Apostolic Friends Forum
Tab Menu 1
Go Back   Apostolic Friends Forum > The Foyer > The Information Station > Tech Talk: with Bit & Byte
Facebook

Notices

Tech Talk: with Bit & Byte For all those that speak Geek & Greek among us! Or for those technically challenged who don't!


Reply
 
Thread Tools Display Modes
  #21  
Old 11-10-2007, 10:48 PM
Praxeas's Avatar
Praxeas Praxeas is offline
Go Dodgers!


 
Join Date: Feb 2007
Posts: 45,774
Quote:
Originally Posted by SisBeezer View Post
said it was a trojan but i dont remember what the name was, guess i should have written it down



thanks. i may be in the linux section before long, i am so sick of windows, and refuse to go vista, so when its a force to upgrade i KNOW i will go linux


thanks both of you!
If you have logs I'd like to see what it found and removed. I had an idea of what it was, but I'd like to find out for sure.
__________________
Let it be understood that Apostolic Friends Forum is an Apostolic Forum.
Apostolic is defined on AFF as:


  1. There is One God. This one God reveals Himself distinctly as Father, Son and Holy Ghost.
  2. The Son is God himself in a human form or "God manifested in the flesh" (1Tim 3:16)
  3. Every sinner must repent of their sins.
  4. That Jesus name baptism is the only biblical mode of water baptism.
  5. That the Holy Ghost is for today and is received by faith with the initial evidence of speaking in tongues.
  6. The saint will go on to strive to live a holy life, pleasing to God.
Reply With Quote
  #22  
Old 11-11-2007, 07:28 AM
SisBeezer
Guest


 
Posts: n/a
Quote:
Originally Posted by Praxeas View Post
If you have logs I'd like to see what it found and removed. I had an idea of what it was, but I'd like to find out for sure.
C:\Program Files\Common Files\System\grwwxgp.exe
C:\Program Files\Common Files\Microsoft Shared\vnwbekj.exe

are the two files it removed, and one other file that i dont remember the name. for some reason it wouldnt show the files, even with all files showing, and i had it search for hidden files and in zips and stuff. but i didnt save a log file and cant remember what the other file was called, it just said it was a trojan and it removed it.
Reply With Quote
  #23  
Old 11-11-2007, 02:02 PM
Praxeas's Avatar
Praxeas Praxeas is offline
Go Dodgers!


 
Join Date: Feb 2007
Posts: 45,774
Quote:
Originally Posted by SisBeezer View Post
C:\Program Files\Common Files\System\grwwxgp.exe
C:\Program Files\Common Files\Microsoft Shared\vnwbekj.exe

are the two files it removed, and one other file that i dont remember the name. for some reason it wouldnt show the files, even with all files showing, and i had it search for hidden files and in zips and stuff. but i didnt save a log file and cant remember what the other file was called, it just said it was a trojan and it removed it.
That's weird. Like when I use Spybot it does not just say "this is a trojan". but it gives the name
__________________
Let it be understood that Apostolic Friends Forum is an Apostolic Forum.
Apostolic is defined on AFF as:


  1. There is One God. This one God reveals Himself distinctly as Father, Son and Holy Ghost.
  2. The Son is God himself in a human form or "God manifested in the flesh" (1Tim 3:16)
  3. Every sinner must repent of their sins.
  4. That Jesus name baptism is the only biblical mode of water baptism.
  5. That the Holy Ghost is for today and is received by faith with the initial evidence of speaking in tongues.
  6. The saint will go on to strive to live a holy life, pleasing to God.
Reply With Quote
  #24  
Old 11-12-2007, 06:35 PM
SisBeezer
Guest


 
Posts: n/a
sorry it took me so long to get back with you. this is all i have on what it said, i forgot to save a log file

W32.Dotex Worm.Generic
more information... http://research.sunbelt-software.com...hreatid=142603
Status: Deleted

Files detected
C:\Program Files\Common Files\Microsoft Shared\vnwbekj.exe
C:\Program Files\Common Files\System\grwwxgp.exe
C:\Program Files\meex.exe
D:\yvtcxhx.exe
Reply With Quote
  #25  
Old 11-12-2007, 08:50 PM
Praxeas's Avatar
Praxeas Praxeas is offline
Go Dodgers!


 
Join Date: Feb 2007
Posts: 45,774
Quote:
Originally Posted by SisBeezer View Post
sorry it took me so long to get back with you. this is all i have on what it said, i forgot to save a log file

W32.Dotex Worm.Generic
more information... http://research.sunbelt-software.com...hreatid=142603
Status: Deleted

Files detected
C:\Program Files\Common Files\Microsoft Shared\vnwbekj.exe
C:\Program Files\Common Files\System\grwwxgp.exe
C:\Program Files\meex.exe
D:\yvtcxhx.exe
Do you have two hard drives or is one HD have more than one partition?
__________________
Let it be understood that Apostolic Friends Forum is an Apostolic Forum.
Apostolic is defined on AFF as:


  1. There is One God. This one God reveals Himself distinctly as Father, Son and Holy Ghost.
  2. The Son is God himself in a human form or "God manifested in the flesh" (1Tim 3:16)
  3. Every sinner must repent of their sins.
  4. That Jesus name baptism is the only biblical mode of water baptism.
  5. That the Holy Ghost is for today and is received by faith with the initial evidence of speaking in tongues.
  6. The saint will go on to strive to live a holy life, pleasing to God.
Reply With Quote
  #26  
Old 11-12-2007, 08:52 PM
Praxeas's Avatar
Praxeas Praxeas is offline
Go Dodgers!


 
Join Date: Feb 2007
Posts: 45,774
It's pretty new
__________________
Let it be understood that Apostolic Friends Forum is an Apostolic Forum.
Apostolic is defined on AFF as:


  1. There is One God. This one God reveals Himself distinctly as Father, Son and Holy Ghost.
  2. The Son is God himself in a human form or "God manifested in the flesh" (1Tim 3:16)
  3. Every sinner must repent of their sins.
  4. That Jesus name baptism is the only biblical mode of water baptism.
  5. That the Holy Ghost is for today and is received by faith with the initial evidence of speaking in tongues.
  6. The saint will go on to strive to live a holy life, pleasing to God.
Reply With Quote
  #27  
Old 11-12-2007, 09:00 PM
Praxeas's Avatar
Praxeas Praxeas is offline
Go Dodgers!


 
Join Date: Feb 2007
Posts: 45,774
W32.Dotex is a worm that copies itself to the root of all drives and downloads potentially malicious files on to the compromised computer. It also attempts to disable various antivirus programs.

Also called
W32/Webbew.worm is written in Delphi which spreads via removable drives. This worm is designed to silently download and execute malicious content from a remote server.

W32/Webbew.worm is written in Delphi which spreads via removable drives. This worm is designed to silently download and execute malicious content from a remote server.
When the executable is run on the victim machine, the worm copies itself to the following locations.
  • %Program Files%\bhbsdrx.inf (169 bytes) --> used to autorun the worm when the drive is accessed
  • %Program Files%\meex.exe (25,824 bytes ) -- > Copy of the worm
  • %Program Files%\Common Files\Microsoft Shared\pxpfern.exe (25,824 bytes) --> Copy of the worm
  • %Program Files%\Common Files\System\tnmgncd.exe (25,824 bytes ) --> Copy of the worm
The autorun.inf files are dropped into the root of every removable drive on the victim's system. This inf file facilitates to autorun the worm when the drive is accessed. The autorun.inf is currently detected as Generic!atr.
The contents of the file will be similar to the following:
[AutoRun]
open=htocusa.exe
shell\open="opens"
shell\open\Command=htocusa.exe
shell\open\Default=1
shell\explore="Resource Management"
shell\explore\Command=htocusa.exe
This worm exists purely to download and run other remote files. The downloader is installed on the victim machine in a way that assists in masking its activity.

Removal -

Removal -

A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.
__________________
Let it be understood that Apostolic Friends Forum is an Apostolic Forum.
Apostolic is defined on AFF as:


  1. There is One God. This one God reveals Himself distinctly as Father, Son and Holy Ghost.
  2. The Son is God himself in a human form or "God manifested in the flesh" (1Tim 3:16)
  3. Every sinner must repent of their sins.
  4. That Jesus name baptism is the only biblical mode of water baptism.
  5. That the Holy Ghost is for today and is received by faith with the initial evidence of speaking in tongues.
  6. The saint will go on to strive to live a holy life, pleasing to God.
Reply With Quote
  #28  
Old 11-12-2007, 09:16 PM
SisBeezer
Guest


 
Posts: n/a
yeah i have two hard drives in each computer. it installed a file called _install.exe into every single folder on all four drives, ugh. but that program called counter spy seems to have taken care of it. (i hope)

it was strange that it would show back up after i took out the other hard drives and put in new ones.

not sure where it even came from because i go to few sites online anymore.
Reply With Quote
  #29  
Old 11-12-2007, 09:52 PM
Praxeas's Avatar
Praxeas Praxeas is offline
Go Dodgers!


 
Join Date: Feb 2007
Posts: 45,774
Quote:
Originally Posted by SisBeezer View Post
yeah i have two hard drives in each computer. it installed a file called _install.exe into every single folder on all four drives, ugh. but that program called counter spy seems to have taken care of it. (i hope)

it was strange that it would show back up after i took out the other hard drives and put in new ones.

not sure where it even came from because i go to few sites online anymore.
other removable drives? External? USB Key? Network drive?
__________________
Let it be understood that Apostolic Friends Forum is an Apostolic Forum.
Apostolic is defined on AFF as:


  1. There is One God. This one God reveals Himself distinctly as Father, Son and Holy Ghost.
  2. The Son is God himself in a human form or "God manifested in the flesh" (1Tim 3:16)
  3. Every sinner must repent of their sins.
  4. That Jesus name baptism is the only biblical mode of water baptism.
  5. That the Holy Ghost is for today and is received by faith with the initial evidence of speaking in tongues.
  6. The saint will go on to strive to live a holy life, pleasing to God.
Reply With Quote
  #30  
Old 11-13-2007, 05:40 AM
SisBeezer
Guest


 
Posts: n/a
Quote:
Originally Posted by Praxeas View Post
other removable drives? External? USB Key? Network drive?
i have one 500 gig usb removable hard drive that i use for storage, but i ran scans on everything there and nothing was found on it.
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
The problem with the AMF Ferd Fellowship Hall 11 02-19-2007 02:48 PM

 
User Infomation
Your Avatar

Latest Threads
- by Salome
- by Salome

Help Support AFF!

Advertisement




All times are GMT -6. The time now is 11:24 PM.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.