*

Account

Welcome, Guest. Please login or register.
Did you miss your activation email?
December 03, 2024, 02:29:45 pm

Login with username, password and session length

Resources

Recent posts

[November 01, 2024, 12:46:37 pm]

[October 05, 2024, 07:29:20 am]

[September 05, 2024, 01:54:13 pm]

[July 16, 2024, 11:30:34 pm]

[June 22, 2024, 06:49:40 am]

[March 08, 2024, 12:13:38 am]

[March 08, 2024, 12:12:54 am]

[March 08, 2024, 12:09:37 am]

[December 30, 2023, 08:00:58 pm]

[February 04, 2023, 11:46:41 am]
Pages: [1]   Go Down
  Print  
Author Topic: Trojan Horse Agent.AZOH 2  (Read 6569 times)
0 Members and 1 Guest are viewing this topic.
Tymathee Offline
Donator
*
Posts: 9741



« on: February 21, 2009, 01:44:52 pm »

Now I'm getting it, here are 4 .dll's that get deleted if I choose to heal.

libcurl, libeay32, libidn-11, and libssh2 i think they are, the download is too fast.

maybe libssl32 & zlib1 as well because they were all installed at the same time and there's been no updates to these files recently.



Logged

"I want proof!"
"I have proof!"
"Whatever, I'm still right"

Dafuq man, don't ask for proof if you'll refuse it if it's not in your favor, logic fallacy for the bloody win.
Ausargentallied Offline
EIR Regular
Posts: 2


« Reply #1 on: February 22, 2009, 05:34:22 am »

I also have the trojan alert since attempting to use Autoupdater 1.03.  I also get a crash.
Logged
Ausargentallied Offline
EIR Regular
Posts: 2


« Reply #2 on: February 22, 2009, 05:57:50 am »

The solution seems to be to delete libcurl.dll and reupdate.  Unfortunately you can log in and setup battles but then on launch it crashes.
Logged
nugnugx Offline
Donator
*
Posts: 4051



« Reply #3 on: February 22, 2009, 06:17:35 am »

that's what you get from visiting porn sities w/o protection lol...

my pc is clean

and your virus is in svchost.exe not libcurll
« Last Edit: February 22, 2009, 06:19:13 am by nugnugx » Logged

EIRRMod Offline
Administrator / Lead Developer
*
Posts: 11009



« Reply #4 on: February 22, 2009, 06:24:50 am »

If your libcurl.dll is 126kb, delete it.

It should be 400+

That may not be enough either.  Salan had an issue where even though the file he was downloading from the ftp - the file would still be the old 126kb one that he deleted.

If this happens to you, you will need to DELETE the 126kb one, and overwrite it manually somehow - will try to find the link thats on this site...
Logged

Quote from: brn4meplz
Shit I'm pretty sure you could offer the guy a cup of coffee and he'd try to kill you with the mug if you forgot sugar.
Quote from: tank130
That's like offering Beer to fuck the fat chick. It will work for a while, but it's not gonna last. Not only that, but there is zero motivation for the Fat chick to loose weight.
Quote from: tank130
Why don't you collect up your love beads and potpourri and find something constructive to do.
nugnugx Offline
Donator
*
Posts: 4051



« Reply #5 on: February 22, 2009, 06:28:14 am »

just made a scan of dlls to be sure on jotti

libacml_mp libcurll libguide40 libifcoremd libmmd


Status:     
OK
MD5:    3a1432a6618a0931feffa670214299db
Packers detected:    
-
Scanner results
Scan taken on 22 Feb 2009 12:25:50 (GMT)
A-Squared    
Found nothing
AntiVir    
Found nothing
ArcaVir    
Found nothing
Avast    
Found nothing
AVG Antivirus    
Found nothing
BitDefender    
Found nothing
ClamAV    
Found nothing
CPsecure    
Found nothing
Dr.Web    
Found nothing
F-Prot Antivirus    
Found nothing
F-Secure Anti-Virus    
Found nothing
Ikarus    
Found nothing
Kaspersky Anti-Virus    
Found nothing
NOD32    
Found nothing
Norman Virus Control    
Found nothing
Panda Antivirus    
Found nothing
Sophos Antivirus    
Found nothing
VirusBuster    
Found nothing
VBA32    
Found nothing


all clean ,

you had your virus from somewhere else TYM
Logged
Baine Offline
Steven Spielberg
*
Posts: 3713


« Reply #6 on: February 22, 2009, 06:32:11 am »

But i noticed the same. After several days of always getting the virus alert on libcurll when starting the launcher and the game, i finally get the same alert that Tym got: SystemVolumeInformation/blabla .

I put it in quarantane and now all is ok for me.
Logged

nugnugx Offline
Donator
*
Posts: 4051



« Reply #7 on: February 22, 2009, 06:35:38 am »

libcurl, libeay32, libidn-11, and libssh2  on jotti



Status:     
OK
MD5:    b32be42f9da207293c8a5389e660c1b0
Packers detected:    
-
Scanner results
Scan taken on 22 Feb 2009 12:33:58 (GMT)
A-Squared    
Found nothing
AntiVir    
Found nothing
ArcaVir    
Found nothing
Avast    
Found nothing
AVG Antivirus    
Found nothing
BitDefender    
Found nothing
ClamAV    
Found nothing
CPsecure    
Found nothing
Dr.Web    
Found nothing
F-Prot Antivirus    
Found nothing
F-Secure Anti-Virus    
Found nothing
Ikarus    
Found nothing
Kaspersky Anti-Virus    
Found nothing
NOD32    
Found nothing
Norman Virus Control    
Found nothing
Panda Antivirus    
Found nothing
Sophos Antivirus    
Found nothing
VirusBuster    
Found nothing
VBA32    
Found nothing

all clean
Logged
EIRRMod Offline
Administrator / Lead Developer
*
Posts: 11009



« Reply #8 on: February 22, 2009, 06:48:55 am »

nugnugx - the *UPDATED* libcurl is fine.

The *OLD* one wasnt.

So, scanning the new dlls wont come up with anything =p
Logged
Waffen 17th.SS Offline
EIR Veteran
Posts: 88



« Reply #9 on: February 22, 2009, 11:23:15 pm »

Was it infected or not?
Logged

"War is the hardest on those with morals."
Tymathee Offline
Donator
*
Posts: 9741



« Reply #10 on: March 05, 2009, 06:37:21 pm »

I haven't gotten anything lately thank god. last time i got it i deleted the files and it took out my network drivers lol
Logged
Unshod Offline
EIR Regular
Posts: 1


« Reply #11 on: March 09, 2009, 11:48:14 pm »

Im getting the infected status on kaspersky
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.9 | SMF © 2006-2009, Simple Machines LLC
Valid XHTML 1.0! Valid CSS!
Page created in 0.095 seconds with 36 queries.