WinZip_8.x_(including_SR).rar_virus_trojan

Discussion in 'Windows - Virus and spyware problems' started by tegas, Feb 16, 2008.

  1. tegas

    tegas Member

    Joined:
    Feb 16, 2008
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    11
    WinZip_8.x_(including_SR).rar_virus_trojan

    symptoms
    ----------
    slow computer;
    hijacked web-browser start page with "...jack..." in the url;
    creation of extra temp files in root;
    creation of folder called WinZip 8.x (including SR) which is
    undeletable, unremovable, unrenamable.

    process of infection
    ---------------------
    on internet,
    57946.html --> (there is also a popup window);
    download link --> leads to WinZip 8.x (including SR).rar
    unpacking the rar gives:
    code57496.txt
    crack.exe
    keygen.exe
    click on crack.exe
    click on keygen.exe

    unknown which of these steps is responsible for the infection.

    full scan with a current "Microsoft® Windows® Malicious Software Removal Tool"
    revealed no positive infections.

    for the source code of html, see 57946.html.jpg

    [​IMG]
     
  2. QuikDraw

    QuikDraw Regular member

    Joined:
    Sep 29, 2007
    Messages:
    808
    Likes Received:
    0
    Trophy Points:
    26
  3. tegas

    tegas Member

    Joined:
    Feb 16, 2008
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    11
    hi again,
    i guess i'm trying to inform people. it's too late for my computer.
    but i did further research & it looks like the files contain 2 trojans.
    the vundo and a dialer.
    here is an addition to my first post: http://tegasvegas.orgfree.com/
     
  4. LTDevil

    LTDevil Guest

    Why is it too late for your computer, did you already reformat?
     
  5. tegas

    tegas Member

    Joined:
    Feb 16, 2008
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    11
    yes i have reformatted computer with a fresh install using the included discs.
    but more to the point: the two anti-vundo cleaners i found were -
    vundofix.exe by Atribune (version 6.7.9 built late2007/early2008)
    fixvundo.exe by Symantec (version 1.5 built 2005? 2006?)

    i think vundoFix would be the better choice as it is more current.

    (p.s. a subsequent virus-scan says the trojan is called vundo-1137)

    thanks to all concerned.
    sincerely, tegas.

    p.p.s. i am going to download hjt for use in the future if needed. (another newbie question though, ... does hjt become dated? ie, do you need a current hjt to look for infections)
     
  6. QuikDraw

    QuikDraw Regular member

    Joined:
    Sep 29, 2007
    Messages:
    808
    Likes Received:
    0
    Trophy Points:
    26
    Last edited: Feb 28, 2008

Share This Page