User comments on ISPs
  >> PlusNet plc


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
  Print Thread
Standard User k_e_v
(learned) Thu 17-May-07 13:27:57
Print Post

Which trojan?


[link to this post]
 
So, exactly which trojan(s) found their way onto the compromised webmail server? From perusing the multitude of posts here, it looks like it was possibly JS/downloader-AUD, although some other names have been mentioned.

As far as I can tell, at present PlusNet have not specifically named the trojan
Standard User rsharma
(knowledge is power) Thu 17-May-07 13:48:40
Print Post

Re: Which trojan?


[re: k_e_v] [link to this post]
 
Hi,

This is the list:
# Generic3.VXL
# TROJ_ALPIOK.A
# TSPY_BZUB.A
# EXPL_ANICMOO.GEN

Hope that helps.

-------------------------------------------------------
Plusnet: The Truth (Blog)
Formal Complaints Process
Testing Connection Speeds
Plusnet LLU and Your Rights
Standard User jelv
(fountain of knowledge) Thu 17-May-07 14:05:24
Print Post

Re: Which trojan?


[re: rsharma] [link to this post]
 
Why they haven't put that in a service status posting I can't imagine as they have posted it freely on the portal forums!

jelv

Plusnet ADSL PAYG Jan 2004 -
Plusnet Dialup Nov 2001 to Jan 2004
Previously Compuserve, BT & LineOne Dialup


Register (or login) on our website and you will not see this ad.

Standard User deleted
(deleted) Thu 17-May-07 14:08:21
Print Post

Re: Which trojan?


[re: jelv] [link to this post]
 
There is not even a sticky in their own forum.. I appreciate they may be busy but how much time does that take!
Standard User deleted
(deleted) Thu 17-May-07 14:08:38
Print Post

Re: Which trojan?


[re: jelv] [link to this post]
 
There is not even a sticky/product announcement in their own forum.. I appreciate they may be busy but how much time does that take!
Standard User h0tblack
(fountain of knowledge) Thu 17-May-07 14:24:54
Print Post

Re: Which trojan?


[re: jelv] [link to this post]
 
This information should have been in the service status last week when they first identified (or were informed) the problem.
Standard User stevebasford
(committed) Thu 17-May-07 14:31:17
Print Post

Re: Which trojan?


[re: rsharma] [link to this post]
 
Yikes, you can see the *possible* picture forming....

.ANI exploit on web mail server... plus unpatched windows machines:

EXPL_ANICMOO.GEN:

"This is the Trend Micro detection for the specially crafted cursor, animated cursor (.ANI), and icon formats that exploit a vulnerability in the way Windows handles these files. Successfully exploiting the said vulnerability can allow remote users to issue commands on the affected system."

TROJ_ALPIOK.A:

"This Trojan may be downloaded from remote site(s) by other malware. Once connected, it uses its integrated SMTP engine to act as a proxy server and send spam email messages from the mentioned servers."

TSPY_BZUB.A:

"As a BHO, it is able to monitor and collect the user names and passwords that an affected user keys in while browsing through the Internet. It then saves its gathered information, presumably for future retrieval by a remote malicious user. The said user can use the stolen information to access the affected user's account/s."

I hope your wrong about the trojans used


Powered by ZeN
  Print Thread

Jump to