My recent run-in with a couple of backdoor trojans...

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
EmperorMing
Sith Devotee
Posts: 3432
Joined: 2002-09-09 05:08am
Location: The Lizard Lounge

My recent run-in with a couple of backdoor trojans...

Post by EmperorMing »

Noticed on the one computer I use for downloading that an additional browser window would open when I opened my homepage, clued me off that something was not right. Soooo I go and check the startup list and find these little gems in my system32 folder:

msiexec16.exe
realupd.exe
vujokic.exe
msrexe.exe
ntdll.exe

Netstat -a command also pointed to a connection to 65.75.181.110; whoever owns that domain has a bunch of spammer/scammer sites registered to it (courtesy of whois.com)

During the required surgery to remove them I also noticed that my admin password was changed. Fucker!! :evil:

Long story short, they're all gone for now and the system is updated. I'm sure Einey will have fun with this one.
Image

DILLIGAF: Does It Look Like I Give A Fuck

Kill your God!
Post Reply