|  | | |
29 Jun 2011
|
#1 | | Windows 7x64 Home Premium SP1 x 2 Australia |
Stolen.data Malwarebytes has just detected and quarantined "stolen.data" on my computer. A Trojan I believe.
Location: c:\programdata\carbon
NIS2011 with current update missed it.
Has anyone experience with this or advice?
Last edited by mjf; 29 Jun 2011 at 11:41 PM..
Reason: Add
| My System Specs |
| System Manufacturer/Model Number Own build (+ Recased Acer Aspire x1800) OS Windows 7x64 Home Premium SP1 x 2 CPU Intel i7 2600k Motherboard ASUS P8Z68 Deluxe Memory G.Skill Ripjaws (DDR3-1600) 2x4GB Graphics Card Nvidia GeForce GTS 450; Intel HD Graphics 3000(GT2+) Monitor(s) Displays Dell Ultrasharp IPS panel U2311H, Samsung SyncMaster P2350 Screen Resolution 1920x1080 Keyboard Logitech MK520 (wireless) Mouse Logitech MK520 PSU Seasonic M12II 520W Case Lian Li Lancool PC-K60 Cooling Case: 1x120mm, 3x140mm CPU: Hyper 212+ Hard Drives Crucial M4 128GB (000F), Seagates 1TB Barracuda ST31000528AS + Internet Speed 6-7 Mbps Antivirus Norton NIS, Malwarebytes on 2 (MSE on 3rd PC) Browser FireFox Other Info Audio: Logitech Z523 2.1 |
29 Jun 2011
|
#2 | | |
Hmm I haven't suggested this in awhile SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!
Apparently it only really fell out of favor because it didn't have win 7 support until some time after it's release. It does now though.
As for this specific malware 
Quote: Originally Posted by nosirrah" (malwarebytes forum administrator) Without a file path there is no way to give much info .
Stolen.Data are static paths to files where known spyware stores stolen credentials . I think that sums it up best. | My System Specs | | System Manufacturer/Model Number Insane hobo technologies. ;-) OS Windows 7 x64 CPU Intel i7 2600k Motherboard Asrock z68 extreme 4 gen 3 Memory G.skill Ripjaw 16gigs @ 1866 Graphics Card Nvidia gtx580 (evga) Sound Card Integrated HD audio + hdmi Monitor(s) Displays 24" ASUS widescreen + 42" insignia Screen Resolution 1080p (1920x1080) Keyboard Microsoft wireless 3000 (v2) Mouse MS - wireless 5000 (bluetrack) PSU 1 kilowatt SLI/Crossfire rated Silverstone modular Case NZXT Phantom + additional 220 fan Cooling Zalmann Hard Drives 128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA) Internet Speed depends on if you ask me or my provider. Other Info The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism. |
29 Jun 2011
|
#3 | | Windows 7 Ultimate SP1 (x64) South Australia |
Hi,
Did a bit of research and found that it is considered by some to be a variant of Trojan-Spy.Win32.Zbot.
See this link : Endpoint protected machine compromised CASE# 411-396-061 | Symantec Connect Community
Perhaps you could contact Jacee and/or Corinne for more info?
Regards,
Golden | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Golden Mk. I.3 OS Windows 7 Ultimate SP1 (x64) CPU Intel i7 860 @ 2.80 GHz Motherboard Gigabyte P55A-UD3R Rev.1. Award BIOS F13 Memory 16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24) Graphics Card EVGA NVidia GTX 560 1024MB Sound Card Realtek Integrated Monitor(s) Displays Dual Samsung SyncMaster 2494HS Screen Resolution 1920*1080 and 1920*1080 Keyboard Logitech G110 Mouse Logitech MX518 PSU Thermaltake ToughPower QFan 750W Case Thermaltake Element S VK60001W2Z Cooling Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans Hard Drives 1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
3*Samsung F1 SpinPoint 1TB in RAID5;
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0 Internet Speed Not fast enough!!! Antivirus MSE and Malwarebytes Pro Browser Chrome Version 25 Other Info Laptop: ASUS X54C, Intel Core i3-2330M @ 2.0Ghz, 4GB RAM, Intel HD on-board graphics, Windows 7 Professional SP1 (x64), LinuxMint 14 (x64), PepperMint 3 (x86) |
30 Jun 2011
|
#4 | | Windows 7 & Windows Vista Ultimate Upstate NY |
Hi, mjf.
Based on the information in the link provided by Golden, if this is indeed a password-stealing trojan, I strongly recommend that you go to a clean computer and change your passwords. Keep a close eye on any banking and credit card accounts.
It would be a good idea to do an online scan by another vendor. Please go here to run an on-line scan from ESET. - Note: It is easiest if you use Internet explorer for this scan. (If you use an alternate browser, it will be necessary to download the ESET Smart Installer)
- Turn off the real time scanner of any existing antivirus program while performing the online scan
- Tick the box next to YES, I accept the Terms of Use.
- Click Start
- When asked, allow the ActiveX control to install
- Click Start
- Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
- Click Scan
- Wait for the scan to finish -- it may take quite a while.
| My System Specs | | OS Windows 7 & Windows Vista Ultimate |
30 Jun 2011
|
#5 | | |
Good luck with that mjf.
I have ESET online scanner on all my pe3 media. (smart installer is only a couple of mb )
Never needed to use it myself - but friends have used it with great success. | My System Specs | | OS Vista x64 / 7 X64 CPU E8400 Motherboard ASRock 1333 GLAN R2.0 Memory 2x1 gb 800mhz Graphics Card 9500gt 1gb Case Coolermaster Cooling Winpower 500w Hard Drives Maxtor 160gb-2mb cache |
30 Jun 2011
|
#6 | | Windows 7x64 Home Premium SP1 x 2 Australia |
Thanks for the replies (I need to learn more!!)
I ran the ESET online scan after Quarantining the malware with Malwarebytes. After 4+ hours it detected no threats. Fortunately I don't store or use transaction passwords or account numbers on my computer.
I've changed other passwords. Is there anything else to be done?
---------------------------------------
Interestingly, it appears only the most recent Malwarebytes update detected this threat. Yet by going back to a 2 month old image the threat was present and both Malwarebytes and NIS2011 have been kept current between then and now. | My System Specs | | System Manufacturer/Model Number Own build (+ Recased Acer Aspire x1800) OS Windows 7x64 Home Premium SP1 x 2 CPU Intel i7 2600k Motherboard ASUS P8Z68 Deluxe Memory G.Skill Ripjaws (DDR3-1600) 2x4GB Graphics Card Nvidia GeForce GTS 450; Intel HD Graphics 3000(GT2+) Monitor(s) Displays Dell Ultrasharp IPS panel U2311H, Samsung SyncMaster P2350 Screen Resolution 1920x1080 Keyboard Logitech MK520 (wireless) Mouse Logitech MK520 PSU Seasonic M12II 520W Case Lian Li Lancool PC-K60 Cooling Case: 1x120mm, 3x140mm CPU: Hyper 212+ Hard Drives Crucial M4 128GB (000F), Seagates 1TB Barracuda ST31000528AS + Internet Speed 6-7 Mbps Antivirus Norton NIS, Malwarebytes on 2 (MSE on 3rd PC) Browser FireFox Other Info Audio: Logitech Z523 2.1 |
01 Jul 2011
|
#7 | | Windows 7 & Windows Vista Ultimate Upstate NY |
Definitions are updated regularly, mjf, but until the vendor becomes aware of the threat it cannot be submitted. We can speculate about what changed that resulted in the addition, but that won't provide answers.
I suggest creating a fresh restore point and then clearing all the old, infected points using Disk Cleanup. For Windows Vista and Windows 7: - Click start, type Disk Cleanup in the search box
- Right-Click Disk Cleanup and select "Run as Administrator" and accept the UAC elevation prompt.
- Select the drive where Windows is installed (if you have more than one drive) and click "OK".
- When the scan completes, check/uncheck desired boxes.
- Next, please click the More Options tab at the top.
- Click the "Clean up..." button under the "System Restore and Shadow Copies" section at the bottom.
- Click Delete in response to the question "Are you sure you want to delete all but the most recent restore point?", click OK and answer Yes again.
- The disk clean up utility will remove the selected items. When it completes, please restart the computer to properly record the changes made to the hard disk.
| My System Specs | | OS Windows 7 & Windows Vista Ultimate |
02 Jul 2011
|
#8 | | |
Since you guys use ESET regularly, you did actually agree to these... Quote: 2. Forwarding of infiltrations and information to the Provider.
The Information may contain data (including personal data*) about the End User and/or other users of the computer on which the Software is installed, information about the computer and operating system, suspicious files from the computer on which the Software is installed and files affected by the Infiltration and any information about such files. *-Emphasis mine... Quote: 22. Governing Law.
The End User and the Provider agree that conflict provisions of the governing law and United Nations Convention on Contracts for the International Sale of Goods shall not apply. You expressly agree that exclusive jurisdiction for any claim or dispute with the Provider or relating in any way to Your use of the Software resides in District Court Bratislava I., Slovakia and you further agree and expressly consent to the exercise of the personal jurisdiction in the District Court Bratislava I. in connection with any such dispute or claim. Based on these, the scan results with personal data will end up in former Yugoslavia that has jurisdiction for any of the conflicts that may arise.
While the service provided might be good, there are plenty of other malware detection tools that can run locally instead of over the Internet; there's no need for possibly disclosing personal data with Internet based tools... | My System Specs | | System Manufacturer/Model Number Custom built at Home OS Windows 7 64-bit CPU Intel i5-3350P 3.1 GHz Motherboard Gigabyte GA-Z77X-UP5 TH Memory 16 GBs GSkill Sniper Graphics Card Radeon HD 7850 Sound Card VIA HD Audio Monitor(s) Displays Dell U2410 24" Screen Resolution 1920x1200 Keyboard Dell Multimedia keyboard Mouse Logitech Trackball PSU Thermaltake 850W Case Antec P183 Cooling Noctua NH-D14 Heatsink 2 x 120mm fans, 4 x 120mm case fans Hard Drives 1 x Intel 520 240 GBs
1 x Seagate 1TBs SATA 2.0,
1 x Seagate 1TBs eSATA 2.0 Internet Speed 28.5 Mb/s |
02 Jul 2011
|
#9 | | Windows 7 Home Premium x64 SP1 SoCal USA |
I would also run a scan with HitMan Pro. I doesn't need to be installed on your machine, and is a great multi vendor scanner. Home - SurfRight | My System Specs | | OS Windows 7 Home Premium x64 SP1 |
02 Jul 2011
|
#10 | | Windows 7 & Windows Vista Ultimate Upstate NY |

Quote: Originally Posted by Cr00zng Since you guys use ESET regularly, you did actually agree to these... Quote: 2. Forwarding of infiltrations and information to the Provider.
The Information may contain data (including personal data*) about the End User and/or other users of the computer on which the Software is installed, information about the computer and operating system, suspicious files from the computer on which the Software is installed and files affected by the Infiltration and any information about such files. *-Emphasis mine... Quote: 22. Governing Law.
The End User and the Provider agree that conflict provisions of the governing law and United Nations Convention on Contracts for the International Sale of Goods shall not apply. You expressly agree that exclusive jurisdiction for any claim or dispute with the Provider or relating in any way to Your use of the Software resides in District Court Bratislava I., Slovakia and you further agree and expressly consent to the exercise of the personal jurisdiction in the District Court Bratislava I. in connection with any such dispute or claim. Based on these, the scan results with personal data will end up in former Yugoslavia that has jurisdiction for any of the conflicts that may arise.
While the service provided might be good, there are plenty of other malware detection tools that can run locally instead of over the Internet; there's no need for possibly disclosing personal data with Internet based tools... You are basing your comments on very outdated information. See ESET Online Scanner End User License and Service Agreement. | My System Specs | | OS Windows 7 & Windows Vista Ultimate All times are GMT -5. The time now is 01:24 AM. | |