Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 24th, 2002, 09:43 AM
Steff Wiltersen
 
Posts: n/a
Default SubSARI?

When I scanned my computer for trojans, I found a trojan on my harddrive. The name on the trojan, was SubSARI.
Do you no about this trojan? Is this a dangerous trojan? And what meaning have the word "SARI"?

Thanks for all help!

-Steff
  #2  
Old February 24th, 2002, 10:37 AM
spy1's Avatar
spy1 spy1 is offline
Massive Poster
 
Join Date: Dec 2002
Location: Clover, SC
Posts: 3,129
Default Re: SubSARI?

Steff - Welcome to the forum!

A little info here: http://www.safersite.com/PestInfo/S/Subsari.asp . Pete
__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis
  #3  
Old February 24th, 2002, 10:44 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re: SubSARI?

Hi Steff,

In addition to Pete's reply:

You didn't mention what software you have been using to detect this one. Be sure to remove/delete the malware from your system.

After doing so, change all passwords. Although your system has been cleaned, passwords most probably are known by several, and thus can be abused.

Finally: practicing safe computing *will avoid infections like these. Any idea how it ended up in your system?

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #4  
Old February 24th, 2002, 06:36 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,947
Default Re: SubSARI?

BOClean found Subsari on my drive while I was installing Editpad lite.
According to both Kevin McAleavy and Jan Goyvaerts of JGSoft this was a false positive because of BOClean somehow misjudging the Editpad installer.

As usual Kevin was lighntning fast in providing a fix, which entailed editing BOClean.ini, but unfortunately, whatever we tried, we couldn't get BC to accept Editpad.

However, I hasten to add, this is the only false positive I've ever had with BOClean.

Otherwise it's proved failsafe and completely reliable.

Greetz, *Tony

__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #5  
Old February 24th, 2002, 08:18 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re: SubSARI?

Thanks for the info, Tony *

regards.

paul

__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #6  
Old February 24th, 2002, 08:26 PM
FanJ
 
Posts: n/a
Default Re: SubSARI?

Hi Tony,

A big, warm welcome ! *
It's very nice that you visit the forum!!!

And thanks for the info with respect to BOClean and Editpad Lite. Yep, Kevin always tries to help you; absolutely first class customer support.

Cheers, Jan.
  #7  
Old February 24th, 2002, 08:42 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,947
Default Re: SubSARI?

Hi Jan and Paul,

Thanks for the warm welcome!

I've been in and out, checking this place out, and I must say you guys have done a *fine job!.

It looks great, and you seem to have gathered an absolutely first rate band of moderators and regulars.

Although I've always been interested in everything concerning computer security, *I still feel very much the newbie in this respect, and I'll be sure to drop by regularly to deepen my understanding of these matters.

About the SubSARI issue, *I'm sure we'd have cornered it in the end, *if we'd kept at it, *but it wasn't that important to me, and I decided to install Notepad lite instead, which BOClean didn't object to...

Cheers, *Tony
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #8  
Old February 24th, 2002, 08:57 PM
FanJ
 
Posts: n/a
Default Re: SubSARI?

Thanks Ton ! *

Please be assured I have very much respect for the way you are helping others!

Cheers, Jan.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:03 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums