i just scanned the latest version of sroking..
i find virus..
scanned @ virustotal.com
a-squared 4.0.0.101 2009.03.20 Riskware.AdWare.Win32.Cinmus!IK
AhnLab-V3 5.0.0.2 2009.03.20 -
AntiVir 7.9.0.120 2009.03.20 -
Authentium 5.1.2.4 2009.03.20 -
Avast 4.8.1335.0 2009.03.20 -
AVG 8.5.0.283 2009.03.20 -
BitDefender 7.2 2009.03.20 -
CAT-QuickHeal 10.00 2009.03.20 -
ClamAV 0.94.1 2009.03.20 -
Comodo 1074 2009.03.20 -
DrWeb 4.44.0.09170 2009.03.20 -
eSafe 7.0.17.0 2009.03.19 Suspicious File
eTrust-Vet 31.6.6408 2009.03.20 -
F-Prot 4.4.4.56 2009.03.20 -
F-Secure 8.0.14470.0 2009.03.20 Suspicious:W32/Malware!Gemini
Fortinet 3.117.0.0 2009.03.20 -
GData 19 2009.03.20 -
Ikarus T3.1.1.48.0 2009.03.20 not-a-virus:AdWare.Win32.Cinmus
K7AntiVirus 7.10.676 2009.03.19 Trojan-Downloader.Win32.Delf
Kaspersky 7.0.0.125 2009.03.20 -
McAfee 5558 2009.03.20 -
McAfee+Artemis 5558 2009.03.19 Generic!Artemis
McAfee-GW-Edition 6.7.6 2009.03.20 -
Microsoft 1.4502 2009.03.20 -
NOD32 3951 2009.03.20 -
Norman 6.00.06 2009.03.20 -
nProtect 2009.1.8.0 2009.03.20
Trojan-Downloader/W32.Banload.161279
Panda 10.0.0.10 2009.03.20 -
PCTools 4.4.2.0 2009.03.20 -
Prevx1 V2 2009.03.20 -
Rising 21.21.42.00 2009.03.20 -
Sophos 4.39.0 2009.03.20 -
Sunbelt 3.2.1858.2 2009.03.19 -
Symantec 1.4.4.12 2009.03.20 -
TheHacker 6.3.3.0.286 2009.03.20 Trojan/Spy.Banker.boi
TrendMicro 8.700.0.1004 2009.03.20 -
VBA32 3.12.10.1 2009.03.19 -
ViRobot 2009.3.20.1658 2009.03.20 -
VirusBuster 4.6.5.0 2009.03.19 -
try to search in google the trojan in RED..
here is the description:
This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent. It is a Windows PE EXE file. It is 113152 bytes in size. It is not packed in any way. This Trojan is written in Visual Basic.
In order to ensure that the Trojan is launched automatically each time the system is rebooted, the Trojan registers its executable file in the system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"lsass" = "%Program Files%\Microsoft Studio Files\lsass.exe"
Virus description:
Conclusion: After I reboot my system a several times, the virus takes effect. it doesn't load the windows taskbar or anything after you log on your windows user account. It just display black. it doesn't hang because i can run the task manager. Btw, i am using vista. to be able to run the bot, you must disable your UAC or User Account Control. UAC helps in preventing malicious programs and spyware attacks. I guess when you disable your UAC, the TROJAN colored in red perform its task to download another trojan.
I had just reformatted my system 3 times. i just figure out the problem when i scanned sroking bot. and look over the net for the trojan's definition. it's your own risk to download the bot guys.. its up to you..