PDA

View Full Version : PremiumSearch , Inc Trojan Horses.



Amsalem
2007-11-22, 14:53
Hey,

Im a World of Warcraft player and i got hacked in the past.. Didin't had any protection or whatsoever.. And always visited links.. I didin't even knew what Trojan horses, or keyloggers were.. But anyway..

This is what i get, and im very concerned my account my be comprimised once again. I have removed it with my Spybot search & Destroy program but im concerned about this: This trojan horse gets installed in background, it registers itself to the system start and winlogon. It has multiple exe files and dlls with variable names running in background which protect each other and connect to the internet in background. The hosts file gets hijacked and all search sites for example from yahoo, google and msn are getting redirected to PremiumSearch. The computer gets slowed down and the security settings get compromised. The trojan horse also uses rootkit functionality to hide some of its parts. Removal of this trojan horse will require a reboot. After the reboot the explorer may not start anymore, this will require to open Spybot via the taskmanager and fix the remaining parts of PremiumSearch.

I don't understand what i should do.. I need some better information about this. I am immume to everything. And am fully updated. I got AVG, Spywareblaster and Spybot ofcourse ;)

Thanks in advance,
Naor Amsalem.

Amsalem
2007-11-22, 14:59
Oh and btw.. I use mozzila Firefox for those who are intrested :)

Yodama
2007-11-23, 10:46
Which version of Spybot-S&D do you have, 1.5?
If you do not have 1.5 , please update to 1.5, it is required for removal of Premiumsearch.

* switch Spybot S&D into advanced mode
* navigate to tools - view reports
* check all boxes
* click view report button to create the report
* export the report to a textfile and send it via email to: detections(at)spybot.info (Replace AT with @)

A link back to this topic would be appreciated, so that we know who you are.