<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3028803908742866245</id><updated>2011-12-08T13:23:59.812-08:00</updated><category term='Antivirus file infected'/><category term='worm'/><category term='AV file infected'/><category term='antivirus'/><category term='AV file infected by virut'/><category term='msnworm'/><category term='msn worm'/><title type='text'>Security Research Blog</title><subtitle type='html'>All about malware/virus research and related articles.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://anandavgeek.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3028803908742866245/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://anandavgeek.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Anand A</name><uri>http://www.blogger.com/profile/01803961522571506034</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3028803908742866245.post-3155109741267332324</id><published>2008-02-14T06:50:00.000-08:00</published><updated>2008-02-14T07:12:41.864-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='msn worm'/><category scheme='http://www.blogger.com/atom/ns#' term='msnworm'/><title type='text'>New MSN worm variant - In the Wild</title><content type='html'>Today, I got a zip file as an attachment (named as "&lt;span style="font-weight: bold;"&gt;image014.zip&lt;/span&gt; with saying "&lt;span style="font-weight: bold;"&gt;have you seen the newest iphone? its so amazing check it out&lt;/span&gt;") through MSN Messenger from one of my friend's email-ID. There it looks suspicious (later confirmed that he didn't send) to me and further downloaded the file for  analysis. After extraction, there was a file named "&lt;span style="font-weight: bold; font-style: italic;"&gt;image016.JPG-www.facebook.com&lt;/span&gt;".&lt;br /&gt;&lt;br /&gt;Its actually a new variant of MSN worm which is in the wild (more similar to this &lt;a href="http://isc.sans.org/diary.html?storyid=3961"&gt;one&lt;/a&gt;) where as 3 AV's detected as per the &lt;a href="http://www.virustotal.com/analisis/44a99df89c0579ccb614397e51ef752c"&gt;&lt;span style="font-weight: bold;"&gt;virustotal&lt;/span&gt;&lt;/a&gt; result. The detected worm's name looks like that AV's have created a generic (based on the behaviour) signature for it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3028803908742866245-3155109741267332324?l=anandavgeek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anandavgeek.blogspot.com/feeds/3155109741267332324/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3028803908742866245&amp;postID=3155109741267332324' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3028803908742866245/posts/default/3155109741267332324'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3028803908742866245/posts/default/3155109741267332324'/><link rel='alternate' type='text/html' href='http://anandavgeek.blogspot.com/2008/02/new-msn-worm-variant-in-wild.html' title='New MSN worm variant - In the Wild'/><author><name>Anand A</name><uri>http://www.blogger.com/profile/01803961522571506034</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3028803908742866245.post-2193061013997484380</id><published>2008-02-11T23:19:00.001-08:00</published><updated>2008-02-12T04:22:04.703-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AV file infected'/><category scheme='http://www.blogger.com/atom/ns#' term='Antivirus file infected'/><category scheme='http://www.blogger.com/atom/ns#' term='AV file infected by virut'/><category scheme='http://www.blogger.com/atom/ns#' term='antivirus'/><title type='text'>Antivirus Setup File infected by VIRUT variant</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Update:&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;  After reporting this issue to their Technical support, now they have changed the infected binary file (removed exactly the Extradat section from the whouses.exe file) and below is the result shown by &lt;/span&gt;&lt;a style="color: rgb(255, 0, 0);" href="http://www.virustotal.com/analisis/485ef7cc9341a54a839cec749ff4a44d"&gt;virustotal&lt;/a&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_5jrZvTFkPvE/R7GJ_mD9ipI/AAAAAAAAAAk/KjiRf6Yvl-E/s1600-h/NetProtector2008_Virut_latest.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_5jrZvTFkPvE/R7GJ_mD9ipI/AAAAAAAAAAk/KjiRf6Yvl-E/s400/NetProtector2008_Virut_latest.JPG" alt="" id="BLOGGER_PHOTO_ID_5166061973212596882" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;When I download &lt;a href="http://www.indiaantivirus.com/downloadtrialversion.html"&gt;NetProtector 2008&lt;/a&gt;  trial version from  Pune(INDIA) based &lt;a href="http://www.indiaantivirus.com/"&gt;Antivirus&lt;/a&gt; company's website, one of the file looks malicious to me.  Then I picked that file "&lt;span style="font-weight: bold;"&gt;whouses.exe&lt;/span&gt;" and after analyzing I found that its infected by one of the VIRUT variant but not active, as its code is in the last section of the file (extradat section with no reference to it).&lt;br /&gt;&lt;br /&gt;Later, I uploaded to &lt;a href="http://www.virustotal.com/analisis/d15bf08e6404686e111ec939ccc05963"&gt;VirusTotal&lt;/a&gt; for further results from other antivirus products and result was scary.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_5jrZvTFkPvE/R7FUUWD9ioI/AAAAAAAAAAc/s4TfKss_htc/s1600-h/NetProtector2008_Virut.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_5jrZvTFkPvE/R7FUUWD9ioI/AAAAAAAAAAc/s4TfKss_htc/s400/NetProtector2008_Virut.JPG" alt="" id="BLOGGER_PHOTO_ID_5166002956066982530" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Flagging virus onto one of the file of an antivirus product itself is scary and shows the carelessness from the security firm which is supposed to protect their users from the malicious programs.&lt;br /&gt;&lt;br /&gt;It shows that one of their development machine could have been infected by virus and finally the result is Antivirus product itself infected!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3028803908742866245-2193061013997484380?l=anandavgeek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anandavgeek.blogspot.com/feeds/2193061013997484380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3028803908742866245&amp;postID=2193061013997484380' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3028803908742866245/posts/default/2193061013997484380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3028803908742866245/posts/default/2193061013997484380'/><link rel='alternate' type='text/html' href='http://anandavgeek.blogspot.com/2008/02/antivirus-setup-file-infected-by-virut.html' title='Antivirus Setup File infected by VIRUT variant'/><author><name>Anand A</name><uri>http://www.blogger.com/profile/01803961522571506034</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_5jrZvTFkPvE/R7GJ_mD9ipI/AAAAAAAAAAk/KjiRf6Yvl-E/s72-c/NetProtector2008_Virut_latest.JPG' height='72' width='72'/><thr:total>1</thr:total></entry></feed>
