PDA

View Full Version : Pretty Sure I Got A Trojan



arghwashier
10-25-2003, 10:31 AM
ok i downloaden sygate personal firewall pro and tried a keygen from astalavista.com and i'm pretty sure the keygen installed a trojan :blink: :unsure:
(i was already running the free version of the sygate firewall)
first it called itself slave.exe trying to contact the internet than it tried all sorts of tricks renaming itsself mmtask0.exe (i went into my register and saw a rename)

antway i run norton 2003 antivirus but it didn't detect any trojans i looked on the internet slave.exe in a commercial program but can also be used as a trojan the normal and this version that came with the keygen. has some extra tricks up it's sleave like the renaming bit and there are a lot more registry entries than the normal version.

anyway 2 questions why didn't norton detect anything (my definition were up-to-date)

are there any good trojan scan around on the internet?

scribblec
10-25-2003, 10:35 AM
http://www.webattack.com/


try searching spy sweeper that mite work :)

nikita69
10-25-2003, 10:37 AM
The clostest any program can get ur pc to 100% anti-trojan is
TDS-3 Trojan Defence Suite easy to get the program, yet hard to get the qwak. they update their database more than anyone in the bus. Several governments' orgs use it.

look for it, if u find a working qwak for the latest version, let me know and visa versa.

arghwashier
10-25-2003, 11:56 AM
Originally posted by nikita69@25 October 2003 - 10:37
The clostest any program can get ur pc to 100% anti-trojan is
TDS-3 Trojan Defence Suite easy to get the program, yet hard to get the qwak. they update their database more than anyone in the bus. Several governments' orgs use it.

look for it, if u find a working qwak for the latest version, let me know and visa versa.
well it actually found 3 trojans that came with the keygen!

neither norton antivirus, spybot, adaware or spysweep detected them, though they were in a zip!

though the program looks hard to use to but it requires you to pay instead of enter a key....

nikita69
10-25-2003, 04:14 PM
on the contrary, TDS3 is by far the simplest program I've seen in a while. One reason u may see it as hard is cos it doesn't rely much on the user. I have the previous version and just last night, my server was attacked by someone from 159.137.146.49. I had TDS3, NIS 2004, Sygate, NAV 04 and my (buddy) AReplicator. ALL picked it up NAV04, NIS04 & sygate went crazy like it's the end of the world :lol: however, TDS3 SILENTLY detected and blocked, whil AReplicator SILENTLY replicated the attack and send it back to initial source other than the above IP.http://www.mcbriens.net/liam/img/smilies/whistle.gifhttp://www.mcbriens.net/liam/img/smilies/whistle.gif

Frankly I was bothered by Sygate & Norton more than the attack it self. :lol:

arghwashier
10-25-2003, 04:53 PM
nah the graphical interface looks like shit and it has a lot of functions

anyway a found a working version of 3.2.0 and i'm glad i lost those 3 trojans! (which spybot adaware spysweeper and norton all missed, luckily i had a gut feeling something was wrong.....)

although i'm a bit paranoid suppose this crack also includes some malware....

arghwashier
10-25-2003, 05:25 PM
damn the program found the illegal key <_<

nikita69
10-25-2003, 05:56 PM
Originally posted by arghwashier@25 October 2003 - 23:25
damn the program found the illegal key <_<
talking about TDS3? if so, then i&#39;m not surprised, i&#39;ve been trying for months. initially, this program was co-created by a hacker (tho they don&#39;t claim that).

Wizzandabe
10-25-2003, 05:57 PM
Cracks AM. :D
Nothing else.
..oh and a pop up stopper :P

arghwashier
10-25-2003, 06:14 PM
Originally posted by Wizzandabe@25 October 2003 - 17:57
Cracks AM. :D
Nothing else.
..oh and a pop up stopper :P
i tried the crack am crack but tds says it&#39;s an illegal key and opens it website and thanks you for helping stop software piracy :rolleyes: :lol:

almost thinking of buying it......

nikita69
10-25-2003, 06:26 PM
Originally posted by arghwashier+26 October 2003 - 00:14--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (arghwashier &#064; 26 October 2003 - 00:14)</td></tr><tr><td id='QUOTE'><!--QuoteBegin-Wizzandabe@25 October 2003 - 17:57
Cracks AM. :D
Nothing else.
..oh and a pop up stopper :P
i tried the crack am crack but tds says it&#39;s an illegal key and opens it website and thanks you for helping stop software piracy :rolleyes: :lol:

almost thinking of buying it......[/b][/quote]
that&#39;s not a bad idea, keep it legal. Send me a PM with ur credit card info (ur full name is enoughhttp://www.mcbriens.net/liam/img/smilies/whistle.gif) and I&#39;ll reply with a keygen. :lol: :lol: :lol: :lol: just kidding

MUSLEMAN
10-25-2003, 06:46 PM
its not illegal to post your credit card and bank account info here, you don&#39;t have to pm nikita just post it :lol:

djweiser
10-26-2003, 12:12 AM
hmm

id remove it asap. ;)

Blade025
10-26-2003, 02:34 AM
i also downloaded something from astalavista.com and got a virus as well, is that site safe?

MUSLEMAN
10-26-2003, 03:22 AM
Originally posted by Blade025@25 October 2003 - 22:34
i also downloaded something from astalavista.com and got a virus as well, is that site safe?
yes but as anywhere you have to scan what you download you never know

zapjb
10-26-2003, 07:14 AM
Anti-Trojan 5.5 b421 is well respected & stays cracked. :P

Jay
10-26-2003, 08:41 AM
Originally posted by Blade025@26 October 2003 - 03:34
i also downloaded something from astalavista.com and got a virus as well, is that site safe?
i dont trust anything from that site cause everytime i tried to download anything from up there it kept trying to install a sex-thing on my system

nikita69
10-28-2003, 06:21 AM
Originally posted by Jay+26 October 2003 - 14:41--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (Jay &#064; 26 October 2003 - 14:41)</td></tr><tr><td id='QUOTE'> <!--QuoteBegin-Blade025@26 October 2003 - 03:34
i also downloaded something from astalavista.com and got a virus as well, is that site safe?
i dont trust anything from that site cause everytime i tried to download anything from up there it kept trying to install a sex-thing on my system [/b][/quote]
the combination of:

PROXY - don&#39;t visit any such warez sites without hi-anon ssl proxy
NIS 04
NAV 04
Sygate pro 5.1
HERE (http://www.klboard.ath.cx/index.php?showtopic=64831&view=findpost&p=499791) and HERE (http://www.klboard.ath.cx/index.php?showtopic=64831&view=findpost&p=567015)

would definetly elimnate this problem and others.

I visit it often, have the above and never had any problems.