Jump to content

Vundo False Positive


S!Ri

Recommended Posts

  • Staff

Hello

c:\documents and settings\user\Bureau\capicom-kb931906-v2102.exe (Trojan.Vundo) -> No action taken. [sTRING=A0C400016AFCFF7508FF15B41100015DC20800CCCCCCCCCC8BFF558BEC817D0CB1000000

7510837D1000750A837D14FE750433C0EB18FF7514FF7510FF750CFF7508FF35A0C40001FF15BC11

0

0015DC2]

01002BFF  |.  A3 A0C40001		MOV DWORD PTR DS:[100C4A0],EAX				 ; |01002C04  |.  6A FC			  PUSH -4										; |Index = GWL_WNDPROC01002C06  |.  FF75 08			PUSH DWORD PTR SS:[EBP+8]					  ; |hWnd01002C09  |.  FF15 B4110001	  CALL DWORD PTR DS:[<&USER32.SetWindowLongA>]   ; \SetWindowLongA01002C0F  |.  5D				 POP EBP01002C10  \.  C2 0800			RET 801002C13	  CC				 INT301002C14	  CC				 INT301002C15	  CC				 INT301002C16	  CC				 INT301002C17	  CC				 INT301002C18	  8BFF			   MOV EDI,EDI01002C1A  /.  55				 PUSH EBP01002C1B  |.  8BEC			   MOV EBP,ESP01002C1D  |.  817D 0C B1000000   CMP DWORD PTR SS:[EBP+C],0B101002C24  |.  75 10			  JNZ SHORT 01002C3601002C26  |.  837D 10 00		 CMP DWORD PTR SS:[EBP+10],001002C2A  |.  75 0A			  JNZ SHORT 01002C3601002C2C  |.  837D 14 FE		 CMP DWORD PTR SS:[EBP+14],-201002C30  |.  75 04			  JNZ SHORT 01002C3601002C32  |.  33C0			   XOR EAX,EAX01002C34  |.  EB 18			  JMP SHORT 01002C4E01002C36  |>  FF75 14			PUSH DWORD PTR SS:[EBP+14]					 ; /lParam01002C39  |.  FF75 10			PUSH DWORD PTR SS:[EBP+10]					 ; |wParam01002C3C  |.  FF75 0C			PUSH DWORD PTR SS:[EBP+C]					  ; |Message01002C3F  |.  FF75 08			PUSH DWORD PTR SS:[EBP+8]					  ; |hWnd01002C42  |.  FF35 A0C40001	  PUSH DWORD PTR DS:[100C4A0]					; |PrevProc = NULL01002C48  |.  FF15 BC110001	  CALL DWORD PTR DS:[<&USER32.CallWindowProcA>]  ; \CallWindowProcA01002C4E  |>  5D				 POP EBP01002C4F  \.  C2 1000			RET 10
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.