Welcome, Guest. Please login or register.
November 18, 2008, 06:33:57 PM

Login with username, password and session length

212234 Posts
24531 Topics
57714 Members

Latest Member: wilhoit

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Web-MediaPlayer
« previous next »
Pages: [1] Go Down Print
Author Topic: Web-MediaPlayer  (Read 4140 times)
PegHorse
Newbie
*
Offline Offline

Posts: 18


« on: August 07, 2007, 09:26:42 AM »

Hi,


The Web-mediaplayer is a french application that allow to view TV and Radio by using WMP11.
It contains more than 400 Thousands TV & Radio in all countries.

The problem is i suspect this program contain spywares, worms or even trojan !
The Comodo Antivirus did not find anything suspitious, however the HIPS interactive allowed me to Block BUT the problem is that spyware or malware install itself with the Setup so first i have allowed all.

But when i saw that a weird program called lbfkxcjpei.exe i told myself "Man you've got pawned".
First, the file is not visible on Windows, but it is on MS-DOS Console by using "ATTRIB" which show all attributs about a file or folder.
Even on Windows, when you setup to Show all files including protected files, the file remain invisible.

So i've guess, if the file is so hard to find, it means its a malware who try to remain hidden.


Then, Comodo Firewall react and tell me "lbfkxcjpei.exe try to use OLE of FTPRush with invisible connection", doh, i'm right, i've got pawned.


My solution is : Using Hijackthis, not from TrendSecure but the old, then i go to Misc Tools and i choose "Delete file on reboot", then i write the full path(that i can't see) and when i press Open, then Hijackthis could open Smiley
Then, i clean my registry with RegSeeker by searching about lbfkxcjpei.exe and i remove all links about that file.(About 100 links)
So i had rebooted my system, the file is gone and guess what ? I can see his brothers ! So i removed all !


Now i try to search where did i got that ? What was the last program i tried to install ? Web-MediaPlayer ! Ok then let's restart it... Guess what ? Comodo Firewall tell me that program want to drop another random file... Cool now i know where did i get infected. The Comodo Antivirus cannot find it but the firewall helped me =)

The new random file has been submitted to Comodo Antivirus by the HIPS control which i press Block, and i have enabled the file submission. The file has been successfully sent BUT it is not removed yet because its not active.


If you wanna test your skills :
http://www.web-mediaplayer.com/
have fun, just click "Télécharger ici" with IE only because with Firefox it doesn't work lol
Then run it... and install and look for the surprises...

Logged
Rotty
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 793

http://www.venganza.org/ - Noodly Appendage


« Reply #1 on: August 14, 2007, 01:21:59 AM »

Sorry for the late reply.

Since you have sent the file to Comodo Labs, they should be able to look at it.
Logged

The opinions expressed in my posts are my own. 
They do NOT necessarily represent or reflect the views of my employer.
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #2 on: August 14, 2007, 06:38:53 AM »


Now i try to search where did i got that ? What was the last program i tried to install ? Web-MediaPlayer ! Ok then let's restart it... Guess what ? Comodo Firewall tell me that program want to drop another random file... Cool now i know where did i get infected. The Comodo Antivirus cannot find it but the firewall helped me =)



Layered security, what one misses another catches!

 Smiler
Logged

Post proelia praemia.
Die dulci fruere.
Tags: TV infected 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.188 seconds with 20 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com