MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
Welcome to MSMVPS.COM Sign in | Help
in Search

Harry Waldron - Microsoft MVP Blog

Security News and Best Practices for corporate and home users

New Storm Worm variant - AV Protection continuing to improve

Lightning Below are results from a submission this morning of the AGENT.BRK trojan horse from a copy received in my personal email. AV protection is improving and hopefully will be now found in some of the companies missing protection earlier today.

 Complete scanning result of "fungame.zip", processed in VirusTotal at
 07/30/2007 15:08:24 (CET).
 
 [ file data ]
 * name: fungame.zip
 * size: 19363
 * md5.: e32407039e10ab1be6e639e6fe4c9ee9
 * sha1: 166733488b62628278ada4a8b29954c097f42af9
 
 
[ scan result ]
 
AhnLab-V3 2007.7.28.0/20070730 found nothing

 AntiVir 7.4.0.50/20070730 found [Worm/Nuj.A.124]
 Authentium 4.93.8/20070727 found [W32/Downldr2.AOUA]
 Avast 4.7.997.0/20070730 found [Win32:Agent-JSL]
 AVG 7.5.0.476/20070730 found [Downloader.Agent.OGE]
 BitDefender 7.2/20070730 found [Trojan.Kobcka.A]
 
CAT-QuickHeal 9.00/20070728 found nothing
 ClamAV 0.91/20070730 found [Trojan.Downloader-12017]
 DrWeb 4.33/20070730 found [BackDoor.Bulknet]
 eSafe 7.0.15.0/20070729 found [Win32.Agent.brk]
 eTrust-Vet 31.1.5016/20070730 found [Win32/Cutwail.T]
 
Ewido 4.0/20070730 found nothing
 F-Prot 4.3.2.48/20070727 found [W32/Downldr2.AOUA]
 F-Secure 6.70.13030.0/20070730 found
 [Trojan-Downloader.Win32.Agent.brk]
 
FileAdvisor 1/20070730 found nothing
 Fortinet 2.91.0.0/20070730 found [W32/Agent.AUH!tr]
 
Ikarus T3.1.1.8/20070730 found nothing
 Kaspersky 4.0.2.24/20070730 found [Trojan-Downloader.Win32.Agent.brk]
 
McAfee 5085/20070727 found nothing
 Microsoft 1.2704/20070730 found [Worm:Win32/Nuwar.JU]
 NOD32v2 2429/20070730 found [Win32/TrojanDownloader.Agent.BRK]
 
Norman 5.80.02/20070730 found nothing
 Panda 9.0.0.4/20070729 found nothing
 Prevx1 V2/20070730 found nothing
 Rising 19.34.02.00/20070730 found nothing

 
Sophos 4.19.0/20070726 found nothing
 Sunbelt 2.2.907.0/20070728 found nothing

 Symantec 10/20070730 found [Trojan.Pandex]
 TheHacker 6.1.7.158/20070730 found [Trojan/Downloader.Agent.brk]
 VBA32 3.12.2.1/20070730 found [Trojan.Win32.Agent.auh]
 VirusBuster 4.3.26:9/20070730 found [Trojan.DL.Agent.Gen.8]
 Webwasher-Gateway 6.0.1/20070730 found [Worm.Nuj.A.124]

Only published comments... Jul 30 2007, 09:53 PM by Harry Waldron

Comments

 

Kerry Lingo MSD said:

I was infected with Trojan: Cutwail .T on 7-27-2007, date of first report and CA failed to locate until an update on 7-30-07.  It was discovered by the I have CA Secuirty Suite aka whatever they call it updated for XP Prfessional.  

CA Web site had removal instructions and I found NOTHING in regitry entries nor the files allegedly left.  I assume CA cleaned the thing up on a complete scan/cure.

Logs show I acquired this from the website WebMd.com, which reuires a user login.

Thx for this web site.

August 26, 2007 1:24 PM

Leave a Comment

(required) 
(optional)
(required) 
Submit
Powered by Community Server (Commercial Edition), by Telligent Systems