twisted humor.com infect you with TROJANS!!
#1
Posted 24 October 2001 - 07:49 PM
id recommend to anyone who has visited and downloaded from twistedhumor.com, go to c:WINDOWS and look for a file called wnad.exe and wnad.dat
there may be other components too (obviously its in the registry too)
this is a [b:2242809db2]TROJAN[/b:2242809db2] luckily i blocked it access to the net.. but on a few occasions my firewalls been down, it would explain why my ctrl alt del window is messed up and a few other things.. now i have to format again as theres enough damage done to warrant it.
this is the same trojan that chris has had and how his pc was broken into before, norton will not repair the file, and cant wipe it, you might be able to shut it off in ctrl alt del > services menu or boot in safe mode and kill it. norton hasnt found it on my pc in any scans... it wasnt till chris asked me about it and i opened the WINDOWS directory that norton went off when i highlighted the file.. until that piint it didnt make a peep, got updates today and we both found this file.. anyone else??
[b:2242809db2]BE WARNED[/b:2242809db2]
we are not responsible if you have problems with removing this or of any effects caused by attampting DO SO AT YOUR OWN RISK!!
#2
Posted 24 October 2001 - 07:56 PM
-Chris
#3
Posted 24 October 2001 - 08:07 PM
Ben
#4
Posted 24 October 2001 - 08:08 PM
#5
Posted 24 October 2001 - 08:31 PM
Ben
#6
Posted 24 October 2001 - 08:36 PM
#7
Posted 24 October 2001 - 08:41 PM
Ben
#8 Guest_LouCypher_*
Posted 24 October 2001 - 09:22 PM
I update NAV regularly and ran The Cleaner after XPerties recent problems and nothing was found by either program.
I think you guys are just sharing files with the [b:e3d1f46de1]wrong[/b:e3d1f46de1] people. Might also explain the [cheaters] file some of you are finding on your system. If you're getting a virus or trojan than modified ISO images or something.
I DON'T think this is a devils0wn issue, unless somebody hacked your copy before you downloaded it.
Size of my ISO: 512,342,016 (yours [b:e3d1f46de1]should[/b:e3d1f46de1] be the same?)
Size on disk: 512,344,064 (maybe different?)
#9
Posted 24 October 2001 - 09:45 PM
Ben
#10 Guest_LouCypher_*
Posted 24 October 2001 - 09:53 PM
Any dumb script kiddie can scan you system for usernames, open shares, Remote Desktop service, etc. If you don't set a password and leave these users in Administrator group then they can easily copy whatever they want to your system.
By default all the harddrives have a secret share of C$, D$, etc.. in addition to IPC$. I've disabled mine (registry edit in my Tweaks thread sticky post).
If you don't believe me:
Right click "My Computer" -> Manage -> Shared Folders -> Shares.
#11
Posted 24 October 2001 - 09:59 PM
Did the people who have this visit ht*p://www.twistedhumor.com and check out the 'Yo Mama Osama' game that's been posted there, and linked to by some major sites? I did, and I think thats where this came from. Here's why:
I've gone through the binary, and after only looking at it for about 5 minutes, I've discovered some things.
1) It appears to *NOT* be a trojan, despite what norton says, but simple a program that launches popups, at an interval depending on how much your transfering. At least thats what it APPEARS to do, Im not an expert that works at SARC, but I am a programmer
2) It appears to popup an ad from: ht*p://www.twistedhumor.com/cgi-bin/redneck/redneck_show_popup.cgi?test_popup=1&company_name=SwapNutSoftware which appears to simply give a URL for it to connect to.
3) This has the ability to update its software, How I do not know yet
4) Other URL's that are hard coded into this binary:
ht*p://www.rankyou.com/wnad/
ht*p://www.srv2cpt.com/ad/
5) The name alone, wnAD, further makes me feel this is simply a VERY god awful and intrusive way of advertising.
I visited that site, and killed Osama, and now examining it, I truly believe that is where this originated.
Ah, I think it checks for updates from ht*p://www.rankyou.com/wnad/wnad.php and if theres a newer version, it uses ht*p://www.rankyou.com/wnad/wnad-update.exe, there is a wnad.exe there as well, but no wnad-update yet.
Someone want to compare these results? Like I said, I dont work for SARC
I will post more when I find out more....
--
XxMaNsOnX
[color=red:5660f4cede]Do not post active links on the forums....Edited by Mod[/color:5660f4cede]
#12
Posted 24 October 2001 - 10:17 PM
I have been to this website and Im preety sure that FthrJACK was to. Im postitive that my girlfriends father also went to this site (He also found it on his system)....So Now I feel that something should be done about this. This if in fact turns out to be true is a invasion of our privacy.
One major question why would Nortan pick up on it but your statement leans towrds it not being a virus. You education expressed here is greatly appreciated...Ill be waiting to see what else you come up with.
-Chris
PS. I wounder if it some sort of terriost attack?! :mad:
#13
Posted 24 October 2001 - 10:56 PM
Here's a simple way to just get rid of it:
First, Turn off Norton, as it wont let you run it. then, run wnad.exe /quit
Then you'll be allowed to delete it and what not, then remove it from running in the registry, its stored at:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun and just delete the WNAD key.
That's all it does to the registry, again, that I know of.
Other options that wnad will take (for those interested):
/log=on
/log=off
/use
/install
/quit
It also will not show any popups for 72 hours after it's been installed, I guess to prevent you from realizing how you got it.
I really don't think it's a trojan in any way. So I just want to make sure, If you have it, did you check out twistedhumor? If not, then I dont know.
Just remember that it autoupdates itself, so this could all change.
If it is in fact originating from that game, (which I felt cautious trying anyway, I dislike ActiveX, and now I remember why
[size=24:6e3674edd5][b:6e3674edd5]AHA! PROOF![/b:6e3674edd5][/size:6e3674edd5]
Okay. Definate proof now. I just tried to reinstall the game to see if this was the cause. Sure enough, before installing it, I read the EULA. This is what it says:
The Osama Software includes added software and technology which allows Lions Pride Enterprises, Inc. to provide advertising content.
And:
TWISTEDHUMOR.COM DOES NOT WARRANT THAT THE OSAMA SOFTWARE, THE TWISTEDHUMOR.COM SERVERS, OR E-MAIL SENT FROM TWISTEDHUMOR.COM ARE FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS.
So there we have it, Then after accepting the EULA, sure enough, Norton popped up with it's warning. Now, the EULA says they aren't respnsible, but I'm sure the law says another, class action anybody? I'll leave that to the lawyers :cool:
--
XxMaNsOnX
#14
Posted 25 October 2001 - 02:23 PM
-Chris
#15
Posted 25 October 2001 - 02:29 PM
did you check wnad.dat? i didnt get round to hex editing it so i havent found exactly what it does... but you obviously beat me to it, nice work mate, and about time you posted LOL
welcome to the forums :beer
#16
Posted 25 October 2001 - 07:18 PM
#17
Posted 25 October 2001 - 08:16 PM
TwistedHumor.com (TWISTEDHUMOR-DOM)
7770 regents Road Suite 113-413
San Diego, CA 92122
US
Domain Name: TWISTEDHUMOR.COM
Administrative Contact:
Coats, M (MCP429) ads@TWISTEDHUMOR.COM
Lions Pride Enterprises, Inc.
7770 Regents Rd #113-413
San Diego , CA 92122
858-271-8650 (FAX) 858-566-3911
Technical Contact:
Kukuruzovic, Vladimir (KV338-ORG) noc@TWISTEDHUMOR.COM
Twistedhumor
Lions Pride Enterprises, Inc.
7770 Regents Rd #113-413
San Diego, CA 92122
USA
858-271-8650
Fax- 858-566-3911
Billing Contact:
Coats, M (MC20525) questions@TWISTEDHUMOR.COM
Lions Pride Enterpises, Inc.
7770 regents Road Suite 113-413
San Diego, CA 92122
619-458-3695 (FAX) 619-458-3695
Record last updated on 03-Jul-2001.
Record expires on 30-Jun-2003.
Record created on 30-Jun-1999.
Database last updated on 25-Oct-2001 11:27:00 EDT.
Domain servers in listed order:
SERVER8.TWISTEDHUMOR.COM 64.37.103.98
SERVER9.TWISTEDHUMOR.COM 64.37.114.66
ISP is ht*p://www.cybercon.com
#18
Posted 25 October 2001 - 09:48 PM
-Chris:D
#19
Posted 26 October 2001 - 09:25 PM
www.srv2cpt.com
and twisted humor all have the same isp.
and are in the same city. hmmm...
#20
Posted 28 October 2001 - 08:20 PM
[i:121b6c0689]
Dear sir
Im writting to you after being infected with a Trojan horse program and key logging programs contained in a file i downloaded from twistedhumor.com hosted on your web servers.
I find it disgusting that these people are taking advantage of peoples feelings after the attrocaties on September the 11th, in order to infect people with a stealth Trojan and then extract personal information of all kinds from them and submit them to endless pop up advertisements.
As the creators of this site and the Trojan horse file will not stop their illegal activities i would like to formally request that this site be closed down imediatley ( subject to your legal obligation) in order to prevent the spread of this virus and to stop the perpetrators collecting anymore personal information on any of its victims.
The site is being monitored and a group of victims is currently spreading the word of this site and the security risk envolved. We feel let down by the fact that to date the site is still operational and that no action seems to have been taken by cybercon.com in order to stop this activity, we feel that if Microsoft where to contact you over a warez site or site offering serial keys etc you would not fail in your legal obligation to shut the site down imediately.
Please can you ensure that action is taken.[/i:121b6c0689]



Help
Back to top










