Computing.Net > Forums > Security and Virus > Bugs that make you...PART TWO

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Bugs that make you...PART TWO

Reply to Message Icon

Name: aosclay
Date: April 8, 2005 at 07:39:25 Pacific
OS: Unix for Windows for Linu
CPU/Ram: 4.8 ghz / 3 gig
Comment:

Hey all,

Thanks for the input. Guess i should have specified what had already been done before i posted originally :)

The bug i posted about (which still eludes me) had already dodged the following cocktail of tools and detections:

Shredder
AASE
SBSD 1.4 beta
PestPatrol (i forget what version)
TDS-3
plus...

a healthy dose of manual surgery (when i say "delete on reboot", that's what i mean you nasty little bug!)

This was a Win2k Pro PC with NAV 04 installed at the time of infection (and of course, NAV was no help).

This machine was a bloody shipwreck (you'd love the logs) when i got my hands on it, and this last bug is the sole survivor of my surgery. It impresses me.

You should have seen what happened when i plugged it back into a live internet connection....

All immunizations and protections enabled in SBSD and SpywareBlaster. It laughed at these and went right back to work.

TeaTimer noted most of its nefarious activity once it phoned home, but TeaTimer scares the customers :)

This PC will require more manual surgery at a later date.

Still scratching my head and swearing a little. I don't like getting beat.

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ninr.exe

O4 - HKLM\..\Run: [KavSvc] C:\WINNT\system32\vkviza.exe

O20 - Winlogon Notify: Shell Extensions - C:\WINNT\system32\mvj2l91o1.dll
(yes, the 9-character random filename appears to be consistent)

This bug impressed me. Keep thinking gang, and thank you Sabertooth for yanking my chain and giving me some ideas i hadn't thought about yet (but i haven't gone completely stupid...win2k pc, no system restore, and i always unhide all files just in hopes of finding something good - haha) :)

Consider your chain yanked back :)

Its good to see all of you again. Peace kids.

AOSCLAY
PEBKAC, baby



Sponsored Link
Ads by Google

Response Number 1
Name: tommy o
Date: April 8, 2005 at 10:18:46 Pacific
Reply:

Welcome back, my friend. Glad to see your posts again! Take care...

~Tommyo


0

Response Number 2
Name: Kevin The Tech Dude
Date: April 8, 2005 at 12:42:20 Pacific
Reply:

Get some tech skills ya tard... LOL!!!!

KTTD


P.S. Clay is a personal friend of mine so don't blow a fuse folks.


0

Response Number 3
Name: Abnormal
Date: April 8, 2005 at 12:46:58 Pacific
Reply:

Welcome back

BetterInternet/vx2/Transponder/look2me,
newest qoologic/narrator rootkit trojan?

Found a example post for you to work with.
http://castlecops.com/postp504086.html

I could dig up some more find it tools,
no good without instructions though.

Abnormal



0

Response Number 4
Name: josh (by jpag3074)
Date: April 8, 2005 at 13:10:07 Pacific
Reply:

i dont know how you do your manual removal it might be just the same as my manual removal tech. but normally i stop system restore (which u said there is none) boot the machine into safe mode, search the for the file on the machine, delete any reference to it (if it still dont let me delete i do it from CMD PRMPT, and if that dont work i hook the drive into another machine as slave and kill it there) now you maybe be able to blow away the file but where you issue probably lies is in the registry, i would then search the registry for any reference of that file with the .exe on the end and then without the .exe on the end, note any other location that i find fromt the keys that it pulls up before i blow that whole key away, delete all references and restart and see what happens, sometimes it takes a few times cuz some of the spyware BS like to hide itself in the key (i dont remember which one it is) under an alternate name that it recreates itself in the registry startup and recreating the file...i hope that can help you out a little bit if not, hey it was worth a shot right...

Complete Computer Service Inc.
NW Indiana


0

Response Number 5
Name: aosclay
Date: April 8, 2005 at 14:13:12 Pacific
Reply:

Now i feel loved! :)

Hey Kevin, Abs, tommy o (and you too josh, though we've not met).

First bug it brings back in (after everything else is cleaned) is ABetterInternet.

Starbucks ads! Lots of them. LOL. And who says there isn't big money in adware?

Oh well, i'll go back tomorrow and do more surgery on it.

Unfortunately, its a customer's machine, so i'll have to FFR it before too long (can't play with it indefinately). And you all know i HATE that.

Kevin, Abs, Tommy O (and you josh)... good to see all of you again, even though Kevin is a loser and mildy retarded. :)

Thanks for the look, guys.


AOSCLAY
PEBKAC, baby


0

Related Posts

See More



Response Number 6
Name: josh (by jpag3074)
Date: April 8, 2005 at 14:23:20 Pacific
Reply:

man starbucks is the shiznit, dissapoints me that they gots to SPAM...

Complete Computer Service Inc.
NW Indiana


0

Response Number 7
Name: Dog
Date: April 8, 2005 at 16:58:39 Pacific
Reply:

Almost sounds like the good old pepper virus....

D4Dog


0

Response Number 8
Name: Kevin The Tech Dude
Date: April 8, 2005 at 17:52:05 Pacific
Reply:

Clay,

Don't be dissing me, remember I got the power of "remove this message" LOL!!!

Good to see ya.

KTTD


0

Response Number 9
Name: aosclay
Date: April 10, 2005 at 09:41:04 Pacific
Reply:

Dis....
Dis....
Dis....

Good to see you too Kevin. :)

(Hey Dog, yeah, similar to peper, but peper was easier to get rid of, LOL)

AOSCLAY
PEBKAC, baby


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Bugs that make you...PART TWO

Bugs that make you go hmmm... www.computing.net/answers/security/bugs-that-make-you-go-hmmm/15543.html

virus alert!! www.computing.net/answers/security/virus-alert/6836.html

Help! (Warning! Spyware detected... www.computing.net/answers/security/help-warning-spyware-detected/23124.html