occamsrezr All American 6985 Posts user info edit post |
Hey all,
I thought I'd let you guys know that I picked up a combination password stealer/cracker/trojan over the weekend. It didn't get picked up by Ad-aware, hijackthis or NOD32. That being said, check your compies for the following files.
Running on the computer could be files
urlmon.exe manager.exe brute.exe brutesav.exe
The only way I picked up on it was my computer was dragging ass on both cores of the proc, checked the window and saw that a program called brute.exe was running.
The trojan also fucked up my hosts file so that it would send passwords to a certain IP address ( 76.23.147.113 .) I managed to delete all of the files and .dll's associated and fixed my hosts file, plus I changed all my passwords, but you guys should be on the lookout for this until it gets noticed by the antivirus companies.
http://www.spywaredb.com/remove-brute-executables-1-0/
http://spywarefiles.prevx.com/RRFCGH3749357/URLMON.EXE.html 7/26/2007 7:59:32 PM |