GABSharkY

Costello

Headmaster
OP
Administrator
Joined
Oct 24, 2002
Messages
14,203
Trophies
4
XP
19,743
A few hours ago, we announced here the release of a new tool, GABSharkY.
If you have downloaded this program, please do NOT open it.
It might contain malicious code - which should not cause damage to your computer.
We should be able to give you more details when we can talk to the author.

Thanks,
the staff.

Update a la Mole -

This program contains a very nasty worm called SDBOT, more info can be found, including removal instructions, at -

http://it.trendmicro-europe.com/enterprise...DBOT.ER&VSect=T

This is a REALLY nasty virus. If you have ever run this program, immediatly do a virus scan.
 
  • Like
Reactions: MUDD_BR

amy test

Well-Known Member
Member
Joined
Jul 4, 2004
Messages
68
Trophies
0
Age
43
Location
nomad
Website
Visit site
XP
189
Country
Huh..? Now that's sneaky..
ph34r.gif
 

kiczek

Well-Known Member
Member
Joined
Mar 1, 2003
Messages
60
Trophies
0
XP
385
Country
United States
i would like to say SORRY FOR HOSTING THIS SITE ppl

I was very entusiastic about this new tool and offered him hosting but there is no way I will allow mondayz to use my website anymore

http://gabsharky.kiczek.com

PS fuck you mondayz you piece of shit!
 

Opium

PogoShell it to me ™
Former Staff
Joined
Dec 22, 2002
Messages
8,202
Trophies
0
Age
36
Location
Australia
Website
www.gbatemp.net
XP
1,163
Country
Australia
i would like to say SORRY FOR HOSTING THIS SITE ppl

I was very entusiastic about this new tool and offered him hosting but there is no way I will allow mondayz to use my website anymore

http://gabsharky.kiczek.com

PS fuck you mondayz you piece of shit!
There's no reason for you to appologize kiczek, there's no way you could have known.

Well I did download GABSharkY but i didn't get around to opening it and running it. Strange how being busy pays out in the end
happy.gif
funny old world we live in.
 
  • Like
Reactions: MUDD_BR

Outrager

Well-Known Member
Member
Joined
Dec 28, 2003
Messages
103
Trophies
0
XP
185
Country
United States
Wait... so it "It might contain malicious code" but that doesn't matter because it "should not cause damage to your computer."
Or was that just worded totally wrong?
 

WrathofGod

Well-Known Member
Member
Joined
Jul 16, 2004
Messages
185
Trophies
0
XP
301
Country
United States
I know it dropped the files mentioned on your website but what do they do. By chance have you figured out what there exactly doing?
 

mole_incarnate

Watermelon!
Former Staff
Joined
Nov 3, 2002
Messages
2,596
Trophies
0
Age
37
Location
Perth,WA
Website
www.iinet.net.au
XP
237
Country
Heres a tidbit on the winupdate.exe (one of the files it drops), knew I had seen it before -

http://it.trendmicro-europe.com/enterprise...DBOT.ER&VSect=T

Behold, the worm.

This can be fairly nasty, so if you've run this proggy, immediatly do a virus scan.

More info on other files coming.

Okay, all the other files are just normal files to run the program, not malware of any kind, cept maybe loadex.exe, pretty sure ive seen that one before.

This cannot be accidental, this little punk did it deliberatly.
 

djgarf

I Am A Raver
Former Staff
Joined
Oct 24, 2002
Messages
2,954
Trophies
2
Age
44
Location
England U.K.
Website
www.gbatemp.net
XP
867
Country
These instructions are for Windows XP ONLY!

1. Close all open programs.
2. Press Win+R. This brings up the "Run" dialog.
3. Type "taskmgr" and press enter.
4. Click "Processes."
5. Highlight "winupdate.exe," then click "End Process," followed by "Yes."
If you do not see this file, skip this step.
6. Highlight "explorer.exe," then click "End Process," followed by "Yes."
Your desktop will disappear.
7. Go to "File" and select "New Task (Run)."
8. Type "cmd" and press enter.
9. Type the following commands, pressing enter after each one.
Ignore any 'File does not exist" warnings.

cd windowssystem32
del explorer.exe
del wpa.dbl
del pnbak.dll
del pnupd.dll
del pnstrt.dll
del winupdate.exe
del native.exe
del loadex.exe
cd windows
del explore.exe
del explorer.exe
exit

10. Go to "File" and select "New Task (Run)."
11. Type "explorer" and press enter. Your desktop will be restored.

At this point your system should be cleaned.
To verify that explorer.exe is correct, run Windows Explorer, browse to
c:windows, highlight explorer.exe, right click it and select properties.
Verify that BOTH the "Created" and "Modified" dates say either
"August 29, 2002, 04:41:24" or "May 11, 2003, 21:12:10."

big thanx and shouts go out to qoop on irc for taking the time to install this crap on his pc to work out how to remove it properly

none of the registry entries listed on the trendmicro page were actually present in the registry too
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    SylverReZ @ SylverReZ: https://www.youtube.com/watch?v=fv6vlP2qSyo