Jump to content

Malwarebytes

Hijack.ControlPanel Style


6 replies to this topic

#1
frankmcatee

    New Member

  • Members
  • Pip
  • 13 posts
I received this error and another that stated Heuristics.reserved.Word.Expoloit.
Malware bytes scanned and deleted them... but the user that I support and I would like to know what this malware "does" to your PC.
What is it's intended purpose? Besides frustrating the user?

#2
GT500

    Mostly Cantankerous

  • Trusted Advisors
  • PipPipPipPipPipPip
  • 6,016 posts
  • Gender:Male
  • Location:Fortville, IN
It a heuristic hit on something that was using a known exploit. There is nothing there that specifically says what malware it was, so we can't really say what the does.

Quote

For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...

#3
frankmcatee

    New Member

  • Members
  • Pip
  • 13 posts

View PostGT500, on Apr 28 2009, 02:42 PM, said:

It a heuristic hit on something that was using a known exploit. There is nothing there that specifically says what malware it was, so we can't really say what the does.



If he gets the virus again and I am able to get a Hijack this log... would that tell you?

#4
GT500

    Mostly Cantankerous

  • Trusted Advisors
  • PipPipPipPipPipPip
  • 6,016 posts
  • Gender:Male
  • Location:Fortville, IN

frankmcatee said:

If he gets the virus again and I am able to get a Hijack this log... would that tell you?

We'd have to have a copy of the malicious file to be able to say what it does, but since I'm not part of the research team I can't really guarantee that I would be able to tell you what it did.

You can always upload it to VirusTotal, and see if other security software detects it. Sometimes that can give you a clue as to what type of malware it is.

Quote

For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...

#5
frankmcatee

    New Member

  • Members
  • Pip
  • 13 posts
It would seem that the virus attaches itself somehow to the installation of Windows Update agent as when Malwarebytes cleans the malware Windows updates stop working. I then have to go through and do the following to get updates to work again:
Open a Command Prompt and forced a re-install of the Windows Update Agent with the following command:
C:\WUAGENT\WindowsUpdateAgent30-x86.exe /wuforce
Attempt to download and install the Windows Updates again.

Malwarebytes may need/want to look at their clean up procedure regarding this as it actually opens up a huge vulnerabiltiy with Windows Updates not being installed...

Can you send this issue to your team please?

#6
frankmcatee

    New Member

  • Members
  • Pip
  • 13 posts
I will send the Hijack this log. Not sure what else I can send you.

#7
GT500

    Mostly Cantankerous

  • Trusted Advisors
  • PipPipPipPipPipPip
  • 6,016 posts
  • Gender:Male
  • Location:Fortville, IN
Post a scan log in developers mode. Follow the instructions at the link below to get it:
http://www.malwareby...?showtopic=3228

Quote

For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us