New trojan

Dinesh

Wonder Man
Guru
Gold Member
SF Team
Local time
9:24 AM
Messages
8,471
Location
Mumbai, India
Hi, there's this new trojan which I found on a website.
Its filename is Bookmark.exe.
Strange is that only 22/40 anti malware engines were able to detect it.
Currently, I was trying Norton 360 beta 4 which has failed to detect it. :shock:
So far, this trojan has changed my IE8 homepage. Not sure what else it will do.

Here's the Virustotal link about the file analysis :
Virustotal. MD5: edc631287a36a3b91990ec4f90fd7dc2 Trojan.Pasta.dyq Generic.Malware.sp!.20613D67 Generic.Malware.sp!.20613D67


Edit: I ran a quick scan from Vipre AV and it has detected everything of this trojan.
Also, this trojan tried to execute itself and Vipre deteted it.
Capture.PNG
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
Hi, there's this new trojan which I found on a website.
Its filename is Bookmark.exe.
Strange is that only 22/40 anti malware engines were able to detect it.
Currently, I was trying Norton 360 beta 4 which has failed to detect it. :shock:
So far, this trojan has changed my IE8 homepage. Not sure what else it will do.

Here's the Virustotal link about the file analysis :
Virustotal. MD5: edc631287a36a3b91990ec4f90fd7dc2 Trojan.Pasta.dyq Generic.Malware.sp!.20613D67 Generic.Malware.sp!.20613D67


Edit: I ran a quick scan from Vipre AV and it has detected everything of this trojan.
Also, this trojan tried to execute itself and Vipre deteted it.
View attachment 35882
Yes you see now why AV never reach 100% in detection of new malware - this is also what I was talking about in this post: http://www.sevenforums.com/366139-post8.html

BTW. score 22/40 isn't so bad, what if you catch virus which was created few hours/weeks ago with AV detection rate equal... 0/40 or 4/39... like in this example: Virustotal. MD5: 5a34fd85bdac65d50a56a2c69228a726 Packed.Generic.187 VirTool:Win32/Obfuscator.EF High Risk Fraudulent Security Program

Your protection should start from first very important layer:
1. Prevention
then... detection and then cure.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Windows 7 Home Premium x32 SP1
CPU
x2 2.6 GHz
Motherboard
Asus
Memory
A-Data 2GB DDR2-800
Graphics Card(s)
ATI X1250
Sound Card
SB 5.1 Live!
Hard Drives
WD and Seagate FAP
PSU
Tagan TG-480-U01
Keyboard
BTC 6300
Mouse
Logitech VX Nano
Antivirus
None
Hi, there's this new trojan which I found on a website.
Its filename is Bookmark.exe.
Strange is that only 22/40 anti malware engines were able to detect it.
Currently, I was trying Norton 360 beta 4 which has failed to detect it. :shock:
So far, this trojan has changed my IE8 homepage. Not sure what else it will do.

Here's the Virustotal link about the file analysis :
Virustotal. MD5: edc631287a36a3b91990ec4f90fd7dc2 Trojan.Pasta.dyq Generic.Malware.sp!.20613D67 Generic.Malware.sp!.20613D67


Edit: I ran a quick scan from Vipre AV and it has detected everything of this trojan.
Also, this trojan tried to execute itself and Vipre deteted it.
View attachment 35882
Yes you see now why AV never reach 100% in detection of new malware - this is also what I was talking about in this post: http://www.sevenforums.com/366139-post8.html

BTW. score 22/40 isn't so bad, what if you catch virus which was created few hours/weeks ago with AV detection rate equal... 0/40 or 4/39... like in this example: Virustotal. MD5: 5a34fd85bdac65d50a56a2c69228a726 Packed.Generic.187 VirTool:Win32/Obfuscator.EF High Risk Fraudulent Security Program

Your protection should start from first very important layer:
1. Prevention
then... detection and then cure.
very well stated.
 

My Computer

Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
Hi, there's this new trojan which I found on a website.
Its filename is Bookmark.exe.
Strange is that only 22/40 anti malware engines were able to detect it.
Currently, I was trying Norton 360 beta 4 which has failed to detect it. :shock:
So far, this trojan has changed my IE8 homepage. Not sure what else it will do.

Here's the Virustotal link about the file analysis :
Virustotal. MD5: edc631287a36a3b91990ec4f90fd7dc2 Trojan.Pasta.dyq Generic.Malware.sp!.20613D67 Generic.Malware.sp!.20613D67


Edit: I ran a quick scan from Vipre AV and it has detected everything of this trojan.
Also, this trojan tried to execute itself and Vipre deteted it.
View attachment 35882

Hi there
How about publishing the website so this can either be Blacklisted or checked with other programs (or both) or even better to see if one's own computer is resistant against the infection.

Publishing that trojan xxxx can or cannot be detected isn't of any use to man or beast unless you can give some indications as to where and how the infection arose.

Some of the analyses on the Security forum are just like asking the question "How long is a piece of String".

Cheers
jimbo
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built, several laptops HP/ASUS
OS
Linux CENTOS 7 / various Windows OS'es and servers
CPU
Intel i7 Intel i5
Memory
8GB, 16GB
Graphics Card(s)
On Motherboard
Sound Card
Realtek HD audio
Monitor(s) Displays
Apple Cinema display, Samsung LCD
Screen Resolution
1920 X 1080
Hard Drives
4 X 1TB SATA
Mouse
Toshiba wireless laser
Internet Speed
> 20MB up
Dinesh,

Have you tried detecting it with MSE?
 

My Computer

Computer Manufacturer/Model Number
HP DV7-1170us
OS
Windows 7 Ultimate 64 Bit
CPU
Processor Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz,
Motherboard
Compal
Keyboard
IBM Enhanced Keyboard
Mouse
Synaptics PS/2 Touchpad
Jimbo, Dinesh,

I would prefer if this was not posted in the open - no problem to send it via a PM but things in the open could cause problems to less experienced users ;)
 

My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
Jimbo, Dinesh,

I would prefer if this was not posted in the open - no problem to send it via a PM but things in the open could cause problems to less experienced users ;)
I agree hence i didnt post the link in the forum.

@richfrogg:
I have tried scanning it with MSE and it didnt detect it.
 

My Computer

Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
No Anti-Virus software out there is 100% full proof no matter what they say, its just to with sales.
Its just a endless cycle that will never end.
 

My Computer

OS
Windows 7 Ultimate x64 Service Pack 1 (Build 6.1.7601)
CPU
Intel Core 2 Quad Q6600 (G0 Kentsfield) LGA775 (FC-LGA6)
Motherboard
GIGABYTE GA-EP35C-DS3R (Rev. 2.1)
Memory
Corsair TW3X4G1333C9A 4GB PC-10600 (2x XMS3 2GB)
Graphics Card(s)
ASUS nVIDIA GeForce 560
Sound Card
RealTek ALC885/889A/890
Monitor(s) Displays
ChiMei CMV CT-730D 17inch (LCD Monitor)
Screen Resolution
1280-1024 60Hertz (Ture Colour 32bit)
Hard Drives
2x Barracuda 7200.10 SATA 3.0Gb/s 160-GB Hard Drive ST3160815AS (AHCI)
PSU
ANTEC 750w Earthwatts
Case
Thermaltake Shark (VA7000SWA ATX) Full Tower
Cooling
Front 120mm fan (1400 RPM) /Rear 120mm (1400 RPM) blue LED
Keyboard
Labtec Media Desktop Y-SAD65
Mouse
Razer DeathAdder 3G Infrared Sensor (1800DPI)
Internet Speed
Telstra BigPond Elite Liberty ADSL2+ 24Mbps/256kbps
Other Info
ASUS PCE-N13 802.11n Wireless LAN card
Jimbo, Dinesh,

I would prefer if this was not posted in the open - no problem to send it via a PM but things in the open could cause problems to less experienced users ;)


Just to make this completely clear - ANYBODY that posts a link to any form of Virus/malware will get an instant life ban on all our sites.

Where viruses etc are concerned we have a zero tolerance policy.
 

My Computer

Computer type
PC/Desktop
OS
Windows 11
This has now been re-named to Trojan.StartPage.SSSPP ... This is a 'start page' hijacking.

URL's are changed all the time so this infection could be just about anywhere the site owner doesn't keep up with good surveillance and security.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top