Virus

A General Discussion forum for cars and other topics, and a great place to introduce yourself if you are new to NICO!
The Mic
Posts: 5871
Joined: Sat Dec 21, 2002 6:33 am
Car: 3Z Wmb
Contact:

Post

I got 2 viruses from [email protected]

i clicked on this link http//members.lycos.co.uk/hmh2004/nissaninfiniti505.bat (i know i shouldnt have)good thing my NAV deleted them. anyone else get this in their mail??


IvoryJ30t
Posts: 3076
Joined: Sun Aug 17, 2003 1:36 pm
Car: 95 Maxima GLE, 95 Maxima GXE

Post

im checking. i wonder if this is related.

may be an opportunity to nail the *******.

a bat file is a batch of commands. did you see what the commands were? [probably deletes folder/files from %systemroot%]

IveBeenBad
Posts: 1138
Joined: Sun Jan 12, 2003 11:53 am
Car: 1990 Nissan 240SX Fastback STOCK BIOTCH

Post

yeh a .bat file basically tells DOS to run the commands listed in the file. Its actually pretty neat. I used it to whip up a small .exe to copy files to a server.

IvoryJ30t
Posts: 3076
Joined: Sun Aug 17, 2003 1:36 pm
Car: 95 Maxima GLE, 95 Maxima GXE

Post

i downloaded the file, and its not a batch file. [it has a .bat extension, but it is not correct]

its part binary, part ascii.

wierd. i figure at most, it would crash the computer.

what did you AV program identify it as?

i think the arabic lettering on the site is supect.

The Mic
Posts: 5871
Joined: Sat Dec 21, 2002 6:33 am
Car: 3Z Wmb
Contact:

Post

C:\Documents and Settings\none-1\Application Data\Mozilla\Firefox\Profiles\default.aku\Cache\1B0C6B37d01

thats where my NAV picked it up. it identified it as a Bloodhound.W32.EP virus

jdmfreak
Posts: 9350
Joined: Thu Jul 03, 2003 5:06 am
Contact:

Post

Damn! All this computer talk is giving me a headache.

IveBeenBad
Posts: 1138
Joined: Sun Jan 12, 2003 11:53 am
Car: 1990 Nissan 240SX Fastback STOCK BIOTCH

Post

jdmfreak03 wrote:Damn! All this computer talk is giving me a headache.


Well first you take the Motherboard and introduce her to the Fatherboard and then they make a Daughterboard...

IvoryJ30t
Posts: 3076
Joined: Sun Aug 17, 2003 1:36 pm
Car: 95 Maxima GLE, 95 Maxima GXE

Post

thats wierd. at most, that file would have crashed the computer.

NAV with definitions dated 8/20/04 did not detect anything unusual with the batch file.

NAV is working properly, as verified by the EICAR test string [ i keep the test string handy because im paranoid. hardware and software firewall...]

jmattick
Posts: 6
Joined: Tue Mar 30, 2004 10:04 am

Post

While it's been a long time since I posted, I also recieved this...

It isn't the correct file extension, I think it is supposed to be .exe instead of .bat

It has something to do with networking, because in the beginning of the file, it is supposed to open ports to allow connections, somewhat like the blaster worm, that went around a few months ago. I ran a few online scans, and it didn't detect it as anything.

I have a feeling this is someones poor excuse at coding.

EDIT: I decided, to change the file extension from .bat to .exe. This time, I think I found out what the person who wrote the virus was trying to do. It changed the icon from that of an .exe to a image file icon associated with Photoshop.

I re-scanned it, found nothing. I'm half tempted to run the file, just to see what happens, but I won't, cause I don't have a test machine here.

The Mic
Posts: 5871
Joined: Sat Dec 21, 2002 6:33 am
Car: 3Z Wmb
Contact:

Post

The compressed file BlackBox.class within C:\Documents and Settings\none-1\Local Settings\Temp\jar_cache4473.tmp is infected with the Trojan.ByteVerify virus.

The compressed file Dummy.class within C:\Documents and Settings\none-1\Local Settings\Temp\jar_cache49509.tmp is infected with the Trojan.ByteVerify virus.

The compressed file Dummy.class within C:\Documents and Settings\none-1\Local Settings\Temp\jar_cache4473.tmp is infected with the Trojan.ByteVerify virus.

The file C:\WINDOWS\SYSTEM32\svc.exe is infected with the Backdoor.Madfind virus.

The compressed file VerifierBug.class within C:\Documents and Settings\none-1\Local Settings\Temp\jar_cache4473.tmp is infected with the Trojan.ByteVerify virus.

All automatically deleted after a full system scan.

IvoryJ30t
Posts: 3076
Joined: Sun Aug 17, 2003 1:36 pm
Car: 95 Maxima GLE, 95 Maxima GXE

Post

i was thinking it might have been mis-extensioned, but i cant figure what might be correct.

way too much ascii text to be executable.

jdmfreak
Posts: 9350
Joined: Thu Jul 03, 2003 5:06 am
Contact:

Post

IveBeenBad wrote:Well first you take the Motherboard and introduce her to the Fatherboard and then they make a Daughterboard...


Oooooooooohhhhh......Now I get it.:thinker

(jd)
Posts: 249
Joined: Mon Mar 29, 2004 1:32 pm
Car: 03 Chevy Silverado
Contact:

Post

I hate viruses... waste of time:)

PhaneSoul
Posts: 844
Joined: Sun Apr 04, 2004 7:10 pm
Car: 89 Nissan 240SX SE Black 5spd Wrecked
95 Nissan 240SX SE Green 5spd s14.5 yay!
Contact:

Post

i also got this e-mail......

The Mic
Posts: 5871
Joined: Sat Dec 21, 2002 6:33 am
Car: 3Z Wmb
Contact:

Post

LOL this is what teh email consisted of:

From : [email protected] <mailto:[email protected]>Sent : Saturday, August 21, 2004 5:32 AMTo : [email protected]Subject : hi all

it msn club new

General Chat

http//members.lycos.co.uk/hmh2004/nissaninfiniti505.bat

welcome

jmattick
Posts: 6
Joined: Tue Mar 30, 2004 10:04 am

Post

I recieved the same thing.

Here's what I did. I submitted the file to Trend Micro.

Case Number: 0820048342

That should allow them to figure things out from here.

Edit: After checking out the Full Headers of the message. I have this info from the IP.

Anyone else who reads the headers will also notice that they spoofed the headers from teksolvers.com. Now, visit teksolvers.com; you'll notice it takes a bit of time to load, and then it loads a page. Now, wait 5 mins, then press enter on the address bar, reloading the webpage. You'll see a completely different webpage. It's is using a redirect script on the domain name's server.

But... You'll notice, from the hacked thread, that teksolvers take care of NICO's server, etc.

My guess is this is the same person, and they have gotten access to Tekserver's mail server & webserver.

(jd)
Posts: 249
Joined: Mon Mar 29, 2004 1:32 pm
Car: 03 Chevy Silverado
Contact:

Post

Damn I just deleted it

User avatar
AZhitman
Administrator
Posts: 54542
Joined: Mon Apr 29, 2002 2:04 am
Car: 58 L210, 63 Bluebird RHD, 64 NL320, 65 SPL310, 66 411 RHD, 67 WRL411, 68 510 SR20, 75 280Z RB25, 77 620 SR20, 79 B310, 90 Z32, 91 GTi-R, 92 Silvia Qs, 98 S14, 23 Z.
Location: Surprise, Arizona
Contact:

Post

Good work guys!

I'm forwarding this info to them.

silkk
Posts: 2357
Joined: Tue Apr 27, 2004 5:49 pm
Car: 94 B13
89 S13
07 S2000

Post

i got 2 emails and checked the forums to make sure before clicking it :)

oh and i deleted msn. and and! "it msn club new" :confused:

User avatar
Cold_Zero
Posts: 6714
Joined: Sun Oct 20, 2002 4:15 pm
Car: 2003 Nissan Altima SE 3.5
2005 Nissan Pathfinder

Post

I feel left out, I didnt get it.bud

User avatar
ilovedrifting
Posts: 689
Joined: Sun May 09, 2004 9:23 am
Car: skateboarding and drifting

Post

I got it, deleted just a second ago

User avatar
ilovedrifting
Posts: 689
Joined: Sun May 09, 2004 9:23 am
Car: skateboarding and drifting

Post

it prolly came from those bastards who hacked us

[Zero-S]
Posts: 5295
Joined: Wed Apr 16, 2003 10:56 am
Car: Tell me whats wrong with this picture. 3 240's, only one runs.

Post

I didn't get it, cox filtered it automatically

w1ngzer0
Posts: 7535
Joined: Sun May 04, 2003 7:49 pm
Car: Pfft. i don't own a box
Contact:

Post

IveBeenBad wrote:Well first you take the Motherboard and introduce her to the Fatherboard and then they make a Daughterboard...


so true dude so true. :D

NICOmom
Posts: 200
Joined: Mon Mar 29, 2004 8:28 am

Post

I got the email late last night and forwarded it to teksolvers. Hopefully they are as savy as you guys and were able to put a stop to this stuff. You guys are so cool! :)

[Zero-S]
Posts: 5295
Joined: Wed Apr 16, 2003 10:56 am
Car: Tell me whats wrong with this picture. 3 240's, only one runs.

Post

:D

See that! Mom praised us!

IvoryJ30t
Posts: 3076
Joined: Sun Aug 17, 2003 1:36 pm
Car: 95 Maxima GLE, 95 Maxima GXE

Post

Cold_Zero wrote:I feel left out, I didnt get it.bud


i didnt get it either.

jdmfreak
Posts: 9350
Joined: Thu Jul 03, 2003 5:06 am
Contact:

Post

^Ditto


Return to “General Chat”