Flag: Tornado! Hurricane!

 Forums >>  Target Specific - General  >>  Yahoo autoupdater virus or not?

Topic created on: January 27, 2010 17:26 CST by 0xff0xff .

im new to reversing code but i was able to with the help of google take a hidden exe named yahooautoupdater and decompile it back to its vb code im not into virus writing so im not positive if this is infact a virus heres a piece of of the code this references if it isnt a legit call for yahoo auto updater someone shoot me a pm and tell me what u think of this starnge program i can tell that it uses the zlib compression dll also taps some weird api calls including adding itself to the firewall impersonating a process hooking the kernel directly and another piece of info on this it was preloaded on a windows xp pro sp3 disc pirated my own fault but it crashes the os if i kill the process and every time i hook it with ida or something else it seems to delete itself i also looked at the calls it has enemies,proxies and zombie.getinfo and i googled that it appears to be a virus tecnique is this a new ddos variant it can read current user lanmanager info etc does yahoo update need these things to work or do we have a new virus on our hands?

http://pastebin.com/m7ad9afc0 submain
http://pastebin.com/m243793fd CC
[url] http://pastebin.com/m2a3abe61[/url] MDWK
[url]http://pastebin.com/m7c0356ef [/url] CWK
[url] http://pastebin.com/m6ce08685 [/url] IWE
http://pastebin.com/m4617bdfc CAC
[url] http://pastebin.com/m71a39f31[/url] mdFS
[url] http://pastebin.com/m2e4e7bbb [/url] CTmr
http://pastebin.com/m309918b8 mdlM

those are the decompiled segments of code directly from the running exe

(and finally the API calls)

[url]http://pastebin.com/m1e3a8a28 [/url] API CALLS

  invisghost     January 28, 2010 23:12.15 CST
Can you upload the file somewhere? It would be alot easier to figure out if you could.

Note: Registration is required to post to the forums.

There are 16,646 total registered users.


Recently Created Topics
SSL keyfindert plugi...
Mar/15
ApiHooks.com down
Mar/15
how to crate a PATC...
Mar/10
wsnpoem audio.dll
Mar/09
suggestions - RE tra...
Mar/09
Requesting Suggestio...
Mar/06
Force enable debug p...
Mar/05
upgrading new image ...
Mar/03
upgrading new image ...
Mar/03
upgrading new image ...
Mar/03


Recent Forum Posts
suggestions - RE tra...
enm16
wsnpoem audio.dll
zhane
suggestions - RE tra...
Silkut
how to crate a PATC...
Silkut
suggestions - RE tra...
RolfRolles
wsnpoem audio.dll
debbie
Requesting Suggestio...
secursig
Requesting Suggestio...
phn1x
how to get executabl...
RabidCi...
how to get executabl...
RabidCi...


Recent Blog Entries
RolfRolles
Mar/08
Compiler Optimizations for ...

ReWolf
Mar/04
When memory management goes...

thesprawler
Feb/20
log1949.txt -- Wondering ho...

thesprawler
Feb/20
log1949.log -- created on C...

thesprawler
Feb/17
Trying to reverse the firmw...

More ...


Recent Blog Comments
Boken on:
Mar/12
Compiler Optimizations for ...

wildinto on:
Mar/10
Compiler Optimizations for ...

Orr on:
Mar/10
Compiler Optimizations for ...

bughoho on:
Mar/09
Compiler Optimizations for ...

cliffwolf on:
Mar/08
Compiler Optimizations for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit