Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Trojan Win32.Agent.pz from Stoneybrook Assisted Living site
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
AVG Free8 WatchDog service terminated unexpectedly »
« Flash Player/Silverlight  
AuthorAll Replies

calathea

join:2001-12-29
Corvallis, OR
·Comcast Formerly ..
·Earthlink TrueVoice

reply to calathea
Re: Trojan Win32.Agent.pz from Stoneybrook Assisted Living site

This morning I booted up with the LAN cable disconnected and used task manager to kill logWatnt.exe and uphclean.exe before connecting to the internet. The machine was functional, except the digital badge had gotten corrupted. I installed a new digital badge (which worked) but it quit working after about 10 minutes. I need that to get to most of the websites at work

Then I reinstalled Symantec, because I had uninstalled it to run some other security software. It didn't show up on the taskbar so I rebooted. This trojan seems like it goes after Symantec.

This time (the second time I rebooted w/o a network connection) the task manager didn't work. There was an icon for it in the system tray but no dialog window. Symantec wouldn't launch at all. At this point I gave up and walked it down to support to be reimaged.

Craig08

join:2008-03-31
.

Ok, on the testbed PC, I had an older version of Java 5.0 Update 15 but latest opera. So when I went there and clicked that coupon, I got a Java security alert with a security certificate that wanted to install. When I allowed the certificate to install, it was transferring data from hxxp:guidetosuccess.name , and immediatelt afterward, windows security center said the xp firewall was turned off...
Still not sure of everything thats going on, but maybe someone can take it from there. Was going to get the rest of screenshots but I not seeing this everytime.

mysec
Premium
join:2005-11-29

said by Craig08 See Profile :

Ok, on the testbed PC, I had an older version of Java 5.0 Update 15 but latest opera. So when I went there and clicked that coupon, I got a Java security alert with a security certificate that wanted to install.

I got the same result using Opera. Nothing malicious attempted to download.

In IE, I don't get a java security certificate alert, and nothing suspicious was cached. Just the ususal advertising and cookies stuff.

---

Craig08

join:2008-03-31
.

I was able to pick up a couple files that are pretty much widely detected. »www.malwaredomainlist.com/mdl.ph···ess.name shows the Java file and this other one »virscan.org/report/003b47a99dd50···e7b.html

Not too knowledgeable about the certificates and how they work with IE./Opera
Thread is
-
Forums » Up and Running » Security » SecurityAVG Free8 WatchDog service terminated unexpectedly »
« Flash Player/Silverlight  


Wednesday, 07-Jan 21:13:53 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [160] New Comcast Throttling System 100% Online
· [110] After 10 Years Of Service, Charter Declares Home 'Unserviceable'
· [105] iTunes Dumps The DRM
· [70] AT&T, Verizon Stocks Tumble
· [54] Feds Start Wait List For DTV Converter Coupons
· [52] Cable To Grab 75% Of New Subs In 2009
· [41] DOCSIS 3.0 Gets Faster
· [38] Netflix Via LG HDTVs
· [36] New Zealand's 'One Strike' Piracy Law
· [35] ISPs Won't Admit Participation In New RIAA Plan
Most people now reading
· aluminium wiring? [Home Repair & Improvement]
· MLPPP: Fail - ERX06 [TekSavvy]
· Should I open this USPS insured package that is BEAT TO SH#* [General Questions]
· Powering AC worklights off of DC batteries [Home Repair & Improvement]
· 3.0.8 Patch Notes [World of Warcraft]
· Customers punished and sent to ERX06 ! [TekSavvy]
· [ Professions] Northrend Herbalism and Mining Tracks [World of Warcraft]
· Worst Guide ever - 2009 guide thread [Verizon FIOS TV]