<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3906359852962611562</id><updated>2011-12-15T03:05:33.770Z</updated><category term='submitted'/><category term='all'/><category term='results'/><title type='text'>VSUB - Malware Submissions</title><subtitle type='html'>Details on new malware submitted to anti-malware vendors for inclusion in their products...</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>29</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-619177239498914379</id><published>2010-03-26T12:49:00.001Z</published><updated>2010-03-26T12:52:17.875Z</updated><title type='text'>This blog has moved</title><content type='html'>&lt;br /&gt;       This blog is now located at http://malsub.blogspot.com/.&lt;br /&gt;       You will be automatically redirected in 30 seconds or you may click &lt;a href='http://malsub.blogspot.com/'&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;       For feed subscribers, please update your feed subscriptions to&lt;br /&gt;       http://malsub.blogspot.com/feeds/posts/default.&lt;br /&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-619177239498914379?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://malsub.blogspot.com/' title='This blog has moved'/><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/619177239498914379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=619177239498914379' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/619177239498914379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/619177239498914379'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2010/03/this-blog-has-moved.html' title='This blog has moved'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-2696614580742658414</id><published>2008-01-15T19:15:00.000Z</published><updated>2008-01-15T19:17:20.527Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0801002 Possible New Malware [Nuwar?]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via an e-mail with a link to a fake Valentine ecard.&lt;br /&gt;&lt;br /&gt;I have included data on a sample of the file&lt;br /&gt;offered on the site for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: withlove.exe&lt;br /&gt;FileDateTime: 15/01/2008 18:47:22&lt;br /&gt;Filesize: 114688&lt;br /&gt;MD5: 62b32aaf553e515ba4967aaf64f84a6e&lt;br /&gt;CRC32: 25C30FDE&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: withlove.exe.1&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender -&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe -&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 Win32/Nuwar worm (variant)&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal -&lt;br /&gt;Rising -&lt;br /&gt;Sophos -&lt;br /&gt;Sunbelt -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Win32.Malware.gen!88 (suspicious)&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-2696614580742658414?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/2696614580742658414/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=2696614580742658414' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/2696614580742658414'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/2696614580742658414'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2008/01/vs0801002-possible-new-malware-nuwar.html' title='VS0801002 Possible New Malware [Nuwar?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-2527856529383448092</id><published>2008-01-15T11:13:00.000Z</published><updated>2008-01-15T11:15:33.106Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0801001 Possible New Malware [Agent?]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via an e-mail with a link to a fake MySpace website.&lt;br /&gt;&lt;br /&gt;I have included data on a sample of the file&lt;br /&gt;offered on the site for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: install_flash_player.exe&lt;br /&gt;FileDateTime: 15/01/2008 10:33:54&lt;br /&gt;Filesize: 43008&lt;br /&gt;MD5: 602e3b55391b8ac990c4c6620e9aac7a&lt;br /&gt;CRC32: C36C8998&lt;br /&gt;File Type: PE Executable&lt;br /&gt;Packer: UPX &lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: install_flash_player.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir TR/Agent.43008.15&lt;br /&gt;Avast! -&lt;br /&gt;AVG SHeur.AMSM (Trojan horse)&lt;br /&gt;BitDefender DeepScan:Generic.Malware.FBldld.1B33C1C9&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe Trojan/Worm [101] (suspicious)&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure Backdoor:W32/Agent.CTH&lt;br /&gt;F-Secure (BETA) Backdoor:W32/Agent.CTH&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus Win32.SuspectCrc&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) Proxy-Agent.af trojan&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman W32/Agent.DVRK&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal Win32.Backdoor.Agent.aju&lt;br /&gt;Rising -&lt;br /&gt;Sophos Sus/Dropper-A (suspicious)&lt;br /&gt;Sunbelt -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Trojan.Agent.43008.15&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot Worldsecurityonline.FakeAlert,,Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-2527856529383448092?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/2527856529383448092/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=2527856529383448092' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/2527856529383448092'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/2527856529383448092'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2008/01/vs0801001-possible-new-malware-agent.html' title='VS0801001 Possible New Malware [Agent?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-471492010415110756</id><published>2007-11-13T20:55:00.000Z</published><updated>2007-11-13T22:33:00.958Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0711003 Possible New Malware [Trojan.VB?]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via an e-mail with a link to a fake Microsoft website.&lt;br /&gt;&lt;br /&gt;I have included data on a sample of the file offered on&lt;br /&gt;the site for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: WindowsXP-KB923810-x86-ENU.exe&lt;br /&gt;FileDateTime: 13/11/2007 20:23:46&lt;br /&gt;Filesize: 1057651&lt;br /&gt;MD5: b59d788bc907d9aecb15375abe09c606&lt;br /&gt;CRC32: 303D13C6&lt;br /&gt;File Type: PE Executable&lt;br /&gt;Packer: UPX &lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: WindowsXP-KB923810-x86-ENU.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender -&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe Trojan/Worm [101] (suspicious)&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet -&lt;br /&gt;Fortinet (BETA) -&lt;br /&gt;Ikarus Trojan.Win32.VB.azd&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal -&lt;br /&gt;Rising -&lt;br /&gt;Sophos -&lt;br /&gt;Sunbelt -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Win32.ModifiedUPX.gen!84 (suspicious)&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot Smitfraud-C.,,Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;More details on this latest malware, including screenshots of both the e-mail and the website, and some commentary can be found &lt;a href="http://momusings.com/momusings/2007/11/one-msupdate-you-dont-want.html"&gt;here&lt;/a&gt; on my Momusings blog.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-471492010415110756?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/471492010415110756/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=471492010415110756' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/471492010415110756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/471492010415110756'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/11/vs0711003-possible-new-malware-trojanvb.html' title='VS0711003 Possible New Malware [Trojan.VB?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-3509586256560038528</id><published>2007-11-12T13:24:00.000Z</published><updated>2007-11-12T14:43:14.122Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0711002 Possible New Malware [Agent?]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via an e-mail with a link to a fake YouTube website.&lt;br /&gt;&lt;br /&gt;I have included data on a sample of the file offered on &lt;br /&gt;the site for your information and analysis.&lt;br /&gt;&lt;br /&gt;2 copies have been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: install_flash_player.exe.1&lt;br /&gt;FileDateTime: 12/11/2007 12:09:43&lt;br /&gt;Filesize: 1228800&lt;br /&gt;MD5: 29a8b08786a6a5bd253df5b2a42e7979&lt;br /&gt;CRC32: E8ED5280&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: install_flash_player.exe.1&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender -&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe -&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) Trojan-Dropper:W32/Agent.CPL&lt;br /&gt;Fortinet -&lt;br /&gt;Fortinet (BETA) -&lt;br /&gt;Ikarus Win32.SuspectCrc&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal -&lt;br /&gt;Rising -&lt;br /&gt;Sophos -&lt;br /&gt;Sunbelt -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher -&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;More details can be found &lt;a href="http://momusings.com/momusings/2007/11/do-you-youtube.html"&gt;here&lt;/a&gt; on my MoMusings blog.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-3509586256560038528?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/3509586256560038528/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=3509586256560038528' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/3509586256560038528'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/3509586256560038528'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/11/vs0711002-possible-new-malware-agent.html' title='VS0711002 Possible New Malware [Agent?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-7413528979062365997</id><published>2007-11-08T10:28:00.000Z</published><updated>2007-11-08T10:30:41.239Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0711001 Possible New Malware [Zhelatin?]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via an e-mail with a link to a website.&lt;br /&gt;&lt;br /&gt;I have included data on sample of the file offered on the&lt;br /&gt;site for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: dancer.exe&lt;br /&gt;FileDateTime: 08/11/2007 09:33:24&lt;br /&gt;Filesize: 125283&lt;br /&gt;MD5: bf9dfa4e8f6ea259b3aff05cf5509215&lt;br /&gt;CRC32: 44507CCE&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: dancer.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir WORM/Zhelatin.Gen&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender Trojan.Peed.INS (suspected)&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web Trojan.Packed.209&lt;br /&gt;eSafe File [100] (suspicious)&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee New Malware.cn (trojan or variant)&lt;br /&gt;McAfee (BETA) New Malware.cn (trojan or variant)&lt;br /&gt;Microsoft TrojanDropper:Win32/Nuwar.gen!avkill (suspicious)&lt;br /&gt;Nod32 NewHeur_PE (probably unknown virus)&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising -&lt;br /&gt;Sophos Mal/Dorf-F&lt;br /&gt;Sunbelt -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) Trojan.Peacomm.D&lt;br /&gt;Trend Micro WORM_NUCRP.GEN&lt;br /&gt;Trend Micro (BETA) WORM_NUCRP.GEN&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Worm.Zhelatin.Gen&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-7413528979062365997?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/7413528979062365997/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=7413528979062365997' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/7413528979062365997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/7413528979062365997'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/11/vs0711001-possible-new-malware-zhelatin.html' title='VS0711001 Possible New Malware [Zhelatin?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-4161077835075817565</id><published>2007-10-05T13:54:00.000Z</published><updated>2007-10-05T13:56:20.630Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0710002 Possible New Malware [BZub?]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via an e-mail with a link to a website.&lt;br /&gt;&lt;br /&gt;I have included data on a sample of the file being&lt;br /&gt;offered on the site for your information and analysis.&lt;br /&gt;&lt;br /&gt;6 copies have been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: behnert.exe&lt;br /&gt;FileDateTime: 05/10/2007 14:30:03&lt;br /&gt;Filesize: 122584&lt;br /&gt;MD5: a1d660fa9ba56edd66b8387ba1574742&lt;br /&gt;CRC32: B35A3AD1&lt;br /&gt;File Type: PE Executable&lt;br /&gt;Packer: Standard PE File &lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: behnert.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS Malicious (Cancelled)&lt;br /&gt;AntiVir DR/Delphi.Gen&lt;br /&gt;Avast! -&lt;br /&gt;AVG Generic8.FMB (Trojan horse)&lt;br /&gt;BitDefender Trojan.Dropper.Delf.HT (suspected)&lt;br /&gt;ClamAV Trojan.Dropper-2665&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe -&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure Trojan-Spy.Win32.BZub.bmj&lt;br /&gt;F-Secure (BETA) Trojan-Spy.Win32.BZub.bmj&lt;br /&gt;Fortinet -&lt;br /&gt;Fortinet (BETA) -&lt;br /&gt;Ikarus Trojan-Spy.Win32.Goldun.lw&lt;br /&gt;Kaspersky Trojan-Spy.Win32.BZub.bmj&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft PWS:Win32/Cimuz.D&lt;br /&gt;Nod32 -&lt;br /&gt;Norman W32/Malware.AZOM&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal -&lt;br /&gt;Rising -&lt;br /&gt;Sophos Mal/Basine-C&lt;br /&gt;Sunbelt -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro TSPY_CIMUZ.AT&lt;br /&gt;Trend Micro (BETA) TSPY_CIMUZ.AT&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster Trojan.DR.BZub.Gen.13&lt;br /&gt;WebWasher Trojan.Delphi.Gen&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-4161077835075817565?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/4161077835075817565/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=4161077835075817565' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/4161077835075817565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/4161077835075817565'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/10/vs0710002-possible-new-malware-bzub.html' title='VS0710002 Possible New Malware [BZub?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-4019601634442991869</id><published>2007-10-05T11:43:00.000Z</published><updated>2007-10-05T11:45:18.332Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0710001 Possible New Malware [Agent?]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via an attachment to a new Storm Worm, Nuwar spam e-mail.&lt;br /&gt;&lt;br /&gt;I have data on the attached zip file, and the file in the&lt;br /&gt;zip for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: hent.zip&lt;br /&gt;FileDateTime: 05/10/2007 11:54:09&lt;br /&gt;Filesize: 18971&lt;br /&gt;MD5: 285bce50962a29a65196285491816e7d&lt;br /&gt;CRC32: CBB7DF5C&lt;br /&gt;File Type: ZIP Archive File&lt;br /&gt;&lt;br /&gt;Contains:&lt;br /&gt;&lt;br /&gt;FileName: hent.exe&lt;br /&gt;FileDateTime: 05/10/2007 12:16:46&lt;br /&gt;Filesize: 20992&lt;br /&gt;MD5: 083bb18514c67dd0d795aedfcac88477&lt;br /&gt;CRC32: 72B5B404&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: hent.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir TR/Dropper.Gen&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender Trojan.Pandex.U&lt;br /&gt;ClamAV Trojan.Dropper-2667&lt;br /&gt;Command -&lt;br /&gt;Dr Web BackDoor.Bulknet.78&lt;br /&gt;eSafe -&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure Trojan-Downloader:W32/Agent.DTH&lt;br /&gt;F-Secure (BETA) Trojan-Downloader:W32/Agent.DTH&lt;br /&gt;Fortinet -&lt;br /&gt;Fortinet (BETA) Pushdo!tr&lt;br /&gt;Ikarus Win32.Outbreak&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal -&lt;br /&gt;Rising -&lt;br /&gt;Sophos Troj/Pushdo-Gen&lt;br /&gt;Sunbelt -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Trojan.Dropper.Gen&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot Worldsecurityonline.FakeAlert,,Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-4019601634442991869?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/4019601634442991869/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=4019601634442991869' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/4019601634442991869'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/4019601634442991869'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/10/vs0710001-possible-new-malware-agent.html' title='VS0710001 Possible New Malware [Agent?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-363432660783730014</id><published>2007-09-11T15:55:00.000Z</published><updated>2007-09-11T15:58:58.637Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0709003 Possible New Malware [Tibs/Nuwar?]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via a link in a new Storm Worm, Nuwar spam e-mail.&lt;br /&gt;&lt;br /&gt;I have included data on a sample downloaded from the website&lt;br /&gt;in the link for your information and analysis.&lt;br /&gt;&lt;br /&gt;Seems to be a new wave with a new or repacked file.&lt;br /&gt;&lt;br /&gt;4 copies have been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: tracker.exe&lt;br /&gt;FileDateTime: 11/09/2007 16:26:29&lt;br /&gt;Filesize: 142095&lt;br /&gt;MD5: 5a4ca687e45143d11dfff92d85bf6fc4&lt;br /&gt;CRC32: 284A41&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: tracker.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir Worm/Storm.tcp&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender -&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe Trojan/Worm [100] (suspicious)&lt;br /&gt;eTrust-VET Win32/Sintun.AF&lt;br /&gt;eTrust-VET (BETA) Win32/Sintun.AF&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) Tibs-Packed trojan&lt;br /&gt;Microsoft TrojanDropper:Win32/Nuwar.gen!avkill (suspicious)&lt;br /&gt;Nod32 -&lt;br /&gt;Norman Tibs.gen134&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising -&lt;br /&gt;Sophos Mal/Dorf-D&lt;br /&gt;Sunbelt VIPRE.Suspicious&lt;br /&gt;Symantec Trojan.Packed.13&lt;br /&gt;Symantec (BETA) Trojan.Packed.13&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Worm.Storm.tcp&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-363432660783730014?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/363432660783730014/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=363432660783730014' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/363432660783730014'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/363432660783730014'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/09/vs0709003-possible-new-malware.html' title='VS0709003 Possible New Malware [Tibs/Nuwar?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-5973912347272319591</id><published>2007-09-09T12:25:00.000Z</published><updated>2007-09-09T13:56:30.483Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0709002 Possible New Malware [Tibs/Nuwar?]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via a link in a new Storm Worm, Nuwar spam e-mail.&lt;br /&gt;&lt;br /&gt;I have included data on a sample downloaded from the website&lt;br /&gt;in the link for your information and analysis.&lt;br /&gt;&lt;br /&gt;10 copies have been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: tracker.exe&lt;br /&gt;FileDateTime: 09/09/2007 12:41:37&lt;br /&gt;Filesize: 140456&lt;br /&gt;MD5: c4b6c6cb417561135021cf5ee22625c5&lt;br /&gt;CRC32: 3EB1AEC8&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: tracker.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG Downloader.Tibs&lt;br /&gt;BitDefender DeepScan:Generic.Zlob.0A51F123&lt;br /&gt;ClamAV Trojan.Small-3688&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe Trojan/Worm [100] (suspicious)&lt;br /&gt;eTrust-VET Win32/Sintun.AF&lt;br /&gt;eTrust-VET (BETA) Win32/Sintun.AF&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure Packed.Win32.Tibs.bs&lt;br /&gt;F-Secure (BETA) Packed.Win32.Tibs.bs&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky Packed.Win32.Tibs.bs&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) Tibs-Packed trojan&lt;br /&gt;Microsoft TrojanDropper:Win32/Nuwar.gen!avkill (suspicious)&lt;br /&gt;Nod32 -&lt;br /&gt;Norman Tibs.gen134&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising -&lt;br /&gt;Sophos Mal/Dorf-D&lt;br /&gt;Sunbelt VIPRE.Suspicious&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Win32.Malware.gen (suspicious)&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;More details can be found here, including screenshots of one of the e-mails and the website: &lt;a href="http://momusings.com/momusings/2007/09/nfl-nuwar-file-link.html"&gt;http://momusings.com/momusings/2007/09/nfl-nuwar-file-link.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-5973912347272319591?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/5973912347272319591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=5973912347272319591' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/5973912347272319591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/5973912347272319591'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/09/vs0709002-possible-new-malware.html' title='VS0709002 Possible New Malware [Tibs/Nuwar?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-1277360309173915229</id><published>2007-09-06T14:39:00.000Z</published><updated>2007-09-09T12:27:36.054Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0709001 Possible New Malware [Tibs/Nuwar?]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via a link in a new Storm Worm, Nuwar spam e-mail.&lt;br /&gt;&lt;br /&gt;I have included data on a sample downloaded from the website&lt;br /&gt;in the link for your information and analysis.&lt;br /&gt;&lt;br /&gt;4 copies have been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: tor.exe&lt;br /&gt;FileDateTime: 06/09/2007 15:02:16&lt;br /&gt;Filesize: 140608&lt;br /&gt;MD5: 36825962ec1860a6c3da778b85f519d8&lt;br /&gt;CRC32: FF6FA7A4&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: tor.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender -&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe Trojan/Worm [100] (suspicious)&lt;br /&gt;eTrust-VET Win32/Sintun.AF&lt;br /&gt;eTrust-VET (BETA) Win32/Sintun.AF&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee Tibs-Packed trojan&lt;br /&gt;McAfee (BETA) Tibs-Packed trojan&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 Win32/Nuwar worm (probably variant)&lt;br /&gt;Norman Tibs.gen134&lt;br /&gt;Panda Suspicious file&lt;br /&gt;Panda (BETA) Suspicious file&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising -&lt;br /&gt;Sophos Mal/Dorf-E&lt;br /&gt;Sunbelt VIPRE.Suspicious&lt;br /&gt;Symantec Trojan.Packed.13&lt;br /&gt;Symantec (BETA) Trojan.Packed.13&lt;br /&gt;Trend Micro Possible_Nucrp-3&lt;br /&gt;Trend Micro (BETA) Possible_Nucrp-3&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Win32.Malware.gen (suspicious)&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-1277360309173915229?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/1277360309173915229/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=1277360309173915229' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/1277360309173915229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/1277360309173915229'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/09/vs0709001possible-new-malware-tibsnuwar.html' title='VS0709001 Possible New Malware [Tibs/Nuwar?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-247377425331436926</id><published>2007-08-12T19:49:00.000Z</published><updated>2007-09-06T14:50:29.981Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0708001 Possible New malware [PolyCrypt?]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via a spam e-mail with an attached rar file.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;Also included is data onn the file extracted from the RAR.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: Information (Money Gram).rar&lt;br /&gt;FileDateTime: 12/08/2007 17:48:54&lt;br /&gt;Filesize: 42949&lt;br /&gt;MD5: 0a6f685bd13b8deb963e3c1a8270b66f&lt;br /&gt;CRC32: 476C16CE&lt;br /&gt;File Type: RAR Archive File&lt;br /&gt;&lt;br /&gt;Contains:&lt;br /&gt;&lt;br /&gt;FileName: MG information for my angel 20870432 5-32 PM 08.11.07 order number 11-0427. jpeg.scr&lt;br /&gt;FileDateTime: 12/08/2007 08:23:30&lt;br /&gt;Filesize: 65872&lt;br /&gt;MD5: 35e750f66efa5edda40d5ed3e3c8694e&lt;br /&gt;CRC32: B52AB8AA&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: MG information for my angel 20870432 5-32 PM 08.11.07 order number 11-0427. jpeg.scr&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir TR/Crypt.CFI.Gen&lt;br /&gt;Avast! -&lt;br /&gt;AVG Win32/PolyCrypt&lt;br /&gt;BitDefender -&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe -&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus Trojan-Downloader.Win32.Banload.ams&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman LdPinch.JVR&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising Packer.RyCrypt&lt;br /&gt;Sophos Mal/Basine-C&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster Trojan.DR.Cimuz.Gen.1&lt;br /&gt;WebWasher Trojan.Crypt.CFI.Gen&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-247377425331436926?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/247377425331436926/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=247377425331436926' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/247377425331436926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/247377425331436926'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/08/vs0708001-possible-new-malware.html' title='VS0708001 Possible New malware [PolyCrypt?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-7292171437726547389</id><published>2007-07-24T10:38:00.000Z</published><updated>2007-07-24T11:02:58.794Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0707002 - Possible New Malware [Spambot?]</title><content type='html'>All,&lt;br /&gt;&lt;br /&gt;Data on a sample of a suspected new malware being seeded&lt;br /&gt;via a spam e-mail with a link to the attached sample.&lt;br /&gt;&lt;br /&gt;URL used: http://[SITE NAME REMOVED]/media/cell_phone_prank.scr&lt;br /&gt;&lt;br /&gt;4 copies have been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: cell_phone_prank.scr&lt;br /&gt;FileDateTime: 20/07/2007 17:07:48&lt;br /&gt;Filesize: 219256&lt;br /&gt;MD5: 7c63924fdb8046940d77bfffa6772d7b&lt;br /&gt;CRC32: B8574631&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: cell_phone_prank.scr&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender -&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe -&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet Possible_MLWR.5&lt;br /&gt;Fortinet (BETA) Possible_MLWR.5&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft Trojan:Win32/Mespam.B&lt;br /&gt;Nod32 Win32/TrojanProxy.Jaber.NAD trojan&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising -&lt;br /&gt;Sophos Sus/UnkPacker (suspicious)&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro Possible_MLWR-5&lt;br /&gt;Trend Micro (BETA) Possible_MLWR-5&lt;br /&gt;VBA32 Trojan.Spambot&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Heuristic.Crypted&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-7292171437726547389?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/7292171437726547389/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=7292171437726547389' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/7292171437726547389'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/7292171437726547389'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/07/vs0707002-possible-new-malware-spambot.html' title='VS0707002 - Possible New Malware [Spambot?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-5251672266531684103</id><published>2007-07-06T15:09:00.000Z</published><updated>2007-07-06T15:31:24.638Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0707001 Possible New Malware [Bancos]</title><content type='html'>Data on a sample of a suspected new malware being seeded&lt;br /&gt;via a spam e-mail with a link to the sample detailed below.&lt;br /&gt;&lt;br /&gt;URL used: http://[SITE NAME REMOVED]/media/iphone.scr&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: iphone.scr&lt;br /&gt;FileDateTime: 06/07/2007 15:19:52&lt;br /&gt;Filesize: 41472&lt;br /&gt;MD5: 2c6af05edab480d6a6ed3b9b7ea32f51&lt;br /&gt;CRC32: D0A94CFB&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: iphone.scr&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir TR/Crypt.XPACK.Gen&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender Trojan.Spy.Wsnpoem.A&lt;br /&gt;ClamAV Trojan.Spy-8403&lt;br /&gt;Command W32/Backdoor.ATPB&lt;br /&gt;Dr Web Trojan.Proxy.1872&lt;br /&gt;eSafe Trojan/Worm [100] (suspicious)&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot W32/Backdoor.ATPB&lt;br /&gt;F-Secure Trojan-Spy.Win32.Bancos.aam&lt;br /&gt;F-Secure (BETA) Trojan-Spy.Win32.Bancos.aam&lt;br /&gt;Fortinet W32/Agent.BRW!tr&lt;br /&gt;Fortinet (BETA) W32/Agent.BRW!tr&lt;br /&gt;Ikarus Trojan-Spy.Win32.Bancos.aam&lt;br /&gt;Kaspersky Trojan-Spy.Win32.Bancos.aam&lt;br /&gt;McAfee New Malware.fh (trojan or variant)&lt;br /&gt;McAfee (BETA) New Malware.fh (trojan or variant)&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman -&lt;br /&gt;Panda Suspicious file&lt;br /&gt;Panda (BETA) Suspicious file&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising -&lt;br /&gt;Sophos Mal/EncPk-W&lt;br /&gt;Symantec Infostealer.Banker.C&lt;br /&gt;Symantec (BETA) Infostealer.Banker.C&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Trojan.Crypt.XPACK.Gen&lt;br /&gt;YY_A-Squared -&lt;br /&gt;YY_Spybot Smitfraud-C.,,Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;The site has also been reported to the hosting company, hopefully they can remove the file or pull the site before too many people get infected.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-5251672266531684103?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/5251672266531684103/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=5251672266531684103' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/5251672266531684103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/5251672266531684103'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/07/vs0707001-possible-new-malware-bancos.html' title='VS0707001 Possible New Malware [Bancos]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-1711833430232974315</id><published>2007-04-10T10:26:00.000Z</published><updated>2007-04-10T10:29:31.413Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0704001 Possible new malware [Small/Tibs?]</title><content type='html'>Data on three samples of a suspected new malware being seeded&lt;br /&gt;via e-mail.&lt;br /&gt;&lt;br /&gt;These were caught by my bayesian malware filter.&lt;br /&gt;&lt;br /&gt;I have included multiple samples for your information and analysis.&lt;br /&gt;&lt;br /&gt;3 copies have been trapped so far.&lt;br /&gt;&lt;br /&gt;Subject lines seen:&lt;br /&gt;Missle Strike: The USA kills more then 1000 Iranian citizens&lt;br /&gt;Missle Strike: The USA kills more then 10000 Iranian citizens&lt;br /&gt;&lt;br /&gt;Attachment names seen:&lt;br /&gt;Click Here.exe&lt;br /&gt;Video.exe&lt;br /&gt;Read Me.exe&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: Video.exe&lt;br /&gt;FileDateTime: 08/04/2007 20:50:15&lt;br /&gt;Filesize: 51342&lt;br /&gt;MD5: 99cdc9be6334d73efc241ce93c7ed2fe&lt;br /&gt;CRC32: B2A3D3A6&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;FileName: Click Here.exe&lt;br /&gt;FileDateTime: 08/04/2007 20:59:17&lt;br /&gt;Filesize: 51342&lt;br /&gt;MD5: 4a32764f9165980e255a80ee63edf402&lt;br /&gt;CRC32: 96651D8&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;FileName: Read Me.exe&lt;br /&gt;FileDateTime: 08/04/2007 20:49:10&lt;br /&gt;Filesize: 51342&lt;br /&gt;MD5: 95c563731b7828d6e98eae81ee08869f&lt;br /&gt;CRC32: ED8E7715&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: Click Here.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender Trojan.Peed.Gen&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web Trojan.Packed.80&lt;br /&gt;eSafe Trojan/Worm [100] (suspicious)&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot W32/Trojan.ADUB&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising -&lt;br /&gt;Sophos -&lt;br /&gt;Symantec Trojan.Packed.13&lt;br /&gt;Symantec (BETA) Trojan.Packed.13&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;UNA -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Worm.Win32.Malware.gen (suspicious)&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: Read Me.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender Trojan.Peed.Gen&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web Trojan.Packed.80&lt;br /&gt;eSafe Trojan/Worm [100] (suspicious)&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot W32/Trojan.ADUB&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising -&lt;br /&gt;Sophos -&lt;br /&gt;Symantec Trojan.Packed.13&lt;br /&gt;Symantec (BETA) Trojan.Packed.13&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;UNA -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Worm.Win32.Malware.gen (suspicious)&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: Video.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender Trojan.Peed.Gen&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web Trojan.Packed.80&lt;br /&gt;eSafe Trojan/Worm [100] (suspicious)&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot W32/Trojan.ADUB&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising -&lt;br /&gt;Sophos -&lt;br /&gt;Symantec Trojan.Packed.13&lt;br /&gt;Symantec (BETA) Trojan.Packed.13&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;UNA -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Worm.Win32.Malware.gen (suspicious)&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-1711833430232974315?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/1711833430232974315/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=1711833430232974315' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/1711833430232974315'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/1711833430232974315'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/04/vs0704001-possible-new-malware.html' title='VS0704001 Possible new malware [Small/Tibs?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-4240568729482834963</id><published>2007-03-19T11:12:00.000Z</published><updated>2007-03-19T11:14:39.720Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0703001 Possible new malware [Banload?]</title><content type='html'>Data on a sample of a suspected new malware being downloaded&lt;br /&gt;from a fake e-card site.&lt;br /&gt;&lt;br /&gt;This was caught by an end-user.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: voxcards.exe&lt;br /&gt;FileDateTime: 19/03/2007 08:44:25&lt;br /&gt;Filesize: 148992&lt;br /&gt;MD5: d9ef82e2e71375404b81e3c846b2461e&lt;br /&gt;CRC32: 87379A9F&lt;br /&gt;File Type: PE Executable&lt;br /&gt;Packer: DoomPack&lt;br /&gt;File Attributes: A&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: voxcards.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS Malicious (Cancelled)&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender BehavesLike:Trojan.Downloader (suspected)&lt;br /&gt;ClamAV Trojan.Downloader.Banload-11&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe Trojan/Worm [100] (suspicious)&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus BehavesLikeTrojan.Downloader&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman W32/Downloader (Sandbox)&lt;br /&gt;Panda Suspicious file&lt;br /&gt;Panda (BETA) Suspicious file&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising -&lt;br /&gt;Sophos -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;UNA -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Worm.Win32.Malware.gen!94 (suspicious)&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-4240568729482834963?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/4240568729482834963/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=4240568729482834963' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/4240568729482834963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/4240568729482834963'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/03/vs0703001-possible-new-malware-banload.html' title='VS0703001 Possible new malware [Banload?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-703032452520401700</id><published>2007-02-15T20:03:00.000Z</published><updated>2007-02-15T20:03:23.087Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='results'/><title type='text'>Re: VS0702004 Possible new malware [Downloader?]</title><content type='html'>&lt;strong&gt;Response from F-Secure:&lt;/strong&gt;&lt;br /&gt;The file is indeed a downloader of a password stealer, namely the bzub malware.&lt;br /&gt;&lt;br /&gt;We are adding detection for this file. And this will be included in our next&lt;br /&gt;database update.&lt;br /&gt;&lt;br /&gt;I will update this if  get any further resposnses from the AV vendors.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-703032452520401700?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/703032452520401700/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=703032452520401700' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/703032452520401700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/703032452520401700'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/02/re-vs0702004-possible-new-malware.html' title='Re: VS0702004 Possible new malware [Downloader?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-8426542528586501341</id><published>2007-02-14T20:00:00.000Z</published><updated>2007-02-15T20:02:11.911Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0702004 Possible new malware [Downloader?]</title><content type='html'>Data on a sample of a suspected new malware being seeded via a&lt;br /&gt;fake valentine e-card link which arrives via e-mail.&lt;br /&gt;&lt;br /&gt;Example links:&lt;br /&gt;http:// [removed] .info/uk/view.pd.htm&lt;br /&gt;[URL made safe.]&lt;br /&gt;&lt;br /&gt;which downloads:&lt;br /&gt;http:// [removed] .info/uk/flash/install_flash_player.exe&lt;br /&gt;[URL made safe.]&lt;br /&gt;&lt;br /&gt;This was caught by an end-user.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;2 copies have been trapped so far.&lt;br /&gt;&lt;br /&gt;Screenshots and more details can be found on my momusings blog&lt;br /&gt;&lt;a href="http://momusings.blogsome.com/2007/02/13/stupid-cupid-stop-picking-on-me/"&gt;http://momusings.blogsome.com/2007/02/13/stupid-cupid-stop-picking-on-me/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: install_flash_player.exe&lt;br /&gt;FileDateTime: 13/02/2007 14:56:25&lt;br /&gt;Filesize: 9480&lt;br /&gt;MD5: 95b221b32a46b3918c07e0e22a110f53&lt;br /&gt;CRC32: 56D781F8&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: install_flash_player.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender -&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe -&lt;br /&gt;eTrust-INO -&lt;br /&gt;eTrust-INO (BETA) -&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet -&lt;br /&gt;Fortinet (BETA) -&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal -&lt;br /&gt;Rising -&lt;br /&gt;Sophos -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;UNA -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher -&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-8426542528586501341?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/8426542528586501341/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=8426542528586501341' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/8426542528586501341'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/8426542528586501341'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/02/vs0702004-possible-new-malware.html' title='VS0702004 Possible new malware [Downloader?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-5645414963499309192</id><published>2007-02-13T15:09:00.000Z</published><updated>2007-02-19T15:24:43.236Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0702003 Possible new malware [Sdbot?]</title><content type='html'>Data on a sample of a suspected new malware from a suspected&lt;br /&gt;infected system.&lt;br /&gt;&lt;br /&gt;This was caught by an end-user.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: svrhost.exe&lt;br /&gt;FileDateTime: 11/05/2003 21:12:10&lt;br /&gt;Filesize: 337920&lt;br /&gt;MD5: a37215501c4c8e08295d8407dd571aca&lt;br /&gt;CRC32: DE48337&lt;br /&gt;File Type: PE Executable&lt;br /&gt;File Attributes: RHSA&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: svrhost.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir Worm/Sdbot.337920&lt;br /&gt;Avast! Win32:Eggdrop-AC [Trj]&lt;br /&gt;AVG -&lt;br /&gt;BitDefender DeepScan:Generic.Sdbot.F305D174&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe -&lt;br /&gt;eTrust-INO -&lt;br /&gt;eTrust-INO (BETA) -&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet -&lt;br /&gt;Fortinet (BETA) -&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 NewHeur_PE (probably unknown virus)&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal -&lt;br /&gt;Rising Backdoor.SdBot.wkz&lt;br /&gt;Sophos Troj/IRCBot-UB&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) W32.Spybot.Worm&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) TROJ_IRCBOT.PG&lt;br /&gt;UNA -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Worm.Sdbot.337920&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-5645414963499309192?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/5645414963499309192/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=5645414963499309192' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/5645414963499309192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/5645414963499309192'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/02/vs0702003-possible-new-malware-sdbot.html' title='VS0702003 Possible new malware [Sdbot?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-2323045638067403188</id><published>2007-02-13T15:07:00.000Z</published><updated>2007-02-19T19:33:31.136Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0702002 Possible new malware [Trojan BHO?]</title><content type='html'>Data on a sample of a suspected new malware being served via an FDIC&lt;br /&gt;phishing site.&lt;br /&gt;&lt;br /&gt;This was caught by an end-user.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: safeConnect.exe&lt;br /&gt;FileDateTime: 13/02/2007 10:34:54&lt;br /&gt;Filesize: 817152&lt;br /&gt;MD5: 454284b824688c9949ca58986c57a0b4&lt;br /&gt;CRC32: 2F71CDC&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: safeConnect.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir TR/BHO.AC&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender Trojan.BHO.AC&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe -&lt;br /&gt;eTrust-INO -&lt;br /&gt;eTrust-INO (BETA) -&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet -&lt;br /&gt;Fortinet (BETA) -&lt;br /&gt;Ikarus Trojan.BHO.AC&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman -&lt;br /&gt;Panda -&lt;br /&gt;Panda (BETA) -&lt;br /&gt;QuickHeal -&lt;br /&gt;Rising -&lt;br /&gt;Sophos -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;UNA -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Trojan.BHO.AC&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-2323045638067403188?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/2323045638067403188/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=2323045638067403188' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/2323045638067403188'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/2323045638067403188'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/02/vs0702002-possible-new-malware-trojan.html' title='VS0702002 Possible new malware [Trojan BHO?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-6461966512291786249</id><published>2007-02-12T15:15:00.000Z</published><updated>2007-02-19T19:34:55.748Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0702001 Possible new malware [Delf?]</title><content type='html'>Data on a sample of a suspected new malware from a suspected&lt;br /&gt;infected system.&lt;br /&gt;&lt;br /&gt;This was caught by an end-user.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: test.exe&lt;br /&gt;FileDateTime: 12/02/2007 17:00:26&lt;br /&gt;Filesize: 69120&lt;br /&gt;MD5: 6cca05415f565cb252df71e2a588f722&lt;br /&gt;CRC32: 8D748AF7&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: test.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir BDS/Hupigon.DP&lt;br /&gt;Avast! Win32:Trojano-1315 [Trj]&lt;br /&gt;AVG -&lt;br /&gt;BitDefender -&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web -&lt;br /&gt;eSafe Trojan/Worm [100] (suspicious)&lt;br /&gt;eTrust-INO -&lt;br /&gt;eTrust-INO (BETA) -&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus Trojan-PWS.Win32.Delf.of&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman -&lt;br /&gt;Panda Suspicious file&lt;br /&gt;Panda (BETA) Suspicious file&lt;br /&gt;QuickHeal Suspicious (warning)&lt;br /&gt;Rising -&lt;br /&gt;Sophos -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;UNA -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Trojan.Hupigon.DP&lt;br /&gt;YY_Spybot -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-6461966512291786249?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/6461966512291786249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=6461966512291786249' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/6461966512291786249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/6461966512291786249'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/02/vs0702001-possible-new-malware-delf.html' title='VS0702001 Possible new malware [Delf?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-4343429805866217279</id><published>2007-01-27T15:27:00.000Z</published><updated>2007-02-19T15:27:53.193Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0701007 Possible New Malware [Sdbot?]</title><content type='html'>Data on a sample of a suspected new malware from a suspected infected system.&lt;br /&gt;&lt;br /&gt;This was caught by an end-user.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: msrdc.exe&lt;br /&gt;FileDateTime: 26/01/2007 16:35:00&lt;br /&gt;Filesize: 1262592&lt;br /&gt;MD5: 7a108a8fda9ab48b5bcb23873530d480&lt;br /&gt;CRC32: 3282F443&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: msrdc.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS    -&lt;br /&gt;AntiVir    Worm/Sdbot.1262592&lt;br /&gt;Avast!    -&lt;br /&gt;AVG    IRC/BackDoor.SdBot2.PLI (Trojan horse)&lt;br /&gt;BitDefender    -&lt;br /&gt;ClamAV    -&lt;br /&gt;Command    W32/Backdoor.ZLO&lt;br /&gt;Dr Web    -&lt;br /&gt;eSafe    Win32.SdBot.bcf&lt;br /&gt;eTrust-INO    -&lt;br /&gt;eTrust-INO (BETA)    -&lt;br /&gt;eTrust-VET    -&lt;br /&gt;eTrust-VET (BETA)    -&lt;br /&gt;Ewido    Backdoor.SdBot.bcf&lt;br /&gt;F-Prot    W32/Backdoor.ZLO&lt;br /&gt;F-Secure    Backdoor.Win32.SdBot.bcf&lt;br /&gt;F-Secure (BETA)    Backdoor.Win32.SdBot.bcf&lt;br /&gt;Fortinet    W32/IRCBot.YW!tr.bdr&lt;br /&gt;Fortinet (BETA)    W32/IRCBot.YW!tr.bdr&lt;br /&gt;Ikarus    -&lt;br /&gt;Kaspersky    Backdoor.Win32.SdBot.bcf&lt;br /&gt;McAfee    W32/Sdbot.worm.gen.ca&lt;br /&gt;McAfee (BETA)    W32/Sdbot.worm.gen.ca&lt;br /&gt;Microsoft    -&lt;br /&gt;Nod32    -&lt;br /&gt;Norman    -&lt;br /&gt;Panda    Suspicious file&lt;br /&gt;Panda (BETA)    Suspicious file&lt;br /&gt;QuickHeal    -&lt;br /&gt;Rising    -&lt;br /&gt;Sophos    -&lt;br /&gt;Symantec    W32.Spybot.Worm&lt;br /&gt;Symantec (BETA)    W32.Spybot.Worm&lt;br /&gt;Trend Micro    WORM_SDBOT.BTV&lt;br /&gt;Trend Micro (BETA)    WORM_SDBOT.BTV&lt;br /&gt;UNA    Backdoor.SdBot.EA0B&lt;br /&gt;VBA32    Backdoor.Win32.SdBot.bcf&lt;br /&gt;VirusBuster    -&lt;br /&gt;WebWasher    Worm.Sdbot.1262592&lt;br /&gt;YY_Spybot    -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-4343429805866217279?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/4343429805866217279/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=4343429805866217279' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/4343429805866217279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/4343429805866217279'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/01/vs0701007-possible-new-malware-sdbot.html' title='VS0701007 Possible New Malware [Sdbot?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-242242283661669428</id><published>2007-01-27T15:25:00.000Z</published><updated>2007-02-19T15:28:58.883Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0701006 Possible New Malware [Spybot?]</title><content type='html'>Data on a sample of a suspected new malware from a suspected infected system.&lt;br /&gt;&lt;br /&gt;This was caught by an end-user.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: jamesbond.exe&lt;br /&gt;FileDateTime: 26/01/2007 16:35:00&lt;br /&gt;Filesize: 1339392&lt;br /&gt;MD5: deab1ca16db657329a183bfea8e1f92f&lt;br /&gt;CRC32: EA59BBA6&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: jamesbond.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS    -&lt;br /&gt;AntiVir    PCK/Themida&lt;br /&gt;Avast!    -&lt;br /&gt;AVG    Worm/Spybot.AIQ&lt;br /&gt;BitDefender    -&lt;br /&gt;ClamAV    -&lt;br /&gt;Command    -&lt;br /&gt;Dr Web    -&lt;br /&gt;eSafe    Win32.Spybot&lt;br /&gt;eTrust-INO    -&lt;br /&gt;eTrust-INO (BETA)    -&lt;br /&gt;eTrust-VET    -&lt;br /&gt;eTrust-VET (BETA)    -&lt;br /&gt;Ewido    -&lt;br /&gt;F-Prot    -&lt;br /&gt;F-Secure    -&lt;br /&gt;F-Secure (BETA)    -&lt;br /&gt;Fortinet    W32/RBot.FZO&lt;br /&gt;Fortinet (BETA)    W32/RBot.FZO&lt;br /&gt;Ikarus    -&lt;br /&gt;Kaspersky    -&lt;br /&gt;McAfee    W32/Spybot.worm.gen.p&lt;br /&gt;McAfee (BETA)    W32/Spybot.worm.gen.p&lt;br /&gt;Microsoft    -&lt;br /&gt;Nod32    -&lt;br /&gt;Norman    -&lt;br /&gt;Panda    Suspicious file&lt;br /&gt;Panda (BETA)    Suspicious file&lt;br /&gt;QuickHeal    -&lt;br /&gt;Rising    -&lt;br /&gt;Sophos    W32/Rbot-FZO&lt;br /&gt;Symantec    W32.Spybot.Worm&lt;br /&gt;Symantec (BETA)    W32.Spybot.Worm&lt;br /&gt;Trend Micro    -&lt;br /&gt;Trend Micro (BETA)    -&lt;br /&gt;UNA    -&lt;br /&gt;VBA32    -&lt;br /&gt;VirusBuster    -&lt;br /&gt;WebWasher    Heuristic.Crypted&lt;br /&gt;YY_Spybot    -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-242242283661669428?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/242242283661669428/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=242242283661669428' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/242242283661669428'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/242242283661669428'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/01/vs0701006-possible-new-malware-spybot.html' title='VS0701006 Possible New Malware [Spybot?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-2579949235691757405</id><published>2007-01-24T15:29:00.000Z</published><updated>2007-02-19T15:30:53.945Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0701005 Possible New Malware [Sdbot?]</title><content type='html'>Data on a sample of a suspected new malware from a suspected infected system.&lt;br /&gt;&lt;br /&gt;This was caught by an end-user.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: rundll.exe&lt;br /&gt;FileDateTime: 19/01/2007 14:05:00&lt;br /&gt;Filesize: 1364992&lt;br /&gt;MD5: 71fd1205f6d7550967bda6bf4491a50a&lt;br /&gt;CRC32: 36E8176E&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: rundll.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS    -&lt;br /&gt;AntiVir    -&lt;br /&gt;Avast!    -&lt;br /&gt;AVG    -&lt;br /&gt;BitDefender    -&lt;br /&gt;ClamAV    -&lt;br /&gt;Command    -&lt;br /&gt;Dr Web    -&lt;br /&gt;eSafe    -&lt;br /&gt;eTrust-INO    -&lt;br /&gt;eTrust-INO (BETA)    -&lt;br /&gt;eTrust-VET    -&lt;br /&gt;eTrust-VET (BETA)    -&lt;br /&gt;Ewido    -&lt;br /&gt;F-Prot    -&lt;br /&gt;F-Secure    -&lt;br /&gt;F-Secure (BETA)    -&lt;br /&gt;Fortinet    suspicious&lt;br /&gt;Fortinet (BETA)    suspicious&lt;br /&gt;Ikarus    -&lt;br /&gt;Kaspersky    -&lt;br /&gt;McAfee    -&lt;br /&gt;McAfee (BETA)    -&lt;br /&gt;Microsoft    -&lt;br /&gt;Nod32    -&lt;br /&gt;Norman    -&lt;br /&gt;Panda    W32/Sdbot.JHH.worm&lt;br /&gt;Panda (BETA)    W32/Sdbot.JHH.worm&lt;br /&gt;QuickHeal    -&lt;br /&gt;Rising    -&lt;br /&gt;Sophos    -&lt;br /&gt;Symantec    -&lt;br /&gt;Symantec (BETA)    -&lt;br /&gt;Trend Micro    -&lt;br /&gt;Trend Micro (BETA)    -&lt;br /&gt;UNA    -&lt;br /&gt;VBA32    -&lt;br /&gt;VirusBuster    -&lt;br /&gt;WebWasher    Heuristic.Crypted&lt;br /&gt;YY_Spybot    -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-2579949235691757405?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/2579949235691757405/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=2579949235691757405' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/2579949235691757405'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/2579949235691757405'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/01/vs0701005-possible-new-malware-sdbot.html' title='VS0701005 Possible New Malware [Sdbot?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-8588154991346285341</id><published>2007-01-24T15:00:00.000Z</published><updated>2007-02-19T15:32:30.732Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0701004 Possible New Malware [Sdbot?]</title><content type='html'>Data ona sample of a suspected new malware from a suspected infected system.&lt;br /&gt;&lt;br /&gt;This was caught by an end-user.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;1 copy has been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test them on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: dflrwsxq.exe&lt;br /&gt;FileDateTime: 11/05/2003 20:12:10&lt;br /&gt;Filesize: 158720&lt;br /&gt;MD5: 27376b472d43d2be1baf9eec9c130d93&lt;br /&gt;CRC32: 30381941&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: dflrwsxq.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS    Malicious (Cancelled)&lt;br /&gt;AntiVir    Worm/Sdbot.148609&lt;br /&gt;Avast!    -&lt;br /&gt;AVG    IRC/BackDoor.SdBot2.RHT (Trojan horse)&lt;br /&gt;BitDefender    GenPack:Generic.Sdbot.83DF54A9&lt;br /&gt;ClamAV    -&lt;br /&gt;Command    -&lt;br /&gt;Dr Web    Win32.HLLW.MyBot.based&lt;br /&gt;eSafe    Trojan/Worm [100] (suspicious)&lt;br /&gt;eTrust-INO    -&lt;br /&gt;eTrust-INO (BETA)    -&lt;br /&gt;eTrust-VET    -&lt;br /&gt;eTrust-VET (BETA)    -&lt;br /&gt;Ewido    -&lt;br /&gt;F-Prot    -&lt;br /&gt;F-Secure    -&lt;br /&gt;F-Secure (BETA)    -&lt;br /&gt;Fortinet    -&lt;br /&gt;Fortinet (BETA)    -&lt;br /&gt;Ikarus    -&lt;br /&gt;Kaspersky    -&lt;br /&gt;McAfee    -&lt;br /&gt;McAfee (BETA)    -&lt;br /&gt;Microsoft    -&lt;br /&gt;Nod32    Win32/Rbot trojan (variant)&lt;br /&gt;Norman    W32/Malware.HIY&lt;br /&gt;Panda    Suspicious file&lt;br /&gt;Panda (BETA)    Suspicious file&lt;br /&gt;QuickHeal    Suspicious (warning)&lt;br /&gt;Rising    -&lt;br /&gt;Sophos    Mal/Packer&lt;br /&gt;Symantec    W32.Spybot.Worm&lt;br /&gt;Symantec (BETA)    W32.Spybot.Worm&lt;br /&gt;Trend Micro    -&lt;br /&gt;Trend Micro (BETA)    -&lt;br /&gt;UNA    Backdoor.SdBot.C625&lt;br /&gt;VBA32    Win32.HLLW.MyBot.based&lt;br /&gt;VirusBuster    -&lt;br /&gt;WebWasher    Worm.Sdbot.148609&lt;br /&gt;YY_Spybot    -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-8588154991346285341?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/8588154991346285341/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=8588154991346285341' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/8588154991346285341'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/8588154991346285341'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/01/vs0701004-possible-new-malware-sdbot.html' title='VS0701004 Possible New Malware [Sdbot?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-8844164881551763863</id><published>2007-01-20T15:33:00.000Z</published><updated>2007-02-19T15:34:32.445Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0701003 Possible New Malware [Small?]</title><content type='html'>Data on a sample of a suspected new malware being spread via an e-mail with an attachment.&lt;br /&gt;&lt;br /&gt;This was caught by my Bayesian filter trained to catch e-mail borne malware.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;60 copies have been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: Video.exe&lt;br /&gt;FileDateTime: 19/01/2007 23:24:26&lt;br /&gt;Filesize: 26624&lt;br /&gt;MD5: 01a1115bcb0d5e32a98c76a50ac8868d&lt;br /&gt;CRC32: 79C8760C&lt;br /&gt;File Type: PE Executable&lt;br /&gt;Packer: UPX&lt;br /&gt;&lt;br /&gt;Subject Lines Seen:&lt;br /&gt;Russian missle shot down Chinese satellite&lt;br /&gt;Chinese missile shot down USA satellite&lt;br /&gt;Sadam Hussein alive!&lt;br /&gt;Sadam Hussein safe and sound!&lt;br /&gt;&lt;br /&gt;Attachments Seen:&lt;br /&gt;Full Story.exe&lt;br /&gt;Read More.exe&lt;br /&gt;Full Clip.exe&lt;br /&gt;Video.exe&lt;br /&gt;Full Text.exe&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: Video.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS -&lt;br /&gt;AntiVir -&lt;br /&gt;Avast! -&lt;br /&gt;AVG -&lt;br /&gt;BitDefender -&lt;br /&gt;ClamAV -&lt;br /&gt;Command -&lt;br /&gt;Dr Web BackDoor.Groan&lt;br /&gt;eSafe Trojan/Worm [101] (suspicious)&lt;br /&gt;eTrust-INO -&lt;br /&gt;eTrust-INO (BETA) -&lt;br /&gt;eTrust-VET -&lt;br /&gt;eTrust-VET (BETA) -&lt;br /&gt;Ewido -&lt;br /&gt;F-Prot -&lt;br /&gt;F-Secure -&lt;br /&gt;F-Secure (BETA) -&lt;br /&gt;Fortinet suspicious&lt;br /&gt;Fortinet (BETA) suspicious&lt;br /&gt;Ikarus -&lt;br /&gt;Kaspersky -&lt;br /&gt;McAfee -&lt;br /&gt;McAfee (BETA) -&lt;br /&gt;Microsoft -&lt;br /&gt;Nod32 -&lt;br /&gt;Norman -&lt;br /&gt;Panda Suspicious file&lt;br /&gt;Panda (BETA) Suspicious file&lt;br /&gt;QuickHeal -&lt;br /&gt;Rising -&lt;br /&gt;Sophos -&lt;br /&gt;Symantec -&lt;br /&gt;Symantec (BETA) -&lt;br /&gt;Trend Micro -&lt;br /&gt;Trend Micro (BETA) -&lt;br /&gt;UNA -&lt;br /&gt;VBA32 -&lt;br /&gt;VirusBuster -&lt;br /&gt;WebWasher Win32.ModifiedUPX.gen!90 (suspicious)&lt;br /&gt;YY_Spybot Smitfraud-C.,,Installer&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;This is a new variant of the threat reported as VS0701002 on this blog.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-8844164881551763863?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/8844164881551763863/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=8844164881551763863' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/8844164881551763863'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/8844164881551763863'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/01/vs0701003-possible-new-malware-small.html' title='VS0701003 Possible New Malware [Small?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-5229240040184669109</id><published>2007-01-19T15:35:00.000Z</published><updated>2007-02-19T17:52:59.040Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0701002 Possible New Malware [Small?]</title><content type='html'>Data on a sample of a suspected new malware being spread via an e-mail with an attachment.&lt;br /&gt;&lt;br /&gt;This was caught by my Bayesian filter trained to catch e-mail borne malware.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;35 copies have been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: Video.exe&lt;br /&gt;FileDateTime: 18/01/2007 23:00:39&lt;br /&gt;Filesize: 29347&lt;br /&gt;MD5: 8cb9492e06662a7b4a072cbbe03bbffe&lt;br /&gt;CRC32: 714168B3&lt;br /&gt;File Type: PE Executable&lt;br /&gt;Packer: UPX&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Subject lines seen:&lt;br /&gt;230 dead as storm batters Europe.&lt;br /&gt;A killer at 11, he's free at 21 and kill again!&lt;br /&gt;U.S. Secretary of State Condoleezza Rice has kicked German Chancellor Angela Merkel&lt;br /&gt;Naked teens attack home director.&lt;br /&gt;British Muslims Genocide&lt;br /&gt;&lt;br /&gt;Attachments seen:&lt;br /&gt;Video.exe&lt;br /&gt;Full Story.exe&lt;br /&gt;Read More.exe&lt;br /&gt;Full Clip.exe&lt;br /&gt;Full Video.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: Video.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS    -&lt;br /&gt;AntiVir    -&lt;br /&gt;Avast!    -&lt;br /&gt;AVG    -&lt;br /&gt;BitDefender    MemScan:Trojan.Agent.AHS&lt;br /&gt;ClamAV    Trojan.Downloader-647&lt;br /&gt;Command    W32/Downloader.AYDY&lt;br /&gt;Dr Web    Trojan.Spambot&lt;br /&gt;eSafe    Trojan/Worm [101] (suspicious)&lt;br /&gt;eTrust-INO    -&lt;br /&gt;eTrust-INO (BETA)    -&lt;br /&gt;eTrust-VET    Win32/Tibs!generic&lt;br /&gt;eTrust-VET (BETA)    Win32/Pecoan.B&lt;br /&gt;Ewido    -&lt;br /&gt;F-Prot    W32/Downloader.AYDY&lt;br /&gt;F-Secure    Trojan-Downloader.Win32.Small.dam&lt;br /&gt;F-Secure (BETA)    Trojan-Downloader.Win32.Small.dam&lt;br /&gt;Fortinet    -&lt;br /&gt;Fortinet (BETA)    -&lt;br /&gt;Ikarus    Trojan-Downloader.Win32.Small.dam&lt;br /&gt;Kaspersky    Trojan-Downloader.Win32.Small.dam&lt;br /&gt;McAfee    -&lt;br /&gt;McAfee (BETA)    Downloader-BAI trojan&lt;br /&gt;Microsoft    -&lt;br /&gt;Nod32    Win32/Nuwar.Q worm&lt;br /&gt;Norman    W32/Tibs.gen12&lt;br /&gt;Panda    -&lt;br /&gt;Panda (BETA)    Trj/Alanchum.NX&lt;br /&gt;QuickHeal    -&lt;br /&gt;Rising    -&lt;br /&gt;Sophos    Troj/DwnLdr-FYD&lt;br /&gt;Symantec    Trojan.Packed.8&lt;br /&gt;Symantec (BETA)    Trojan.Packed.8&lt;br /&gt;Trend Micro    TROJ_SMALL.EDW&lt;br /&gt;Trend Micro (BETA)    TROJ_SMALL.EDW&lt;br /&gt;UNA    -&lt;br /&gt;VBA32    -&lt;br /&gt;VirusBuster    Trojan.DL.Tibs.Gen!Pac13&lt;br /&gt;WebWasher    Trojan.Dldr.Small.DBX&lt;br /&gt;YY_Spybot    Smitfraud-C.,,Installer&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;More details and some commentary can be found here [&lt;a href="/momusings/2007/02/when-is-damaged-malware-not-damaged.html"&gt;on my other blog&lt;/a&gt;].&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-5229240040184669109?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/5229240040184669109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=5229240040184669109' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/5229240040184669109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/5229240040184669109'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/01/vs0701002-possible-new-malware-small.html' title='VS0701002 Possible New Malware [Small?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-6552954072730606537</id><published>2007-01-12T15:36:00.000Z</published><updated>2007-02-19T15:37:07.623Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='submitted'/><title type='text'>VS0701001 Possible New Malware [VSBot?]</title><content type='html'>Data on a sample of a suspected new malware being spread via a website,&lt;br /&gt;using a fake e-card e-mail alert to tempt the user to download the fake e-card, whch is actually an executable.&lt;br /&gt;&lt;br /&gt;This was caught by an end-user.&lt;br /&gt;&lt;br /&gt;I have included data on a sample for your information and analysis.&lt;br /&gt;&lt;br /&gt;12 copies have been trapped so far.&lt;br /&gt;&lt;br /&gt;I haven't had a chance to test it on a goat system yet.&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;FileName: Greeting.gif.exe&lt;br /&gt;FileDateTime: 11/01/2007 09:39:16&lt;br /&gt;Filesize: 132838&lt;br /&gt;MD5: c48cbb9ad058eb2d7d0166447b0a2ed9&lt;br /&gt;CRC32: 4DE50071&lt;br /&gt;File Type: PE Executable&lt;br /&gt;Packer/Archiver: NSIS&lt;br /&gt;&lt;br /&gt;============================================================&lt;br /&gt;&lt;br /&gt;Scan report of: Greeting.gif.exe&lt;br /&gt;&lt;br /&gt;@Proventia-VPS    -&lt;br /&gt;AntiVir    TR/Drop.VB.apv.7&lt;br /&gt;Avast!    -&lt;br /&gt;AVG    -&lt;br /&gt;BitDefender    Backdoor.IRCBot.AG&lt;br /&gt;ClamAV    -&lt;br /&gt;Command    -&lt;br /&gt;Dr Web    -&lt;br /&gt;eSafe    -&lt;br /&gt;eTrust-INO    Win32/VSBot.2ob!Trojan&lt;br /&gt;eTrust-INO (BETA)    Win32/VSBot.2ob!Trojan&lt;br /&gt;eTrust-VET    Win32/Veesbot.A&lt;br /&gt;eTrust-VET (BETA)    Win32/Veesbot.A&lt;br /&gt;Ewido    -&lt;br /&gt;F-Prot    -&lt;br /&gt;F-Secure    Backdoor.Win32.VB.apv&lt;br /&gt;F-Secure (BETA)    Backdoor.Win32.VB.apv&lt;br /&gt;Fortinet    W32/VB.APV!tr.bdr&lt;br /&gt;Fortinet (BETA)    W32/VB.APV!tr.bdr&lt;br /&gt;Ikarus    Backdoor.Win32.VB.apv&lt;br /&gt;Kaspersky    Backdoor.Win32.VB.apv&lt;br /&gt;McAfee    -&lt;br /&gt;McAfee (BETA)    -&lt;br /&gt;Microsoft    -&lt;br /&gt;Nod32    -&lt;br /&gt;Norman    -&lt;br /&gt;Panda    -&lt;br /&gt;Panda (BETA)    ERROR&lt;br /&gt;QuickHeal    -&lt;br /&gt;Rising    -&lt;br /&gt;Sophos    -&lt;br /&gt;Symantec    -&lt;br /&gt;Symantec (BETA)    -&lt;br /&gt;Trend Micro    -&lt;br /&gt;Trend Micro (BETA)    -&lt;br /&gt;UNA    -&lt;br /&gt;VBA32    -&lt;br /&gt;VirusBuster    Trojan.DR.VB.YYW&lt;br /&gt;WebWasher    Trojan.Drop.VB.apv.7&lt;br /&gt;YY_Spybot    -&lt;br /&gt;&lt;br /&gt;============================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-6552954072730606537?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malsub.blogspot.com/feeds/6552954072730606537/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3906359852962611562&amp;postID=6552954072730606537' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/6552954072730606537'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/6552954072730606537'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2007/01/vs0701001-possible-new-malware-vsbot.html' title='VS0701001 Possible New Malware [VSBot?]'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3906359852962611562.post-1512452566529702064</id><published>2006-01-01T09:00:00.000Z</published><updated>2007-03-27T13:53:45.520Z</updated><title type='text'>About VSUB</title><content type='html'>&lt;strong&gt;About VSUB&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Virus Sample Submission System&lt;/strong&gt;&lt;br /&gt;VSUB is a an e-mail address used to send new (or suspected) malware samples to a list of anti-malware companies for review.  Just send suspect files to the following e-mail address: vsub@arachnid.homeip.net. Alternatively, if you can't send e-mails with encrypted [password-protected] zips, then please contact me to find out how to submit samples via FTP.&lt;br /&gt;&lt;br /&gt;VSUB is for end-users and security staff to submit suspicious files for review.&lt;br /&gt;&lt;br /&gt;All samples posted will be checked by the administrator to ensure that only new malware samples are forwarded onto the anti-malware vendors.&lt;br /&gt;&lt;br /&gt;All samples will be repackaged as required to ensure that the anti-malware vendors can accept them.&lt;br /&gt;&lt;br /&gt;Samples submitted which are found to be infected by a known, rather than a new malware strain or variant will not be forwarded to the anti-malware companies. In this case the person who submitted the file will be informed of the result and sources of further information and protection from the known malware.&lt;br /&gt;&lt;br /&gt;Samples that are (or appear to contain) new malware will be forwarded to the anti-malware vendors for full analysis. &lt;br /&gt;&lt;br /&gt;Data on new samples submitted to the AV vendors can be found on the vsub blog at &lt;a href="http://momusings.com/vsub/"&gt;http://momusings.com/vsub/&lt;/a&gt;. If you want to keep up to date with new samples submitted, then you can subscribe to the RSS feed for the data on the new samples submitted.&lt;br /&gt;&lt;br /&gt;Details of who supplied the sample will NOT be posted to the vsub blog, only details on the sample itself (such as Filename, Size, Type, MD5 hash, CRC32 checksum and other sample specific information) will be posted. Furthermore this will ONLY happen if the sample is a new malware strain or variant.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;More details below:&lt;/strong&gt;&lt;br /&gt;ALL postings come to the moderator for evaluation, and will be actioned accordingly:&lt;br /&gt;&lt;br /&gt;New malware samples (new variants/malcode not detected by a test suite of products) and a quick analysis will be:&lt;br /&gt;&lt;br /&gt;a. catalogued, and this data posted on my site, as a heads-up (no samples, only data).&lt;br /&gt;&lt;br /&gt;b. sent onto the anti-malware companies for analysis. Data received back from the anti-malware vendors may be posted on the site.&lt;br /&gt;&lt;br /&gt;Known malware samples received&lt;br /&gt;&lt;br /&gt;a. Person who submitted the sample will be informed, along with links for further information. &lt;br /&gt;&lt;br /&gt;Anyone can submit samples. &lt;br /&gt;&lt;br /&gt;Submitting samples to the vsub e-mail address does &lt;em&gt;NOT&lt;/em&gt; automatically send them onto the anti-malware vendors.&lt;br /&gt;&lt;br /&gt;ALL postings are moderated, and all samples are validated and catalogued.&lt;br /&gt;&lt;br /&gt;Samples will only be sent to the anti-malware vendors.&lt;br /&gt;&lt;br /&gt;No user data will be posted to the blog only passed onto the anti-malware vendors along with the samples (to aid resolution or to gain more information from the person who submitted the sample).&lt;br /&gt;&lt;br /&gt;If you represent an anti-malware company which is not already on my list of vendors, then please send details to me for review and possible inclusion.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3906359852962611562-1512452566529702064?l=malsub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/1512452566529702064'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3906359852962611562/posts/default/1512452566529702064'/><link rel='alternate' type='text/html' href='http://malsub.blogspot.com/2006/01/about-vsub.html' title='About VSUB'/><author><name>Martin</name><uri>http://www.blogger.com/profile/15755026122180374114</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://momusings.com/images/Vb2003-sml.gif'/></author></entry></feed>
