Results 1 to 10 of 10
  1. #1
    Lead Foot
    Join Date
    May 2008
    Location
    GA
    Posts
    462

    Default Need 3 Files examined by Security Expert

    I am typing via Blackberry, as my Desktop has been keylogged.

    I have 3 files that I desperately need a security expert to examine.
    The files are highly private "mods" for an online computer game.

    All 3 files function as intended. One of them contains a keylogger.


    2 of the files are similar in nature. They are a rar package that contains several files.. In each of them are a few text config files, a .dLL, and a .exe. The .exe, called the "injector", injects the DLL into a running process named "game.exe" to allow the "mod" to work.

    The third file is a .mpq file that is placed in the directory of the game.



    All files scan clean with virustotal.com

    System that was infiltrated was running:
    ProcessGuard
    Avira
    Comodo


    Shoot me a PM or post if you think you can help. I Really need to determine which file the keylogger came from.
    Last edited by Cauhauna; 06-30-2010 at 11:32 AM.

  2. #2
    Professional
    Join Date
    Jul 2009
    Location
    127.0.0.1
    Posts
    1,295

    Default Re: Need 3 Files examined by Security Expert

    Most likely you have downloaded a botnet, not just a normal keylogger. Open MSCONFIG from your run menu, go to startup, and look for any file that has an unknown publisher and the only information on it is a name something.exe. Find it, disable it. If you have teamviewer I can take over your screen and help you out with it when I get off of work later. I have quite a bit of experience with these as I used to be an admin on one of the biggest xbox modding sites on the internet and had to deal with these files daily.

  3. #3
    Radar Fanatic
    Join Date
    Jan 2006
    Location
    SoCal - OC Style
    Posts
    2,479

    Default Re: Need 3 Files examined by Security Expert

    Upload them to Jotti and run a check.

    Jotti's malware scan

    Download Malwarebytes and Super Anti Spyware (both have portable versions) and run scans on your infected computer.

  4. #4
    Lead Foot
    Join Date
    Mar 2010
    Posts
    438

    Default Re: Need 3 Files examined by Security Expert

    It's more than likely the executable that has caused the problem. First try a recovery, as in rollback to the last working config that was virus free. Some "botnet" or trojan creators can enable this feature tho'. Also, try booting in safe mode using F8 when you get a chance.

    When the .exe was opened it creates other files, and creates registry keys in your reg. editor. So even if you delete the .exe, it will recreate itself upon startup. If you can upload your file to RapidShare: 1-CLICK Web hosting - Easy Filehosting, and post the link I will examine it. =)

  5. #5
    Professional
    Join Date
    Jun 2010
    Location
    Passing on the right
    Posts
    1,274

    Default Re: Need 3 Files examined by Security Expert

    Once a system has been compromised in this way, the only sure way to be clean is a format and re-install from trusted sources. This is what I would be looking to do if I were you.

    The problem is that no matter how many tools you use to scan your computer, no one really knows the true extent of the damage. To continue to operate your computer after this, you have to always be on the lookout for suspicious activity.

    Take an afternoon, back up your files, format the hard disk and re-install everything. At least you won't have to worry and you will spend less time n the end.

  6. #6
    Lead Foot
    Join Date
    May 2008
    Location
    GA
    Posts
    462

    Default Re: Need 3 Files examined by Security Expert

    Quote Originally Posted by switch626 View Post
    Once a system has been compromised in this way, the only sure way to be clean is a format and re-install from trusted sources. This is what I would be looking to do if I were you.

    The problem is that no matter how many tools you use to scan your computer, no one really knows the true extent of the damage. To continue to operate your computer after this, you have to always be on the lookout for suspicious activity.

    Take an afternoon, back up your files, format the hard disk and re-install everything. At least you won't have to worry and you will spend less time n the end.
    I agree. I never try to recover after infection. I always DBAN 7 pass and rewrite MBR every time without fail. That is not why I created the thread.

    I created thread because I need to figure out which file caused the infection --- not for removal, but so that I know I can safely use the other files after reformat, as I need all of them badly.

  7. #7
    Banned
    Join Date
    Oct 2009
    Location
    USA
    Posts
    2,534

    Default Re: Need 3 Files examined by Security Expert

    Do you make regular backups so you can reinstall Windows and restore from known-good archives?

  8. #8
    Lead Foot
    Join Date
    May 2008
    Location
    GA
    Posts
    462

    Default Re: Need 3 Files examined by Security Expert

    Quote Originally Posted by The Chariot View Post
    Do you make regular backups so you can reinstall Windows and restore from known-good archives?
    I'm not interested in doing any restoring or recovery. I always wipe a computer after a virus. Always.

    I just need to know which file the virus came from.

  9. #9
    Banned
    Join Date
    Oct 2009
    Location
    USA
    Posts
    2,534

    Default Re: Need 3 Files examined by Security Expert

    Quote Originally Posted by Cauhauna View Post
    Quote Originally Posted by The Chariot View Post
    Do you make regular backups so you can reinstall Windows and restore from known-good archives?
    I'm not interested in doing any restoring or recovery. I always wipe a computer after a virus. Always.

    I just need to know which file the virus came from.
    That's what I do. Wipe, re-install Windows and restore data from a known-good backup from before the time of the infection.

  10. #10
    Lead Foot
    Join Date
    Mar 2010
    Posts
    438

    Default Re: Need 3 Files examined by Security Expert

    So it used EasyPlay injector to inject Houndini.dll:

    Anubis - Analysis Report

    There's my anubis scan, it created a process, prob changed a few registry keys/created them.

    If you did a login to use this software it acted as a phisher, and sent your PW/Username to: http://members.multimania.co.uk/orlyz/

    You can report the site and get it banned for violation of TOS if you have proof.

    It's 3:07 AM, I'm tired, half of this is probably incorrect, so don't hate, just trying to help.

 

 

Similar Threads

  1. How to Change Alert Sound Files?
    By Car-Nar in forum Laser Interceptor
    Replies: 3
    Last Post: 06-05-2011, 12:40 PM
  2. Voice Files
    By GreenRadar in forum Laser Interceptor
    Replies: 18
    Last Post: 07-12-2010, 06:34 PM
  3. Any V1 X, K, KA alert sound files?
    By lordhawhaw in forum Valentine One
    Replies: 15
    Last Post: 06-30-2008, 07:02 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •