View Full Version : thanks to tds-3 I caught a trojan
baddreams
December 31st, 2003, 05:46 PM
I had just downloaded the tds-3 trial and on the first run it shutdown before I could even read what it was doing. This puzzled me so I ran it several more times with basically the same results but on a couple of occasions I saw 3 entries at the bottom in the ALARM area i made note of a file named 001.sys and a registery entry with a filename winupdate.exe. I did a search for the 001.sys file and was amazed at what it contained.. every keystroke I had made over the last 3 hours including 2 credit card purchases. I deleted the file. It came back. ??? :'( So then I searched Google.com for the 001.sys file and found out it was a file made by a backdoor trojan and found more info on deleting the entry in the registry and then deleting the keylog file.
Thanks again for the wonderful product PC-Cillin 2004 didn't even make a sound. I had no idea I had any problems on my computer.
Happy New Year!!!!!!!!!!!
Jooske
December 31st, 2003, 05:53 PM
Hi Baddreams, welcome to the TDS experience on this wonderful almost new year!
Glad it worked for you!
You might like if ever happens such a thing again (hope NEVERR!) to zip such a file and try to snipe out who is receiving your data. Hope somehow you are able to change whatever can be changed, passwords and all the kind to be extra safe just in case some data was sent out already.
baddreams
December 31st, 2003, 06:00 PM
I went through my router log file and found the I.P. and port used. I also disabled my router from sending or recieving anything to or from that I.P. but I have not been able to find any more info on the I.P :'( >:( I would like very much to get more info on the I.P. and return the favor lol..
Jooske
December 31st, 2003, 06:19 PM
Get the Port Explorer with it, so you can see all possible data packets between that IP and your system. It would be nice to create a nice log for him with that name, doesn't it? His own data in it for example (very nasty grin)
DolfTraanberg
January 1st, 2004, 09:10 PM
You might even want to conceder installing Process Guard to protect TDS from being killed.
Dolf
gkweb
January 2nd, 2004, 03:24 AM
that was i thought :)
the demo version allows you to protect only one process, but it's exactly what you need, protect TDS-3.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums