PDA

View Full Version : kuodsshmkiuu.sys


studiot
07-23-2009, 05:32 PM
Anyone know anything about this file?

It's in %windir%/system32/drivers and is 9k in size.

Reading inside it seems to be something left behind by an old installation of Panda a couple of years ago.

It came to light because I was testing Exterminate IT which threw it up
as a backdoor trojan.

None of the more normal scanners notice it.

rusty.nells
07-23-2009, 05:49 PM
Anyone know anything about this file?

It's in %windir%/system32/drivers and is 9k in size.

Reading inside it seems to be something left behind by an old installation of Panda a couple of years ago.

It came to light because I was testing Exterminate IT which threw it up
as a backdoor trojan.

None of the more normal scanners notice it.

Check it at virustotal.com (http://www.virustotal.com/)

studiot
07-23-2009, 08:44 PM
Well Virus total said they had analysed it before under the guise of another bit of alphabet soup.

Two engines reported a trojan, the rest pass

Rising 21.39.34.00 2009.07.23 RootKit.Win32.Undef.ov

all Google reports in some far eastern language

Norman 6.01.09 2009.07.22 W32/Rootkit.AMIO

all Google reports in an east european language

Threat Expert thinks it originated in Spain, which is conssitent with the Panda details in the header.

So I guess this was something not uninstalled when Panda was removed from the system a couple of years ago.

I knew Symantec left stuff in case you ever went back to them, but I didn't realiese Panda did it as well.

iisjman07
07-24-2009, 04:30 PM
If you're concerned of its legitimacy, upload it to analysis.avira.com

Within 2 days they'll email you with the outcome