View Full Version : kuodsshmkiuu.sys
studiot
07-23-2009, 05:32 PM
Anyone know anything about this file?
It's in %windir%/system32/drivers and is 9k in size.
Reading inside it seems to be something left behind by an old installation of Panda a couple of years ago.
It came to light because I was testing Exterminate IT which threw it up
as a backdoor trojan.
None of the more normal scanners notice it.
rusty.nells
07-23-2009, 05:49 PM
Anyone know anything about this file?
It's in %windir%/system32/drivers and is 9k in size.
Reading inside it seems to be something left behind by an old installation of Panda a couple of years ago.
It came to light because I was testing Exterminate IT which threw it up
as a backdoor trojan.
None of the more normal scanners notice it.
Check it at virustotal.com (http://www.virustotal.com/)
studiot
07-23-2009, 08:44 PM
Well Virus total said they had analysed it before under the guise of another bit of alphabet soup.
Two engines reported a trojan, the rest pass
Rising 21.39.34.00 2009.07.23 RootKit.Win32.Undef.ov
all Google reports in some far eastern language
Norman 6.01.09 2009.07.22 W32/Rootkit.AMIO
all Google reports in an east european language
Threat Expert thinks it originated in Spain, which is conssitent with the Panda details in the header.
So I guess this was something not uninstalled when Panda was removed from the system a couple of years ago.
I knew Symantec left stuff in case you ever went back to them, but I didn't realiese Panda did it as well.
iisjman07
07-24-2009, 04:30 PM
If you're concerned of its legitimacy, upload it to analysis.avira.com
Within 2 days they'll email you with the outcome
vBulletin® v3.8.4, Copyright ©2000-2010, Jelsoft Enterprises Ltd.