Welcome, Guest. Please login or register.
January 05, 2010, 08:16:54 AM

Login with username, password and session length

347698 Posts
38469 Topics
87438 Members

Latest Member: black widow

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Web-MediaPlayer
« previous next »
Pages: [1] Go Down Print
Author Topic: Web-MediaPlayer  (Read 6403 times)
PegHorse
Comodo Family Member
***
Offline Offline

Posts: 81



WWW
« on: August 07, 2007, 09:26:42 AM »

Hi,


The Web-mediaplayer is a french application that allow to view TV and Radio by using WMP11.
It contains more than 400 Thousands TV & Radio in all countries.

The problem is i suspect this program contain spywares, worms or even trojan !
The Comodo Antivirus did not find anything suspitious, however the HIPS interactive allowed me to Block BUT the problem is that spyware or malware install itself with the Setup so first i have allowed all.

But when i saw that a weird program called lbfkxcjpei.exe i told myself "Man you've got pawned".
First, the file is not visible on Windows, but it is on MS-DOS Console by using "ATTRIB" which show all attributs about a file or folder.
Even on Windows, when you setup to Show all files including protected files, the file remain invisible.

So i've guess, if the file is so hard to find, it means its a malware who try to remain hidden.


Then, Comodo Firewall react and tell me "lbfkxcjpei.exe try to use OLE of FTPRush with invisible connection", doh, i'm right, i've got pawned.


My solution is : Using Hijackthis, not from TrendSecure but the old, then i go to Misc Tools and i choose "Delete file on reboot", then i write the full path(that i can't see) and when i press Open, then Hijackthis could open Smiley
Then, i clean my registry with RegSeeker by searching about lbfkxcjpei.exe and i remove all links about that file.(About 100 links)
So i had rebooted my system, the file is gone and guess what ? I can see his brothers ! So i removed all !


Now i try to search where did i got that ? What was the last program i tried to install ? Web-MediaPlayer ! Ok then let's restart it... Guess what ? Comodo Firewall tell me that program want to drop another random file... Cool now i know where did i get infected. The Comodo Antivirus cannot find it but the firewall helped me =)

The new random file has been submitted to Comodo Antivirus by the HIPS control which i press Block, and i have enabled the file submission. The file has been successfully sent BUT it is not removed yet because its not active.


If you wanna test your skills :
http://www.web-mediaplayer.com/
have fun, just click "Télécharger ici" with IE only because with Firefox it doesn't work lol
Then run it... and install and look for the surprises...

Logged
Rotty
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 898


http://www.venganza.org/ - Noodly Appendage


« Reply #1 on: August 14, 2007, 01:21:59 AM »

Sorry for the late reply.

Since you have sent the file to Comodo Labs, they should be able to look at it.
Logged

The opinions expressed in my posts are my own. 
They do NOT necessarily represent or reflect the views of my employer.
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #2 on: August 14, 2007, 06:38:53 AM »


Now i try to search where did i got that ? What was the last program i tried to install ? Web-MediaPlayer ! Ok then let's restart it... Guess what ? Comodo Firewall tell me that program want to drop another random file... Cool now i know where did i get infected. The Comodo Antivirus cannot find it but the firewall helped me =)



Layered security, what one misses another catches!

 Smiler
Logged

Post proelia praemia.
Die dulci fruere.
Regression
Malware Research Group
Comodo Family Member
*****
Offline Offline

Posts: 79


Peace... just Peace


« Reply #3 on: October 17, 2009, 01:15:35 AM »

This one was a fake russian player, basically a rogue "copycat" dropping a bunch of malwares/spywares.

( The real french player was ''web media player'' not ''web mediaplayer'' here http://www.azertysite.new.fr/ it is outdated )

If you got infected you can use Navilog1 or mbam
Logged

HeffeD
Comodo's Hero
*****
Offline Offline

Posts: 1529


« Reply #4 on: October 17, 2009, 01:50:05 AM »

You might want to look at post dates before replying. This thread last saw action in 2007...
Logged

Tags: TV infected 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.035 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com