Someone who never talks to me on msn sent me a link that went to this site:
www.kurci.info
It had my msn email in the link, probably as an ID to see if I clicked it.
I found it kinda odd as it was not even a picture or anything. It had .com as an extension but it was the end of my email, but that's still an executable file.
So I downloaded it and put it in a vm and ran it. It gives a picture viewer error, which is odd, as I'm not actually opening it with any picture viewer as it's an exe, so that error is clearly coded right into it.
Using filemon and regmon and briefly looking through it, it looks like it does some weird stuff to the system, but nothing really noticable.
Has anyone heard of this one before, or is this a new one? Avira does not detect as a virus. With some google research I found logs saying it is malware, but not more then that, no official report or anything.
If it's not well known guess I can dig deeper and code a repair util for it and put it on my site.
Thread moved from Software For Windows to Security.
AnandTech Moderator
mechBgon
www.kurci.info
It had my msn email in the link, probably as an ID to see if I clicked it.
I found it kinda odd as it was not even a picture or anything. It had .com as an extension but it was the end of my email, but that's still an executable file.
So I downloaded it and put it in a vm and ran it. It gives a picture viewer error, which is odd, as I'm not actually opening it with any picture viewer as it's an exe, so that error is clearly coded right into it.
Using filemon and regmon and briefly looking through it, it looks like it does some weird stuff to the system, but nothing really noticable.
Has anyone heard of this one before, or is this a new one? Avira does not detect as a virus. With some google research I found logs saying it is malware, but not more then that, no official report or anything.
If it's not well known guess I can dig deeper and code a repair util for it and put it on my site.
Thread moved from Software For Windows to Security.
AnandTech Moderator
mechBgon