Jump to content

Malwarebytes

malware-doc.com


11 replies to this topic

#1
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
Got notified of this one via e-mail by an hpHosts user (would've posted it sooner but was working on an hpObserver update)

Host: malware-doc.com
IP: 193.138.172.5 (AS44245)

Family:
http://hosts-file.ne....5&view=matches
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#2
Azlan

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 111 posts
  • Gender:Male
  • Location:Malaysia
Please add this to the definitions..!!! Fast!! My clean virtual machine is now infected...!!
Posted Image Posted Image

#3
Jaxryley

    Forum Deity

  • Malware Hunters
  • PipPipPipPipPipPip
  • 6,718 posts
  • Gender:Male
  • Location:West Aussie
  • Interests:Gardening and computers.

View PostAzlan, on Feb 18 2009, 09:38 PM, said:

Please add this to the definitions..!!! Fast!! My clean virtual machine is now infected...!!
Turn off and delete changes?

Surely you have Undo Disks - Enabled?

#4
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,155 posts
  • Gender:Male
  • Location:127.0.0.1

View PostAzlan, on Feb 18 2009, 01:38 PM, said:

Please add this to the definitions..!!! Fast!! My clean virtual machine is now infected...!!

Please update and run MBAM quick scan :)

DB 1775 included defs to take down this rogue install.

http://www.malwarebytes.org/malwarenet.php...gue.MalwareDoc+
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5
Azlan

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 111 posts
  • Gender:Male
  • Location:Malaysia

View PostFatdcuk, on Feb 18 2009, 11:38 PM, said:

Please update and run MBAM quick scan :)

DB 1775 included defs to take down this rogue install.

http://www.malwarebytes.org/malwarenet.php...gue.MalwareDoc+

K thanks. I just deleted it with Hijackthis
Posted Image Posted Image

#6
Serious

    Advanced Member

  • Malware Hunters
  • PipPipPip
  • 188 posts
  • Gender:Male
People using Kaspersky should be protected from this threat as of Yesterday

Kaspersky Threat Name: not-a-virus:FraudTool.Win32.MalwareDoctor.a
Who reported this? Me :)

#7
vasketo

    New Member

  • Members
  • Pip
  • 4 posts

View PostSerious, on Feb 19 2009, 12:01 PM, said:

People using Kaspersky should be protected from this threat as of Yesterday

Kaspersky Threat Name: not-a-virus:FraudTool.Win32.MalwareDoctor.a
Who reported this? Me :)

Congratulations!! You won a sweet :)

#8
Raid

    Malware Researcher

  • Experts
  • PipPipPipPipPipPip
  • 1,549 posts
  • Gender:Male
  • Location:United States
Our defs automatically kill it, but just to make sure, I've added the latest rendition of it's executables...

#9
Michael Townsend

    New Member

  • Members
  • Pip
  • 2 posts
What if you are caught inbetween? I did not install this malware but my IE pages are still stuck to IP BLOCKED BY XYZ (Yahoo, Google, MSN) due to Malware install this to fix.... , trying to get me to install MALWARE DOC, I have run Malwarebytes with db 1814. But I am still being reditrected. Malware Bytes (Quick and Full scans) and SPYBOT both show clean bills of health.

#10
Guest_remixed_*

  • Guests
Try...
http://majorgeeks.co..._Fix_d4372.html

#11
Michael Townsend

    New Member

  • Members
  • Pip
  • 2 posts
already tried WINSOCKFIX no dice.

#12
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
Please see;

http://www.malwareby...?showtopic=9573
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us