Go Back   Megalomania Clan Forum > Megalomania Forum > IT / Tech
Make payments with PayPal - it's fast, free and secure!

Closed Thread
 
LinkBack Thread Tools Display Modes

Crappy virus
Old 11th-October-2008, 03:12   #1 (permalink)
 
 
{M}istiqe's Avatar
 
{M}istiqe is offline
Join Date: Jun 2006
Location: Low stairs
Posts: 6,398
Tossed 261 Scoobie Snacks
Popped 224 Scoobie Snacks in 134 Posts
My Mood:
My Tracker: Click here

poland
Default Crappy virus

Ah man, now it got me too.

Today i downloaded Brothers in Arms: Hell's Highway from Rapidshare. It included a link to a "cookie" from RELOADED You know what i mean. I alwasy check that kind of files with antivirus before i run them. Kaspersky didn't show anything. So i replaced the game exe with the "cookie". Run it. Game didn't start. Wrong "cookie" i thought...so i went on a website with game "cookies" (rofl, this name is starting to be funny) to dl another one.
In the meantime, my firewall started to display some stuff. Actually a module of my firewall called "component controll". It checks every file for it's activity. At start i didn't notice that those message coming from firewall are suspicious. But then i saw a file called "myconfig.php" is trying to gain access to network. That's the time when i started to block further connections and suspicious system activities. Too late. Some files has been already installed and added to registry.
So back to the "cookie". I went on that site and what do i see? There is only 1 "cookie" for BiA:HH from RELOADED so it has to work. I downloaded it anyway and compared with the one i dlded from RS. A tiny difference:

good "cookie": 52 106 544 bytes
bad "cookie": 52 408 128 bytes

301 584 bytes difference. That's a lot and enough for a malicious code. I will disassemble both files and compare it's codes later.
The first symptom of infection occured when i rebooted my comp. After a short time my net stopped to respond. It was working but no website could be loaded. So i checked my firewall for network activities, and i see this:

Quote:
02:01:03 Block IN UDP 86.14.30.208 17010 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:03 Block IN TCP 90.176.83.38 19347 78.34.46.186 54269 RST Blocked by the Attack Detecton component
02:01:03 Block IN TCP 124.82.113.221 55843 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN TCP 87.232.83.150 56520 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN UDP 81.220.177.9 37890 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:02 Block IN TCP 91.82.67.160 37036 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN TCP 66.130.146.145 59936 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN UDP 125.228.247.227 8249 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:02 Block IN TCP 76.66.136.178 1678 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN TCP 79.79.100.78 62579 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN TCP 88.207.73.249 62623 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN TCP 83.131.25.239 63585 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN UDP 222.208.225.191 18385 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:02 Block IN TCP 80.203.137.246 61094 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN TCP 77.29.220.42 10183 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN UDP 59.149.54.112 14076 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:01 Block IN TCP 88.207.73.206 2557 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN TCP 79.183.157.233 60043 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN TCP 83.86.195.90 57167 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN TCP 145.120.19.145 63088 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN TCP 89.172.57.222 54087 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN UDP 78.37.123.6 29851 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:01 Block IN TCP 68.146.248.49 30348 78.34.46.186 54269 RST Blocked by the Attack Detecton component
02:01:00 Block IN TCP 82.23.239.176 2148 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:00 Block IN UDP 211.133.45.229 7916 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:00 Block IN TCP 87.232.83.150 56520 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:00 Block IN TCP 124.82.113.221 55843 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:59 Block IN TCP 220.233.89.118 2954 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:59 Block IN TCP 66.130.146.145 59936 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:59 Block IN TCP 75.172.71.155 50386 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:59 Block IN TCP 80.203.137.246 61094 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:59 Block IN TCP 63.228.179.6 62169 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:58 Block IN TCP 203.45.24.15 2346 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:58 Block IN TCP 88.207.73.206 2557 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:58 Block IN UDP 98.227.172.250 44298 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:58 Block IN TCP 145.120.19.145 63088 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:58 Block IN UDP 151.50.6.24 10063 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:57 Block IN UDP 221.4.165.82 26883 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:57 Block IN TCP 90.197.176.152 4593 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:57 Block IN TCP 77.250.245.226 32902 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:57 Block IN UDP 77.251.121.88 4977 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:56 Block IN TCP 220.233.89.118 2954 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:56 Block IN TCP 75.172.71.155 50386 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:56 Block IN TCP 91.82.67.160 37036 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:56 Block IN UDP 218.107.141.45 16110 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:55 Block IN UDP 83.148.83.18 24292 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:55 Block IN TCP 203.45.24.15 2346 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:55 Block IN TCP 77.29.220.42 10183 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:55 Block IN UDP 74.36.244.105 47810 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:55 Block IN TCP 79.183.0.236 49169 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:55 Block IN UDP 189.57.70.3 9120 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:55 Block IN TCP 74.140.176.239 62086 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:55 Block IN TCP 90.176.83.38 19347 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:55 Block IN UDP 213.113.224.233 21665 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:54 Block IN TCP 89.172.57.222 54087 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:54 Block IN TCP 82.23.239.176 2148 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:54 Block IN TCP 90.197.176.152 4593 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:54 Block IN TCP 92.131.144.117 2342 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:54 Block IN TCP 61.170.240.223 2541 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:53 Block IN TCP 77.250.245.226 32902 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:53 Block IN TCP 91.82.67.160 37036 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:53 Block IN TCP 63.228.179.6 62169 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:52 Block IN TCP 77.29.220.42 10183 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:52 Block IN TCP 79.183.0.236 49169 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:52 Block IN TCP 74.140.176.239 62075 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:51 Block IN UDP 118.161.220.55 12127 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:51 Block IN UDP 71.230.187.18 6881 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:51 Block IN UDP 202.86.149.235 16062 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:51 Block IN TCP 82.23.239.176 2148 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:51 Block IN TCP 89.172.57.222 54087 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:50 Block IN TCP 92.131.144.117 2342 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:50 Block IN TCP 61.170.240.223 2541 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:50 Block IN UDP 99.139.86.252 15097 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:50 Block IN UDP 92.255.179.29 44026 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:50 Block IN TCP 78.96.200.93 4897 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:50 Block IN UDP 120.66.201.62 19418 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:50 Block IN UDP 189.18.70.2 48272 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:50 Block IN TCP 92.234.182.191 1589 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:50 Block IN TCP 63.228.179.6 62169 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:49 Block IN TCP 189.30.64.115 1846 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:49 Block IN TCP 77.127.198.89 63833 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:49 Block IN UDP 58.174.107.247 11660 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:49 Block IN UDP 219.102.252.220 9584 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:49 Block IN TCP 90.176.83.38 19347 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN UDP 118.169.71.44 18516 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:48 Block IN TCP 82.15.24.97 56330 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN TCP 68.122.105.230 60031 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN TCP 85.126.85.159 34058 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN TCP 219.86.39.140 63135 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN TCP 98.192.204.161 3557 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN TCP 78.156.112.137 64726 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:47 Block IN UDP 218.172.105.208 14129 78.34.46.186 54269 Blocked by the Attack Detecton component
and that's just a tiny, little, itsy bitsy part of the log. Ok, i'm being DDoS'ed. But the funniest thing is...when i search google for something, whatever result i click, i'm being redirected to some advertising site. Either my HOSTS file has been compromised or a malicious network driver layer has been installed. I hope the 1st one.

But the most rediculous thing is...that i can't fucking find what's causing all this. I ran several different tools, rootkit scanners included, checked vulnerable places, deep registry check... and nothing has been found. NOTHING. Like i had ghosts in my PC.

I finally have some challenge...Wish me luck. I don't like to do format c:
__________________


I am against PIRACY...so please, do not attack ships.

Don't look for trouble when there isn't any... 'cause if you don't find it, you end up creating it.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

Old 11th-October-2008, 03:46   #2 (permalink)
 
 
{M}istiqe's Avatar
 
{M}istiqe is offline
Join Date: Jun 2006
Location: Low stairs
Posts: 6,398
Tossed 261 Scoobie Snacks
Popped 224 Scoobie Snacks in 134 Posts
My Mood:
My Tracker: Click here

poland
Default

Geez, it's also blocking sites like "www.kaspersky.com" and other security related sites. I can't download tools to fix it god damnit. At least i found the cause now. It's a rootkit.
__________________


I am against PIRACY...so please, do not attack ships.

Don't look for trouble when there isn't any... 'cause if you don't find it, you end up creating it.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

Old 11th-October-2008, 04:09   #3 (permalink)
 
 
{M}istiqe's Avatar
 
{M}istiqe is offline
Join Date: Jun 2006
Location: Low stairs
Posts: 6,398
Tossed 261 Scoobie Snacks
Popped 224 Scoobie Snacks in 134 Posts
My Mood:
My Tracker: Click here

poland
Default

Pfffffffffffffffffffffff, that was quick. HAD tdssserv rootkit. Needed one program to fix it but i couldn't dl it bcz it was being blocked by the rootkit. I couldn't open any security related site containing virus fix tools. Luckily Max was still on msn so he dlded me the necessary proggie and i was able to fix that crap.

Thanks Max

Now my comp is clean.
__________________


I am against PIRACY...so please, do not attack ships.

Don't look for trouble when there isn't any... 'cause if you don't find it, you end up creating it.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

Old 11th-October-2008, 04:12   #4 (permalink)
 
{M}disnoMax is offline
Join Date: Apr 2007
Location: Behind you
Posts: 1,762
Tossed 225 Scoobie Snacks
Popped 128 Scoobie Snacks in 91 Posts
My Mood:

israel
Default

Love you Mist
__________________
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

Old 11th-October-2008, 07:33   #5 (permalink)
 
{M}Baloo is offline
Join Date: Jun 2007
Location: Hunting either opfors or my kids
Posts: 3,553
Tossed 621 Scoobie Snacks
Popped 501 Scoobie Snacks in 323 Posts
My Mood:
My Tracker: Click here

sweden
Default

lol so it wasnt much of a challange then?
Good that it all got sorted
__________________

 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

Old 11th-October-2008, 15:49   #6 (permalink)
 
 
{M}istiqe's Avatar
 
{M}istiqe is offline
Join Date: Jun 2006
Location: Low stairs
Posts: 6,398
Tossed 261 Scoobie Snacks
Popped 224 Scoobie Snacks in 134 Posts
My Mood:
My Tracker: Click here

poland
Default

I thought it's gonna be some challenge cuz i couldn't find the reason what's causing all that mess. All AV and malware scans failed. Like ghosts, as mentioned. But i just had to use the rest of my braincells and i got it all figured. I checked which files in my system were created at the time when i ran the "cookie". I noticed this file tdssserver.sys which installed itself as a driver without my permission. I digged deeper and found more tdss*.* files which were messing with my computer ports and network activities. So there, that was it. Unloaded the driver+removed all the files+cleaned the registry and comp was fixed.

Still waiting for some challenge then...
__________________


I am against PIRACY...so please, do not attack ships.

Don't look for trouble when there isn't any... 'cause if you don't find it, you end up creating it.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +2. The time now is 04:28.


vBulletin skin developed by: eXtremepixels
Powered by vBulletin®
Megalomania

Content Relevant URLs by vBSEO 3.3.0