Greenguy's Board


Go Back   Greenguy's Board > General Business Knowledge
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2005-05-24, 07:34 AM   #1
stuveltje
Live and learn. And take very careful notes!
 
stuveltje's Avatar
 
Join Date: Apr 2003
Location: Sunny Holland
Posts: 6,157
Send a message via ICQ to stuveltje
wowwwwwwwwwwww Mrhackula i am wokrking on it thanks
stuveltje is offline   Reply With Quote
Old 2005-05-25, 03:01 AM   #2
MrHackula
If something goes wrong at the plant, blame the guy who can't speak English
 
MrHackula's Avatar
 
Join Date: Sep 2003
Location: Montana
Posts: 32
Quote:
Originally Posted by stuveltje
wowwwwwwwwwwww Mrhackula i am wokrking on it thanks
You are welcome.

Now, the mitglieder worm you already know about. Here is the details page at symantec:

http://securityresponse.symantec.com...glieder.b.html

The most interesting line is this one:

"The Trojan also downloads and executes PWSteal.Ldpinch"

... so any common passwords in use are to be suspect and should be changed.

For the hijack this log... There is another tool you might find helpful if you can't reach the first:

http://hjt.iamnotageek.com/

In my opinion the only really bad thing there was already pointed out by someone else(f69j69b):

C:\WINDOWS\System32\system.exe


The actual file in this case is called:

"ssgrate.exe"

... it is just lyint to the system process manager to make it think it has a true filename of: "system.exe"

Read the removal instructions at symantec's site (linked above) and all should be well.

If you need anything else, just ask.

Dealing with this shit is fun, isn't it?

Now you know why my blacklist is up to 67,126 domains.

Pity there aren't enough non-"traffic-trading" (circle jerk) sites out there to bother making a communal blacklist.

Most sites approve anything because the surfer only has a 1-10 chance of seeing an actual gallery anyway. :-(

I hope it is easy fixing from here on out.

Mr. H.
__________________
Integrity = Longevity
MrHackula is offline   Reply With Quote
Old 2005-05-25, 03:23 AM   #3
stuveltje
Live and learn. And take very careful notes!
 
stuveltje's Avatar
 
Join Date: Apr 2003
Location: Sunny Holland
Posts: 6,157
Send a message via ICQ to stuveltje
Quote:
Originally Posted by MrHackula
You are welcome.

Now, the mitglieder worm you already know about. Here is the details page at symantec:

http://securityresponse.symantec.com...glieder.b.html

The most interesting line is this one:

"The Trojan also downloads and executes PWSteal.Ldpinch"

... so any common passwords in use are to be suspect and should be changed.

For the hijack this log... There is another tool you might find helpful if you can't reach the first:

http://hjt.iamnotageek.com/

In my opinion the only really bad thing there was already pointed out by someone else(f69j69b):

C:\WINDOWS\System32\system.exe


The actual file in this case is called:

"ssgrate.exe"

... it is just lyint to the system process manager to make it think it has a true filename of: "system.exe"

Read the removal instructions at symantec's site (linked above) and all should be well.

If you need anything else, just ask.

Dealing with this shit is fun, isn't it?

Now you know why my blacklist is up to 67,126 domains.

Pity there aren't enough non-"traffic-trading" (circle jerk) sites out there to bother making a communal blacklist.

Most sites approve anything because the surfer only has a 1-10 chance of seeing an actual gallery anyway. :-(

I hope it is easy fixing from here on out.

Mr. H.
thanks it seems i got rid of the thing but i got rid of more then needed, i still need to reinstal some of ie and my mail because they dont work good anymore. what a hell, so i am not done yet....i will be back here question is only to ask more or to say i did it
stuveltje is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 06:30 AM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc