A new type of virus???

Hi i downlaoded EZuse , a mkv to avi file converter. it had two trojans init which avg caught, that was fine. But when i was installing it, it looked for access to comodo avg and other virus malware detection software. I disconnected from the net and continued. It made changes to anti-virus software. if I had used installation mode when instaliing I might not have caught it. EZuse is also legitimate software, it does what it’s supoosed to, apparent having sophisticated virus in it. Is EZuse a virus??

http ://www.tomkv.com/download/EZuse-MKV-Converter.exe

Direct link changed just in case.

Virustotal.com says: Result: 0/36 (0%) This means that they scanned it with 36 different malware-scanning engines and it came up negative.

So, let’s see what else we can do with this…

Fileadvisor is going to be crunching on it for a while. Maybe if you post the file’s MD5 hash (c0ad563cf3c522744fb57b0fb6f4f5a9) into their site (http://fileadvisor.bit9.com) later, they can give you some more info (since I just sent it to them for the first time, they’ve not yet analyzed it).

Comodo recently released a free online malware analysis tool: http://camas.comodo.com which I am currently testing with your sample. Let’s see what she can do.


Comodo:
[Verdict]
Not Rated as Suspicious

You may want to get yourself a copy of md5sum and make sure the hash for your copy matches the one I just posted in case the file was somehow modified on your system. Even if that doesn’t turn out to be the case, something else could be manipulating the process when you run it, but that seems unlikely since (I’m assuming) none of your other programs seem to be acting up.

Comodo’s analysis doesn’t show any terribly odd behavior.

If I were you, and I really wanted to know the answer, I would get myself a copy of SandboxIE and make sure there’s nothing in the sandbox, and then run this program inside the sandbox. See what it does by analyzing the files and registry entries it creates (you will find a new temporary top-level key in your registry while a sandboxed app is running, but it won’t affect the rest of your registry, and it will be gone when you stop the sandbox).

Next, close the sandbox and delete its contents again, then install your antivirus software into that sandbox. Now, with the antivirus software installed in the sandbox, reinstall eZuse to the sandbox and note any changes it makes to any of the files. In particular, get hashes of the files about which you are concerned, and
then check them again after you’ve installed eZuse into the sandbox. This will tell you if any of those files were changed.

Running anything you’re not sure about is best done with the aide of SandboxIE, especially anything that could be potentially shady.

Malware can jump out of the Sandbox too FYI.

Josh

I ran it diskshielded, it doesn’t look suspisious though

Xan

THanks for your attention everyone. Some of your suggestions are beyond my technical ability which is more modest :slight_smile: Attached is the Defense+ log of it’s activities before I stopped it. I just couldn’t think why an mkv file converter would want to modify AVG and Comodo. I was made suspicious already because it downloaded with two viruses. I did end up with a backdoor virus as well for a while - comodo anti-virus caught that one and I don’t know how that one came in. FYI

COMODO Firewall Pro Logs

Date Created: 03/10/2008 10:28:19
Log Scope: All The Times
Date/Time Application Action Target
30/09/2008 23:59:29 C:\Program Files\EZuse\EZuse MKV Converter\EZuse MKV Converter.exe Access Memory C:\Program Files\COMODO\Firewall\cfp.exe
01/10/2008 00:00:55 C:\Program Files\EZuse\EZuse MKV Converter\EZuse MKV Converter.exe Access Memory C:\Program Files\COMODO\Firewall\cfp.exe
01/10/2008 00:01:02 C:\Program Files\EZuse\EZuse MKV Converter\EZuse MKV Converter.exe Access Memory C:\Program Files\COMODO\Firewall\cfp.exe
01/10/2008 02:52:05 C:\Program Files\EZuse\EZuse MKV Converter\EZuse MKV Converter.exe Access Memory C:\Program Files\Grisoft\AVG7\avgcc.exe
01/10/2008 02:52:18 C:\Program Files\EZuse\EZuse MKV Converter\EZuse MKV Converter.exe Access Memory C:\Program Files\Virtual CD v4 SDK\System\vcsplay.exe
01/10/2008 02:52:42 C:\Program Files\EZuse\EZuse MKV Converter\EZuse MKV Converter.exe Access COM Interface \RPC Control\ntsvcs
01/10/2008 02:53:24 C:\Program Files\EZuse\EZuse MKV Converter\EZuse MKV Converter.exe Access Memory C:\WINDOWS\explorer.exe
01/10/2008 02:53:27 C:\Program Files\EZuse\EZuse MKV Converter\EZuse MKV Converter.exe Access Memory C:\WINDOWS\explorer.exe
01/10/2008 02:53:30 C:\Program Files\EZuse\EZuse MKV Converter\EZuse MKV Converter.exe Send Message C:\WINDOWS\system32\csrss.exe
01/10/2008 02:53:38 C:\Program Files\EZuse\EZuse MKV Converter\EZuse MKV Converter.exe Send Message C:\WINDOWS\system32\csrss.exe
End of The Report

thanks for your time