Remember, you MUST register to post on the Fiesta Fan forums. It's completely free to join. Just click HERE to become a member for free!


REGISTER NOW TO REMOVE ALL ADS ON THIS FORUM!

Closed Thread
 
Thread Tools Search this Thread Display Modes
Old 12-31-2008, 08:45 PM   #1
Mindspank
Flying Staff
 
Mindspank's Avatar
 

In-Game Name: Mindspank
Current Level: 103 Sharpshooter
Server: Bijou
Posts: 337
Mindspank will become famous soon enough
Send a message via Yahoo to Mindspank
Virus Alert: Trojan.Agent.AQTW

The reason I posted this is because Vista Machines, firewall or no, are HIGHLY vulnerable to this. It will affect alot of casual internet users "surfers"

Originally Posted by http://www.threatexpert.com

Installs a default debugger that is injected into the execution sequence of a target application. If a threat is installed as a default debugger, it will be run every time a target application is attempted to be launched - either to mimic it and hide its own presence (e.g. an open port or a running process), or simply to be activated as often as possible.

Registers a 32-bit in-process server DLL.

Registers a Browser Helper Object (Microsoft's Internet Explorer plugin module).

Contains characteristics of an identified security risk.


The following files were created in the system:
1 %System%qnkfqvs.dll
2 %System%wkgszvx.exe Trojan-Downloader.Win32.Agent.aukz [Kaspersky Lab] Troj/Vundeb-A [Sophos]


Memory Modifications

There was a new process created in the system:

wkgszvx.exe %System%wkgszvx.exe 16,384 bytes

The following Registry Keys were created:
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{B05D9B24-659E-3715-B858-2D1B1CCD131A}
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{B05D9B24-659E-3715-B858-2D1B1CCD131A}InprocServer32
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{8B70FAF 4-9E89-33B9-9CA7-6C4765B2CCF8}
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{8B70FAF 4-9E89-33B9-9CA7-6C4765B2CCF8}ProxyStubClsid
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{8B70FAF 4-9E89-33B9-9CA7-6C4765B2CCF8}ProxyStubClsid32
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{8B70FAF 4-9E89-33B9-9CA7-6C4765B2CCF8}TypeLib
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{1E5E364E-BAEE-37C2-BA28-2520937A874C}
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{1E5E364E-BAEE-37C2-BA28-2520937A874C}1.0
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{1E5E364E-BAEE-37C2-BA28-2520937A874C}1.0
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{1E5E364E-BAEE-37C2-BA28-2520937A874C}1.0win32
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{1E5E364E-BAEE-37C2-BA28-2520937A874C}1.0FLAGS
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{1E5E364E-BAEE-37C2-BA28-2520937A874C}1.0HELPDIR
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentV ersionExplorerBrowser Helper Objects
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentV ersionExplorerBrowser Helper Objects{B05D9B24-659E-3715-B858-2D1B1CCD131A}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsiexplore.exe

The newly created Registry Values are:
[HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{B05D9B24-659E-3715-B858-2D1B1CCD131A}InprocServer32]
(Default) = "[file and pathname of the sample #1]"
ThreadingModel = "Apartment"
[HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{B05D9B24-659E-3715-B858-2D1B1CCD131A}]
(Default) = "D"
[HKEY_LOCAL_MACHINESOFTWAREClassesInterface{8B70FAF 4-9E89-33B9-9CA7-6C4765B2CCF8}TypeLib]
(Default) = "{1E5E364E-BAEE-37C2-BA28-2520937A874C}"
Version = "1.0"
[HKEY_LOCAL_MACHINESOFTWAREClassesInterface{8B70FAF 4-9E89-33B9-9CA7-6C4765B2CCF8}ProxyStubClsid32]
(Default) = "{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINESOFTWAREClassesInterface{8B70FAF 4-9E89-33B9-9CA7-6C4765B2CCF8}ProxyStubClsid]
(Default) = "{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINESOFTWAREClassesInterface{8B70FAF 4-9E89-33B9-9CA7-6C4765B2CCF8}]
(Default) = "IDOMPeek"
[HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{1E5E364E-BAEE-37C2-BA28-2520937A874C}1.0win32]
(Default) = "[file and pathname of the sample #1]"
[HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{1E5E364E-BAEE-37C2-BA28-2520937A874C}1.0HELPDIR]
(Default) = "%System%"
[HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{1E5E364E-BAEE-37C2-BA28-2520937A874C}1.0FLAGS]
(Default) = "0"
[HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{1E5E364E-BAEE-37C2-BA28-2520937A874C}1.0]
(Default) = "LIB"
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentV ersionExplorerBrowser Helper Objects{B05D9B24-659E-3715-B858-2D1B1CCD131A}]
IExplore = 0x00000001
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsiexplore.exe]
Debugger = "%System%wkgszvx.exe"

so that wkgszvx.exe is injected into the execution sequence of iexplore.exe by being installed as its default debugger
Be warned, as of today there is a new drive by downloader (injects itself into your browser via websites).

I picked this one up today. Rather annoying. Opens like...Thirty iexplore.exe processes. I dont know what else it does though I do know that it completely axes internet explorer when you remove it. Its a simple fix though.

Open your registry editor and navigate to the key:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe

There will be an entry that says "Debugger". In that entry you will see the trojan file set as your debugger. Right click the key and select modify and delete the entire entry so its blank. That will restore your IE back to working order. If I find any other adverse affects, I will be sure to let you know.

Information gathered from:

http://www.threatexpert.com/report.a...435103713cb32f
__________________


Fiesta - Mindspank - Bijou - 103 Sharpshooter
Aion - Mindspank - Israphel - 65 Ranger

Last edited by Mindspank; 12-31-2008 at 08:54 PM.. Reason: I accidentally posted it halfway through creating it.
Mindspank is offline  
Old 12-31-2008, 09:39 PM   #2
Blaaaaaaaah
WONDERCLERIC

 
Blaaaaaaaah's Avatar
 
Tournaments Won: 15

In-Game Name: Bla~ahs
Current Level: 7x
Server: Teva
Posts: 10,496
Blaaaaaaaah has disabled reputation
lmao@your edit.

Lucky I don't have Vista o_o
__________________
=)
Blaaaaaaaah is offline  
Old 12-31-2008, 09:42 PM   #3
Ivramire
Where shall we wander?

 
Ivramire's Avatar
 

Posts: 3,666
Ivramire has much to be proud ofIvramire has much to be proud ofIvramire has much to be proud ofIvramire has much to be proud ofIvramire has much to be proud ofIvramire has much to be proud ofIvramire has much to be proud ofIvramire has much to be proud ofIvramire has much to be proud ofIvramire has much to be proud of
noobish question:-


I assume it doesn't affect Firefox?
Ivramire is offline  
Old 12-31-2008, 09:57 PM   #4
viasta
RAGING OVERHEATTT!!!!!!!!
 
viasta's Avatar
 
Tournaments Won: 4

In-Game Name: viaAoE
Current Level: Level of viasta
Server: Epith
Posts: 1,612
viasta is a splendid one to beholdviasta is a splendid one to beholdviasta is a splendid one to beholdviasta is a splendid one to beholdviasta is a splendid one to beholdviasta is a splendid one to beholdviasta is a splendid one to behold
Send a message via MSN to viasta
this happens once to me only when I opened AIM, then it stopped happening and I don't use IE. dumb AIM..opens IE for "AIM Homepage". It just happens once you open IE I think
__________________

Thanks Loveless!
viasta is offline  
Old 12-31-2008, 10:41 PM   #5
JokerX
Little Hob
 
JokerX's Avatar
 

In-Game Name: Pajamas, JesterX,
Current Level: Im da highest lvl ever! =D
Server: Epith
Posts: 73
JokerX is on a distinguished road
Yes...Quite.....Luck for those who dont have this
__________________
TOO KOOL FOR U
JokerX is offline  
Old 12-31-2008, 11:53 PM   #6
Mindspank
Flying Staff
 
Mindspank's Avatar
 

In-Game Name: Mindspank
Current Level: 103 Sharpshooter
Server: Bijou
Posts: 337
Mindspank will become famous soon enough
Send a message via Yahoo to Mindspank
Im not too sure if it affects XP or not. All I know is that I have both OS's (I dualboot) and was on windows vista at the time of infection, WITH a 3rd party firewall enabled AND spybot S&D immunization, though I dont think spybot would stop it.
__________________


Fiesta - Mindspank - Bijou - 103 Sharpshooter
Aion - Mindspank - Israphel - 65 Ranger
Mindspank is offline  
Old 01-01-2009, 12:11 AM   #7
Shader
Little Hob
 
Shader's Avatar
 

In-Game Name: Kallien, Avaia, Istral, Elennecia, Nuada, Nuala
Current Level: (Following order of above)38, 30, 28, 22, 8, 7
Server: Bijou, Apoline
Posts: 70
Shader is on a distinguished road
Send a message via AIM to Shader
I heard about this a couple of weeks or so ago. I don't use IE anymore because of problems it had for me months ago. Firefox just works better in my opinion. I E wouldn't load all websites I visited. T.T

I still need better Firewalls. *sniff* I'm worried for my computer.
__________________


(Made by moi using Paint Shop Pro 7.)
Shader is offline  
Old 01-01-2009, 08:40 AM   #8
Ralath
Bbang ggoo ddong ggoo

 
Ralath's Avatar
 
Tournaments Won: 36

Posts: 3,677
Ralath is a splendid one to beholdRalath is a splendid one to beholdRalath is a splendid one to beholdRalath is a splendid one to beholdRalath is a splendid one to beholdRalath is a splendid one to beholdRalath is a splendid one to behold
Send a message via MSN to Ralath
I think I used to have something similar to this on my Windows XP.

It would open Internet Explorer non-stop for like... 5 minutes and I had to keep closing windows... =.=
__________________

Ralath is offline  
Old 01-01-2009, 03:27 PM   #9
Yosei
Corgi Addict


 
Yosei's Avatar
 

In-Game Name: Cubyrop(WoW)
Current Level: 85
Server: Maelstrom
Posts: 5,902
Yosei has much to be proud ofYosei has much to be proud ofYosei has much to be proud ofYosei has much to be proud ofYosei has much to be proud ofYosei has much to be proud ofYosei has much to be proud ofYosei has much to be proud ofYosei has much to be proud of
Send a message via AIM to Yosei Send a message via Yahoo to Yosei
Good thing I'm not much of a browser o: I only go to a few websites.
Yosei is offline  
Old 01-01-2009, 06:32 PM   #10
iDerrick
Symphony

 
iDerrick's Avatar
 
Tournaments Won: 2

Posts: 970
iDerrick has a brilliant futureiDerrick has a brilliant futureiDerrick has a brilliant futureiDerrick has a brilliant futureiDerrick has a brilliant futureiDerrick has a brilliant futureiDerrick has a brilliant futureiDerrick has a brilliant futureiDerrick has a brilliant futureiDerrick has a brilliant futureiDerrick has a brilliant future
So this won't affect firefox right?
iDerrick is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 12:35 AM.
Design by Vjacheslav Trushkin, color scheme by ColorizeIt!.
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.