Author Topic: Nasty one.  (Read 11453 times)

0 Members and 1 Guest are viewing this topic.

May 27, 2018, 11:31:40 PM

Syl

  • Newbie

  • Offline
  • *

  • 6
  • Reputation:
    0
  • Personal Text
    Goth rocker, citoyen du monde en resistance contre le fascisme et l'obscurantisme.
    • View Profile
Nasty one.
« on: May 27, 2018, 11:31:40 PM »
Greetings!

Just to report a virus. Dunno what happen, why my kaspersky didn't stop it from that page: hxxps://telecharger-jeux24.fr/horizon-zero-dawn-telecharger-version-complete-pc/ As it is stopped now. Downloaded it, dunno where, had to subscribe between some options in order to get the activation key. Classical. Closed it, but the damage was done. All my browsers were unusable, and the pc slowed. Tried to restore it two days back, but it didn't worked, though everything seems fine at present. Malwarebyte and roguekiller didn't find it.

By the way had to create a third account, as my session was timed out...

Cheers roguekillers!
« Last Edit: May 28, 2018, 02:48:41 PM by Curson »

Reply #1May 28, 2018, 02:52:42 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Nasty one.
« Reply #1 on: May 28, 2018, 02:52:42 PM »
Hi Syl,

This is a known bug with Simple Machines forum software.
What are your other accounts ? Could you please try logging in with another browser ?

Do you want to check your system for malware ?
By the way, for security reasons, I edited your message to desactivate the link.

Regards.

Reply #2May 29, 2018, 12:57:59 AM

Syl

  • Newbie

  • Offline
  • *

  • 6
  • Reputation:
    0
  • Personal Text
    Goth rocker, citoyen du monde en resistance contre le fascisme et l'obscurantisme.
    • View Profile
Re: Nasty one.
« Reply #2 on: May 29, 2018, 12:57:59 AM »
Hi,
A bug? blocking my browsers and slowing my pc? There was no forum eh, only a download page, the boasting of the best hacker in france, and then the subscriptions for the activation key. Silly me, but I risked it to test that game (there are too less demos with games, and you're quickly trapped into buying something that you'll regret).

My others accounts are Johyn and ajohin if I remember well. Every time that I try to log in, I cannot because of that timed out session, and that on chrome and firefox (eh, that works now). I have to register with my twitter account, but it works fine with explorer.

New check from roguekiller, with new version, and it found that threat: [4492] svchost.exe, C:\Windows\Systeme32\svchost.exe The 10 hours of kaspersky analysis didn't find it. A bit worrying as it didn't warned me when entering the site, nor protected me from that bug. I'm on my trial to buy it, and wondering. You never thought about making your own internet security software? Roguekiller as a warder, that would feel secure on the net eh. :)

Cheers!

« Last Edit: May 29, 2018, 02:03:28 AM by Syl »

Reply #3May 29, 2018, 01:43:50 AM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Nasty one.
« Reply #3 on: May 29, 2018, 01:43:50 AM »
Hi Syl,
Quote
A bug? blocking my browsers and slowing my pc? There was no forum eh, only a download page[...]
I was talking about our forum here, at forum.adlice.com.

Quote
ew check from roguekiller, with new version, and it found that threat: [4492] svchost.exe, C:\Windows\Systeme32\svchost.exe
Could you please attach RogueKiller JSON report with your next reply ?

Regards.

Reply #4May 29, 2018, 02:09:41 AM

Syl

  • Newbie

  • Offline
  • *

  • 6
  • Reputation:
    0
  • Personal Text
    Goth rocker, citoyen du monde en resistance contre le fascisme et l'obscurantisme.
    • View Profile
Re: Nasty one.
« Reply #4 on: May 29, 2018, 02:09:41 AM »
Here it is. The log in is working now.
« Last Edit: May 29, 2018, 02:15:50 AM by Syl »

Reply #5May 30, 2018, 02:48:53 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Nasty one.
« Reply #5 on: May 30, 2018, 02:48:53 PM »
Hi Syl,

Thanks for your feedback.
This is a false positive. We will fix this as soon as possible.

Regards.

Reply #6May 31, 2018, 12:12:16 AM

Syl

  • Newbie

  • Offline
  • *

  • 6
  • Reputation:
    0
  • Personal Text
    Goth rocker, citoyen du monde en resistance contre le fascisme et l'obscurantisme.
    • View Profile
Re: Nasty one.
« Reply #6 on: May 31, 2018, 12:12:16 AM »
Thxs, but then, we can never be sure that virus are really eliminated, without that json check?
« Last Edit: May 31, 2018, 12:22:15 AM by Syl »

Reply #7May 31, 2018, 03:05:28 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Nasty one.
« Reply #7 on: May 31, 2018, 03:05:28 PM »
Hi Syl,

You do.
Please check the scan reports, if an entry is flagged as "Removed" or "Replaced", that usually means the threat has been eliminated.

Regards.

Reply #8May 31, 2018, 06:08:26 PM

Syl

  • Newbie

  • Offline
  • *

  • 6
  • Reputation:
    0
  • Personal Text
    Goth rocker, citoyen du monde en resistance contre le fascisme et l'obscurantisme.
    • View Profile
Re: Nasty one.
« Reply #8 on: May 31, 2018, 06:08:26 PM »
Hi,
I see, and for my threat then?

Reply #9May 31, 2018, 10:25:26 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Nasty one.
« Reply #9 on: May 31, 2018, 10:25:26 PM »
Hi Syl,

Usually, the process is first killed (processes module), then deleted (files module). In your case, the svchost process is killed ("Tué(e) [TermThr]") but the file itself is left alone. The simplitec directory is part of Windows and cannot be removed ("ERROR [3]").

Regards.

Reply #10June 01, 2018, 12:45:06 PM

Syl

  • Newbie

  • Offline
  • *

  • 6
  • Reputation:
    0
  • Personal Text
    Goth rocker, citoyen du monde en resistance contre le fascisme et l'obscurantisme.
    • View Profile
Re: Nasty one.
« Reply #10 on: June 01, 2018, 12:45:06 PM »
Hi,

thxs for your time and help.

Regards.


Reply #11June 02, 2018, 03:06:16 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Nasty one.
« Reply #11 on: June 02, 2018, 03:06:16 PM »
Hi Syl,

You are welcome.

Regards.