Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » SuperSick2008
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Exploit Code for Kaminsky DNS Bug Goes Wild »
« Admin Question  
AuthorAll Replies

noway1

join:2004-11-29


edit:
July 28th, @11:46PM

reply to SipSizzurp
Re: SuperSick2008

said by SipSizzurp See Profile :

...This is another NOD32 case, green dot and all.
Q1. Sorry, I don't understand what you mean by this sentence.

Q2. AV Version? Sig version?

Q3. Has the updater been updating regularly or have there been some updates missed? (some NOD32 v3 users are having some updater problems right now)

Q4. Do you know how you got this Vundo?

SipSizzurp
Fo' Shizzle
Premium
join:2005-12-28
Hilo, HI
·RoadRunner Cable


edit:
July 29th, @12:40AM

Q1 The system tray has a green dot. Maximum protection. Number of blocked attacks = 0

Q2 ESET NOD32 AntiVirus 3.0.650.0 Sig Ver. 3304 2008728

Q3 I assume it has been running since it is current.

Q4 No. I wish you hadn't have asked. I just checked it's browser history. It has been to numerous porn sites. The virus may be responsible for some of them, but knowing where I picked the computer up from, not all of them. There was a lot more wrong than Vundo. There was a plethora of trojans and hijackers detected. Spybot found only one more. It is now partially cured, I can get to the local resources in "My Computer" and the start menu is back. It was also empty earlier. Desktop background is still whited out with the icons looking weird. I've got the Exaspery tool running now. It is at about 20% and has found nothing yet. I'm planning to run prevx, and then attempt an exorcism with RKU. After that I'll run SFC to see if I can repair some damage. I'm not sure what else to throw at it.

Looks like the main site for the primary viral download was antivirusxp2008 dot com. The homepage is being hijacked to : softwarereferral dot com. Might make for some interesting whois reading.

Edit - I wonder if she would answer her phone. Easy number to remember !

Domain Name: ANTIVIRUSXP2008.COM

Registrant:
Goya interco llc
Alice Velaques (alice.velasues@botiquestomp.com)
La vaal sq 47 of 54
Kemi
Ahvenanmasnlääni,10755
FI
Tel. +001.41512345678
Fax. +001.41512345678

Creation Date: 17-Jun-2008
Expiration Date: 17-Jun-2009

--
I spent most of my money on Women and Beer, and the rest I just wasted !


SnowyOne
Premium
join:2003-04-05
Kailua, HI
·RoadRunner Cable
·Clearwire Wireless

said by SipSizzurp See Profile :

Creation Date: 17-Jun-2008
Expiration Date: 17-Jun-2009

FWIW, the initial infection probably happened sometime after 17-Jun-2008
-
Forums » Up and Running » Security » SecurityExploit Code for Kaminsky DNS Bug Goes Wild »
« Admin Question  


Friday, 09-Jan 16:22:33 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [162] New Comcast Throttling System 100% Online
· [130] Obama Urges Congress To Delay DTV Transition
· [112] After 10 Years Of Service, Charter Declares Home 'Unserviceable'
· [112] iTunes Dumps The DRM
· [78] Taxing ISPs to Prop Up Failing Newspapers?
· [73] AT&T, Verizon Stocks Tumble
· [62] DOCSIS 3.0 Gets Faster
· [60] Rumor: Google Cooking Up Own Router
· [57] Cable To Grab 75% Of New Subs In 2009
· [56] Feds Start Wait List For DTV Converter Coupons
Most people now reading
· How to download windows 7 beta [Microsoft help]
· [Beta] Windows 7 Beta will be available Friday Jan, 9 2009 [Microsoft help]
· Argh! Mandatory Overtime. [General Questions]
· Is it all down? [World of Warcraft]
· Ten Free Must-Have Security Tools - eWeek.com [Security]
· I just got owned: fraudulent SSL Cert (Comodo) [Security]
· What do you feel happens after someone dies? [General Questions]
· Car insurance [General Questions]
· Archivis' Guide to Naxx (10-man) [World of Warcraft]