@vorhaut23 Basically a hacker injected a javascript (HTML friendly programming language) redirect to a different website, which prompted java to run, load and save an executable file to the local computer. Therefore infecting it with a virus, trojan or whatever the byte code contained. Pretty simple.
The Antivirus solutions that identified it are: ByteHero, ClamAV, Kaspersky, Rising, TrendMicro and TrendMicro-HouseCall. ClamAV and TrendMicro-HouseCall seem to have free versions available.
@drunkennewfiemidget I had to work for years with the "sequel" speaking peoples lol. Took me a little while especially late at night to figure they wanted to DB work done lol... as noted it's SQL! higher upper-case acronym not a word itself!
@drunkennewfiemidget And why not? People rarely say, "N A S A", they say NASA as one word. Why does this offend you so? I swear, white people problems.
@DrSupahFly Those were the first things that came to my mind. I've scanned my PC both with Microsoft Security Essentials and Kaspersky in safe mode, they found nothing. I also scanned WIN and TEMP directory for the files which matches the MD5 hashes with those in the video, nothing. And I can't "just reformat"...
@MatejTomcik then you must have not been vulnerable to any of those exploits. sure you can just reformat. you can just keep everything in a new partition (your current installation will be moved to that) and re-install. are you sure you're even infected?
@DrSupahFly No I'm not sure, I can't find it, that doesn't meen I'm not infected. I was on dev.mysql.com that day and Google warned me about malware, but I was like "mysql . com? malware? nooo...". It seems like I have underestimated hackers and their sneaky ways... Does anyone know what does that virus do?
2:06 Malware "permanently installed"? No, lol. It's not permanent. You can get rid of it.
Daniel15au 5 months ago
ИНФОРМАЦИЮ О ДОГОВОРНЫХ МАТЧАХ КУПИТЬ МОЖНО ЗДЕСЬ dogmatch.3dn.ru/
dogmatch100 5 months ago
Так умер Гуф 80 лвл.
ifnotxtheny 5 months ago
Please translate me in Russian what the man said on the site total virus?
vchkogpu 5 months ago
Hello!!!
Please Release: File Monitor Software For Home Users!!!
Thank you so much!!!
adictodigital 5 months ago
Damn. Your using Windows! O.o and then XP o.O
WebMasterGadgets 5 months ago
@WebMasterGadgets He's using an virtual machine.
mykill1221 5 months ago
@WebMasterGadgets XP ( professional ) is the best OS from microsoft.. Vista and Win 7 is just crap! ;)
r3alw0rld 5 months ago
I have brother mysql died from
PoyTep 5 months ago
Can't believe that root access to mysql.com was sold on russian hacker forums for just $3k which lead to this
Boozle061083 5 months ago 2
well done dude
viner922 5 months ago
what am i look at?! :D
TheAffemitWaffe 5 months ago
What typ of Trojan or Worm... w/e, is it exacly ?
SMTyou 5 months ago
@SMTyou It's something that locks your PC. It want 100 Euro for unlock it again
mykill1221 5 months ago
@mykill1221 Lmfao
SMTyou 5 months ago
@SMTyou Is that really funny?!
mykill1221 5 months ago
@mykill1221 Actually, yes. I never heard of that typ of trojan. Even though it's bad or not funny, you could simply reinstall your computer.
SMTyou 5 months ago
This has been flagged as spam show
yeah, anybody debugged that file? any malware analysis experts here? what actions does this file take?
immuneDay 5 months ago
Comment removed
immuneDay 5 months ago
i dont get what happend
vorhaut23 5 months ago
@vorhaut23 Basically a hacker injected a javascript (HTML friendly programming language) redirect to a different website, which prompted java to run, load and save an executable file to the local computer. Therefore infecting it with a virus, trojan or whatever the byte code contained. Pretty simple.
SkitchThat 5 months ago
Why does he always mention his secret account ?
LeiErebus 5 months ago
Muy buena la explicación.
carlosrevillah 5 months ago
The Antivirus solutions that identified it are: ByteHero, ClamAV, Kaspersky, Rising, TrendMicro and TrendMicro-HouseCall. ClamAV and TrendMicro-HouseCall seem to have free versions available.
JaapBeetstra 5 months ago
Thanks for the video.
Now stop fucking pronouncing 'sql' as 'sequel'.
drunkennewfiemidget 5 months ago
@drunkennewfiemidget I had to work for years with the "sequel" speaking peoples lol. Took me a little while especially late at night to figure they wanted to DB work done lol... as noted it's SQL! higher upper-case acronym not a word itself!
stonerscolony 5 months ago
@drunkennewfiemidget And why not? People rarely say, "N A S A", they say NASA as one word. Why does this offend you so? I swear, white people problems.
Warkive 5 months ago
@drunkennewfiemidget That's actually its intended pronunciation.
hoboX10 5 months ago 2
@hoboX10 No, it isn't. SQL was what it was renamed to FROM sequel.
drunkennewfiemidget 1 month ago
That is why you should ALWAYS use your browser in secure sandboxed environment (I suggest sandboxie, google it up :) )
ChieftainY2k 5 months ago
Please, let us know if you find a way how to get rid of that virus or where is it hidding...
MatejTomcik 5 months ago
@MatejTomcik just reformat? if not.. look in msconfig, startup directory, or scheduled tasks.
DrSupahFly 5 months ago
@DrSupahFly Those were the first things that came to my mind. I've scanned my PC both with Microsoft Security Essentials and Kaspersky in safe mode, they found nothing. I also scanned WIN and TEMP directory for the files which matches the MD5 hashes with those in the video, nothing. And I can't "just reformat"...
MatejTomcik 5 months ago
@MatejTomcik then you must have not been vulnerable to any of those exploits. sure you can just reformat. you can just keep everything in a new partition (your current installation will be moved to that) and re-install. are you sure you're even infected?
DrSupahFly 5 months ago
@DrSupahFly No I'm not sure, I can't find it, that doesn't meen I'm not infected. I was on dev.mysql.com that day and Google warned me about malware, but I was like "mysql . com? malware? nooo...". It seems like I have underestimated hackers and their sneaky ways... Does anyone know what does that virus do?
MatejTomcik 5 months ago
Good video, well done. :)
lVl477H13Ll 5 months ago
nice work, very intellectual!
Thorndepth 5 months ago
不是我干的(╯▽╰)
xiaoshiqi 5 months ago
Thanks for showing the tools in use!
Stasoline 5 months ago 2
nicely done
TartaroZ 5 months ago
Very nice work!
Yessj 5 months ago