ThreatFire Research Blog Home
 
 
« Retirement Community Computers, brastk.exe and AntiVirus 2009
Who Gave These Guys a Cert? »

Crack.exe

If you find yourself installing and running cracks and keygens that you’re downloading over Limeware, stop what you’re doing. First, stop using cracks and pirated software. Secondly, nothing truly is for free.

Limewire users have been seeing various keygens offered over their P2P connections. Over the past few days, there have been multiple releases of AVG LICENSE KEY CRACK BY [SSG].ZIP, HALO KEYGEN BY [ZWT].ZIP, REALTEK AUDIO DRIVER CRACKED BY -=ROGUE=-.ZIP, and NERO 9 NO PATENT CRACK BY ZWT.ZIP. And surprise, surprise, all of these files come with a little treat inside, crack.exe. We’ve seen this sort of keygen package bundled with some severe malware in the past, and we continue to see downloaders and adware installed by this stuff.

Taking a quick look, we find that this dropper will disable the Windows Security Center and Firewall. It will then scan through the system32 directory, attempting to find a random dll name string to borrow from, and then select some digits from the system time to create its dropped dll name string, always ending with “32.dll”. For our ThreatExpert report, the malicious downloader file name created was “glu3232.dll”, and we can identify pieces of the code used to create a random portion of the name here:


and the concatenation of that semi-randomized string with “32.dll” here:

This entry was posted on Tuesday, December 2nd, 2008 at 12:14 pm and is filed under AntiMalware Solutions, Dropper, Undetected malware. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

2 Responses to “Crack.exe”

  1. BRADLEY says:
    December 31, 2008 at 1:45 am

    even though my antivirus cant find this file i used ad watch to see registry changes it is allways changing in registry and using your internet! i found the file locked, then used the repair console function on os setup cd to remove the file glu3232.dll in dos since locked files dont lock in dos after that the internet was clear.

  2. BRADLEY says:
    December 31, 2008 at 1:47 am

    ALSO FYI: i intentionally ran this file on a dummy pc to find its weakness, hey guys gotta have a hobby.

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • Koobface on Yuotube
    • Spamvertizing Social Networks and Why Legitimate Money Will Help Clean Them Up
    • Zbot: Not Your Typical Malware
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • AV-Comparatives weblog
    • Bill Mullins’ Weblog – Tech Thoughts
    • Security Response Blogs
    • Swatkat’s rants
    • ThreatExpert Blog
  • Links

    • AMTSO
    • AV-Test
    • Frank Boldewin’s Reconstructor
    • PC Tools
    • ThreatExpert
    • ThreatFire
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).