weird xp behaviour

weird xp behaviour

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
weird xp behaviour luna 08-15-2006
Posted by luna on August 15, 2006, 5:56 am
If you were  Registered and logged in, you could reply and use other advanced thread options
anyone heard of something that can open start/run and auto pastes a url with
an .exe in the URL which
automatically downloads ? and tries to install ?

ive not seen anything like it before, all i can think of is an exploit
in opera, (im using v9) - ive ran nothing from emails, or used any bad files
that
i know of (im an experienced PC user)
ive killed the process and found the thing in RUN/and RUNONCE,
this happened once last week and i fixed it with a different URL to the one
i have
today

Ive also noticed it pasting the URL into open windows.




Posted by Steven Burn on August 15, 2006, 10:56 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> anyone heard of something that can open start/run and auto pastes a url
with
> an .exe in the URL which
> automatically downloads ? and tries to install ?
>
> ive not seen anything like it before, all i can think of is an exploit
> in opera, (im using v9) - ive ran nothing from emails, or used any bad
files
> that
> i know of (im an experienced PC user)
> ive killed the process and found the thing in RUN/and RUNONCE,
> this happened once last week and i fixed it with a different URL to the
one
> i have
> today
>
> Ive also noticed it pasting the URL into open windows.

What URL/file is it pointing to?

... and have you ran the file through Jotti's online scanner?

http://virusscan.jotti.org

--
Regards

Steven Burn
Ur I.T. Mate Group
www.it-mate.co.uk

Keeping it FREE!



Posted by luna on August 15, 2006, 1:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>>
>> Ive also noticed it pasting the URL into open windows.
>
> What URL/file is it pointing to?
>
> ... and have you ran the file through Jotti's online scanner?
>
> http://virusscan.jotti.org
>
> --
> Regards
>
> Steven Burn
> Ur I.T. Mate Group
> www.it-mate.co.uk
>
> Keeping it FREE!
>
>


today its http://65.98.57.2/~zuluzet/.../x.exe , it was a different url last
time with msconfig2.exe filename

online scan reveals the file is (quite an old one?)

AntiVir Found Worm/Rbot.193504
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found IRC/BackDoor.SdBot2.FWA
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found Win32.HLLW.MyBot
F-Prot Antivirus Found nothing
Fortinet Found W32/RBot.BFA!tr.bdr
Kaspersky Anti-Virus Found Backdoor.Win32.Rbot.bfa
NOD32 Found a variant of Win32/Rbot
Norman Virus Control Found nothing
UNA Found nothing
VirusBuster Found nothing
VBA32 Found Backdoor.Win32.Rbot.bfa



Posted by Steven Burn on August 15, 2006, 1:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> today its http://65.98.57.2/~zuluzet/.../x.exe , it was a different url
last
> time with msconfig2.exe filename
>
> online scan reveals the file is (quite an old one?)

Most likely a new variant rather than an old one.

Download yourself the trial copy of both of the following and allow them to
run full system scans (after updating the sig files of course).

Might want to see if you can identify the process thats causing it aswell.
HJT will help with this.

www.merijn.org

--
Regards

Steven Burn
Ur I.T. Mate Group
www.it-mate.co.uk

Keeping it FREE!



Posted by Steven Burn on August 15, 2006, 1:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Download yourself the trial copy of both of the following and allow them
to
> run full system scans (after updating the sig files of course).

Helps if I mention the app's, lol.

1. Ewido - www.ewido.com
2. NOD32 - www.eset.com

Might also want to get WinPatrol if you don't already have it.

www.winpatrol.com

--
Regards

Steven Burn
Ur I.T. Mate Group
www.it-mate.co.uk

Keeping it FREE!



Similar ThreadsPosted
AVG 7.5 free - weird behavior March 26, 2008, 9:46 pm
Weird search engines? April 6, 2008, 11:04 am
Weird problem on Flash Drive seems like a virus but no virus detected August 28, 2007, 12:04 pm

The site map in XML format XML site map

Contact Us | Privacy Policy