- Joined
- Jan 16, 2004
- Messages
- 353
- Reaction score
- 235
- Trophies
- 2
- Age
- 45
- Website
- www.caitsith2.com
- XP
- 2,520
- Country

I investiged that uips.exe that was included with the zelda patch.
It is definitely a trojan. The official uips.exe is available at http://www.neillcorlett.com (with source code available.) Aparently, helga/mugs took that source code, and built a trojan into it, in this type of fashion.
The initial exe is UPX packed, and is just the loader, to unpack all of the exe files that will infect the system. Next, it loads up the first unpacked exe, which is the trojaned version of uips.exe. At that point, it installs all of the necessary .exe/.dll files (also included with that upx packed loader), to appropiate directories. Finally, the first unpacked exe does its legitimate job, apply the IPS patch, in the way the original uips source code was written.
Strangely enough, norton doesn't detect this trojaned version of uips.exe, so I submitted it to symantec to have a more thourough analysis done.
It is definitely a trojan. The official uips.exe is available at http://www.neillcorlett.com (with source code available.) Aparently, helga/mugs took that source code, and built a trojan into it, in this type of fashion.
The initial exe is UPX packed, and is just the loader, to unpack all of the exe files that will infect the system. Next, it loads up the first unpacked exe, which is the trojaned version of uips.exe. At that point, it installs all of the necessary .exe/.dll files (also included with that upx packed loader), to appropiate directories. Finally, the first unpacked exe does its legitimate job, apply the IPS patch, in the way the original uips source code was written.
Strangely enough, norton doesn't detect this trojaned version of uips.exe, so I submitted it to symantec to have a more thourough analysis done.














