need to figure out if an .scr file contains a security threat

need to figure out if an .scr file contains a security threat

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
need to figure out if an .scr file contains a security threat name 06-15-2007
Posted by name on June 15, 2007, 5:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

Hello.

On MSN, I received an scr file and being the stupid idiot that I am, I
clicked on it. It didn't appear to do anything and when asking the
person who send it, he told me it was some kind of virus that was send
via msn. So now I'm extremely pissed off with myself but before
formatting my HD and installing everything once again, I was thinking
it might be possible to determine if the .scr file has actually
compromised my system in any way.

I've put the file online here:
http://www.ibbu.nl/~nsprakel/possible_virus.rar

I was wondering if anyone could help me out analyzing whether or not
the file is likely to have infected my computer? Or perhaps someone
can suggest a website where I could submit the file to have it scanned
to assess the potential threat.
I have my system fully updated (win xp pro sp2) and use AVG, which
didn't appear to find any virus in it.

Kind regards and thanks in advance for any help, Niek


Posted by name on June 15, 2007, 5:43 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Hello.
>
> On MSN, I received an scr file and being the stupid idiot that I am, I
> clicked on it. It didn't appear to do anything and when asking the
> person who send it, he told me it was some kind of virus that was send
> via msn. So now I'm extremely pissed off with myself but before
> formatting my HD and installing everything once again, I was thinking
> it might be possible to determine if the .scr file has actually
> compromised my system in any way.
>
> I've put the file online here:http://www.ibbu.nl/~nsprakel/possible_virus.rar
>
> I was wondering if anyone could help me out analyzing whether or not
> the file is likely to have infected my computer? Or perhaps someone
> can suggest a website where I could submit the file to have it scanned
> to assess the potential threat.
> I have my system fully updated (win xp pro sp2) and use AVG, which
> didn't appear to find any virus in it.
>
> Kind regards and thanks in advance for any help, Niek

I scanned the file online and it did indeed contain a virus... here is
a screenshot
of Kaspersky's scan results for that file:
http://www.ibbu.nl/~nsprakel/virus.jpg

Ok, so now what do I do... would it really be necessary to format my
HD and install all the software again or is there a less cumbersome
solution?


Posted by David H. Lipman on June 15, 2007, 5:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


|
| I scanned the file online and it did indeed contain a virus... here is
| a screenshot
| of Kaspersky's scan results for that file:
| http://www.ibbu.nl/~nsprakel/virus.jpg
|
| Ok, so now what do I do... would it really be necessary to format my
| HD and install all the software again or is there a less cumbersome
| solution?

Please REMOVE that file from the http://www.ibbu.nl server.


Complete scanning result of "possible_virus.scr", processed in VirusTotal at
06/16/2007 00:03:27
(CET).

[ file data ]
* name: possible_virus.scr
* size: 345088
* md5.: 90e8e9e296ce9e19d1d1da97db4b62b5
* sha1: d82d2262bd4087cb4b939929b2101bb5b8a2ee59

[ scan result ]
AhnLab-V3 2007.6.16.0/20070615 found nothing
AntiVir 7.4.0.32/20070615 found [BDS/Bifrose.NU]
Authentium 4.93.8/20070615 found nothing
Avast 4.7.997.0/20070615 found nothing
AVG 7.5.0.467/20070615 found nothing
BitDefender 7.2/20070615 found [Backdoor.IRCBot.ABDD]
CAT-QuickHeal 9.00/20070615 found [(Suspicious) - DNAScan]
ClamAV devel-20070416/20070615 found [Trojan.Pakes-248]
DrWeb 4.33/20070615 found nothing
eSafe 7.0.15.0/20070614 found [Win32.IRCBot.aaq]
eTrust-Vet 30.7.3721/20070615 found nothing
Ewido 4.0/20070615 found [Backdoor.IRCBot.aaq]
F-Prot 4.3.2.48/20070615 found nothing
F-Secure 6.70.13030.0/20070615 found [Backdoor.Win32.IRCBot.aaq]
FileAdvisor 1/20070615 found [Not analyzed yet]
Fortinet 2.85.0.0/20070615 found [W32/IRCBot.AAQ!tr.bdr]
Ikarus T3.1.1.8/20070615 found [Backdoor.VB.EV]
Kaspersky 4.0.2.24/20070615 found [Backdoor.Win32.IRCBot.aaq]
McAfee 5054/20070615 found nothing
Microsoft 1.2607/20070615 found nothing
NOD32v2 2334/20070615 found nothing
Norman 5.80.02/20070615 found nothing
Panda 9.0.0.4/20070615 found [W32/Gaobot.OXI.worm]
Sophos 4.18.0/20070612 found nothing
Sunbelt 2.2.907.0/20070614 found [Win32.ExplorerHijack]
Symantec 10/20070615 found nothing
TheHacker 6.1.6.133/20070615 found [Backdoor/IRCBot.aaq]
VBA32 3.12.0.2/20070615 found [Backdoor.Win32.IRCBot.aaq]
VirusBuster 4.3.23:9/20070615 found [Backdoor.IRCBot.AZA]
Webwasher-Gateway 6.0.1/20070615 found [Trojan.Bifrose.NU]

[ notes ]
packers: Themida
Bit9 info:
http://fileadvisor.bit9.com/services/extinfo.aspx?md5=90e8e9e296ce9e19d1d1da97db4b62b5




--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by name on June 15, 2007, 6:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
wrote:
>
> |
> | I scanned the file online and it did indeed contain a virus... here is
> | a screenshot
> | of Kaspersky's scan results for that file:
> |http://www.ibbu.nl/~nsprakel/virus.jpg
> |
> | Ok, so now what do I do... would it really be necessary to format my
> | HD and install all the software again or is there a less cumbersome
> | solution?
>
> Please REMOVE that file from thehttp://www.ibbu.nl server.
>

Ok, done, but what do I do about my infected computer?


Posted by David H. Lipman on June 15, 2007, 6:12 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| wrote:
>>
|>> I scanned the file online and it did indeed contain a virus... here is
|>> a screenshot
|>> of Kaspersky's scan results for that file:
|>> http://www.ibbu.nl/~nsprakel/virus.jpg
|>>
|>> Ok, so now what do I do... would it really be necessary to format my
|>> HD and install all the software again or is there a less cumbersome
|>> solution?
>>
>> Please REMOVE that file from thehttp://www.ibbu.nl server.
>>
| Ok, done, but what do I do about my infected computer?

You RAN IT ? Oy vay...

You can use the Kaspersky module of the following Multi AV Scanning Tool and/or
the free
BitDefender 8.

I will submit the file to mAV vendors this evening.

Free BitDefender v8
--------------------
http://www.bitdefender.com/PRODUCT-14-en--BitDefender-8-Free-Edition.html


Multi AV Scanning Tool.
----------------------
Download MULTI_AV.EXE from the URL --
http://www.pctipp.ch/downloads/dl/35905.asp

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file.

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *




--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
The biggest security threat to companies is their own people (The Scotsman) May 20, 2007, 10:05 am
Threat Simulator October 29, 2005, 1:16 am
You should be aware of the threat. October 16, 2008, 12:59 am
VM Rootkits: The Next Big Threat? (PC Magazine) March 12, 2006, 7:20 am
'JS/Downloader.Agent' is it a threat? February 26, 2008, 6:58 am
2007 threat vector: your ass is grass March 22, 2007, 12:35 pm
RE: W32/Threat-HLLSI-based!Maximus real or fake ? October 28, 2006, 1:30 pm
Latest AV product rankings from SRI Malware Threat Center January 4, 2009, 1:29 pm
Re: Latest AV product rankings from SRI Malware Threat Cente January 5, 2009, 9:10 am
New site dedicated to security conferences : www.security-briefings.com May 7, 2006, 4:34 am

The site map in XML format XML site map

Contact Us | Privacy Policy