View Full Version : Whoo Hoo found a trojan!
Mischief
April 24th, 2004, 07:44 PM
Scan Control Dumped @ 19:01:38 24-04-04
Live trojan found (in process memory): DDoS.RAT.SDBot or variant
File: C:\WINDOWS\System32\msnqmgr.exe
Live trojan found (in process memory): DDoS.RAT.SDBot or variant
File: C:\WINDOWS\System32\msnqmgr.exe
Does anyone have info about this trojan or how I can look it up? I already deleted it and its registry items but I'm just curious.
Pilli
April 25th, 2004, 04:07 AM
Hi Mischief, Shame you deleted it as DiamondCS would liked to have analysed it :)
If you get anymore please zip it up and send to submit@diamondcs.com.au
From within TDS3 you can look up the Help - Primary List for basic information
Here is more information about it:
http://www.sophos.com/virusinfo/analyses/trojircbots.html
Do a Google search for even more info'
Glad you got rid of it anyway :) - Pilli
Jooske
April 25th, 2004, 04:39 AM
Did you also run a HijackThis scan? you can post you log in the HJT forum to make sure you're really clean.
http://www.sophos.com/virusinfo/analyses/trojircbots.html
Mischief
April 25th, 2004, 08:37 AM
-{ Quote: "Did you also run a HijackThis scan? you can post you log in the HJT forum to make sure you're really clean.
http://www.sophos.com/virusinfo/analyses/trojircbots.html" }-
Whats a Hijackthis scan? Is it part of TDS or another program? I'm too tired to look it up. Going to sleep now.
Jooske
April 25th, 2004, 08:45 AM
HijackThis is one of the tools used on this (and many other forums) to see if your system is really clean from malware it it's autostarts.
There are quite some experts on this board to help you looking and fixing if necessary.
http://www.wilderssecurity.com/showthread.php?t=15913
You can also use the DiamondCS AutoStartViewer from their products page (free tools) or both :)
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums