What malware is/was this?

See: http://zulu.zscaler.com/submission/show/fdd449eb1159ec9908f3a7aedbec226b-1344465059
and
http://urlquery.net/report.php?id=120305
Attack code found there…TR/Agent.135168.25?
Unable to properly scan site. Unable to connect.
Bitdefender and WOT flag the site as unsafe…
hpHosts give it a EMD qualification = sites engaged in malware distribution,

polonus

virustotal
https://www.virustotal.com/file/ae011807c2c4aface652a43ccb3a07b7f01ce85e319c88851113506a54b5ebf7/analysis/1344467224/

First seen by VirusTotal
2012-08-08 22:44:39 UTC ( 23 minutter ago )

Hi Pondus,

Thanks for checking. This is malignant spyware. It can come under diiferent names, see: http://v.virscan.org/Win32.SuspectCrc!IK.html

polonus

Sent to Avast! yet? Not detected yet. Latest update at Virus Total shows even Trend Micro detects (16 minutes ago).

I sent it to avast! :wink:

this is Trojan.Win32.Jorik.IRCbot.pvn

Hi folks,

This has to be checked thoroughly. Well, it could also be a FP.
The initial flagged malware was only detected by Emisoft and Ikarus and that could mean 1 FP.
See: http://anubis.iseclab.org/?action=result&task_id=1230dfa4f9992cf34cd43c797b23c86e8

polonus

Kaspersky also flags it now:
https://www.virustotal.com/file/ae011807c2c4aface652a43ccb3a07b7f01ce85e319c88851113506a54b5ebf7/analysis/