Ah man, now it got me too.
Today i downloaded Brothers in Arms: Hell's Highway from Rapidshare. It included a link to a "cookie" from RELOADED

You know what i mean. I alwasy check that kind of files with antivirus before i run them. Kaspersky didn't show anything. So i replaced the game exe with the "cookie". Run it. Game didn't start. Wrong "cookie" i thought...so i went on a website with game "cookies" (rofl, this name is starting to be funny) to dl another one.
In the meantime, my firewall started to display some stuff. Actually a module of my firewall called "component controll". It checks every file for it's activity. At start i didn't notice that those message coming from firewall are suspicious. But then i saw a file called "myconfig.php" is trying to gain access to network. That's the time when i started to block further connections and suspicious system activities. Too late. Some files has been already installed and added to registry.
So back to the "cookie". I went on that site and what do i see? There is only 1 "cookie" for BiA:HH from RELOADED so it has to work. I downloaded it anyway and compared with the one i dlded from RS. A tiny difference:
good "cookie": 52 106 544 bytes
bad "cookie": 52 408 128 bytes
301 584 bytes difference. That's a lot and enough for a malicious code. I will disassemble both files and compare it's codes later.
The first symptom of infection occured when i rebooted my comp. After a short time my net stopped to respond. It was working but no website could be loaded. So i checked my firewall for network activities, and i see this:
Quote:
02:01:03 Block IN UDP 86.14.30.208 17010 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:03 Block IN TCP 90.176.83.38 19347 78.34.46.186 54269 RST Blocked by the Attack Detecton component
02:01:03 Block IN TCP 124.82.113.221 55843 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN TCP 87.232.83.150 56520 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN UDP 81.220.177.9 37890 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:02 Block IN TCP 91.82.67.160 37036 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN TCP 66.130.146.145 59936 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN UDP 125.228.247.227 8249 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:02 Block IN TCP 76.66.136.178 1678 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN TCP 79.79.100.78 62579 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN TCP 88.207.73.249 62623 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN TCP 83.131.25.239 63585 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:02 Block IN UDP 222.208.225.191 18385 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:02 Block IN TCP 80.203.137.246 61094 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN TCP 77.29.220.42 10183 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN UDP 59.149.54.112 14076 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:01 Block IN TCP 88.207.73.206 2557 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN TCP 79.183.157.233 60043 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN TCP 83.86.195.90 57167 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN TCP 145.120.19.145 63088 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN TCP 89.172.57.222 54087 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:01 Block IN UDP 78.37.123.6 29851 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:01 Block IN TCP 68.146.248.49 30348 78.34.46.186 54269 RST Blocked by the Attack Detecton component
02:01:00 Block IN TCP 82.23.239.176 2148 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:00 Block IN UDP 211.133.45.229 7916 78.34.46.186 54269 Blocked by the Attack Detecton component
02:01:00 Block IN TCP 87.232.83.150 56520 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:01:00 Block IN TCP 124.82.113.221 55843 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:59 Block IN TCP 220.233.89.118 2954 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:59 Block IN TCP 66.130.146.145 59936 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:59 Block IN TCP 75.172.71.155 50386 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:59 Block IN TCP 80.203.137.246 61094 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:59 Block IN TCP 63.228.179.6 62169 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:58 Block IN TCP 203.45.24.15 2346 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:58 Block IN TCP 88.207.73.206 2557 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:58 Block IN UDP 98.227.172.250 44298 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:58 Block IN TCP 145.120.19.145 63088 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:58 Block IN UDP 151.50.6.24 10063 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:57 Block IN UDP 221.4.165.82 26883 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:57 Block IN TCP 90.197.176.152 4593 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:57 Block IN TCP 77.250.245.226 32902 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:57 Block IN UDP 77.251.121.88 4977 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:56 Block IN TCP 220.233.89.118 2954 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:56 Block IN TCP 75.172.71.155 50386 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:56 Block IN TCP 91.82.67.160 37036 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:56 Block IN UDP 218.107.141.45 16110 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:55 Block IN UDP 83.148.83.18 24292 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:55 Block IN TCP 203.45.24.15 2346 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:55 Block IN TCP 77.29.220.42 10183 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:55 Block IN UDP 74.36.244.105 47810 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:55 Block IN TCP 79.183.0.236 49169 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:55 Block IN UDP 189.57.70.3 9120 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:55 Block IN TCP 74.140.176.239 62086 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:55 Block IN TCP 90.176.83.38 19347 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:55 Block IN UDP 213.113.224.233 21665 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:54 Block IN TCP 89.172.57.222 54087 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:54 Block IN TCP 82.23.239.176 2148 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:54 Block IN TCP 90.197.176.152 4593 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:54 Block IN TCP 92.131.144.117 2342 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:54 Block IN TCP 61.170.240.223 2541 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:53 Block IN TCP 77.250.245.226 32902 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:53 Block IN TCP 91.82.67.160 37036 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:53 Block IN TCP 63.228.179.6 62169 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:52 Block IN TCP 77.29.220.42 10183 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:52 Block IN TCP 79.183.0.236 49169 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:52 Block IN TCP 74.140.176.239 62075 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:51 Block IN UDP 118.161.220.55 12127 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:51 Block IN UDP 71.230.187.18 6881 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:51 Block IN UDP 202.86.149.235 16062 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:51 Block IN TCP 82.23.239.176 2148 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:51 Block IN TCP 89.172.57.222 54087 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:50 Block IN TCP 92.131.144.117 2342 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:50 Block IN TCP 61.170.240.223 2541 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:50 Block IN UDP 99.139.86.252 15097 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:50 Block IN UDP 92.255.179.29 44026 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:50 Block IN TCP 78.96.200.93 4897 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:50 Block IN UDP 120.66.201.62 19418 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:50 Block IN UDP 189.18.70.2 48272 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:50 Block IN TCP 92.234.182.191 1589 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:50 Block IN TCP 63.228.179.6 62169 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:49 Block IN TCP 189.30.64.115 1846 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:49 Block IN TCP 77.127.198.89 63833 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:49 Block IN UDP 58.174.107.247 11660 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:49 Block IN UDP 219.102.252.220 9584 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:49 Block IN TCP 90.176.83.38 19347 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN UDP 118.169.71.44 18516 78.34.46.186 54269 Blocked by the Attack Detecton component
02:00:48 Block IN TCP 82.15.24.97 56330 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN TCP 68.122.105.230 60031 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN TCP 85.126.85.159 34058 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN TCP 219.86.39.140 63135 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN TCP 98.192.204.161 3557 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:48 Block IN TCP 78.156.112.137 64726 78.34.46.186 54269 SYN Blocked by the Attack Detecton component
02:00:47 Block IN UDP 218.172.105.208 14129 78.34.46.186 54269 Blocked by the Attack Detecton component
|
and that's just a tiny, little, itsy bitsy part of the log. Ok, i'm being DDoS'ed. But the funniest thing is...when i search google for something, whatever result i click, i'm being redirected to some advertising site. Either my HOSTS file has been compromised or a malicious network driver layer has been installed. I hope the 1st one.
But the most rediculous thing is...that i can't fucking find what's causing all this. I ran several different tools, rootkit scanners included, checked vulnerable places, deep registry check... and nothing has been found. NOTHING. Like i had ghosts in my PC.
I finally have some challenge...Wish me luck. I don't like to do format c:
