Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 11th, 2006, 08:45 AM
Longboard's Avatar
Longboard Longboard is offline
Massive Poster
 
Join Date: Oct 2004
Location: Sydney, Australia
Posts: 3,097
Default Worse and worse and worse...

This just never ends!
See some of the scan reports from the combined scanning.
http://www.bluetack.co.uk/forums/ind...howtopic=15097

Also, there is no way I could understand any of those pop-ups from PG or SSM or other utilities

Shame that more than one AV cant be run at once.
Reminder to use the on line scans and have layers like you are fighting off the winter.

The world wide spiderweb
__________________
Don't confuse me with someone who actually knows what they are talking about.
Linux Registered user 469135
Please, support Medecins Sans Frontieres
  #2  
Old August 11th, 2006, 10:29 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Re: Worse and worse and worse...

Hope somebody from ESET will take a look at these. Anyway NOD32 seems to cover them well.
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
  #3  
Old August 11th, 2006, 12:36 PM
TOMxEU's Avatar
TOMxEU TOMxEU is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: Slovakia
Posts: 1,534
Default Re: Worse and worse and worse...

If someone willingly download trojan into PC, AV can not do much to stop it.
Thanks for this interesting page, it is good to test security settings of the PC.

IP: 81.177.15.226 opened properly, but there was only written: Not found / pwn3d!!.
The rest: cgi & htm did not load, jar & php opened like txt, exe & wmf did not download.

When I finished, I scanned PC with Ewido and other software like GMER. Ewido Reported:
Code:
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\RENB2Q8V\java[1].txt/GetAccess.class -> Downloader.OpenConnection.aj : No action taken. C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\RENB2Q8V\java[1].txt/Installer.class -> Downloader.OpenConnection.aj : No action taken. C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\XOUIEUP0\xpladv596[1].wmf -> Exploit.MS05-053-WMF : No action taken. C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\RENB2Q8V\java[1].txt/NewSecurityClassLoader.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\RENB2Q8V\java[1].txt/NewURLClassLoader.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\RENB2Q8V\lpokhrbxq[1].htm -> Trojan.ProcKill.DJ : No action taken.
When I wanted to check those files with online scanner, they were already deleted by IE.
__________________
Real-Time: Nothing | On-Demand: Nothing [ Lenovo E525 | Yandex | CCleaner | KC SUMo | WiseCare 365 ] ( BlackViper / DEP / OpenDNS / UAC / WiFiRouter )
  #4  
Old August 11th, 2006, 01:50 PM
gerardwil gerardwil is offline
Massive Poster
 
Join Date: Jan 2004
Posts: 4,508
Default Re: Worse and worse and worse...

I went there as well to try with the attached result.

Gerard
Attached Images
 
__________________
25 forum posting etiquette tips
  #5  
Old August 12th, 2006, 10:51 AM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,883
Default Re: Worse and worse and worse...

Does the site still work or what? I went to the site but the only thing that loads is the .com file, after that nothing happens. And which bug is it exploiting? I mean is this a zero day bug or what? I also get to see "Not found / pwn3d!!".

SSM does alert about the .com executable file, good to know that SSM´s protection really works. And I assume that SSM could also block the driver from loading. Would be proof that it can really save your ass from zero day attacks.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:48 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums