View Single Post
  #29 (permalink)  
Old 07-10-09, 07:28 AM
Boraan's Avatar
Boraan Boraan is offline
Coding Addict
 
Join Date: Jul 2007
Location: Clayton, NC
Posts: 292
Thanks: 0
Thanked 1 Time in 1 Post
Rogue.sysCleanPro is a seriously aggressive malware. Basically what it does is generate pops saying your system is infected and does a fake scan pointing where it obviously finds thing to be fixed that can only be fixed when you purchase the full version.

It is very dangerous as has been known to install additional spyware, dl viruses, repair itself, spread and in some cases compromise account security and credit card/bank security.

Registry entries:
Code:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\System32\memman.vxd
Files:
Code:
C:\ProgramData\{DE097E60-7F86-4350-B083-1F09B6906C92}\OFFLINE\71747601\2302A1E7\memman.vxd (Rogue.SysCleanerPro)
C:\Windows\System32\memman.vxd (Rogue.SysCleanerPro)
Could a hacker use this to compromise your accounts? if it was part of the software bundle that you use for uploading/accessing your godaddy account. Other than that? idk. it seems like you may have have gotten it from another program, maybe a maintenance utility or something. Since it does have a history of compromising security, we'll go ahead and try to elimitate it as a possibility.

Since we now know that you have no known infections, change your passwords and re-upload the site information. If you don't get hacked again then we know that was the point of compromise. If it does then we've basically elimited anything on your pc as a point of compromise with exception to one thing.

How do you access your godaddy account? do you use the browser or another application?
__________________
Dexter Nelson
Techdex Development & Solutions
========================
Internet Marketing For Programmers | Free Market Research in 15 Minutes or Less
My Software: Hotscripts Softpedia software.techdex.net
Reply With Quote