.worm (McAfee)
W32/Malas.C (Norman)
W32/Malas-E (Sophos)
Worm.Win32.P2p.Agent.AL (Sunbelt Software)
W32.Linkfars (Symantec)
WORM_MALAS.H (Trend Micro)
Worm.P2P.Malas.F (VirusBuster)

Thanks much,
Mike
 #19246  by r3shl4k1sh
 Fri May 10, 2013 9:03 am
Based on your criteria simple search on VT gives the following md5:

3920109379a2df71eebdb612670772da
https://www.virustotal.com/en/file/1c5a ... /analysis/

4373d967efe07a80d5281af09e6aad9c
https://www.virustotal.com/en/file/a318 ... /analysis/

63ba7bf986e0935b3debc332d6a4b7ac
https://www.virustotal.com/en/file/9329 ... /analysis/

27e711593a8180b0b1d2763b098af054
https://www.virustotal.com/en/file/8984 ... /analysis/

b8645eb705a9172a7962409f73fe0532
https://www.virustotal.com/en/file/ec43 ... /analysis/