Virus Dowloader.Small.54.2

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • willawake
    Super Modulator
    • Nov 2003
    • 8457
    • Greece

    #1

    Virus Dowloader.Small.54.2

    AVG detected the Trojan Dowloader.Small.54.2 having infected \system32\wsock32.dll on one of my pcs.

    pretty admirable to have got passed zyxel router firewall, AVG and BlackIce.

    i chose to clean the file in AVG and it advised to reboot. now pc bluescreens on login. i did some safe mode checking of the registry and searched for files recently modified but did not find anything abnormal.

    its kinda late for troubleshooting so i will check it on the weekend.

    time to re-evaluate security here.
    capacitor lab yachtmati techmati
  • Fatal0E
    Badcaps Veteran
    • Jan 2004
    • 252

    #2
    Re: Virus Dowloader.Small.54.2

    I've always heard blackICE was a problem. I dont even use a software firewall anymore. I was a fan of AVG, then I used trend micro and liked it more. Now I am using Avast and it found all kinds of crap in my downloaded files that both AVG and Trend missed.

    Comment

    • willawake
      Super Modulator
      • Nov 2003
      • 8457
      • Greece

      #3
      Re: Virus Dowloader.Small.54.2

      blackice has some issues for instance if win2k is connecting to samba server, i had to add the server ip to trusted otherwise problems would occur. (have to figure out the ports sometime)

      Yesterday i found our accounting software Sage Line 50 gives slow performance when blackice is enabled. I had been troubleshooting that for a while. that is from a win2k pc with the data hosted on samba. i am guessing that the accounts software makes many small packets and blackice inspecting them slows it down. it also occasionally doesnt enable itself on boot, i find that on some client pcs.

      i would say that if the router has a good firewall then a local firewall is not really needed anymore. however on dial up at major ISPs here in Greece a firewall is a must, trojans trying to connect every few seconds. It was an eye opener for many clients when i first installed blackice on their pcs.


      here is my office pc's log from blackice. doesnt look bad.
      Attached Files
      capacitor lab yachtmati techmati

      Comment

      • Brandon
        Senior Member
        • Dec 2005
        • 51

        #4
        Re: Virus Dowloader.Small.54.2

        Software firewalls are junk anymore get a good router with NAT/Packet inspection.

        Comment

        • Cprossu
          Member
          • Dec 2005
          • 14

          #5
          Re: Virus Dowloader.Small.54.2

          I found the best way to protect computers these days is with a linux box and good internet habbits (avoid using Internet Explorer-err Exploder, or Outlook, err LookOut!. The linux box will take care of the direct port attacks, and I suggest something like Symantec Corperate Antivirus to take care of virus issues. Where dlinks have smoked up after overheating, belkins had given out, linksys's have been bypassed and hacked through/rebooted, and my trusty cisco 5000 was made into a mash and required a complete nvram reset more than once, my linux box prevailed.

          The easiest way I've found to do that is smoothwall htt://www.smoothwall.org loaded on a junk comp loaded with a few network cards. It'll install in about 10 mins if you can cd boot, longer if you cannot.(you can use smoothwall's boot floppies or Smart Boot Manager if you have a computer which cannot cd boot and have an ATAPI drive) has a great manual to go with it, a good community, is extremely easy to use/configure/modify, and is free.

          I personally like to use P3 450's or equivilent for that purpose with at least 32mb of ram (I overdid mine and made it 192mb, although mine runs folding@home too) and 3 old DECnet cards.

          If you have a good board with good caps, a power supply to match, a small hdd (mine is only 450 megs), then network troubles for you will dissapear. just to give you an idea, my smoothwall's uptime is now 167 days, and that's only because we had a power outage which lasted 8 hours (my UPS is only good for 3 hours on that box) 167 days ago.

          since 3.0 is currently unfinished and has some major flaws, for the moment I would reccomend sticking with 2.0 express.
          Last edited by Cprossu; 12-18-2005, 12:21 AM.

          Comment

          • Rainbow
            Badcaps Legend
            • Aug 2005
            • 1371

            #6
            Re: Virus Dowloader.Small.54.2

            I use 486 box for that:
            UMC GreenCPU U5S/33 (486SX class, 5V, no need for heatsink), TD-4IP-UMC-AIO board (probably made by ECS, UMC chipset), 32MB EDO RAM (yes, the board supports EDO), WD 4.3GB HDD (that's a little too big but I used it because it's quiet), two ISA network cards (one is HP, one is Genius NE2000 compatible) and PCI wifi card (LG LW1100P).
            It runs slackware-current.

            Comment

            • linuxguru
              Badcaps Legend
              • Apr 2005
              • 1564

              #7
              Re: Virus Dowloader.Small.54.2

              I use a P200/MMX on a BCM 430VX board, two NICs, 16 MB of RAM and a 120 MB HD (no typo) to run Routerlinux (http://www.routerlinux.com). It only requires 4 MB of RAM and about 12 MB of disk space, but not many 20 MB IDE hard disks have survived to this day. It will also run on a GCT/Allwell 1030N or similar, where it will run entirely from flash - there are no moving parts on that machine except the CPU fan, and I've replaced that with fully-passive cooling. I've contributed some scripts and packages to Routerlinux - it's basically a very minimal Slackware-like distro based on Busybox/uClibc. It has netfilter/iptables, rp-pppoe, sshd, freeswan/pluto, zebra and lots of other stuff in 12 MB
              installed.

              I also have a Linksys WRT54G running OpenWRT, but I haven't played around much with that distro.

              Comment

              • Rainbow
                Badcaps Legend
                • Aug 2005
                • 1371

                #8
                Re: Virus Dowloader.Small.54.2

                I like having full distribution so I can run anything there when needed.

                Comment

                • Cprossu
                  Member
                  • Dec 2005
                  • 14

                  #9
                  Re: Virus Dowloader.Small.54.2

                  but not many 20 MB IDE hard disks have survived to this day.
                  LOL
                  I put a 3.5" 25 meg Conner IDE hdd into my 286 when I built it up, and I creep out computer teachers every year with it too . (yes it still works too)

                  Comment

                  • willawake
                    Super Modulator
                    • Nov 2003
                    • 8457
                    • Greece

                    #10
                    Re: Virus Dowloader.Small.54.2

                    i think i have enough hardware for a firewall box. i played with smoothwall sometime in the past and it was quite easy. i have been recommended Ipcop though.

                    http://www.ipcop.org/
                    capacitor lab yachtmati techmati

                    Comment

                    • Spacedye69
                      Badcaps Veteran
                      • Nov 2005
                      • 698
                      • US

                      #11
                      Re: Virus Dowloader.Small.54.2

                      I use Suse right now as my Linux desktop/ router on my AMD slot A system right now, but in the past, I always used Coyote Linux on a single floppy with nothing but 16mb ram and 2 nics, no hard drives. Can't hack root with no hard drive and floppy locked.

                      Comment

                      • stretch0069
                        Screwed Up Super Moderator
                        • Oct 2003
                        • 2658
                        • oooo ess aaaaaaaaa

                        #12
                        Re: Virus Dowloader.Small.54.2





                        maybe I should take that internetworking class.........
                        "Its all about the boom....."

                        Guns kill people like spoons made Rosie O'Donnell fat.

                        We now return you to your regularly scheduled drinking.

                        "Fear accompanies the possibility of death.....calm shepherds its certainty"

                        Originally posted by Topcat
                        AWD is just training wheels for RWD.

                        Comment

                        • willawake
                          Super Modulator
                          • Nov 2003
                          • 8457
                          • Greece

                          #13
                          Re: Virus Dowloader.Small.54.2

                          maybe I should take that internetworking class.........
                          its like the wild west on the net these days.

                          anyway i got nowhere and did a repair with the win2k disk which worked fine. installed mcafee this time.
                          capacitor lab yachtmati techmati

                          Comment

                          Related Topics

                          Collapse

                          • Hondaman
                            Hardware firewall to block ad servers?
                            by Hondaman
                            I found an interesting summary on a wiki that Youtube "right to repair" enthusiast Louis Rossman put up. He suggested I could use a hardware firewall and pfSense as a firewall, and use pfSenseNG as an ad blocker. Or use OPNSense as a similar alternative. Seems like it would be easy to set up, but it only runs on the hardware supported by BSD. (I'm sure the developers and maintainers of BSD are super-busy and cannot support every single piece of hardware out there, so I can't fault them.)

                            The trick, apparently, is to "assign IP address lists from sites like I-blocklist...
                            02-05-2025, 05:04 AM
                          • mon2
                            Hunting down a virus in an office
                            by mon2
                            Hi. We have an office client who has been contacted by the local internet provider that one of the office Windows PCs is infected with a virus. The report has been confirmed. Apparently through a remote outside trigger, this virus is performing brute force attacks around the world from this local IP address at varying times. Aside from low level formatting each PC, what is the recommended approach for this case? Running F-prot (suggested by the internet supplier) has come up empty. We are planning to run hijack this. At this time, we do not know which PC is creating this issue. Internet provider...
                            01-09-2025, 09:42 PM
                          • juergenb
                            Sophos XG86w Firewall forgets the date and time as well as the DMI environment variables after power cycle
                            by juergenb
                            Hello,

                            I have a small Sophos XG86w firewall here, which is still working so far. But there is a problem with the BIOS and the DMI environment variables.

                            The hardware forgets the date and time after a reboot or a power failure.
                            The DMI environment variables are also reset to default values.

                            I have now tried 2 different batteries (CR2032).
                            I reset the DMI vars via an EFI shell and with AMIDEEFI64 (v5.21.0057).

                            However, after a reboot or a power cycle, these values are reset again.

                            It is an Apollo Lake platform with an Intel...
                            10-08-2024, 04:19 AM
                          • asigasm
                            UEFI VIRUS
                            by asigasm
                            good evening, I have an HP OMEN 15dh0006la laptop, which is pressed the "A" key, continues to do that even with the keyboard disconnected and after formatting. Could it be an EFI virus?
                            12-27-2022, 10:05 PM
                          • rex98
                            HP DMI Tool
                            by rex98
                            HP DMI Tool is used to Extract DMI information from a HP BIOS Bin.

                            DISCLAIMER: badcaps.net and its members do not support unlocking stolen or company-owned devices.
                            The DMI Tool given here are for personal use only.

                            ************************************************** ***********************************************
                            DISCLAIMER: THE HP DMI Tool IS FREE AND ARE INTENDED FOR EDUCATIONAL PURPOSES ONLY.
                            You CAN download it, use it.use it.I only ask that you DON'T modify it ,sell it or try to make a profit
                            from it, and that you please credit the author...
                            07-02-2025, 05:51 AM
                          • Loading...
                          • No more items.
                          Working...