Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

New Storm Worm variant - AV Protection continuing to improve

Lightning Below are results from a submission this morning of the AGENT.BRK trojan horse from a copy received in my personal email. AV protection is improving and hopefully will be now found in some of the companies missing protection earlier today.

 Complete scanning result of "fungame.zip", processed in VirusTotal at
 07/30/2007 15:08:24 (CET).
 
 [ file data ]
 * name: fungame.zip
 * size: 19363
 * md5.: e32407039e10ab1be6e639e6fe4c9ee9
 * sha1: 166733488b62628278ada4a8b29954c097f42af9
 
 
[ scan result ]
 
AhnLab-V3 2007.7.28.0/20070730 found nothing

 AntiVir 7.4.0.50/20070730 found [Worm/Nuj.A.124]
 Authentium 4.93.8/20070727 found [W32/Downldr2.AOUA]
 Avast 4.7.997.0/20070730 found [Win32:Agent-JSL]
 AVG 7.5.0.476/20070730 found [Downloader.Agent.OGE]
 BitDefender 7.2/20070730 found [Trojan.Kobcka.A]
 
CAT-QuickHeal 9.00/20070728 found nothing
 ClamAV 0.91/20070730 found [Trojan.Downloader-12017]
 DrWeb 4.33/20070730 found [BackDoor.Bulknet]
 eSafe 7.0.15.0/20070729 found [Win32.Agent.brk]
 eTrust-Vet 31.1.5016/20070730 found [Win32/Cutwail.T]
 
Ewido 4.0/20070730 found nothing
 F-Prot 4.3.2.48/20070727 found [W32/Downldr2.AOUA]
 F-Secure 6.70.13030.0/20070730 found
 [Trojan-Downloader.Win32.Agent.brk]
 
FileAdvisor 1/20070730 found nothing
 Fortinet 2.91.0.0/20070730 found [W32/Agent.AUH!tr]
 
Ikarus T3.1.1.8/20070730 found nothing
 Kaspersky 4.0.2.24/20070730 found [Trojan-Downloader.Win32.Agent.brk]
 
McAfee 5085/20070727 found nothing
 Microsoft 1.2704/20070730 found [Worm:Win32/Nuwar.JU]
 NOD32v2 2429/20070730 found [Win32/TrojanDownloader.Agent.BRK]
 
Norman 5.80.02/20070730 found nothing
 Panda 9.0.0.4/20070729 found nothing
 Prevx1 V2/20070730 found nothing
 Rising 19.34.02.00/20070730 found nothing

 
Sophos 4.19.0/20070726 found nothing
 Sunbelt 2.2.907.0/20070728 found nothing

 Symantec 10/20070730 found [Trojan.Pandex]
 TheHacker 6.1.7.158/20070730 found [Trojan/Downloader.Agent.brk]
 VBA32 3.12.2.1/20070730 found [Trojan.Win32.Agent.auh]
 VirusBuster 4.3.26:9/20070730 found [Trojan.DL.Agent.Gen.8]
 Webwasher-Gateway 6.0.1/20070730 found [Worm.Nuj.A.124]

Comments

Kerry Lingo MSD said:

I was infected with Trojan: Cutwail .T on 7-27-2007, date of first report and CA failed to locate until an update on 7-30-07.  It was discovered by the I have CA Secuirty Suite aka whatever they call it updated for XP Prfessional.  

CA Web site had removal instructions and I found NOTHING in regitry entries nor the files allegedly left.  I assume CA cleaned the thing up on a complete scan/cure.

Logs show I acquired this from the website WebMd.com, which reuires a user login.

Thx for this web site.

# August 26, 2007 1:24 PM