Log in

View Full Version : winlogon


seven
June 27th, 2007, 19:29
hi all , i found a tiny proggy with the name ( winlogon) in system dir

so i got 2 proggy called winlogon with 2 dir ( windows + system32 )

which 1 of them iz the trojan ?

WARNING! MALWARE!

esther
June 27th, 2007, 19:47
what you have uploaded is a trojan infected.(trojan.spambot.DU)

seven
June 28th, 2007, 02:42
thatz what i thought, thanx soooo much esther .

esther
June 28th, 2007, 12:21
gee get a better av software like bitdefender....

squidge
June 28th, 2007, 18:40
Maybe someone should now either mark the attached file as infected, or remove it from the post so it doesn't get downloaded by accident or whatever?

seven
June 29th, 2007, 03:50
Quote:
get a better av software like bitdefender

i dont uze any antivirus software , i dont like them

squidge
June 29th, 2007, 05:49
You have a point there, Anti virus software usually is more harm than it is worth. It slows your PC down as it constantly has to check every file you open, and even causes compatibility problems and false positives and negatives.

It's usually easier to just practice safe hex

lcx2005
June 29th, 2007, 06:10
Quote:
[Originally Posted by squidge;66766]Maybe someone should now either mark the attached file as infected, or remove it from the post so it doesn't get downloaded by accident or whatever?


I think they have to read first, what the message and its content,I mean like this --> "which 1 of them iz the trojan ?" .By the way my Symantec (6/14/2007 database)detect as Trojan.Goldun.

When I download the attached file, i expect some trojan/virus since i read the message from esther and seven. But I wanna look .If My computer was infectect then thats my choice right??.

If your Av cannot delete some virus from ur Windows OS ,then why not delete from Linux.When i cannot delete some infected virus/trojan from windows OS , I fired up Linux (Live CD also works - Ubuntu 7.x), and mount my drive where that virus was, and then delete it, manual. But you have to know the location first hehehe.

~Windows Never Restricted deleting files from My Linux OS~
If you want you can delete c:\windows also, try it and you'll never forget

Polaris
June 29th, 2007, 07:15
Quote:
By the way my Symantec (6/14/2007 database)detect as Trojan.Goldun


That sounds like mis-identification. I had no time to check myself, but submitting the file to virustotal shows that most vendors identify the file as Spamtool.

Quote:
You have a point there, Anti virus software usually is more harm than it is worth. It slows your PC down as it constantly has to check every file you open, and even causes compatibility problems and false positives and negatives.


Actually, I think that having an anti-virus software is usually a good thing. Of course, not with the default settings. If you set up property exclusions, type of files scanned and the other settings for the on-access-scan, you won't see any heavy slowdown nor unwanted popups. The memory consumption is of course another matter.

Anyway, what I do is having a Linux host machine with strong security settings, that in turn uses vmware to run several different Xp images. So no AV needed for me

LLXX
June 29th, 2007, 15:30
PKLITE32. Interesting (custom?) packer.

This particular sample isn't very dangerous, as it doesn't seem to be the file-infecting-virus type.

seven
July 6th, 2007, 14:56
Quote:
This particular sample isn't very dangerous, as it doesn't seem to be the file-infecting-virus type


U R RIGHT BUT IF IT WAZ ABOUT PRIVACY THEN ITZ MORE DANGEROUS .

LLXX
July 6th, 2007, 17:02
See that key marked "Caps Lock" beside 'A' on your keyboard? Press it.

seven
July 7th, 2007, 05:59
i got no keyboard

lcx2005
July 7th, 2007, 23:35
Then I wonder how he manage it, copy/paste from others?.If it is online keyboard then,for me its still a keyboard.


Haya... greets to all the *2005 hehehe. It seem i found my lost family member.Ya, thank you for finding the right place to be.

JMI
July 8th, 2007, 01:31
Actually he might have managed "copy and paste" with the "multi-quote" button, second from the right on the bottom of each post. ( It's the one which looks like a page with a "+" mark on it. You check the box in the upper righthand corner of the post(s) you want to quote and then click the quote or multi-quote button.

Regards,