Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 9 posts ] 
Author Message
 Post subject: Yay for Microsft Security Essentials!! (And a question)
PostPosted: January 5th, 2010, 10:56 pm 
Dragon Member
Offline

Joined: January 23rd, 2007, 7:02 pm
Posts: 2600 us
RS Name: Limpin
RS Status: P2P
Dodged a bullet right there.

So I was browsing The Pirate Bay torrent and the page froze unexpectedly (I didn't download it, just looked at it's page). My PC is old and slow, and it's done this before, so I thought it was nothing. Then all of the sudden, the little Micosoft Security Essentials toolbar icon turns red, and has a popup saying something about malicious files or something.

Being me, I freaked the hell out.

I immediately dropped my fork I was using to eat and disconnected my ethernet cable, preventing my PC to access the internet (which prevents the malicious content to continue sending information to it's creator, correct?). I close everything down except for MSE, and then I look at exactly what I was dealing with, here. Turns out it was a "Win32.TrojanDownloader.Reno" and so I completely DELETED THE ****. After it was all over, I issued a virus scan, and then inserted my ethernet cable again.

The weird thing is, why did I get a Trojan Downloader from The Pirate Bay if I haven't ever before? The Pirate bay is my one and only torrent downloading site. It's never done this before.

Thank god I have MSE, had I had AVG Free right now I'd have my PC infested with trojans, probably.

Anyone know why this happened? I didn't issue a download or anything; it just popped up as a warning from MSE. Also, what the hell is a Reno?

Edit: It was a Renos.gen!BC, Wtf is a Renos.gen!BC?

_________________
Image


Last edited by Steven on January 6th, 2010, 1:48 am, edited 1 time in total.

Top
 Profile  
 
 Post subject: Register and login to get these in-post ads to disappear
PostPosted: January 5th, 2010, 10:56 pm 
Dragon Member

Joined: September 9th, 2004, 1:47am
Posts: 9047
Location: In your web browserz


Top
  
 
 Post subject: Re: Yay for Microsft Security Essentials!! (And a question)
PostPosted: January 5th, 2010, 11:02 pm 
Runite Member
User avatar
Offline

Joined: January 4th, 2008, 9:33 pm
Posts: 749
Location: Oregon us
RS Name: Parselmouth
RS Status: P2P
Clan Name: DGS
Sounds good, this makes me happier that I decided to download it as my Anti-Virus.

_________________
Image

RSN: Parselmouth | Jaysawn on ********


Top
 Profile  
 
 Post subject: Re: Yay for Microsft Security Essentials!! (And a question)
PostPosted: January 6th, 2010, 9:03 am 
Moderator
Offline

Joined: February 22nd, 2005, 3:38 pm
Posts: 3200
Location: 127.0.0.1 us
RS Name: Silverwiz9
RS Status: P2P
Clan Name: RsbandbStaff
It was likely from an ad, though without being on your computer I can't say that for certain. TPB doesn't purposely embed malicious content into it's webpages, so I'm guessing it wasn't something intentional. If MSE was doing a routine scan, it could have picked up something new, though I would tend to agree that it happened while you were browsing online.

It's also possible that whatever it was wasn't actually malicious, and you got a false positive. At any rate, I'm glad MSE is working out well for you :D

_________________
PC Gaming Event Global Moderator 12/4/08 Old Informer Tech Articles
—Goals—
Image
Image


Top
 Profile  
 
 Post subject: Re: Yay for Microsft Security Essentials!! (And a question)
PostPosted: January 6th, 2010, 7:44 pm 
Runite Member
Offline

Joined: August 26th, 2009, 8:01 am
Posts: 586
Location: Waterloo, Ontario ca
RS Name: Bonsai99
RS Status: Retired
I find that more and more sites are starting to have malicious ads on them, good idea to have antivirus nowadays.

_________________
Image


Top
 Profile  
 
 Post subject: Re: Yay for Microsft Security Essentials!! (And a question)
PostPosted: January 7th, 2010, 12:58 am 
Cleverly Disguised Spammer
User avatar
Offline

Joined: December 17th, 2004, 12:03 pm
Posts: 10901
Location: Anglia europeanunion
RS Name: Piratesock
RS Status: P2P
Clan Name: The Mushroom Pirate Federation
http://www.threatexpert.com/files/lphc35dj0erc1.exe.html

the link wrote:
The following threats are known to be associated with the file "lphc35dj0erc1.exe":
TrojanDownloader:Win32/Renos.gen!BC [Microsoft]

Might want to have a quick search for iphc35dj0erc1.exe just to make sure it's not floating about on your computer.

Quote:
lphc35dj0erc1.exe is a malware that may attach itself into running system processes and install further pests onto your compromised machine. lphc35dj0erc1.exe may slash the system security and automatically launch its files on to the system. lphc35dj0erc1.exe my compromise your privacy and slash computer security.


There you go. At a guess it's that causing the problem and it's putting this junk on your computer. I'd get rid of it quickly.

_________________


Top
 Profile  
 
 Post subject: Re: Yay for Microsft Security Essentials!! (And a question)
PostPosted: January 7th, 2010, 2:27 am 
Rsbandb Donor
User avatar
Offline

Joined: August 18th, 2008, 12:19 pm
Posts: 357
Location: England england
RS Name: VettelS
RS Status: P2P
Steven wrote:
I immediately dropped my fork I was using to eat and disconnected my ethernet cable, preventing my PC to access the internet (which prevents the malicious content to continue sending information to it's creator, correct?).


Correct.

As Paul said, TPB does not serve up malicious software on its website (to my knowledge). However the trojan could have been triggered by going to TPB. All in all, it really doesn't sound lkike it was your fault for doing anything wrong.

More info here: http://www.microsoft.com/security/porta ... r:Win32/Renos.gen!BG

_________________
My blog


Top
 Profile  
 
 Post subject: Register and login to get these in-post ads to disappear
PostPosted: January 7th, 2010, 2:27 am 
Rsbandb Donor

Joined: September 9th, 2004, 1:47am
Posts: 9047
Location: In your web browserz


Top
  
 
 Post subject: Re: Yay for Microsft Security Essentials!! (And a question)
PostPosted: January 10th, 2010, 1:35 am 
Moderator
Offline

Joined: February 22nd, 2005, 6:49 pm
Posts: 6927
Location: somewhere over the rainbow us
RS Name: j1j2j3
RS Status: P2P
might have been an ad.

hell a few years back i got a virus from coming in. when rsbandb had a lot of pop up ads one popped up and next thing i know my computer says i had a virus.

on another note, a month ago a classmate wanted to grab something from my computer, i took his stick and suddenly i see a trojan. that was interesting

_________________
Image
Image


Top
 Profile  
 
 Post subject: Re: Yay for Microsft Security Essentials!! (And a question)
PostPosted: January 12th, 2010, 7:17 am 
Dragon Member
User avatar
Offline

Joined: November 25th, 2005, 6:49 pm
Posts: 1034
Location: California us
RS Name: Sky Jace
RS Status: P2P
I got this same virus on two computers in my home recently. I had to reformat one computer and the other I managed to remove the file after running a few virus scans. I'm guessing it was attached to adverts on random sites I went to. It gets pretty bad if you don't delete it though, so smooth move on your part. You just have to be careful and make sure you have a good antivirus software installed.

_________________
Image
Image
Dragon Member #90


Top
 Profile  
 
 Post subject: Re: Yay for Microsft Security Essentials!! (And a question)
PostPosted: January 12th, 2010, 2:15 pm 
Rsbandb Donor
Offline

Joined: August 24th, 2008, 3:04 pm
Posts: 1088
Location: Rhode Island us
RS Name: Killjoy4eva
RS Status: Old School (2007)
I also got a virus from pb once without downloading anything... That's one of the reasons I stick with isohumt.com nowadays. Make sure you have an ad blocker on that site though... The ads can get sort of ummmm.... Revealing.

_________________
Image


Top
 Profile  
 
Display posts from previous:  Sort by  

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Jump to: