Jump to content
Tuts 4 You

Recommended Posts

CodeExplorer
Posted

Is this a real malware?

C:\Users\UserName\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
that file was renamed to Internet Explorer.vir
It just a shortcut:
"C:\Program Files\Internet Explorer\iexplore.exe" http://hi.ru/?dk71

It is detected by some antiviruses:
https://www.virustotal.com/gui/file/9f9002954be80252c9cd7c73114ac2805343b14259619c08bbda50402899c8b4?nocache=1

InternetExplorer.vir

  • Like 1
Stuttered
Posted

I don't see how, unless the site itself is somehow linked to malware delivery.

  • Like 1
Posted

Hi @CodeExplorer

that shortcut will cause internet explorer (iexplore) to open that website (ofc you already know this).

Now, I used https://www.url2png.com/ to take a look at the content of that URL without visiting it and it seems like there is nothing important there at the moment.

Googling the domain name, I found out that it is quite famous because it has been used by hijackers in the past.

It is possible that you have been infected by a very old and quite silly hijacker (targeting the now-discontinued iexplorer); a simple vir scan should be enough to resolve the situation (or you can search the process yourself).

  • Like 2
Stuttered
Posted (edited)

As a side note, current browsers won't auto-allow a NON-HTTPS (443) connection. You could use the tool Fiddler (or similar) to see if a payload is downloaded. From there, you dissect it (of course).

Edited by Stuttered
  • Like 1
jackyjask
Posted

of course it is :)

alert rate > 50%

the summary is clear - dont install russion SW

  • Like 1
Posted
43 minutes ago, CodeExplorer said:

if this actually a malware

Define "actual malware" :) 

 

Judging from that old VT analysis it's an old pay-per-install adware/browser hijacker.
Back in the old days, this type of software was used to hijack Internet Explorer homepage, inject some ads, run some ad referral/click scams, and/or grab personal information from IE.

Will it destroy your machine today, steal your creditcards and encrypt all your porn collection for a ransom? Unlikely.
Would I personally want such activity on my real machine? Hell, no.

 

CodeExplorer
Posted (edited)

Besides that strange Internet Explorer.lnk I've noticed that portable Firefox doesn't work any more: can't load any website. I also noticed that something is installed as stand alone program (in uninstall) - I can't remember what.
I restored my OS from backup.
I've reinstalled SuperMariotySetup.exe and is not the source of shortcut Internet Explorer.vir
 

Edited by CodeExplorer
CodeExplorer
Posted
1 hour ago, jackyjask said:

have you checked AUtoruns?

I restored my OS from backup. My system is now clean.
 

jackyjask
Posted

how exaclty did you restore your OS?

some super advanced virii might even jump into BIOS
 

CodeExplorer
Posted
1 hour ago, jackyjask said:

how exaclty did you restore your OS?

I have a backup of C:\ partition with "Paragon Backup and Recovery 14 Free"
I just restored C:\ partition from backup.
 

Posted
4 hours ago, CodeExplorer said:

I restored my OS from backup

HUGE respect to you for actually having a backup. :thumbsup:

But given that VMWare Workstation is now free for personal use, why aren't you using it to test the weird and suspicious software you encounter? :wacko:

_blaCKlBYte_
Posted

I saw some adv about "Selling Shortcut .lnk Downloader Builder" in some russian hacking forums.

they sell this app or builder for make undetectable malware downloader.

So be aware ...

  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...