Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This forum contains self-help guides on removing common malware and viruses. These guides can be advanced so please use them at your own risk.
If after following the self-help guide, or you can not find an appropriate guide, then you can receive step-by-step instructions directly from one of our experts by following the instructions in this topic: Preparation Guide For Use Before Posting A Hijackthis Log
![]() ![]() |
Feb 2 2005, 06:36 PM
Post
#1
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 31,022 Joined: 24-January 04 From: USA Member No.: 3 |
Horseserver.net, klikfeed.com & Backdoor.Haxdoor.D Analysis Note: Urls have been stripped from this public analysis to protect against infection. This the analysis for the new infection that Hijacks search engines and creates popups. It also logs keystrokes and opens a backdoor to the machine. The keystrokes are sent as an email to an undetermined location. Symptoms of a HijackThis log are: QUOTE O2 - BHO: (no name) - {0F9561D0-03B2-44a3-89A6-E95E417CBA25} - C:\WINDOWS\cerbmod.dll O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\System32\DSMANA~1.DLL O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe O4 - Startup: winupdate32617713[1].exe A file similar in name to winupdate32617713[1].exe is placed in the user's startup directory under their profile. The path is: C:\Documents and Settings\username\Start Menu\Programs\Startup It then launches the program. The program then does the following steps:
Proscribed steps to remove the infection entirely is :
-------------------- Lawrence
Become a BleepingComputer fan: Facebook |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 3rd July 2009 - 11:17 PM |