MX Logic
Resources Support Contact MX Logic Login
Search
MX Logic Advantage Services Technology Partners News & Events About MX Logic

MX Logic » MX Logic IT Security Blog

03 April 2008

It's Google Spam! It's Video Spam! It's Malware!


Yet another new twist in the never ending array of Google Spam that we have been seeing over the past 2 months.  The sample that just hit our spamtraps within the last hour has a bit of a new twist to it.

When I first opened this message I thought "Neat!  Google video spam!"  It wasn't until I looked at the source code of the message that I realized that this was just another link to malware redirecting through Google with a fake video as the lure.

Here is a screenshot of the spam:



Clicking any of the links downloads a file named  video_codec-v2.12.384.exe.

So far AV pickup is pretty spotty (stats courtesy of Virustotal):

Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - TR/Dropper.Gen
Authentium - - -
Avast - - Win32:Agent-GPS
AVG - - -
BitDefender - - DeepScan:Generic.Malware.FBldld.D22058AD
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - -
eSafe - - suspicious Trojan/Worm
eTrust-Vet - - -
Ewido - - -
FileAdvisor - - -
Fortinet - - -
F-Prot - - W32/Agent.Q.gen!Eldorado
F-Secure - - Suspicious:W32/Malware!Gemini
Ikarus - - Virus.Win32.Agent.GPS
Kaspersky - - -
McAfee - - Proxy-Agent.af.dr
Microsoft - - Trojan:Win32/Danmec.gen!A
NOD32v2 - - a variant of Win32/Agent.NEQ
Norman - - -
Panda - - -
Prevx1 - - Heuristic: Suspicious File With Bad Child Associations
Rising - - -
Sophos - - Troj/Bdoor-AJR
Symantec - - -
TheHacker - - -
VBA32 - - suspected of Trojan-PSW.Pinch.12 (paranoid heuristics)
VirusBuster - - -
Webwasher-Gateway - - Trojan.Dropper.Gen




Posted by smasiello at 12:25 PM | Link | 2 comments
Re: It's Google Spam! It's Video Spam! It's Malware!
I fell for it. I downloaded it. I installed it. When the icon that I downloaded to the desktop disappeared, I downloaded it again. Symantec found nothing
Posted by sucker on April 3, 2008 at 2:42 PM

Re: It's Google Spam! It's Video Spam! It's Malware!
find by "windows search": video_codec-v2.12.384.exe
in my case this file was hidden somewhere in c:/Windows as VIDEO_CODEC-V2.12.384.EXE-3A6500B6.pf
find and delete... hope that enough
Posted by sucker2 on April 3, 2008 at 4:15 PM

Name:   Required
Email:   Required your email address will not be publicly displayed.

Anti-spam key

Type in the text that you see in the above image:

Your comment:

Sorry, no HTML allowed!

Privacy Policy
© MX Logic, Inc.
All Rights Reserved.

MX Logic
9781 S. Meridian Blvd. Suite 400 Englewood, CO 80112
Toll-Free: +1.877.MXLOGIC