Stolen.data

mjf

New member
Guru
Gold Member
VIP
Local time
7:27 AM
Messages
5,968
Location
Australia
Malwarebytes has just detected and quarantined "stolen.data" on my computer. A Trojan I believe.
Location: c:\programdata\carbon

NIS2011 with current update missed it.

Has anyone experience with this or advice?
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build
OS
Windows 7x64 Home Premium SP1
CPU
Intel i7 2600k
Motherboard
ASUS P8Z68 Deluxe
Memory
G.Skill Ripjaws (DDR3-1600) 2x4GB
Graphics Card(s)
Nvidia GeForce GTS 450; Intel HD Graphics 3000(GT2+)
Monitor(s) Displays
Dell Ultrasharp IPS panel U2311H, Samsung SyncMaster P2350
Screen Resolution
1920x1080
Hard Drives
Samsung 850 Pro SSD 256GB, Samsung SSD 840 120GB, Seagates 1TB Barracuda ST31000528AS x2
PSU
Seasonic M12II 520W
Case
Lian Li Lancool PC-K60
Cooling
Case: 1x120mm, 3x140mm CPU: Hyper 212+
Keyboard
Logitech MK520 (wireless)
Mouse
Logitech MK520
Internet Speed
6-7 Mbps
Antivirus
Norton Security Premium, Malwarebytes on 2 (MSE on 3rd PC)
Browser
FireFox
Other Info
Audio: Logitech Z523 2.1
Hmm I haven't suggested this in awhile

SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

Apparently it only really fell out of favor because it didn't have win 7 support until some time after it's release. It does now though.

As for this specific malware
nosirrah" (malwarebytes forum administrator) said:
Without a file path there is no way to give much info .

Stolen.Data are static paths to files where known spyware stores stolen credentials .

I think that sums it up best.
 

My Computer

Computer Manufacturer/Model Number
Insane hobo technologies. ;-)
OS
Windows 7 x64
CPU
Intel i7 2600k
Motherboard
Asrock z68 extreme 4 gen 3
Memory
G.skill Ripjaw 16gigs @ 1866
Graphics Card(s)
Nvidia gtx580 (evga)
Sound Card
Integrated HD audio + hdmi
Monitor(s) Displays
24" ASUS widescreen + 42" insignia
Screen Resolution
1080p (1920x1080)
Hard Drives
128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA)
PSU
1 kilowatt SLI/Crossfire rated Silverstone modular
Case
NZXT Phantom + additional 220 fan
Cooling
Zalmann
Keyboard
Microsoft wireless 3000 (v2)
Mouse
MS - wireless 5000 (bluetrack)
Internet Speed
depends on if you ask me or my provider.
Other Info
The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism.

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Hi, mjf.

Based on the information in the link provided by Golden, if this is indeed a password-stealing trojan, I strongly recommend that you go to a clean computer and change your passwords. Keep a close eye on any banking and credit card accounts.

It would be a good idea to do an online scan by another vendor. Please go here to run an on-line scan from ESET.

  • Note: It is easiest if you use Internet explorer for this scan. (If you use an alternate browser, it will be necessary to download the ESET Smart Installer)
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish -- it may take quite a while.
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Good luck with that mjf.

I have ESET online scanner on all my pe3 media. (smart installer is only a couple of mb )

Never needed to use it myself - but friends have used it with great success.
 

My Computers

System One System Two

  • Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w
Thanks for the replies (I need to learn more!!)

I ran the ESET online scan after Quarantining the malware with Malwarebytes. After 4+ hours it detected no threats. Fortunately I don't store or use transaction passwords or account numbers on my computer.

I've changed other passwords. Is there anything else to be done?

---------------------------------------
Interestingly, it appears only the most recent Malwarebytes update detected this threat. Yet by going back to a 2 month old image the threat was present and both Malwarebytes and NIS2011 have been kept current between then and now.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build
OS
Windows 7x64 Home Premium SP1
CPU
Intel i7 2600k
Motherboard
ASUS P8Z68 Deluxe
Memory
G.Skill Ripjaws (DDR3-1600) 2x4GB
Graphics Card(s)
Nvidia GeForce GTS 450; Intel HD Graphics 3000(GT2+)
Monitor(s) Displays
Dell Ultrasharp IPS panel U2311H, Samsung SyncMaster P2350
Screen Resolution
1920x1080
Hard Drives
Samsung 850 Pro SSD 256GB, Samsung SSD 840 120GB, Seagates 1TB Barracuda ST31000528AS x2
PSU
Seasonic M12II 520W
Case
Lian Li Lancool PC-K60
Cooling
Case: 1x120mm, 3x140mm CPU: Hyper 212+
Keyboard
Logitech MK520 (wireless)
Mouse
Logitech MK520
Internet Speed
6-7 Mbps
Antivirus
Norton Security Premium, Malwarebytes on 2 (MSE on 3rd PC)
Browser
FireFox
Other Info
Audio: Logitech Z523 2.1
Definitions are updated regularly, mjf, but until the vendor becomes aware of the threat it cannot be submitted. We can speculate about what changed that resulted in the addition, but that won't provide answers. :)

I suggest creating a fresh restore point and then clearing all the old, infected points using Disk Cleanup. For Windows Vista and Windows 7:

  • Click start, type Disk Cleanup in the search box
  • Right-Click Disk Cleanup and select "Run as Administrator" and accept the UAC elevation prompt.
  • Select the drive where Windows is installed (if you have more than one drive) and click "OK".
  • When the scan completes, check/uncheck desired boxes.
  • Next, please click the More Options tab at the top.
  • Click the "Clean up..." button under the "System Restore and Shadow Copies" section at the bottom.
  • Click Delete in response to the question "Are you sure you want to delete all but the most recent restore point?", click OK and answer Yes again.
  • The disk clean up utility will remove the selected items. When it completes, please restart the computer to properly record the changes made to the hard disk.
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Since you guys use ESET regularly, you did actually agree to these...

2. Forwarding of infiltrations and information to the Provider.
The Information may contain data (including personal data*) about the End User and/or other users of the computer on which the Software is installed, information about the computer and operating system, suspicious files from the computer on which the Software is installed and files affected by the Infiltration and any information about such files.
*-Emphasis mine...

22. Governing Law.
The End User and the Provider agree that conflict provisions of the governing law and United Nations Convention on Contracts for the International Sale of Goods shall not apply. You expressly agree that exclusive jurisdiction for any claim or dispute with the Provider or relating in any way to Your use of the Software resides in District Court Bratislava I., Slovakia and you further agree and expressly consent to the exercise of the personal jurisdiction in the District Court Bratislava I. in connection with any such dispute or claim.
Based on these, the scan results with personal data will end up in former Yugoslavia that has jurisdiction for any of the conflicts that may arise.

While the service provided might be good, there are plenty of other malware detection tools that can run locally instead of over the Internet; there's no need for possibly disclosing personal data with Internet based tools...
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built at Home
OS
Windows 7 64-bit, Windows 8.1 64-bit, OSX El Capitan, Windows 10 (VMware)
CPU
Intel i5-3350P 3.1 GHz
Motherboard
Gigabyte GA-Z77X-UP5 TH
Memory
16 GBs GSkill Sniper
Graphics Card(s)
Radeon HD 7850
Sound Card
VIA HD Audio
Monitor(s) Displays
Dell U2410 24"
Screen Resolution
1920x1200
Hard Drives
1 x Intel 520 240 GBs
1 x Seagate 1TBs SATA 2.0,
1 x Seagate 1TBs eSATA 2.0
PSU
Thermaltake 850W
Case
Antec P183
Cooling
Noctua NH-D14 Heatsink 2 x 120mm fans, 4 x 120mm case fans
Keyboard
Dell Multimedia keyboard
Mouse
Logitech Trackball
Internet Speed
28.5 Mb/s
I would also run a scan with HitMan Pro. I doesn't need to be installed on your machine, and is a great multi vendor scanner. Home - SurfRight
 

My Computer

OS
Windows 7 Home Premium x64 SP1
Since you guys use ESET regularly, you did actually agree to these...

2. Forwarding of infiltrations and information to the Provider.
The Information may contain data (including personal data*) about the End User and/or other users of the computer on which the Software is installed, information about the computer and operating system, suspicious files from the computer on which the Software is installed and files affected by the Infiltration and any information about such files.
*-Emphasis mine...

22. Governing Law.
The End User and the Provider agree that conflict provisions of the governing law and United Nations Convention on Contracts for the International Sale of Goods shall not apply. You expressly agree that exclusive jurisdiction for any claim or dispute with the Provider or relating in any way to Your use of the Software resides in District Court Bratislava I., Slovakia and you further agree and expressly consent to the exercise of the personal jurisdiction in the District Court Bratislava I. in connection with any such dispute or claim.
Based on these, the scan results with personal data will end up in former Yugoslavia that has jurisdiction for any of the conflicts that may arise.

While the service provided might be good, there are plenty of other malware detection tools that can run locally instead of over the Internet; there's no need for possibly disclosing personal data with Internet based tools...

You are basing your comments on very outdated information. See ESET Online Scanner End User License and Service Agreement.
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
You are basing your comments on very outdated information. See ESET Online Scanner End User License and Service Agreement.
Alright, quote from the referenced page:

2. Scope of the Software.
The Software contains a function, which serves to collect samples of new computer viruses or other similar harmful computer programs (the “Infiltration”) and the subsequent dispatch thereof to the Licensor. This includes, for example, information about the computer and/or platform on which the Software is installed (the “Information”). The Information may contain data (including personal data) about the Licensee and/or other users of the computer on which the Software is installed, information about the computer and operating system, suspicious files from the computer on which the Software is installed, and files affected by the Infiltration and any information about such files.
And while the jurisdiction has been changed to San Diego, CA, did you notice this?

14. Notices.
All notices intended for the Licensor must be delivered to Attn: Chief Legal Officer, ESET, spol. s.r.o., Svoradova 1, 811 03 Bratislava, Slovak Republic.
Would you be surprised, if:

  1. The letter needs to be in some sort Slavic language :cry:
  2. The Slovak court still would be the only venue
And by the way, my initial reading of the term of agreement came from this link (IE only) today. Other browsers need to download smart installer...
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built at Home
OS
Windows 7 64-bit, Windows 8.1 64-bit, OSX El Capitan, Windows 10 (VMware)
CPU
Intel i5-3350P 3.1 GHz
Motherboard
Gigabyte GA-Z77X-UP5 TH
Memory
16 GBs GSkill Sniper
Graphics Card(s)
Radeon HD 7850
Sound Card
VIA HD Audio
Monitor(s) Displays
Dell U2410 24"
Screen Resolution
1920x1200
Hard Drives
1 x Intel 520 240 GBs
1 x Seagate 1TBs SATA 2.0,
1 x Seagate 1TBs eSATA 2.0
PSU
Thermaltake 850W
Case
Antec P183
Cooling
Noctua NH-D14 Heatsink 2 x 120mm fans, 4 x 120mm case fans
Keyboard
Dell Multimedia keyboard
Mouse
Logitech Trackball
Internet Speed
28.5 Mb/s
  • Like
Reactions: mjf
Ok, your eyes are better than mine. :) The information about the jurisdiction was a hot topic at Wilders a year or so go but ended up being heavily moderated.

The Information may contain data (including personal data) about the Licensee and/or other users of the computer on which the Software is installed,
As you see, I elected to bold different words. Including the words may contain is not saying the information will contain. In my opinion, its a basic CYA statement. Computer names and IP address are frequently included in logs I review. Both could be construed personal data about the users of the computer.

As to the language, no, I would not expect that if I were to send a letter to the ESET Chief Legal Officer that it would need to be in Slovak or Hungarian. Why someone using the online scanner would need to send such a letter is another question.

Although I cannot imagine what legal proceedings you would anticipate based on using an antivirus vendor's on-line scanner. However, re-read "12. Dispute Resolution."
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Neither does it say that it will not include personal data....

At least HitPro, while it is an Internet based service, does state clearly what it will transfer. Quote from the HitPro term of agreement... [FONT=&quot]
[/FONT]

[FONT=&quot]
4. Internet-based Services[/FONT]

[FONT=&quot]SurfRight provides Internet-based Services with the Software. It may change or cancel them at any time.[/FONT]
[FONT=&quot]a. Consent for Internet-Based Services[/FONT][FONT=&quot] The Software feature described below connects to SurfRight or service provider computer systems over the Internet. In some cases, you will not receive a separate notice when they connect. By using this feature, you consent to the transmission of this information. SurfRight does not use the information to identify or contact you.[/FONT]
[FONT=&quot]i. Computer Information[/FONT][FONT=&quot] The following feature uses Internet protocols, which send to the appropriate systems computer information, such as your Internet protocol address, the type of operating system, browser and name and version of the security software you are using on the device where you installed the Software. SurfRight uses this information to make the Internet-based service available to you.[/FONT]
[FONT=&quot]● Malicious Software Removal[/FONT][FONT=&quot] When the Software checks your device for Malware, information to identify Malware could be sent to the SurfRight Services. No information included in these reports will be used to identify or contact you.[/FONT]
I prefer tools that do not call home, such as the Sysinternals Suite, MalwareBytes, etc., and perform their function on the local PC. No, I am not posting term of agreement language for these... :shock:
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built at Home
OS
Windows 7 64-bit, Windows 8.1 64-bit, OSX El Capitan, Windows 10 (VMware)
CPU
Intel i5-3350P 3.1 GHz
Motherboard
Gigabyte GA-Z77X-UP5 TH
Memory
16 GBs GSkill Sniper
Graphics Card(s)
Radeon HD 7850
Sound Card
VIA HD Audio
Monitor(s) Displays
Dell U2410 24"
Screen Resolution
1920x1200
Hard Drives
1 x Intel 520 240 GBs
1 x Seagate 1TBs SATA 2.0,
1 x Seagate 1TBs eSATA 2.0
PSU
Thermaltake 850W
Case
Antec P183
Cooling
Noctua NH-D14 Heatsink 2 x 120mm fans, 4 x 120mm case fans
Keyboard
Dell Multimedia keyboard
Mouse
Logitech Trackball
Internet Speed
28.5 Mb/s
Back
Top