Trojans found here...

Hi malware fighters,

Stay clear of this site, has trojans:
http://amada.abuse.ch/?search=ereei.info

010/07/29_19:34 ereei.info/v2/out/20.exe 91.188.60.175 - trojan Viktor Goryanov / GoryanovviktorATmail.com 6851 LV
http://www.threatexpert.com/files/20.exe.html
2010/07/29_19:34 ereei.info/v2/out/winupd.exe 91.188.60.175 - trojan Viktor Goryanov / GoryanovviktorATmail.com 6851 LV

The second trojan one is a beagle infection: Step 1: Use Windows File Search Tool to Find winupd.exe Path

  1. Go to Start > Search > All Files or Folders.
  2. In the “All or part of the the file name” section, type in “winupd.exe” file name
  3. To get better results, select “Look in: Local Hard Drives” or “Look in: My Computer” and then click “Search” button.
  4. When Windows finishes your search, hover over the “In Folder” of “winupd.exe”, highlight the file and copy/paste the path into the address bar. Save the file’s path on your clipboard because you’ll need the file path to delete winupd.exe in the following manual removal steps.

Step 2: Use Windows Task Manager to Remove winupd.exe Processes

  1. To open the Windows Task Manager, use the combination of CTRL+ALT+DEL or CTRL+SHIFT+ESC.
  2. Click on the “Image Name” button to search for “winupd.exe” process by name.
  3. Select the “winupd.exe” process and click on the “End Process” button to kill it.

Step 3: Detect and Delete Other winupd.exe Files

  1. To open the Windows Command Prompt, go to Start > Run > cmd and then press the “OK” button.
  2. Type in “dir /A name_of_the_folder” (for example, C:\Spyware-folder), which will display the folder’s content even the hidden files.
  3. To change directory, type in “cd name_of_the_folder”.
  4. Once you have the file you’re looking for type in del “name_of_the_file”.
  5. To delete a file in folder, type in “del name_of_the_file”.
  6. To delete the entire folder, type in “rmdir /S name_of_the_folder”.
  7. Select the “winupd.exe” process and click on the “End Process” button to kill it,

polonus

I THINK AM GONNA CLICK

Hi Left123,

You get Queue number 409, well it is now number 425, :smiley:
You are ill advised to go there…even as you shout about it, using capitals in messages is very bad Netiquette!

This is one of the links and how it is packed:
htxp://ereei.info/v2/out/20.exe packed by PEPACK

htxp://ereei.info/v2/out/20.exe packed by UPX

htxp://ereei.info/v2/out/20.exe packed by FLY-CODE

htxp://ereei.info/v2/out/20.exe - Ok

you could get infected through an executable file of 883200 bytes, 523023 hidden

http://scanner.novirusthanks.org/analysis/1908052b2f1980a9f1a57feaeb83f611/MjAuZXhl/
Here it says avast does not detect, but you may be lucky with a newer version of it,
it is Gen:Trojan.Heur.1qGfr9mrwPjiD aka W32/Heuristic-210!Eldorado aka Malware-Cryptor.Win32.General.6
Gen.Trojan!IK aka TR/Crypt.ULPM.Gen

polonus

i’m glad,i didnt click ;D