• Please remember to wrap not safe for work text/images in [NSFW][/NSFW] tags.
    Example: [NSFW][img]http://darklygaming.com/images/spinnysgapedass.jpg[/img][/NSFW]

Site compromised

Status
Not open for further replies.

Propaganda

TD Member
We had a site security breech yesterday. It was a hidden redirect to a cgi script for hacktool.rootkit. I suggest anyone who visited the site and got an error and couldn't see the site to disable system restore, restart in safe mode and run a full malware and virus scan.
 

Propaganda

TD Member
It would not have shown a redirect, it would have shown a php sql error and the site would not have been visible.
 

Propaganda

TD Member
I would suggest using MalwareBytes anti-malware. Here's what I did.

Disabled system restore

Restarted in safe mode

Ran a full malware scan and found the files and reg keys that were fucked

These are the infected files:

Code:
Files Infected:
C:\WINDOWS\system32\drivers\ati64si.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\i386si.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\netsik.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\ws2_32sik.sys (Trojan.Agent) -> Quarantined and deleted successfully.

Ran a full virus scan, it detected 4 downloader files in my temp dir

The downloader files all started with a BN and a temp extensions

BNXXXX.tmp

X being random

Additionally Norton found 2 other files in the drivers directory it labeled as the virus hacktool.rootkit

fips32cup.sys
systemntmi.sys

etc etc
 

Steve

TD Admin | Bacon
[quote1242239382=Hawk-Eye]
what if nothing happened and it just as usual?
[/quote1242239382]


You're fucked.
 

Propaganda

TD Member
[quote1242241511=LoW BuDgEt]
Malwarebytes is the shizznat, it's been keeping my PC clean for some time.
[/quote1242241511]

Malwarebytes works pretty good, in fact it works better as an antivirus than fucking norton does for some stuff. I ran both and each program picked up different things.

If you didn't have a problem with the site then you have no need to be concerned. That being said it doesn't hurt to check your system once in awhile.
 

47

TD Admin, Chicken Licker, Top Shelf Sleeper
DLing malwarebytes now.. thx guys.
i hope that my fat bank accts havent been emptied !!!

..panic attack ensues ...
 

DrUgZ

TD Admin
lucky for me my HD died on my gaming rig. Only went here on my ubuntu fileserver. glad to dodge that bullet. gj on locking that shit down prop. u da man!
 
Status
Not open for further replies.
Top