Adware, malware, spyware, hijacker discussion and information

[Gain Knowledge]  [Install Prevention]  [Maintain Security]  [Spyware Removal Help]


It is currently Wed Jun 19, 2013 12:21 pm

All times are UTC - 7 hours




Post new topic Reply to topic  [ 1 post ] 
Author Message
 Post subject: SWAP-X\Win-eto
PostPosted: Fri Mar 18, 2005 12:49 am 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15967
Location: PHX, AZ
Approx Date Of Appearance: Oct-Nov 2005

Samples of infected PC:
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://win-eto.com/sp.htm?id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://win-eto.com/sp.htm?id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://win-eto.com/hp.htm?id=9
O4 - HKLM\..\Run: [Control handler] C:\WINDOWS\system32\j3t53zit6tthd.exe(harder version to remove)
O20 - AppInit_DLLs: v5pbrv56gdx8n4ll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll

The fix:
So far, there is no 'canned fix' as of yet. However, a couple involve using Killbox, to kill the offending files, of which there can be several. Variants with [Control Hnadler] in O4 entry of HJT log, must be killed first.
Also, it seems users who are using AVG are easier to clean up, as it defines the trojan, and does not let whole infection load.
This fix is a work in progress.

UPDATE 2/18/2005
This fix has come around and is pretty much routine. Experts from around the poular security forums banded together to figure it out. Several items to be aware of when fixing.There also are not too many of these infections popping up currently.

_________________
Image



IP:
top
Top
 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 1 post ] 

All times are UTC - 7 hours


Who is online

Users browsing this forum: Google and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  

Who is online

Who is online In total there are 2 users online :: 1 registered, 0 hidden and 1 guest (based on users active over the past 5 minutes)
Most users ever online was 282 on Tue Sep 25, 2012 11:30 am

Users browsing this forum: Google and 1 guest

New posts    No new posts    Forum locked
cron
Powered by phpBB