Welcome Guest [Log In] [Register]
Welcome to The Gang of Five | The Land Before Time. We hope you enjoy your visit.


You're currently viewing our forum as a guest. This means you are limited to certain areas of the board and there are some features you can't use. If you join our community, you'll be able to access member-only sections, and use many member-only features such as customizing your profile, sending personal messages, and voting in polls. Registration is simple, fast, and completely free.


Join our community!


If you're already a member please log in to your account to access all of our features:

Username:   Password:
Add Reply
Trojan Virus Dealt with!
Topic Started: Jun 1 2009, 11:33:45 AM (261 Views)
pokeplayer984
Member Avatar
Yes, that's a new Pokemon!
I'm not sure how it happened, but I had to deal with a rather nasty Trojan this morning. Here's the deal with it.

I'm not sure how I got it because the ONLY thing I've downloaded are some pictures off photobucket. I guess it was a hijacking Trojan of some kind. (Plus the only other places I've been are this site, YouTube, ScrewAttack and my e-mail. (Making sure to get rid of the untrustworthy stuff without looking at it, thank you very much.))

Anyways, what it did was that it infected the "system 32" file and a few registry files. This stopped me from having internet access, thus making me unable to update. I then decided to take action and go into Safe Mode with Networking.

After that, I was able to update, and Malwarebytes took care of the rest. It wasn't able to find it before the update, but after that, it was able to detect it and clean it.

Also, since I update my stuff weekly, what we're looking at here is a brand new Trojan outbreak. Update your arsenal guys, or you won't have internet access.

Well, that's what I wanted to report.

See ya later!
Offline Profile Quote Post Goto Top
 
DarkHououmon
Member Avatar
"Be prepared, Snappy boy. Your luck has run out..."

Losing internet access isn't really new when it comes to malware. I have already been aware that some malware, such as some of the latest rogues, will lock down the computer so badly (not just losing internet access, but other functionality) that there are few options left on how to deal with the threat.
Offline Profile Quote Post Goto Top
 
pokeplayer984
Member Avatar
Yes, that's a new Pokemon!
Oh yeah, I almost forgot, here's what the report said of exactly what it infected so you guys can know what to look out for:

Quote:
 
Malwarebytes' Anti-Malware 1.37
Database version: 2206
Windows 5.1.2600 Service Pack 3

6/1/2009 7:47:36 AM
mbam-log-2009-06-01 (07-47-36).txt

Scan type: Full Scan (C:\|)
Objects scanned: 134408
Time elapsed: 11 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\memsweep2 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\memsweep2 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\memsweep2 (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\1.tmp (Trojan.Agent) -> Quarantined and deleted successfully.


The memsweep2 files apparently. Keep an eye out, guys. :)
Offline Profile Quote Post Goto Top
 
DarkHououmon
Member Avatar
"Be prepared, Snappy boy. Your luck has run out..."

Memsweep2 is associated with Sophos AntiRootkit apparently.

http://www.threatexpert.com/report.aspx?md...7078d8c5ccb79d8
Offline Profile Quote Post Goto Top
 
Kor
Member Avatar


Sounds nasty. Glad you managed to get it cleared up and nice of you to inform folks here and what they could do.
Offline Profile Quote Post Goto Top
 
Petrie.
Member Avatar
GOF Founder

Thanks for the logfile. I was going to ask for it if you hadn't posted it later.
Offline Profile Quote Post Goto Top
 
pokeplayer984
Member Avatar
Yes, that's a new Pokemon!
Ugh! I don't know what's going on but system32 got infected with a Trojan again.

I haven't downloaded anything since the last time I cleaned it.

Then again, my brother has reinstalled and used Limewire as of late. -_-
Offline Profile Quote Post Goto Top
 
DarkHououmon
Member Avatar
"Be prepared, Snappy boy. Your luck has run out..."

Yeah, it could be something your brother downloaded.
Offline Profile Quote Post Goto Top
 
pokeplayer984
Member Avatar
Yes, that's a new Pokemon!
DarkHououmon,Jun 11 2009
09:37 AM
Yeah, it could be something your brother downloaded.

Well, good luck telling him to stop with Limewire. He's addicted to downloading stuff with it. :(
Offline Profile Quote Post Goto Top
 
1 user reading this topic (1 Guest and 0 Anonymous)
« Previous Topic · Computer and Electronics · Next Topic »
Add Reply

Modified version of the theme/skin created by "Jameswgw". Find more great designs at the ZetaBoards Theme Zone.