Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
|
|||||||
Download Now:
Trojan, trojan & more trojans. My kingdom for a fix
|
|
Thread Tools | Search this Thread |
|
#21
|
|||
|
|||
|
Kritius,
Managed to get the logs done. There are three. a, Combo #1 - Scan b, Combo #2 - Scan after CFScript dragged into. As earlier request. c, krustyHLT latest. Cheers, Krusty. |
|
#22
|
||||
|
||||
|
kritius, I know you must be on overload, but take a look at this:
Multiple Vendor SupportSoft SmartIssue ActiveX Control Buffer Overflow Vulnerability: Vulnerable Systems: * tgctlsi.dll version 6.9.545.0 as included with Symantec Corp.'s Norton Internet Security 2006. http://www.securiteam.com/windowsntf...QP0L1PKKM.html I notices the following in the Hijack logs: (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class There are several other Symantec entries that might be involved. |
|
#23
|
||||
|
||||
|
Cheers for that Bobeye, it hasnt filtered down into Castlecops or SpywareBlaster about these ones.
@Krusty, the reason that we renamed HijackThis is because some Malware has gotten wuite good at hiding from HJT so we rename the .exe file to hide it from them. Ill look over your logs and post what I find tomorrow. Last edited by kritius; 04-09-2008 at 07:50 PM.. |
|
#24
|
||||
|
||||
|
Glad to help!
|
|
#25
|
|||
|
|||
|
Bobbye,
As Kritius isn't logged on as yet & hope he wouldn't mind me asking you (don't won't to tread on toes), are you familiar with ntoskrnl.exe ? I'm currently running an AVG scan on the other pc & it has informed me of this file change. It's path is C:\Windows\system32\ntoskrnl.exe ???? Just thought I'd ask whilst its scanning. Cheers, Krusty. |
|
|
|
#26
|
||||
|
||||
|
From the grisoft forums,
Quote:
I would like you to do an online scan so that we can what else may be in your system, Run Kaspersky online scanner With the exception of Internet Explorer, which must be used for this scan, keep ALL programs closed Note: It is recommended to disable onboard antivirus program and antispyware programs while performing scans to speed up scan time and to make sure there are no conflicts. Do not go surfing while your resident protection is disabled! Once the scan is finished remember to re-enable resident antivirus protection along with whatever antispyware application you use. Do an online scan with Kaspersky Online Scanner in Internet Explorer. You will be prompted to install and run an ActiveX component from Kaspersky, Click Yes. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75%. Once the licence accepted, reset to 100%.
|
|
#27
|
||||
|
||||
|
krusty, I'm going to refer you to this page for information about this process:
http://www.liutilities.com/products/...rary/ntoskrnl/ Please look at the relation to the AVG find of this process in the quote from the Grisoft Forum left by kritius. kritius. Last edited by Bobbye; 04-10-2008 at 03:47 PM.. |
|
#28
|
|||
|
|||
|
Hi Kritius,
Unfortunately I can't run Kasperspy online due to the pc's ISP is different to mine. Is there no way, as I've been doing, download here & txfer to the other pc & run offline? failing this, once it's back with my neice, I could ask her to foolow your steps, hopefully she would be able to. Cheers, Krusty. |
|
#29
|
||||
|
||||
|
not really its an online scan, its extremely good at rooting things out.
Post a fresh HijackThis scan and we'll see how things are. |
|
#30
|
|||
|
|||
|
Hi Kritius,
Soz about the Kasper issue. Herewith latest HJT log. For info, earlier today I carried out an AVG scan - no alert bar the change as earlier posted. Performed a spysweeper scan - all clear. Then I installed & scanned 'SuperAntispyware' this did find stuff in the reg & deleted all. Ran again & all was clear. Do we need to create a new restore point now? Also notice that her IE home page was 'about blank'. I've changed this to google as you'll see from log. Thanks again. Are we all clear now? Krusty. |
|
#31
|
||||
|
||||
|
Thats pretty clean.
Without seeing an online scan that about as much as we can do, do you still have OTMoveIt2 installed? |
|
#32
|
|||
|
|||
|
Kritius,
yes still installed? Krusty. |
|
#33
|
||||
|
||||
Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt2 attempting to contact the internet, please allow it to do so.
Re-enable system restore with instructions from tutorial above
Here are some additional utilities that will enhance your safety
Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference! The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware. Also, please read have her read this great article by Tony Klein So How Did I Get Infected In First Place |
|
#34
|
|||
|
|||
|
kritius,
Failed to run OTMove It, as not connected to net. Have taken other steps into account, thanks. I'm happy that it's clean enough to hand back to her now, for further web abuse, I guess. I'll educate her & her boyfriend on how to keep on top. Thanks for all your help. Unless you suggest anything else, I'll let her collect it tomorrow. Cheers a million, Krusty. |
|
#35
|
||||
|
||||
|
if you want to you can get her to run the kaspersky scan and then post it back here and ill have a look at it, other than that its all good.
All the best then |
|
#36
|
|||
|
|||
|
Kritius,
I'll show her the posts when she collects & run her through it. I'll try & get her to run Kasperspy & post me the results & then I'll post them here. Thanks ever so much wrt all done. goin offline now, Cheers, Krusty. |
|
#37
|
||||
|
||||
|
Im here anyway if you need additional help, im a big geek like that!
|
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Tr/Dropper.Gen Trojan, Trojan.Smitfraud Variant-Gen, and other nasties
|
1 | Virus and Malware Removal | ||
Need Help, i have Trojan.Zonebac and Trojan Vundoo
|
1 | Virus and Malware Removal | ||
trojan horse lop.AS Trojan, Unable To Work Out.
|
9 | Virus and Malware Removal | ||
Dialer.Trojan, Trojan.Dropper etc...
|
1 | Virus and Malware Removal | ||
Trojan.dropper and Dialer.trojan, plz help =(
|
8 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 04:05 PM.





Tr/Dropper.Gen Trojan, Trojan.Smitfraud Variant-Gen, and other nasties