republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Trojan Hunter : forum down; strange update
Search Topic:
Uniqs:
2066
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates 08 June 2008 »
« Opera sings anti-malware tune  
page: 1 · 2
AuthorAll Replies

Jrb2
Premium
join:2001-08-31

Trojan Hunter : forum down; strange update

For the TH-users:

1.
The forum is temporarily down. The forum site tells:
quote:
Forums are currently down --
data center in Texas has experienced an explosion in a transformer affecting about 9000 servers.
We hope to have the forums back up late Sunday.

2.
Whether the following is related to that, I don't know but I guess it is.

I got a little bit strange update on Sunday 1 June 2008 using LiveUpdate:
I noticed that some files were reverted back to previous versions:

thguard.exe
I had version 5.0.0.278 with size 1047712.
It is now version 5.0.0.277 with size 1046688.

trojanhunter.exe
I had version 5.0.0.962 with size 2418336.
It is now version 5.0.0.962 with size 2417824.


EGeezer
Summertime -
Premium
join:2002-08-04
Country!

1 edit
See »tech.slashdot.org/article.pl?sid···/1715247

Backup server locations may not have current data.

Jrb2
Premium
join:2001-08-31
Thanks EGeezer for that link !

quote:
Backup server locations may not have current data.

Yes, I was thinking that too.

I guess we can use the European TH-server for updates.

Gavin_TH

join:2003-04-03
Australia

reply to Jrb2
Mail is down as is FTP so I am having an unexpected couple of days off, which is nice

Some functionality is restored, the problems continue to be fixed after a fire at the datacenter (7500 customers servers were affected! ouch..)

Your update must be the last one that was mirrored by the US server ? strange about the EXE change as well, Magnus may need to change something there

FriscoTX

join:2002-10-11
Frisco, TX
reply to Jrb2
Thanks for posting this. I was wondering about the update I received yesterday. This explains it.

Jrb2
Premium
join:2001-08-31

reply to Gavin_TH
Thanks Gavin for coming here and keeping us informed; much appreciated!

As for the changes I noticed: I could have posted detailed info from my file-integrity-checker NISFileCheck but thought that it would not make much sense.

Best regards,
Jan.


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC
reply to Jrb2
In the mix of things..this forum is also down because of that

LandzDown Forum
»www.landzdown.com/


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC
reply to Jrb2
I think they are all back up now..

dannyboy 950
Premium
join:2002-12-30
Port Arthur, TX

Mannnn I am glad I was not on that crew what a mad house it must have been.

I mean several years ago a client had a forklift crash thru a wall and take out a little equipment. I know what a mess that was but it was not near what those people faced.

My hat is off to them. That they are restoreing service as
quick as they are is a near miracle or great disaster planning on their part.

Jrb2
Premium
join:2001-08-31
reply to Name Game
Thanks Name Game. Yes, I can go now to the TH-forum

Yes dannyboy 950, I fully agree: my hat too is off to the folks at the datacenter. Thanks !!!

siliconman01
Premium
join:2005-05-08
Saint Albans, WV

reply to Jrb2
Jrb2,

Did your THG and TH scanner go back to the proper files?

The file C:\Program Files\TrojanHunter 5.0\THGuard.exe has the following Checksum(s)

MD5 - E3A386AFBE97F4D2919395E5D3FCC7A5
---------------------------------------------------
The file C:\Program Files\TrojanHunter 5.0\TrojanHunter.exe has the following Checksum(s)

MD5 - 0EA94DE726F604D7B85C48CEB6E3B6E1


ahulett
Life Without Walls
Premium
join:2003-02-02
Bellevue, WA

reply to Name Game
said by Name Game See Profile :

In the mix of things..this forum is also down because of that

LandzDown Forum
»www.landzdown.com/
I rent the box this site lives on (along with my own personal websites and some other friends' and family's sites) - it's in that datacenter, and it, like everything else in there, is now back online. I'm very appreciative to The Planet's fast response to what happened, and more importantly, I'm glad no one was hurt.
--
Aaron Hulett | Senior Spyware Researcher | Microsoft Malware Protection Center
This posting is provided "AS IS" without warranty, and confers no rights.

Jrb2
Premium
join:2001-08-31

reply to siliconman01
quote:
Jrb2,

Did your THG and TH scanner go back to the proper files?

The file C:\Program Files\TrojanHunter 5.0\THGuard.exe has the following Checksum(s)

MD5 - E3A386AFBE97F4D2919395E5D3FCC7A5
---------------------------------------------------
The file C:\Program Files\TrojanHunter 5.0\TrojanHunter.exe has the following Checksum(s)

MD5 - 0EA94DE726F604D7B85C48CEB6E3B6E1

Hi Tom,

No, it didn't; but see point 2 below.

1.
Here is the report from NISFileCheck together with MD5 checksums (which NISFileCheck doesn't use):

Application: c:\program files\trojanhunter 5.0\thguard.exe
Status: Changed
Version old: 5.0.0.278
Version new: 5.0.0.277
Size old: 1047712
Size new: 1046688
Date old: 2008-03-25 19:08:16
Date new: 2008-06-01 10:45:18
RMD160 Hash old: ECF767E6F6BCD6FB2621BBFA9758F2129A77C649
RMD160 Hash new: 5591691619F1A10E7CCF6047ED1FC2DC455879AA

The file C:\Program Files\TrojanHunter 5.0\THGuard.exe has the following Checksum(s)
MD5 - 2CD163244A3AB1C25DCC41EAB640BEFA

Application: c:\program files\trojanhunter 5.0\trojanhunter.exe
Status: Changed
Version old: 5.0.0.962
Version new: 5.0.0.962
Size old: 2418336
Size new: 2417824
Date old: 2008-03-25 19:08:14
Date new: 2008-06-01 10:45:22
RMD160 Hash old: B1F385FC54AB053FFDF7B93028AF99BC35F27992
RMD160 Hash new: 772038290E904357D62E7E77C4298955BA5D5F2E

The file C:\Program Files\TrojanHunter 5.0\TrojanHunter.exe has the following Checksum(s)
MD5 - 6C31C51AE9A1D99BB0897BB1EEC06149

2.

I re-installed TH, using the install-file which I downloaded in March.
And that gave me the right files back :

Application: c:\program files\trojanhunter 5.0\thguard.exe
Status: Changed
Version old: 5.0.0.277
Version new: 5.0.0.278
Size old: 1046688
Size new: 1047712
Date old: 2008-06-01 10:45:18
Date new: 2008-03-25 19:08:16
RMD160 Hash old: 5591691619F1A10E7CCF6047ED1FC2DC455879AA
RMD160 Hash new: ECF767E6F6BCD6FB2621BBFA9758F2129A77C649

The file C:\Program Files\TrojanHunter 5.0\THGuard.exe has the following Checksum(s)
MD5 - E3A386AFBE97F4D2919395E5D3FCC7A5

Application: c:\program files\trojanhunter 5.0\trojanhunter.exe
Status: Changed
Version old: 5.0.0.962
Version new: 5.0.0.962
Size old: 2417824
Size new: 2418336
Date old: 2008-06-01 10:45:22
Date new: 2008-03-25 19:08:14
RMD160 Hash old: 772038290E904357D62E7E77C4298955BA5D5F2E
RMD160 Hash new: B1F385FC54AB053FFDF7B93028AF99BC35F27992

The file C:\Program Files\TrojanHunter 5.0\TrojanHunter.exe has the following Checksum(s)
MD5 - 0EA94DE726F604D7B85C48CEB6E3B6E1

3.

Then I used LiveUpdate, using the EU-server, to get the last definitions:

Ruleset datestamp : 2008-05-30
Scan kernel : 5.0 (Aurelius)
Ruleset entries : 174080
Trojan definitions : 66668
Detection rules : 174080

4.

PS: I don't understand why different "versions" (they have different size) of the main-file TrojanHunter.exe have the same build-number.

siliconman01
Premium
join:2005-05-08
Saint Albans, WV
I sent an e-mail to Magnus on this. It may be awhile before he responds because it looks like the Texas servers are down again...along with his email.


Telly Boot
Premium
join:2002-05-15
Vancouver, BC
·TELUS

reply to Jrb2
Re: Trojan Hunter : forum down; ...

TH Forum and Website down again: further outages due to generator breakdowns:
From ThePlanet Forum -

"...This morning at approximately 2:45 a.m. CST, the temporary generator supplying power to the servers and environmental control systems located in Phase 1 of our H1 facility shut down. This was caused by some faulty current sensors in the output breaker. The sensors detected an out of balance current condition that did not exist.

Technicians from the generator company were onsite within 15 minutes. After working on the breaker for an hour, they believed the issue was remedied, and the generator was restarted. As the servers and environmental control systems were brought back online, the breaker again caused the generator to trip offline.

At this time we have a replacement breaker in route to the site and will get power restored as soon as physically possible.

We understand the difficult situation this causes for our customers. As such, we are offering to move all H1 Phase 1 customers to our H2 data center here in Houston. This requires physically moving servers to our data center, which is approximately three miles away from the H1 data center. It also requires IP address changes for all servers relocated to H2."
--
Dawn,n,The time when men of reason go to bed. (Ambrose Bierce.)


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

reply to ahulett
Re: Trojan Hunter : forum down; strange update

said by ahulett See Profile :

said by Name Game See Profile :

In the mix of things..this forum is also down because of that

LandzDown Forum
»www.landzdown.com/
I rent the box this site lives on (along with my own personal websites and some other friends' and family's sites) - it's in that datacenter, and it, like everything else in there, is now back online. I'm very appreciative to The Planet's fast response to what happened, and more importantly, I'm glad no one was hurt.
No wonder that data center can't get back on it's feet..you and the family have been plugging in that Magnum XL-200 with too long a power cable.

About time you give it up and head over to Myrtle Beach and take some real rides.
--
Gladiator Security Forum »www.gladiator-antivirus.com/
*
A fun/friendly/informative forum for the mature elder crowd
»www.theover50goldengroup.net


La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
reply to Jrb2
I need to renew my TH subscription. I guess this isn't a good time to attempt doing that.


ahulett
Life Without Walls
Premium
join:2003-02-02
Bellevue, WA
reply to Name Game
What can I say? I am a Power User after all... I guess I was just using too much. :P

Apparently we are both on the first floor of this data center, as I'm offline again as well. (Hi Magnus if you're lurking.)


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

Hang in there Aaron..Phil will get all your data transfered before you lose all your cookies.

»www.youtube.com/watch?v=1pv9psLQ92M


»blog.theplanet.com/flickr/

Cookie crumbs in the Keyboard ?? hmm might be the problem.
»blog.theplanet.com/flickr/album/···ter.html

»blog.theplanet.com/the-planet-videos/

»blog.theplanet.com/flickr/album/···ers.html
--
Gladiator Security Forum »www.gladiator-antivirus.com/
*
A fun/friendly/informative forum for the mature elder crowd
»www.theover50goldengroup.net


Telly Boot
Premium
join:2002-05-15
Vancouver, BC
·TELUS

reply to La Luna
said by La Luna See Profile :

I need to renew my TH subscription. I guess this isn't a good time to attempt doing that.
TrojanHunter forum and website up and running again .
--
Dawn,n,The time when men of reason go to bed. (Ambrose Bierce.)
Forums » Up and Running » Security » SecuritySecurity Software Updates 08 June 2008 »
« Opera sings anti-malware tune  
page: 1 · 2


Tuesday, 10-Nov 07:17:41 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [83] VoIP Over 3G Still Not Working For iPhone
· [83] Verizon Keeps Swinging At AT&T
· [33] Bill Would Force ISPs To Block Financial Scams
· [24] Mediacom Hints At 50, 100 Mbps Speeds
· [14] Clearwire To Get Another $1.5 Billion
· [11] Monday Morning Links
· [9] 15 States Have Now Gotten Broadband Mapping Money
· [6] AT&T Launching New 7.2 Mbps 3G Modem
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· How in the world am I going to get into college? [General Questions]
· My cat is reluctant to exercise. [General Questions]
· 60 Minutes piece on cyber security last night [Security]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· Framed for child porn 151; by a PC virus [Security]
· Opening a file download dialog from a JavaScript function. [Webmasters and Developers]
· [WIN7] Which Services in Win 7 Have You Turned Off? [Microsoft Help]