A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #20369  by Quads
 Sat Aug 03, 2013 10:17 pm
thisisu wrote:
EP_X0FF wrote:For (A) - go to PROGRAMFILES\Google\Desktop\Install, take ownership (replacing ALL access list) and erase directory.
Yes.

Just providing an example:
Code: Select all
swxcacls "c:\program files\Google\Desktop\Install" /reset
swxcacls can be downloaded from here: http://fstaal01.home.xs4all.nl/swxcacls-us.html

But any brute force removal tool (Avenger, Blitzblank, ComboFix, etc..) should do the job.


Combofix with script on XP does not remove the service or on folder location.

TDSSkiller sees the key

*etadpug ( UnsignedFile.Multi.Generic ) - skipped by user
*etadpug ( UnsignedFile.Multi.Generic ) - User select action: Skip

Quads
 #20370  by EP_X0FF
 Sun Aug 04, 2013 3:44 am
unixfreaxjp wrote:We need them, friend. They're willing to help, they did the best they can help and this is the quality that actually exists.
Main problem with all these home made "specialists" - mostly they are not willing to help and their level is too poor to do any real help, and they do not to learn anything -> why bother if they are already "pro". They just want to show off to other people their mad skills. VT full of such fake specialists, "analysts" with big "reputation points" values (they are liking each other - "trust me bro, I trust you!"). Actually they are a sort of malware - because these idiots doing malicious job - marking legitimate software as malware with idiotic conclusions and comments, sending tons of incorrect reports to AV vendors, forcing them to check out all these garbage while AV can spend all this time on researching real malware. So no, I disagree, I don't need all of them.
 #20376  by R136a1
 Sun Aug 04, 2013 12:37 pm
EP_X0FF wrote:
unixfreaxjp wrote:We need them, friend. They're willing to help, they did the best they can help and this is the quality that actually exists.
Main problem with all these home made "specialists" - mostly they are not willing to help and their level is too poor to do any real help, and they do not to learn anything -> why bother if they are already "pro". They just want to show off to other people their mad skills. VT full of such fake specialists, "analysts" with big "reputation points" values (they are liking each other - "trust me bro, I trust you!"). Actually they are a sort of malware - because these idiots doing malicious job - marking legitimate software as malware with idiotic conclusions and comments, sending tons of incorrect reports to AV vendors, forcing them to check out all these garbage while AV can spend all this time on researching real malware. So no, I disagree, I don't need all of them.
Damn right!

Most (not all) of these self-proclaimed security experts are just seeking attention! To become good at something (and especially at computer security which can be at the beginning very dry and frustrating) it takes a lot of work (-> self-discipline), experience and time and most people aren't willing to go this way.
 #20382  by BillyONeal
 Mon Aug 05, 2013 6:58 am
EP_X0FF wrote: Main problem with all these home made "specialists" - mostly they are not willing to help and their level is too poor to do any real help, and they do not to learn anything -> why bother if they are already "pro".
R136a1 wrote:Most (not all) of these self-proclaimed security experts are just seeking attention! To become good at something (and especially at computer security which can be at the beginning very dry and frustrating) it takes a lot of work (-> self-discipline), experience and time and most people aren't willing to go this way.
There are many people as described, "experts" who populate various internet locations for the "glory." We used to have a (admittedly small) number of people who truly knew this kind of analysis and could teach people the ins and outs here. Those people have all left to work for anti-malware vendors.

If you want to improve the quality of volunteers then there need to be people to teach those volunteers. I know that's not an easy task, and I know most people won't be able to deal with it. But at this point there's no way for these people to even try. I can teach programming knowledge if that would be helpful. I can't teach malware analysis because I have no experience there.

I'm sure there are people at various places who would love to help make this better. But we're powerless to affect that kind of change right now.

Billy3
 #20394  by rkhunter
 Tue Aug 06, 2013 8:03 am
Another dropper of the newest modification.

SHA256: 215e37b2c56e74858f610aa6625c64f1b99f9e05f3261d2b4196b0246611a8c6
SHA1: a88ca24aeef56d692feff6fe0f0ac9df09a82796
MD5: cb2d6ea208bbd1e42fb69ceb461d2f72

https://www.virustotal.com/en/file/215e ... /analysis/
Attachments
pass:infected
(126.81 KiB) Downloaded 100 times
 #20406  by unixfreaxjp
 Tue Aug 06, 2013 6:55 pm
EP_X0FF wrote:
unixfreaxjp wrote:We need them, friend. They're willing to help, they did the best they can help and this is the quality that actually exists.
Main problem with all these home made "specialists" - mostly they are not willing to help and their level is too poor to do any real help, and they do not to learn anything -> why bother if they are already "pro". They just want to show off to other people their mad skills. VT full of such fake specialists, "analysts" with big "reputation points" values (they are liking each other - "trust me bro, I trust you!"). Actually they are a sort of malware - because these idiots doing malicious job - marking legitimate software as malware with idiotic conclusions and comments, sending tons of incorrect reports to AV vendors, forcing them to check out all these garbage while AV can spend all this time on researching real malware. So no, I disagree, I don't need all of them.
It looks like I misunderstood :-) I'd better read more carefully next time.
I thought you addressed to new comers who try to give their poor opinion by learning to analyze/
Yes VT community is highly compromised with the scores and trust stuff..

In this case, as per your explained, I completely agree with you.
Thank you for the kindly effort to explain. Very sorry for wasting space and time.

rgds!
 #20563  by N3mes1s
 Thu Aug 22, 2013 3:29 pm
Dropped from a url infected with CookieBomb

SHA256: 8db03cbe00517261540d59b9a6a47647519efb851c2b413f69d352409f1c6884
SHA1: ac3a85d746bd92418ea5905541b0aa954c3730a8
MD5: 33f394f2d041dd77d102779dccb9c7ac
File size: 204.0 KB ( 208896 bytes )
File name: successful_records.php?If=31312d3153
File type: Win32 EXE
Tags: peexe
Detection ratio: 5 / 46
Analysis date: 2013-08-22 14:05:17 UTC

https://www.virustotal.com/en/file/8db0 ... 377180317/
Attachments
password: infected
(118.51 KiB) Downloaded 73 times
  • 1
  • 42
  • 43
  • 44
  • 45
  • 46
  • 56