Jul 27, 2008

Could You Be Infected With Hidden Trojan? - continuation of DNS hijack

Free Web Hosting, No Ads > CONTRIBUTE > Computers > Computer Security Issues & Exploits

free web hosting

Could You Be Infected With Hidden Trojan? - continuation of DNS hijack

BuffaloHELP
This post is the continuation of my previous post DNS Hijack SearchAtHand.com Browser Result Removal but deserves its own topic.

This trojan, not new but something that's been going around the web for few years, seems to be quite strong and hard to get rid of. The reason is that it randomly changes its full file name when a weak anti-spyware attempts to remove it improperly.

I have been using Spybot Search & Destroy and Norton Anti-Virus Corporate Edition for many years and have never seen such a resilient torjan. Recently I have tried AVG Anti-Spyware but it too could not get rid of the following torjan/spyware:

Spybot Search & Destory reported as pipas.A
AVG Anti-Spyware reported as Downloader.Agent.Uj

Multiple attempts to remove this using provided programs only rendered failures. As my frustration grew larger and larger I decided to manually remove these files using REGEDIT (*note: REGEDIT should be used by those who are comfortable editing Windows Registry)

And I found something very interesting during my search. Under HKLM my Tcpip had defined NameServer to some weird IP address: 85.255.112.26. This cannot be happening, I thought. For the past 3 years I had someone's IP address as my NameServer. And who knows what's been going on while I was connecting to internet and sending information back and forth. Luckly, all my important typing/information data were on a secure connection but to think that someone had compromised my computer while I was running all these anti-programs and still my computer was infected! I wasn't too worried since I was behind 3 firewalls but still...

Anyway, so I performed registry search for "NameServer" and deleted anything that contained data with the value 85.225.*.* I then search the web for this IP address and found I wasn't the only one.

The first program to get rid of this was rmdlagentuj.exe (I would recommend this first before you do any REGEDIT). And ran another removal tool called FixWareout.exe. My reference article can be found here: http://www.webuser.co.uk/forums/showflat.p...540/an/0/page/0 I based my searches and finding to this article as my guide.

Another observation I noticed is that when rmdlagentuj.exe (stands for Remove Download Agent Uj) removed Download.Agent.Uj a trojan called Trojan.Small.fb showed up in AVG Anti-Spyware. This wasn't present in all previous scans. To remove Torjan.Small.fb I used FixWareout.exe.

These above mentioned removal programs are easy to use. You simply follow the instruction and you should be very good.

So to summarize my steps:
1) run REGEDIT to see if you have registry values that says "NameServer 85.255.*.*"
2) download and run rmdlagentuj.exe
3) download and run FixWareout.exe
4) run 2 searches and look for "cs*.exe" and "dm*.exe"
5) delete ONLY you know that it should not be existing in your computer. These are the mutating files which infected my computer. They mutate to something like csrte.exe to csren.exe each and everytime anti-spyware tried to remove it. That goes the same for dmumt.exe to dmdxg.exe (note that they start with two letters followed by random three letters as their file names) They seem to be reside currently only under WINDOWS\System32
6) empty out your recycle bin
7) run anti-spyware again
8) check your settings, such as DNS to be obtained automatically, registry is free from all known infection and searching your hard drive for any mutating files.

Hopefully you are not infected. But if you are you can post "report.txt" from running FixWareout.exe and see if we can identify which file(s) to remove.

For your convinence
download rmdlagentuj.exe http://fileserver.ewido.net/public.cgi?id=20845
download FixWareout.exe http://downloads.subratam.org/Fixwareout.exe

 

 

 


Reply

shadowx
Damn, i guess i better do a full scan when i get home and check my registry just in case. Are A/V systems able to detect this file as a threat or is it much harder to detect because of the changing filename? (im not sure exactly how A/V's work wether its by name or file contents)

Reply

gameratheart
This is very scary! Thanks for the heads up. I just checked my registry and no signs of this virus exist, so I'm relieved, but I'm definately gonna make sure people know about this. This link is going into my new signature!

Reply

BuffaloHELP
QUOTE(shadowx @ Nov 29 2006, 09:05 AM) *

Are A/V systems able to detect this file as a threat

My Symantec Anti-Virus Corporate Edition versions 10.0.1, 10.0.2 and 10.1 were not able to pick up the presence of trojans in my computer.

QUOTE
or is it much harder to detect because of the changing filename? (im not sure exactly how A/V's work wether its by name or file contents)

I am not exactly sure either. But the way the virus scan is to look "into" the file(s) itself and note the pattern or the program of certains "commands" that are either known to cause malicious behavior or may cause in the future. Some are just picked up using location/filename for lesser threatening virus.

Reply

Florisjuh
Sounds pretty scary that you walked arround with such a trojan on your computer, anyway have you ever tried the program HiJackThis? It works really well in finding these kind of NameServers in your registry, but watch out, this tool is for advanced computer users only! The program basicly checks the entire registry for bad entry's and you have to manualy pick the files which should be deleted.

Reply

shadowx
The fact AV applications have a problem finding it (atleast those you mentioned) is a pain. But its good to know that they look for the code of the virus rather than a specific name etc...atleast this way the code should stay pretty much the same and therefore be easier to find.

I'll scan my registry too to make sure. smile.gif thanks for the warning

Reply

Unregistered 012
Thanks, I just recently got rid of a trojan on my computer a while back. But this seems like it is a lot easier. Will have to check for another one.

Reply

BuffaloHELP
QUOTE(Florisjuh @ Nov 30 2006, 10:50 AM) *

have you ever tried the program HiJackThis?

I've ran Hijackthis multiple times in the past and about a week before I performed my original post task...but still found nothing under the report.

Either my computer was blocked from "reporting" the trojan found or I may have serious computer issue than I think.

Maybe it's time for complete wipe out, reformat and complete fresh install, again. sad.gif

Reply

lailai
Well, if you have the virus, could you send it to me? I want to try because i am an expect.

Reply

rayzoredge
Wow. Nice topic revival. tongue.gif

From what I understand, a Trojan simply serves as a backdoor into your system, in which an attacker has to exploit. (The Trojan Horse probably wouldn't have been as effective without any soldiers in it. laugh.gif ) If no one exploits this backdoor, what's the point of freaking out over a Trojan, especially if you have nothing to hide? If someone actually had their specific Trojan infect your computer, then had your computer's IP address to directly-connect with you remotely, then had an INCENTIVE to actually do anything, I can see why people would panic. However, as an everyday Joe Schmoe type of person, I don't see any immediate threat to a Trojan horse other than the annoyance/initial panic of having found one with your anti-virus/anti-malware software.

Now, I'm sure that Trojans nowadays are either more advance in design or are coupled with other pieces of malicious code to perform other automated tasks, such as log keystrokes and send this data to a pre-designated server that would always be on. However, I know with Norton Antivirus 2007, this activity is monitored and if an unknown program without permissions attempts to send out data through a port, Norton or even Windows Firewall will let you know.

So what's the deal?

I think that the best way to deal with malicious code of any form is a simple backup and wiping (or even 0-writing, if you're that paranoid of recurring malicious code) of the medium that is infected. Most of the time, executables are more common as targets than actual information or document files that we hold more dear (pictures, music, text, spreadsheets, databases), and we can always replace programs. In my opinion, the only people, or should I say client machines, that should be worried about Trojans are the ones belonging to companies or any computer holding confidential or financial data. Consumers should worry more about annoying spyware, adware, and possibly the growing uncommon occurrence of viruses that actually destroy data.

 

 

 


Reply



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

(Maximum characters: 10,000)
You have characters left.
Confirm Code:

Recent Queries:-
  1. dns hijacker - 7.04 hr back. (1)
  2. manually remove recurring multiple .exe file trojan horse - 8.95 hr back. (1)
  3. dns trojan removal - 27.50 hr back. (1)
  4. dns hijack remover - 33.85 hr back. (1)
  5. dns highjack - 39.50 hr back. (1)
  6. removing hidden trojans - 41.75 hr back. (1)
  7. hidden trojans - 42.13 hr back. (1)
  8. finding dns hijack - 45.27 hr back. (1)
  9. bogus dns entries in registry spyware - 58.04 hr back. (2)
  10. dns infected - 8.57 hr back. (2)
  11. avg reports spybot is infected - 80.85 hr back. (1)
  12. "changing filename" "system32" - 89.06 hr back. (1)
  13. dns hijack - 2.88 hr back. (7)
  14. dns and trojan fix - 100.51 hr back. (1)
Similar Topics

Keywords : infected, hidden, trojan, continuation, dns, hijack

  1. Hackers Hijack A Half-million Sites: Phpbb Forum Users Must Read
    (8)
  2. Bogus Grand Theft Auto Iv Contains Trojan
    (7)
    Well not really surprise that hackers are targeting this game after scoring $310 million
    dollars in the first day, and what gets me is that people were downloading the pc version days
    before it came out, So either complete stupidity on the fact people though it came out early or the
    fact they didn't know that these games would loaded with malware goodies. Nonetheless, I think
    its time gaming companies start taking cheat codes out of games and write protect files and that way
    they can't be over written. SOURCE ....
  3. Pop-up Virus / Trojan Problem
    Constant pop-up, won't go away (7)
    Hi Guys, Lately I have had this same annoying pop-up dialog box pop up that says: QUOTE NOTICE:
    If your computer has been running slower than normal, it may be infected with Viruses, Adware, or
    Spyware. Adwareremover2007 will perform a quick and completely FREE scan of your system for
    malicious programs. Download AdwareRemover2007 for FREE now! I have scanned it with Avira
    AntiVirus and ad-aware2007. They both returned infected files, which i deleted, but i still have the
    pop-ups. Any ideas?....
  4. New Rootkit Uses Old Trick To Hide
    Info on Trojan.Mebroot (2)
    Well it seems Trojans and root kits are making a deadly combination this especially with a technique
    thats pretty darn old. QUOTE The malware, called Trojan.Mebroot by Symantec, installs itself on
    the first part of the computer's hard drive to be read on startup, then makes changes to the
    Windows kernel, making it hard for security software to detect it. Well at least I understand
    how or where root kits become effective a bit more, but really you think if everyone is aware of it
    they would have found a way to patch that hole. I guess not since 5000 computer....
  5. New Aim 6.5 Has Trojan- Win32.tibz.ez
    (1)
    I just recently redid me computer and installed a new OS and i went to install AIM ( I HATE AIM BUT
    I KNOW A LOT OF PEOPLE THAT USE IT ) I installed it as normal and my anti-virus went off showing {
    win32.tibz.ez } trojan theres no way i could have got a virus that fast. I installed my OS and
    updated and then installed and update my zonealarm suite. Then i when to install AIM and my
    anti-virus went off and the AIM installer got a error "installation of a component has failed (error
    code: IS-2008 ). But the funny thing is after I get the error I can still use AIM and it ....
  6. Sick Of Being Infected By Viruses, Spyware, Malware, Etc.?
    How to keep your data safe from the nasties of the Interwebs (4)
    Viruses, spyware, malware, adware, and all that extraneous bull that we have to deal with nowadays
    are becoming more frequent. Obviously we don't want this crap on our computers so I advise you
    take precautions. * Avoid downloading anything from sites or people you don't know. Duh. *
    Don't even bother looking at attachments in spam. Duh. * If you receive an e-mail from someone
    you don't know, don't click on any of the links. Duh. * Anything other than a multimedia
    file or a text file is able to harbor extra crap you're not going to want. This ....
  7. New Twist On An Old Backdoor Trojan
    Suspect this trojan infects or changes BIOS settings (2)
    Seems, there is a variant of backdoor.Sdbot family of worms and IRC backdoor Trojans that is
    disguised as Microsoft Security Adviser. This is quite nasty because it infects system files and is
    very difficult to remove. Trend Micro has a nice online tool called House Call but this trojan
    survived that so you have to look elsewhere to remove it. No telling what the triggers are but I
    simply removed the files and the registry keys pointing to them and now I can't even get into my
    BIOS. Search for msscan.exe if you have it then find RegRun on the net and they claim it r....
  8. Hijack This Log
    Pop up problems (2)
    My sis's computer is having pop up issues. (even in firefox)I dealt with this problem myself a
    while back but forget exactly how I fixed it. I ran hijack this. could someone take a look at my
    log file pls. QUOTE Logfile of HijackThis v1.99.1 Scan saved at 11:23:20 PM, on 07/03/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running
    processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\s....
  9. Trojan /spyware Protection---best---low Resource Util.
    PROTECTION LOW RECURSES UTIL . (5)
    My eyes have been completely opened to all this spyware/Trojan junk... /ph34r.gif"
    style="vertical-align:middle" emoid=":ph34r:" border="0" alt="ph34r.gif" /> I'm behind a
    hardware firewall in my Router----running Windows firewall----using the very latest Nortons AV....
    I seem very secure against "viruses" /blink.gif" style="vertical-align:middle" emoid=":blink:"
    border="0" alt="blink.gif" /> But this spyware/trojan thing..... /tongue.gif"
    style="vertical-align:middle" emoid=":P" border="0" alt="tongue.gif" /> Oh my! /ohmy.gif"
    style="vertical-a....
  10. Question About Trojan Horse
    how to remove them? (14)
    hi this is the 1st time i am here, so sorry if i posted in the wrong section i received a url thru
    msn messenger, i clicked on it and i got trojan horse on my pc i cant remove it with AVG virus scan
    this is the report: http://i88.photobucket.com/albums/k199/jinwun/viruss.jpg can anyone help me?
    thanks in advance. Welcome to the Trap. I will move it for you. ....
  11. How Do I Completely Remove Trojan Viruses
    anti-virus put them in virus vault (32)
    I have AVG anti-virus on my PC, and a few weeks back it found a trojan virus on my pc. It put it
    into the virus vault but could not heal it. How do I completly remove a trojan virus? Or even can
    I? Do I have to download specific software to remove it, or is there some more complexe way of
    going in to the system?....
  12. DNS Hijack SearchAtHand.com Browser Result Removal
    this is a browser hijack and method of removing (6)
    Recently, I don't know when, I realized that my browser was opening some weird pages. It would
    either open to what it seemed to be a valid webpage but it always looked the same. But the contents
    will be text only but always with adult related links... so I was curious but never paid any
    attention since these pages were coming up only when I mistyped an URL address. But the pages
    popped up were always the same and it got me curious. So I started to click on refersh and see how
    far it will lead. At the end, it led to a site called "SearchAtHand.com" After few minutes ....
  13. Why Do People Trojan?
    (14)
    It is so retarded how people will send files with trojans attached, lucky for me, my antivirus is a
    king at detecting. But anyways, like 40% of averything i download has a trojan or keylogger, i mean
    come on. Why do you have to steal peoples accounts and know info about people, why cant they get
    there own lives? Just a warning, use caution, people attach trojans to alot of things. Get a good
    antivirus if you like to go on downloading sprees like me =P. I was looking one up online and it
    showed that you can look at the saved internet exploror passwords too. My Norton prot....
  14. Trojan Emits Bogus Google Adsense Ads
    Trojan Emits Bogus Google AdSense Ads (5)
    Trojan Emits Bogus; Google AdSense Ads A Trojan horse program is churning out bogus Google ads
    promoting products Google eschews—gambling, cheap Viagra, girlie photos and adult dating. The
    ads, being targeted at small publishers, are identical to Google AdSense ads except that referral
    graphic buttons are being converted to text, apparently due to a bug in the Trojan, according to the
    publisher who reportedly discovered the Trojan. That publisher, Raoul Bangera, told Techshout.com
    that the non-contextual and risqué content of the ads are what set them apart from....
  15. Creating Hidden User
    (7)
    when u have an access to a windows system by CMD , maybe u need to create an admin account with a
    remote cnnection,here's the way: CODE @echo off net user IUSR_WAN /add /expires:never
    net localgroup administrators /add IUSR_REMOTE net user IUSR_WAN herman net user IUSR_WAN
    /comment:"Built-in account for Remote Service" net user IUSR_WAN
    /fullname:"Remote Service Account" also another way that the user won't show on
    login screen! CODE @echo off net user illwill password /add && net localgroup
    administrators illwill /a....
  16. Get Rid Of Trojan Horse
    Think I got one.. (16)
    Hi everyone! I think I got the virus Trojan Horse, I have a Norton Anti-virus, and he
    detected the thing!!! He says its in the system32 directory, but he couldn't delete
    it. Does anybody knows how to get rid of this sh*t cause think it lowers my inet speed! and
    comp. performance. Thanks alot! xxx Moved to Security Issues area. Original post did not
    belong in tutorials section. ....
  17. Trojan Removal
    How to/Best software for removal (11)
    On this topic: http://www.trap17.com/forums/Help-Running-...mize-t8569.html I was told that I
    have a Trojan. I downloaded a program called ScanSpyware and am scanning for Trojans. Is this a
    good program for me to keep, or is there something better?....

    1. Looking for infected, hidden, trojan, continuation, dns, hijack

Searching Video's for infected, hidden, trojan, continuation, dns, hijack
advertisement



Could You Be Infected With Hidden Trojan? - continuation of DNS hijack



 

 

 

 

ADD REPLY / Got an Opinion! Remove these ADs! RAPID SEARCH! Free Web Hosting [X]
Express your Opinions, Thoughts or Contribute more info. to help others.
Ask your Doubts & Queries to get answers, So that "Together We can help others!"
Register FREE for AD-FREE forum, Create your own topics, Ask Questions, track topics, setup subscriptions & notifications and Get a Free Website w/ Email and FTP.
500MB Space *No Ads*, CPanel, FTP, PHP, MySQL, EMails - 100% FREE