OK here I go with another AutoIt v3.0 explaination.
First scan of unpacked file from the
kira.rar file>>>
Quote:
Complete scanning result of "KIRA_bot.exe", received in VirusTotal at 04.22.2007, 15:44:00 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.4.21.0 04.20.2007 no virus found
AntiVir 7.3.1.53 04.22.2007 no virus found
Authentium 4.93.8 04.20.2007 no virus found
Avast 4.7.981.0 04.21.2007 no virus found
AVG 7.5.0.464 04.21.2007 no virus found
BitDefender 7.2 04.22.2007 no virus found
CAT-QuickHeal 9.00 04.21.2007 TrojanDownloader.AutoIt.g <-- Notice how it says Autoit!!
ClamAV devel-20070416 04.21.2007 no virus found
DrWeb 4.33 04.22.2007 no virus found
eSafe 7.0.15.0 04.19.2007 suspicious Trojan/Worm <-- UPX packer that is use by AutoIt!!
eTrust-Vet 30.7.3585 04.21.2007 no virus found
Ewido 4.0 04.22.2007 no virus found
FileAdvisor 1 04.22.2007 no virus found
Fortinet 2.85.0.0 04.22.2007 no virus found
F-Prot 4.3.2.48 04.20.2007 no virus found
F-Secure 6.70.13030.0 04.22.2007 no virus found
Ikarus T3.1.1.5 04.22.2007 IM-Worm.Win32.Sohanad.aa <--UPX packer that is used by AutoIt!
Kaspersky 4.0.2.24 04.22.2007 no virus found
McAfee 5014 04.20.2007 no virus found
Microsoft 1.2405 04.22.2007 no virus found
NOD32v2 2210 04.22.2007 no virus found
Norman 5.80.02 04.21.2007 no virus found
Panda 9.0.0.4 04.22.2007 no virus found
Prevx1 V2 04.22.2007 no virus found
Sophos 4.16.0 04.20.2007 no virus found
Sunbelt 2.2.907.0 04.19.2007 no virus found
Symantec 10 04.22.2007 no virus found
TheHacker 6.1.6.095 04.15.2007 no virus found
VBA32 3.11.4 04.21.2007 no virus found
VirusBuster 4.3.7:9 04.21.2007 no virus found
Webwasher-Gateway 6.0.1 04.22.2007 Worm.Win32.ModifiedUPX.gen!90 (suspicious) <--UPX packer
Aditional Information
File size: 213392 bytes <-- Note file size! Now compare to file below.
MD5: e2a067f7bab62471ac44b9aee3699f69
SHA1: cf516578a9f32234a553a3d38e68e0a44537b937
packers: UPX
packers: UPX
packers: UPX
|
There all faulse postives!
Now heres the scan after unpacking
KIRA_bot.exe with UPX option -d>>>
Quote:
Complete scanning result of "KIRA_bot.exe", received in VirusTotal at 04.22.2007, 15:44:21 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.4.21.0 04.20.2007 no virus found
AntiVir 7.3.1.53 04.22.2007 no virus found
Authentium 4.93.8 04.20.2007 no virus found
Avast 4.7.981.0 04.21.2007 no virus found
AVG 7.5.0.464 04.21.2007 no virus found
BitDefender 7.2 04.22.2007 no virus found
CAT-QuickHeal 9.00 04.21.2007 no virus found
ClamAV devel-20070416 04.21.2007 no virus found
DrWeb 4.33 04.22.2007 no virus found
eSafe 7.0.15.0 04.19.2007 no virus found
eTrust-Vet 30.7.3585 04.21.2007 no virus found
Ewido 4.0 04.22.2007 no virus found
FileAdvisor 1 04.22.2007 no virus found
Fortinet 2.85.0.0 04.22.2007 suspicious
F-Prot 4.3.2.48 04.20.2007 no virus found
F-Secure 6.70.13030.0 04.22.2007 no virus found
Ikarus T3.1.1.5 04.22.2007 no virus found
Kaspersky 4.0.2.24 04.22.2007 no virus found
McAfee 5014 04.20.2007 no virus found
Microsoft 1.2405 04.22.2007 no virus found
NOD32v2 2210 04.22.2007 no virus found
Norman 5.80.02 04.21.2007 no virus found
Panda 9.0.0.4 04.22.2007 no virus found
Prevx1 V2 04.22.2007 no virus found
Sophos 4.16.0 04.20.2007 no virus found
Sunbelt 2.2.907.0 04.19.2007 no virus found
Symantec 10 04.22.2007 no virus found
TheHacker 6.1.6.095 04.15.2007 no virus found
VBA32 3.11.4 04.21.2007 no virus found
VirusBuster 4.3.7:9 04.21.2007 no virus found
Webwasher-Gateway 6.0.1 04.22.2007 no virus found
Aditional Information
File size: 429968 bytes <--File size after unUPX, bigger then above file!
MD5: 646592f8f7279cb5760593453b37b245
SHA1: 930ddb322151310af417d35b0e518f0d6733f337
|
All clean now!
You can goto AutoIt Forum site for another explaination of this by going to this link>>>
AutoIt Forums > AutoIt v3 > General Help and Support > Are my AutoIt EXE's really infected?, How and Why your EXE's have been deleted.
[Only registered and activated users can see links. Click Here To Register...]
You could also use the source file that hieitk has posted and make your own bot by downloading
AutoIt yourself and making your own bot then.
@hieitk > Why the passphrase on
KIRA bot.exe when you post the source anyhow? For future refference don't passphrase the file if your going to post the source anyhow. Your doing a good job otherwise! Keep it up. Be prepaired for this kind of thing using
AutoIt v3.0. You might want to include source files for all
AutoIt made programs. That way you can instruct people to make there own bot by using the source file. Also you might think about including the link to there forum about explaination of scans and direct link to download
AutoIt v3.0 for download of there program to make the bot from sorce.
Hope that help you people out.
}^~^{