shanenin Posted June 23, 2006 Author Report Share Posted June 23, 2006 (edited) ya please :-)this must be somthing differenthttp://www.bleepingcomputer.com/startups/p...s.exe-7200.htmlthid looks like what I needhttp://www.beyondlogic.org/solutions/proce...processutil.htm Edited June 23, 2006 by shanenin Quote Link to post Share on other sites
Matt Posted June 23, 2006 Report Share Posted June 23, 2006 Sent to your yahoo account. Put it in System32 Quote Link to post Share on other sites
shanenin Posted June 23, 2006 Author Report Share Posted June 23, 2006 in the following line what does the "r" mean?O4 - HKLM\..\Run: [zdkyzf] C:\WINDOWS\system32\bcqzzkw.exe r Quote Link to post Share on other sites
Metallica Posted June 25, 2006 Report Share Posted June 25, 2006 If you like to play around with a fairly basic rootkit type of infection, install mailskinner.It will install the invisible variant of EGDACCESS The effect on a computer without a phone modem is not too bad, so you can play around with it.The 'r' is a command parameter.You may have seen other examples of those in lines like these:O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundIt feeds the executable some extra information to use when it is run.It could mean the file will behave differently when you simply doubleclick it. Quote Link to post Share on other sites
Matt Posted June 25, 2006 Report Share Posted June 25, 2006 Hey Metallica, haven't seen you around these parts lately! Looks like you got my PM at GTG Thanks for the info!Matt Quote Link to post Share on other sites
shanenin Posted June 25, 2006 Author Report Share Posted June 25, 2006 thanks for clearing that up. Being a linux guy(use command paramters daily), I should have realized that. Quote Link to post Share on other sites
Chappy Posted October 19, 2006 Report Share Posted October 19, 2006 I think the "r" sets the random filename on reboot for these, does it not? Quote Link to post Share on other sites
Chappy Posted October 19, 2006 Report Share Posted October 19, 2006 Oh yah, shaneninIf you want to see some of the stuff this junk does and the calls it makes to other processes N-stuff.Get Install Watch Pro to catch every file added, modified, deleted, and every registry entry made or modified during installation. This helps to see what areas of the system the malware will affect and what other things it will call using the registry entries.Other tools to use:FileMon for WindowsActivePorts Monitors all port activity. NOTE - Symantec incorrectly flags this program as a High security risk, because the API is publicly available and some malicious programs incorporate it for their bad purposes. Having the actual program is not any risk to your system in fact it's a well known security tool.Process ExplorerThese are just some of the tools you can use to see exactly what any Malware is doing in a system. This is how we find areas to fix these buggers, I used to do this to unknown new found files and report back what was found so developers could write fixes. Quote Link to post Share on other sites
baker7 Posted November 13, 2006 Report Share Posted November 13, 2006 Oh, yeah, Shanenin! Didn't know you had kids. That's the ticket! And Limewire, too. But, MommaLiz says you have to tell the kids, no pron!Sweepstakes.com comes up on a Google Search I've read that Poker Party is a nasty. Oh! Gator and Wild Tangent.Lizhave a friend that had her partner install lamewire (limewire) on her laptop - told me that she was getting all these popups - told her to come to BT so that the experts can help her out - Limewore should screw the machine up somewhat hehehehe - just be careful Brian Quote Link to post Share on other sites
shsh21 Posted November 19, 2006 Report Share Posted November 19, 2006 Hi If you want to get infected.I'd heard everything at least I thought I had. Google "Porno Pirate" that will do it! Regards Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.