Posted in Rubbish TalkDecember 30, 2006 7:46 pm
you heard it right.
via Google.com
http://www.google.com/interstitial?url=http://bpa.ums.edu.my/akademik.html
http://www.google.com/interstitial?url=http://bpa.ums.edu.my/exam2/index.html
whether this trojan was intentional (planted by the site admin for tracking reason or whatsoever) or act of hacker(s) or script kiddies or Software Engineering student practicing for the Borneo Hacking Competition. we just don’t know. Email was sent to the site admin, if he ever checked it, we will be ok. I believe others has sent email to the admin, since someone did report it to google.com
Here is what the Trojan behaviour I have seen.
It will save itself in your temporary internet files folder. Remain there and download something from the net in the background when you are online. Then it will install itself to the Windows folder, I believe in System32 folder in a folder name Update. The damage is unknown since I deleted it right after I detected it (I restore my computer using Norton Ghost). Be advise that this trojan also remain in your System Restore folder. Better disable your system restore.
So far Avast antivirus can detect it but can’t delete it because the file was somehow write protected.
bad thing. Even if you go directly to the folder to delete it, it will reappear again. Interesting ehh?
Hope the AV people will get a solution.
for now, stay away from http://bpa.ums.edu.my/akademik.html
If you are adventurous enough and have nothing to loose, you can check the link out and tell me what really happen when you have that trojan.
cheers..