Jump to content

Malwarebytes

lxwar trojans


1 reply to this topic

#1
Dashke

    True Member

  • Malware Hunters
  • PipPipPipPip
  • 277 posts
  • Gender:Male
  • Location:Belgrade
http://a.lxwar.com/img/1.exe
http://a.lxwar.com/img/2.exe
http://a.lxwar.com/img/3.exe
http://a.lxwar.com/img/4.exe
http://a.lxwar.com/img/5.exe
http://a.lxwar.com/img/6.exe
http://a.lxwar.com/img/7.exe
http://d.lxwar.com/img/8.exe
http://d.lxwar.com/img/9.exe
http://d.lxwar.com/img/10.exe
http://b.lxwar.com/img/11.exe
http://b.lxwar.com/img/12.exe
http://b.lxwar.com/img/13.exe
http://b.lxwar.com/img/14.exe
http://b.lxwar.com/img/15.exe
http://b.lxwar.com/img/16.exe
http://b.lxwar.com/img/17.exe
http://b.lxwar.com/img/18.exe
http://b.lxwar.com/img/19.exe
http://b.lxwar.com/img/20.exe
http://c.lxwar.com/img/21.exe
http://c.lxwar.com/img/22.exe
http://c.lxwar.com/img/23.exe
http://c.lxwar.com/img/24.exe
http://c.lxwar.com/img/25.exe
http://c.lxwar.com/img/26.exe
http://c.lxwar.com/img/27.exe
http://c.lxwar.com/img/28.exe
http://c.lxwar.com/img/29.exe
http://c.lxwar.com/img/30.exe
http://d.lxwar.com/img/31.exe
http://d.lxwar.com/img/32.exe
http://d.lxwar.com/img/33.exe
http://d.lxwar.com/img/34.exe
http://d.lxwar.com/img/35.exe
http://d.lxwar.com/img/36.exe
http://d.lxwar.com/img/37.exe
http://d.lxwar.com/img/38.exe

Dr.Web® Antivirus for DOS/386 v5.0 -

Quote

C:\DOCUME~1\Dashke\Desktop\Infected\1.exe probably infected with DLOADER.Trojan
C:\DOCUME~1\Dashke\Desktop\Infected\1.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\11.exe infected with Trojan.PWS.Wsgame.12056
C:\DOCUME~1\Dashke\Desktop\Infected\11.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\12.exe infected with Trojan.PWS.Wsgame.13214
C:\DOCUME~1\Dashke\Desktop\Infected\12.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\13.exe infected with Trojan.PWS.Wsgame.12326
C:\DOCUME~1\Dashke\Desktop\Infected\13.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\14.exe infected with Trojan.PWS.Wsgame.12056
C:\DOCUME~1\Dashke\Desktop\Infected\14.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\15.exe infected with Trojan.PWS.Wsgame.13092
C:\DOCUME~1\Dashke\Desktop\Infected\15.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\16.exe infected with Trojan.PWS.Wsgame.13128
C:\DOCUME~1\Dashke\Desktop\Infected\16.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\17.exe infected with Trojan.PWS.Wsgame.13097
C:\DOCUME~1\Dashke\Desktop\Infected\17.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\18.exe infected with Trojan.PWS.Wsgame.13092
C:\DOCUME~1\Dashke\Desktop\Infected\18.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\19.exe infected with Trojan.PWS.Wsgame.12059
C:\DOCUME~1\Dashke\Desktop\Infected\19.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\2.exe infected with Trojan.PWS.Stealer.192
C:\DOCUME~1\Dashke\Desktop\Infected\2.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\20.exe infected with Trojan.PWS.Wsgame.13092
C:\DOCUME~1\Dashke\Desktop\Infected\20.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\21.exe infected with Trojan.PWS.Wsgame.12654
C:\DOCUME~1\Dashke\Desktop\Infected\21.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\22.exe infected with Trojan.DownLoad.55204
C:\DOCUME~1\Dashke\Desktop\Infected\22.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\23.exe infected with Trojan.PWS.Wsgame.13093
C:\DOCUME~1\Dashke\Desktop\Infected\23.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\24.exe infected with Trojan.PWS.Wsgame.13092
C:\DOCUME~1\Dashke\Desktop\Infected\24.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\25.exe infected with Trojan.PWS.Wsgame.13092
C:\DOCUME~1\Dashke\Desktop\Infected\25.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\26.exe infected with Trojan.PWS.Wsgame.12367
C:\DOCUME~1\Dashke\Desktop\Infected\26.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\27.exe infected with Trojan.PWS.Wsgame.12325
C:\DOCUME~1\Dashke\Desktop\Infected\27.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\28.exe infected with Trojan.PWS.Wsgame.13214
C:\DOCUME~1\Dashke\Desktop\Infected\28.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\29.exe infected with Trojan.PWS.Wsgame.13092
C:\DOCUME~1\Dashke\Desktop\Infected\29.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\3.exe probably infected with DLOADER.Trojan
C:\DOCUME~1\Dashke\Desktop\Infected\3.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\30.exe infected with Trojan.PWS.Wsgame.12665
C:\DOCUME~1\Dashke\Desktop\Infected\30.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\31.exe infected with Trojan.PWS.Wsgame.12056
C:\DOCUME~1\Dashke\Desktop\Infected\31.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\32.exe infected with Trojan.PWS.Wsgame.13128
C:\DOCUME~1\Dashke\Desktop\Infected\32.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\33.exe infected with Trojan.PWS.Wsgame.13602
C:\DOCUME~1\Dashke\Desktop\Infected\33.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\34.exe probably infected with STPAGE.Trojan
C:\DOCUME~1\Dashke\Desktop\Infected\34.exe infected with Trojan.Siggen.564
C:\DOCUME~1\Dashke\Desktop\Infected\34.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\35.exe infected with Trojan.PWS.Qqpass.3117
C:\DOCUME~1\Dashke\Desktop\Infected\35.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\36.exe infected with Trojan.PWS.Wsgame.12058
C:\DOCUME~1\Dashke\Desktop\Infected\36.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\37.exe infected with Trojan.PWS.Qqpass.3115
C:\DOCUME~1\Dashke\Desktop\Infected\37.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\38.exe infected with Trojan.PWS.Gamania.20623
C:\DOCUME~1\Dashke\Desktop\Infected\38.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\4.exe infected with Trojan.PWS.Wsgame.13092
C:\DOCUME~1\Dashke\Desktop\Infected\4.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\5.exe infected with Trojan.PWS.Wsgame.12654
C:\DOCUME~1\Dashke\Desktop\Infected\5.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\6.exe infected with Trojan.PWS.Wsgame.13092
C:\DOCUME~1\Dashke\Desktop\Infected\6.exe - deleted!
C:\DOCUME~1\Dashke\Desktop\Infected\7.exe infected with Trojan.PWS.Wsgame.12116
C:\DOCUME~1\Dashke\Desktop\Infected\7.exe - deleted!

Password for my uploads is virus.

#2
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,155 posts
  • Gender:Male
  • Location:127.0.0.1
Many thanks Dashke,

Have now added the URL's for harvesting :)

Hehe allow 1 object=the holding folder and MBAM just went 100% smack down(38/38) :)

Malwarebytes' Anti-Malware 1.41
Database version: 3036
Windows 5.1.2600 Service Pack 2

26/10/2009 17:02:39
mbam-log-2009-10-26 (17-02-39).txt

Scan type: Quick Scan
Objects scanned: 39
Time elapsed: 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 38

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\1.exe (Malware.Packer) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\10.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\11.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\12.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\13.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\14.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\15.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\16.exe (Trojan.GamesThief) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\17.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\18.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\19.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\20.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\21.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\22.exe (Trojan.GamesThief) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\23.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\24.exe (Password.Stealer) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\25.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\26.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\27.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\28.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\29.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\3.exe (Malware.Packer) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\30.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\31.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\33.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\34.exe (Backdoor.Farfli) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\35.exe (Trojan.GamesThief) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\36.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\37.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\38.exe (Malware.Packer) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\4.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\5.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\6.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\7.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\8.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\documents and settings\0wn3r\my documents\malware samples\RogueNET\9.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us