Category: Malware/Malware Removal

  • Remove the HWCLOCK.EXE/W32.Hwbot-A Trojan

    I got the HWCLOCK.EXE when I was testing my new Internet connection.  I noticed it when my Internet DSL connection started feeling like a  56K dialup. 

    I removed it by going into Showing all files, going into Safe Mode and deleting the HWCLOCK.exe/W32.Hwbot-A Trojan.

    This is a trojan that can actually steal your passwords and other personal data.  On my system is was attacking other system.

    I've got more detail instructions on how to remove the HWCLOCK.exe at http://elamb.blogharbor.com/hacked/hwclock.htm

    If you found this post or others useful, feel free to donate to

    elamb – Home Computer Security.  No amount is too low (or high).

  • Removal of TROJAN-SPY.HTML.SMITFRAUD.C

    A lot of people seem to have the Smitfraud trojan and seem to looking all over the place to get a fix.  So I've consolidated the best resources that I've found on the Smithfraud this blog.  Enjoy.

  • Trojan_Agent.go

    New Trojan Agent Go

    Is a memory-resident trojan that comes through via downloads from malicious web sites.  It executes files from other websites.

    Remove Trojan_Agent.go:

    Open Task Manager:
    Use CTRL+ALT+DELETE or
    CTRL+SHIFT+ESC (on XP), then click the Processes tab.

    locate the process:
    EVTHTM.EXE

    Select the EVTHTM.EXE process, then press either the End Task or the End Process button, depending on the version of Windows on your system.

    1. To check if the malware process has been terminated, close Task Manager, and then open it again.
    2. Close Task Manager.

    If the process does not shutdown, Go to Safe Mode and shut it down.

     

    Recources:

    TrendMicro

    PCHELL

  • Report Phishing Instantly with gmail

    As I was hitting the “Show Original Message” link on my gmail account, I noticed that there is a “Report Phishing” link on my gmail account. 

    Very cool.. Anyway here is the latest phishing attempt I got hit with.

    This one is supposedly from ebay.  It is saying that some has added a seller to my account.  The only thing is that I don't have an ebay account attached to this email. 

    So view the source of an email from your gmail account click “Show Options” Then “Show Original Message.”  Most email software have this feature:

                                                                                                                                                                                                                                                             
    X-Gmail-Received: 330662dcee7d7f96e1a81e48ae9c33265fe033b5
    Delivered-To: elamb.security@gmail.com
    Received: by 10.36.71.17 with SMTP id t17cs20860nza;
            Wed, 11 May 2005 14:15:24 -0700 (PDT)
    Received: by 10.36.147.8 with SMTP id u8mr396722nzd;
            Wed, 11 May 2005 14:15:24 -0700 (PDT)
    Return-Path: <root@localhost.localdomain>
    Received: from localhost.localdomain (cam-in1.ztv.ad.jp [210.236.168.2])
            by mx.gmail.com with ESMTP id 15si749916nzn.2005.05.11.14.15.23;
            Wed, 11 May 2005 14:15:24 -0700 (PDT)
    Received-SPF: neutral (gmail.com: 210.236.168.2 is neither permitted nor denied by domain of root@localhost.localdomain)
    Received: from localhost.localdomain (localhost.localdomain [127.0.0.1])
     by localhost.localdomain (8.13.1/8.13.1) with ESMTP id j4BLAxdC009474
     for <elamb.security@gmail.com>; Thu, 12 May 2005 06:10:59 +0900
    Received: (from root@localhost)
     by localhost.localdomain (8.13.1/8.13.1/Submit) id j4BLAxA5009473
     for elamb.security@gmail.com; Thu, 12 May 2005 06:10:59 +0900
    Date: Thu, 12 May 2005 06:10:59 +0900
    To: elamb.security@gmail.com
    Subject: You have successfully added a new email address
    Message-ID: <1115845859.27531.qmail@paypal.com>
    From: “eBay” <accounts@eBay.com>
    Content-Type: text/html

    <DIV><DIV id=message><TT style=”FONT-SIZE: x-small;
    FONT-FAMILY:'couriernew',monospace”>You have added <A href=”
    http://210.255.65.234/secure/login.html
    target=_blank>phoneseller@yahoo.com </A>as a new email address for your
    eBay account.<BR><BR>If you did not authorize this change or if you need
    assistance with your account, please contact eBay customer service
    at:&nbsp;</TT> <P><TT style=”FONT-SIZE: x-small; FONT-FAMILY:
    'couriernew',monospace”><A
    href=”http://210.255.65.234/secure/login.html
    target=_blank>http://scgi.ebay.com/verify_id=ebay</A><BR><BR><BR>Thank
    you for using eBay!<BR>The PayPal Team<BR><BR><BR>Please do not reply to
    this e-mail. Mail sent to this address cannot be answered. For
    assistance, log in to your eBay account and choose the<BR>”Help” link in
    the header of any
    page.<BR><BR>—————————————————————-<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
    PROTECT YOUR PASSWORD<BR><BR>&nbsp;&nbsp; NEVER give your password to
    anyone and ONLY log in at <A
    href=”http://210.255.65.234/secure/login.html
    target=_blank>http://scgi.ebay.com/verify_id=ebay.</A> Protect yourself
    against fraudulent websites by opening a new web browser (e.g. Internet
    Explorer or Netscape) and typing in the eBay URL every time you log in
    to your account.<BR><BR><BR>
    —————————————————————&nbsp;&nbsp;&nbsp;&nbsp;
    <BR><BR><BR></B>eBay Email ID PP007</TT></P></DIV></DIV>

     

  • I got Hacked: phishing, hacking, social engineering, INFOSEC

    As a tribute to hacking, white hat and black hat (both the Dark Side and Light Side of the Force) I've put together a page called “I Got Hacked.” 

    In it I talk about how I was almost a victim of phishing while on ebay in December 04. I'll also talk more on how I wiped   “trojan-spy.html.smithfraud” from my friends system, since that seems to be popular. 

    I'm still working on getting some more content that is more fitting to home computer security made easy, so relax folx.  If you want some basics on how to get some security on your broadband dsl/cable device go my “Broadband Internet Security” page. 

    Seems the more aware of information security I become the more hacks I am able to reckognize and get rid of  and the more weakness' and risks I see in other peoples systems, software and social practices. 

    I like security and hacking because it can be used to strengthens existing structures be they legal or technological.  And the irony of it all is that all structures must eventually be destroyed for even galaxies die.

    There can not be birth without death, light without shadow or security without hacker exploits.

     

    phishingcomputer security

  • Removing TROJAN-SPY.HTML.SMITFRAUD Trojan

    My friend around the corner calls me about once a month to clean up his computer.  Usually, its just a simple matter of running
    Adaware or HiJackThis.  But this time was different. 

    I
    was helping my partner clean a trojan off of his Dell the other
    day.  And to my surprise Adaware did not remove it.  It also
    removed the ability to get to the Task Manager in order to view the
    processes and added a link to the desktop. 

    I found out it was called TROJANSPY.HTML.SMITFRAUD.  It took more effort than usual to remove, but I did manage to get rid of it with the help of a the Geekstogo! Malware removal forum.  I've found forums to be VERY helpful in getting help cleaing up and securing my home computer with ease.  Here is how I got rid of the Smithfraud.

     http://elamb.blogharbor.com/hacked/removesmitfraud.htm

    computer security Computer And Internet trojans home computer security made easy