Jump to content

Malwarebytes

UACd.sys dropper


4 replies to this topic

#1
Lusitano

    New Member

  • Members
  • Pip
  • 39 posts
Does anyone knows which rogue software installs the UACd.sys rootkit? I would like to test it on a sandbox.

#2
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
There's alot more than one dropping that file, for example;

http://www.threatexpert.com/report.aspx?md...143ade90f228c5b
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
Lusitano

    New Member

  • Members
  • Pip
  • 39 posts
They don't mention the source of the rootkit

#4
GT500

    Mostly Cantankerous

  • Trusted Advisors
  • PipPipPipPipPipPip
  • 5,528 posts
  • Gender:Male
  • Location:Fortville, IN

Lusitano said:

They don't mention the source of the rootkit

The source is probably any number of trojans out there on the Internet waiting for you to find them.

BTW: This doesn't really belong in this forum...

Quote

For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...

#5
Jaxryley

    Forum Deity

  • Malware Hunters
  • PipPipPipPipPipPip
  • 6,718 posts
  • Gender:Male
  • Location:West Aussie
  • Interests:Gardening and computers.

View PostMysteryFCM, on Feb 23 2009, 07:34 AM, said:

There's alot more than one dropping that file, for example;

http://www.threatexpert.com/report.aspx?md...143ade90f228c5b
If I put the url's together at the bottom of that Threat Expert report am I seeing the code for more malware that is downloaded by the original sample?

hxxp://windowslogonex.com/banner/crcmds/main

hxxp://explorerex.com/banner/crcmds/main





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us