Login:Mot de passe:

Vous inscrire | Mot de passe oublié ?

Forums-> Suggestions / Bugs-> Pub InternetGameBox - Attention Spyware:
Auteur Message
ClementXVII

Depuis 511 Jours

29/03/2008 à 20:09:05 Pub InternetGameBox - Attention Spyware

Hello,

Depuis quelques jours, il y a une pub pour InternetGameBox sur Gamersyde.

Cette pub, avec son titre aguicheur, cache en réalité un spyware/trojan, qui installe un rootkit sur la machine infectée. Comme cette pub est fournie à travers Google Ads, je ne sais pas ce qu'il est possible de faire, sinon recommander une extrême prudence quant à ces pubs.

duplicated one of my Virtual Server images and ran the Internet Gamebox installation on it. I had Filemon running on the background logging newly created files and modifications. The installation created a file named 'noffmmtudd.exe' in the windows\system32 directory and executed it. This file didn't show up in Explorer with 'show hidden/system files' turned on. A registry search didn't find a mention of this file either.

Then I turned off the virtual machine and added the disk as a second (non-booting) disk to a clean virtual machine. The file named 'noffmmtudd.exe' was suddenly visible with Explorer in the windows\system32 directory, along with some data files also starting with 'noffmmtudd'.

After rebooting the infected virtual machine the mentioned files were still not visible in Explorer or the registry. I ran the uninstaller which said it had removed all components of Internet Gamebox.
Loading the disk in the clean virtual machine again showed that the files were still there. I then renamed the exe file.

After rebooting the infected virtual machine the renamed exe and data files finally showed up in Explorer. A registry search came up with 'noffmmtudd.exe' being called on startup.

I hope this proves that Internet Gamebox does indeed install a rootkit. I don't know how to check what the rootkit actually does but it can't be good when it tries to hide itself.
Rapport sur GameDev.net

BlimBlim

Tyrannosaurus BlimBlim - Tyrannosaurus
Depuis 1921 Jours

30/03/2008 à 00:49:11

Merci de l'info, j'ai banni le domaine sur adsense.

---
BlimBlim, Tyran.

spyware9

spyware9
Depuis 1346 Jours

30/03/2008 à 16:31:26

J'ai eu peur, j'ai cru qu'on en voulait à la peau de mon win98 dernier cri.

---
Bavure : Marion Cotillard tente de réparer sa gaffe. "C'est pas
les américains qui ont détruit les tours jumelles, c'est King Kong."

Forums-> Suggestions / Bugs-> Pub InternetGameBox - Attention Spyware:
Il faut etre identifie pour participer au forum !