NinjaServe.org Forums
Home | About Us | Contact Us  
Quick Member Login:
Forgot password?
Servers:
Forum Statistics:
Forum Members: 1,682
Total Threads: 7,638
Total Posts: 66,548


There are 6 users
currently browsing forums.
  Server Status Register FAQ Members List Arcade gXboxLive Ninja RPG! Calendar Mark Forums Read
Non Registered Member! Please take the time to register now!

NinjaServe.org Forums » General Chat » Off Topic Discussion » WARNING Virus detected!

Off Topic Discussion General chit-chat that doesnt fit anywhere else! :) No gaming related chat please.

Reply
 
LinkBack Thread Tools Display Modes
Old 06-08-2004, 11:43 AM   #1 (permalink)
Stryker412
Senior Member
 
Stryker412's Avatar
 
Join Date: Mar 2004
Location: NJ
Posts: 3,600


WARNING Virus detected!

I opened my Teamspeak today and got a virus warning. I was on last night and had no problems so I'm not sure when I got this virus. Here's the info from Norton:

PWS.Hooker.Trojan is the detection for known variants in this family of Trojan horses. Trojans in this family attempt to steal passwords and IP addresses from compromised computers.

When the Trojan runs, it does the following:


It copies itself as C:\%System%\Kern32.exe.

NOTE: %System% is a variable. The Trojan locates the \Windows\System folder (by default this is C:\Windows\System or C:\Winnt\System32) and copies itself to that location.


It also drops C:\%System%\Hksdll.dll. This file is a component of, and is detected as W32.Badtrans.gen@mm.

The Trojan adds the value

"kernel32"="C:\%System%\kern32.exe"

to the registry key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunOnce

This causes the Trojan to run the next time you start Windows.

Keystrokes can be logged and sent to the hacker.
__________________

www.shatteredplanet.org
Stryker412 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 06-08-2004, 11:54 AM   #2 (permalink)
Trahn_Lee_Liao
Server Admin/Forum Moderator
 
Trahn_Lee_Liao's Avatar
 
Join Date: Mar 2004
Location: Indiana
Posts: 1,060


Hmmm.. Well, I was not on last night, but I will let you know if I find something when I get home tomorrow night. Thanks for the heads up Stryker.
__________________
EoDDev Trahn Lee Liao NinjaServe Server Admin.
Trahn_Lee_Liao is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 06-08-2004, 12:10 PM   #3 (permalink)
Drayu
Senior Member
 
Join Date: Mar 2004
Posts: 526


Yeah thanks for the heads up....I suppose I should get to reinstalling norton asap! wonder if it spreads through TS, don't see how, but whatever....bastards!


Drayu
Drayu is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Sponsored links
Old 06-08-2004, 12:19 PM   #4 (permalink)
Horsepower
Administrator
 
Horsepower's Avatar
 
Join Date: Mar 2004
Location: Port St. Lucie, FL
Posts: 4,642


Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, etc.

I seriously doubt u got it from using TS. This trojan has been around since 2000. TS would have patched that hole by now, if there ever was one. You probably installed something that was infected, or maybe it was in an email.

Nonetheless, if it is TS related problem, others are now aware. Thanks.
Horsepower is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 06-08-2004, 12:34 PM   #5 (permalink)
ICEPICK
Senior Member
 
ICEPICK's Avatar
 
Join Date: Mar 2004
Posts: 985


I just found the same virus on my cpu too
__________________
Everyone picks their own poison
ICEPICK is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 06-08-2004, 12:37 PM   #6 (permalink)
Fook_Yu
Senior Member
 
Fook_Yu's Avatar
 
Join Date: May 2004
Location: Deutschland!!!!
Posts: 267


its funny, or actual not so funny but i had the same one in my TS folder:

PWS.Hooker.Trojan is the detection for known variants in this family of Trojan horses. Trojans in this family attempt to steal passwords and IP addresses from compromised computers.

The file C:\Program Files\TEAMSP~1\KeyPress.dll is infected with the PWS.Hooker.Trojan virus.

Its easily removed. And look what norton says:
The following is a description of a specific PWS.Hooker.Trojan variant, which the W32.Badtrans.gen@mm worm can drop.

When the Trojan runs, it does the following:


It copies itself as C:\%System%\Kern32.exe.

NOTE: %System% is a variable. The Trojan locates the \Windows\System folder (by default this is C:\Windows\System or C:\Winnt\System32) and copies itself to that location.


It also drops C:\%System%\Hksdll.dll. This file is a component of, and is detected as W32.Badtrans.gen@mm.

The Trojan adds the value

"kernel32"="C:\%System%\kern32.exe"

to the registry key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunOnce

This causes the Trojan to run the next time you start Windows.
__________________
Fook_Yu is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 06-08-2004, 12:40 PM   #7 (permalink)
Horsepower
Administrator
 
Horsepower's Avatar
 
Join Date: Mar 2004
Location: Port St. Lucie, FL
Posts: 4,642


i scanned my system before going to work this morning. no problems.

i'll go to Trend Micro's online scanner and get a second opinion.
Horsepower is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 06-08-2004, 12:57 PM   #8 (permalink)
Stryker412
Senior Member
 
Stryker412's Avatar
 
Join Date: Mar 2004
Location: NJ
Posts: 3,600


I searched my registry and didn't find the key they say it enters. I also didn't have a directory like they said it makes. Maybe I got it before it even started up. I have scanned my entire HD with the latest definitions from Norton. I then disabled system restore and then rebooted. I scanned again thinking it might reassert itself after a reboot but everything is clear. I'm hoping Norton caught it quick enough that nothing happend. Regardless I'm going to uninstall TS and reinstall it fresh.
__________________

www.shatteredplanet.org
Stryker412 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 06-08-2004, 12:59 PM   #9 (permalink)
Horsepower
Administrator
 
Horsepower's Avatar
 
Join Date: Mar 2004
Location: Port St. Lucie, FL
Posts: 4,642


maybe u and Icepick got it from the same source. name the last 3 things u downloaded.
Horsepower is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 06-08-2004, 01:06 PM   #10 (permalink)
Stryker412
Senior Member
 
Stryker412's Avatar
 
Join Date: Mar 2004
Location: NJ
Posts: 3,600


http://www.teamspeak.org/forums/show...ghlight=trojan
__________________

www.shatteredplanet.org
Stryker412 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Sponsored links
Reply



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
W32.Worm virus Stryker412 Help Me! 5 03-07-2006 03:13 PM
wininet.dll virus T3Kmitch Help Me! 6 02-23-2006 03:36 AM
Firefox warning Stryker412 Off Topic Discussion 1 01-18-2006 08:30 PM
Huge virus threat for Windows sers Horsepower Off Topic Discussion 0 01-04-2006 12:12 PM


All times are GMT -4. The time now is 07:07 AM.
Powered by vBulletin® Version 3.6.11
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.0.0
Ad Management by RedTyger Skin Purchased from CompletevB


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101