Trojans from website

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • xant14
    V.I.P. Member
    • Dec 2008
    • 2062

    #1

    Trojans from website

    Just thought I'd post this to show you the maliciousness of some sites. I think I have it all sorted now, but I was worried all day yesterday.
    I downloaded some .rar files from Rapidshare, and when it came to unzipping them, they were password protected. So I popped the file name plus the word password into google. I found a site (I'm still on google page) that showed the password 'TeamVeder', but as the word 'TeamVeder' was at the end of the google description, I wondered if there was anything after this word as part of the password, so I tried to enter the site.

    The chrome browser notified me that it may be a err, bad site, do I wanna navigate away from it... I clicked no! twice !!

    The next thing my hard drive is whirring away like mad, so I closes the website, with the X.
    It says, and I forget the exact words coz I'm panicking, Java script hasnt finished, are you sure I wanna cancel..
    I say yes to this..
    Immediately a pop up comes to say windows firewall has been turned off, click the balloon to rectify this.
    so I do..
    Things seem normal now still so I use the password to unzip the flies. Now I don't think there is anything wrong with these files, still dont.
    Next day I get up, turn the puter on, and I noticed I have a closed umbrella symbol (I am using Avira Anti virus, with an umbrella symbol). My AntiVirus had been disabled!
    So I restarts the AntiVirus, Firewall is off again too.

    I browse explorer and when I click D and E drive it says 'The Disk in Drive E is not Formatted. Do You Want To Format it Now?'

    Obviously not, seeing as I store stuff I want to keep in them drives.

    I do a scan using Avira, and it finds the first trojan, TR/Dldr.Java.OpenConnection.AT .
    Just as I am searching google for that virus, the puter re-boots itself.

    When booting, I click 'boot normal' and the puter goes half way thru the boot, then reboots before it finishes. It did this a couple of times. So I boots up in safe mode.

    Now in explorer I can see the D drive, but not the E drive, same 'Format now?' message comes up.

    I do a rescan while in safe mode and Avira picked up 3 trojans (this scan took 7 hours!)

    TR/Dldr.Java.OpenConnection.AT in My Documents.
    TR/Virtl.22445 in My Documents.
    TR/Vilsel.BLK1 in C:\\windows\system32\xa.tmp

    tried to reboot in normal, the same cycle of re-booting, would not load.

    Back in Safe Mode. Scanned with Malwarebytes (gmb told me about this one ) It picked up 2 registry entries
    Malware.trace
    & Trojan.Agent

    Removed these and rebooted normally. Both D and E drives visible again.

    Let this be a warning to you, its not just ~~~~ screws your system!

    Oh... its a long thread, shoulda done it in instalments like Eastenders.
  • aftermath
    V.I.P. Member
    • Mar 2008
    • 4345

    #2
    i found this a very good read, maybe a lesson for all to watch out for..

    Comment

    • gmb45
      Admin Assistant
      • Nov 2008
      • 7538

      #3
      Originally posted by xant14
      Just thought I'd post this to show you the maliciousness of some sites. I think I have it all sorted now, but I was worried all day yesterday.
      I downloaded some .rar files from Rapidshare, and when it came to unzipping them, they were password protected. So I popped the file name plus the word password into google. I found a site (I'm still on google page) that showed the password 'TeamVeder', but as the word 'TeamVeder' was at the end of the google description, I wondered if there was anything after this word as part of the password, so I tried to enter the site.

      The chrome browser notified me that it may be a err, bad site, do I wanna navigate away from it... I clicked no! twice !!

      The next thing my hard drive is whirring away like mad, so I closes the website, with the X.
      It says, and I forget the exact words coz I'm panicking, Java script hasnt finished, are you sure I wanna cancel..
      I say yes to this..
      Immediately a pop up comes to say windows firewall has been turned off, click the balloon to rectify this.
      so I do..
      Things seem normal now still so I use the password to unzip the flies. Now I don't think there is anything wrong with these files, still dont.
      Next day I get up, turn the puter on, and I noticed I have a closed umbrella symbol (I am using Avira Anti virus, with an umbrella symbol). My AntiVirus had been disabled!
      So I restarts the AntiVirus, Firewall is off again too.

      I browse explorer and when I click D and E drive it says 'The Disk in Drive E is not Formatted. Do You Want To Format it Now?'

      Obviously not, seeing as I store stuff I want to keep in them drives.

      I do a scan using Avira, and it finds the first trojan, TR/Dldr.Java.OpenConnection.AT .
      Just as I am searching google for that virus, the puter re-boots itself.

      When booting, I click 'boot normal' and the puter goes half way thru the boot, then reboots before it finishes. It did this a couple of times. So I boots up in safe mode.

      Now in explorer I can see the D drive, but not the E drive, same 'Format now?' message comes up.

      I do a rescan while in safe mode and Avira picked up 3 trojans (this scan took 7 hours!)

      TR/Dldr.Java.OpenConnection.AT in My Documents.
      TR/Virtl.22445 in My Documents.
      TR/Vilsel.BLK1 in C:\\windows\system32\xa.tmp

      tried to reboot in normal, the same cycle of re-booting, would not load.

      Back in Safe Mode. Scanned with Malwarebytes (gmb told me about this one ) It picked up 2 registry entries
      Malware.trace
      & Trojan.Agent

      Removed these and rebooted normally. Both D and E drives visible again.

      Let this be a warning to you, its not just ~~~~ screws your system!

      Oh... its a long thread, shoulda done it in instalments like Eastenders.
      oh u finished m8 just shows u what shite there is out there good post m8
      support mountain resue

      support digital-kaos here


      forum rules

      no keygens or torrents to be posted no autodata discussions

      pish pt walkers


      Comment

      • hadmad
        Newbie
        • May 2009
        • 7

        #4
        great post there a lot of this goes on on twitter and outer social sites

        Comment

        Working...