Buzus.aanr - Did I dodge this bullet, Sarge?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lichbane, Oct 13, 2008.

  1. Lichbane

    Lichbane Private E-2

    I have a bit of a disaster on Sunday, mainly cause by a lack of thought and being alert on my part. I'm just still a little nervous about the overall outcome and I guess I need to have my mind put to rest.

    The chain of events were as follows:
    1) I downloaded a .rar file with a password and what appeared to be a txt file containing the password ( ... no it was not pron, warez, movies or anything of the sort).

    2) I clicked on what appeared to be the txt file (looking at the icon) and only noticed the .exe extension the oh-no-second after clicking on the file. (I'm not sure what possessed me after that, but the password worked on the compressed file and the contents unzipped just fine). Interesting that I run Vista with UAC running that nothing came up at all. Perhaps it did something. Perhaps nothing. :***

    3) I immediately used the scanner I had available at the time (avast) and it came up nothing. I didn't trust it at all.

    4) I did a System Restore to the previous day. As I hadn't done anything else, it seemed like the safe option at the time.

    5) I went to the site I downloaded from to check comments ... all of which thought it was suss. (Yeh .. all these things I could have checked, but 20/20 hindsight is a bitch) I did a few google searchs on the exe file and variations and they seemed to indicate something was not right. I also downloaded so rootkit finders, malware checkers and so on. Some didn't work. Others found nothing.

    6) I submitted the .exe to a reseach company to investigate and got back some results. It indicated that it did do some suss things. You can see the report here. I also did some investigations on an XP virtual machine to see what changes it made to the registry, but I'm no expert so it didn't make a lot of sense to me. I also grabbed hold of a network sniffer and keylogger detector. I had a couple of interesting network activity running on Process 0, but when I closed uTorrent (which was idle anyway), they went away.

    7) After doing some more investigations on good virus/security/malware systems, I decided to try out Kaspersky. I loaded it up and ran it. Interestingly it discovered the Trojan.Win32.Buzus.aanr on the zipped original exe I still had sitting on my desktop. But apart from some security vulnerabilities with some old copies of java, firefox and some flash dlls I had kicking about, it came up clear. Perhaps the system restore got it before it could do any damage? :confused

    That's where I'm am currently. I'm still not game to access internet banking, tough I did access WoW to dangle a carrot out there and see if anyone would bite; I guess I'll find out this afternoon about that.

    So apart from being a massive diatribe on stupidity of not checking what I'm doing, do people think I've dodged the bullet? Or am I not out of the woods just yet. rolleyes
     
  2. Lichbane

    Lichbane Private E-2

    (Not a bump, just more information)

    I ran a whole bunch of scans last night from the recommended scanners and pretty much came safe.

    The only thing that raised my eyebrow was the Malwarebytes' Anti-Malware log (see attached). It found Trojan.Zlob entries in my registry, however, I'm pretty sure they are false positives as Fireshot is something I've had installed for long time and hasn't caused any issues.

    Unless anyone can offer additional information, I'm going to assume that I've come off lucky.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    can you please upload all 4 of the requested logs? :)

    Those being:
    • superantispyware
    • malware bytes
    • combofix
    • mglogs.zip

    so you need to post 3 more to us before we can move on

    Thanks
    Kestrel13!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds