|
Quick Member Login:
Servers:
Forum Statistics:
Forum Members: 1,682
Total Threads: 7,638
Total Posts: 66,548
There are 6 users
currently browsing forums.
|
|
06-08-2004, 11:43 AM
|
#1 (permalink)
|
|
Senior Member
Join Date: Mar 2004
Location: NJ
Posts: 3,600
|
WARNING Virus detected!
I opened my Teamspeak today and got a virus warning. I was on last night and had no problems so I'm not sure when I got this virus. Here's the info from Norton:
PWS.Hooker.Trojan is the detection for known variants in this family of Trojan horses. Trojans in this family attempt to steal passwords and IP addresses from compromised computers.
When the Trojan runs, it does the following:
It copies itself as C:\%System%\Kern32.exe.
NOTE: %System% is a variable. The Trojan locates the \Windows\System folder (by default this is C:\Windows\System or C:\Winnt\System32) and copies itself to that location.
It also drops C:\%System%\Hksdll.dll. This file is a component of, and is detected as W32.Badtrans.gen@mm.
The Trojan adds the value
"kernel32"="C:\%System%\kern32.exe"
to the registry key
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunOnce
This causes the Trojan to run the next time you start Windows.
Keystrokes can be logged and sent to the hacker.
|
|
|
06-08-2004, 11:54 AM
|
#2 (permalink)
|
|
Server Admin/Forum Moderator
Join Date: Mar 2004
Location: Indiana
Posts: 1,060
|
Hmmm.. Well, I was not on last night, but I will let you know if I find something when I get home tomorrow night. Thanks for the heads up Stryker.
__________________
EoDDev Trahn Lee Liao NinjaServe Server Admin.
|
|
|
06-08-2004, 12:10 PM
|
#3 (permalink)
|
|
Senior Member
Join Date: Mar 2004
Posts: 526
|
Yeah thanks for the heads up....I suppose I should get to reinstalling norton asap! wonder if it spreads through TS, don't see how, but whatever....bastards!
Drayu
|
|
|
06-08-2004, 12:19 PM
|
#4 (permalink)
|
|
Administrator
Join Date: Mar 2004
Location: Port St. Lucie, FL
Posts: 4,642
|
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, etc.
I seriously doubt u got it from using TS. This trojan has been around since 2000. TS would have patched that hole by now, if there ever was one. You probably installed something that was infected, or maybe it was in an email.
Nonetheless, if it is TS related problem, others are now aware. Thanks.
|
|
|
06-08-2004, 12:34 PM
|
#5 (permalink)
|
|
Senior Member
Join Date: Mar 2004
Posts: 985
|
I just found the same virus on my cpu too
__________________
Everyone picks their own poison
|
|
|
06-08-2004, 12:37 PM
|
#6 (permalink)
|
|
Senior Member
Join Date: May 2004
Location: Deutschland!!!!
Posts: 267
|
its funny, or actual not so funny but i had the same one in my TS folder:
PWS.Hooker.Trojan is the detection for known variants in this family of Trojan horses. Trojans in this family attempt to steal passwords and IP addresses from compromised computers.
The file C:\Program Files\TEAMSP~1\KeyPress.dll is infected with the PWS.Hooker.Trojan virus.
Its easily removed. And look what norton says:
The following is a description of a specific PWS.Hooker.Trojan variant, which the W32.Badtrans.gen@mm worm can drop.
When the Trojan runs, it does the following:
It copies itself as C:\%System%\Kern32.exe.
NOTE: %System% is a variable. The Trojan locates the \Windows\System folder (by default this is C:\Windows\System or C:\Winnt\System32) and copies itself to that location.
It also drops C:\%System%\Hksdll.dll. This file is a component of, and is detected as W32.Badtrans.gen@mm.
The Trojan adds the value
"kernel32"="C:\%System%\kern32.exe"
to the registry key
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunOnce
This causes the Trojan to run the next time you start Windows.
|
|
|
06-08-2004, 12:40 PM
|
#7 (permalink)
|
|
Administrator
Join Date: Mar 2004
Location: Port St. Lucie, FL
Posts: 4,642
|
i scanned my system before going to work this morning. no problems.
i'll go to Trend Micro's online scanner and get a second opinion.
|
|
|
06-08-2004, 12:57 PM
|
#8 (permalink)
|
|
Senior Member
Join Date: Mar 2004
Location: NJ
Posts: 3,600
|
I searched my registry and didn't find the key they say it enters. I also didn't have a directory like they said it makes. Maybe I got it before it even started up. I have scanned my entire HD with the latest definitions from Norton. I then disabled system restore and then rebooted. I scanned again thinking it might reassert itself after a reboot but everything is clear. I'm hoping Norton caught it quick enough that nothing happend. Regardless I'm going to uninstall TS and reinstall it fresh.
|
|
|
06-08-2004, 12:59 PM
|
#9 (permalink)
|
|
Administrator
Join Date: Mar 2004
Location: Port St. Lucie, FL
Posts: 4,642
|
maybe u and Icepick got it from the same source. name the last 3 things u downloaded.
|
|
|
06-08-2004, 01:06 PM
|
#10 (permalink)
|
|
Senior Member
Join Date: Mar 2004
Location: NJ
Posts: 3,600
|
|
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -4. The time now is 07:07 AM.
Powered by vBulletin® Version 3.6.11 Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.0.0

Ad Management by RedTyger
Skin Purchased from CompletevB
|
|