WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionHelp I think my computer is infected - Page 1 EmptyRe: Help I think my computer is infected

more_horiz
CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11.INBBFX
----- EOF -----

descriptionHelp I think my computer is infected - Page 1 EmptyRe: Help I think my computer is infected

more_horiz
heffy23 wrote:
Files Infected:
d:\documents and settings\administrator\my documents\downloads\test drive unlimited 2 serial keygen.zip.exe (Trojan.Dropper) -> Quarantined and deleted successfully.


I hope you noticed this one too.

Keygen/crack warning!
There are keygens and/or cracks on your computer. Please be aware that these programs are generally used for illegal purposes. Software piracy is a crime that we at GeekPolice do not recommend or approve (but rest assured that we do not report it either).
Keygens and cracks form a very important distribution network of malware. It might be the reason of your present infection. Even if you use reknown security software, you can never be safe, as you might run into a fresh new variant (a so-called 0-day threat).

Example: Two VirusTotal reports of a keygen, that in reality was a trojan carrying a nasty infection called TDSS.
THIS is the report of the trojan just after release - 0/40 virusscanners detected the deadly load.
THIS is a report of the same file just five days later - 24/40 have updated their signature database to detect it.
If you would repeat the analysis today, it would probably be detected by even more scanners. Tough luck for the users that picked it up early. Make sure you are not among them.

Stay out of trouble: get free software instead! I provide some safe websites where you can pick up free software, often just as good as commercial software.


====================

Download GMER Rootkit Scanner from here and save it to your desktop.
Note that it will have a random name.

  • Double click the file to run the tool. It may take a while to load.
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan, click No
  • In the right panel, you will see several boxes that have been checked
  • Make sure this is unchecked: Show All
  • Make sure only your system drive (usually C:\) is checked and uncheck all other drives you might have on your system
  • Click Scan to start the scan
  • When it has finished, click Save and save the log as gmer.txt on your desktop
  • If GMER reports any <--- ROOTKIT entries, donĀ“t take any action. It could be a false positive.
  • Click OK to quit GMER.
  • Please post the contents of gmer.txt into your next reply.

descriptionHelp I think my computer is infected - Page 1 EmptyRe: Help I think my computer is infected

more_horiz
ok tried to run GMER and halfway through the scan the top left hand corner of my screen went red and then it reset my pc

descriptionHelp I think my computer is infected - Page 1 EmptyRe: Help I think my computer is infected

more_horiz
ok re-running the program now. It's still scanning i'll post it up when it's done

descriptionHelp I think my computer is infected - Page 1 EmptyRe: Help I think my computer is infected

more_horiz
GMER 1.0.15.15640 - http://www.gmer.net
Rootkit scan 2011-07-15 23:48:04
Windows 5.1.2600 Service Pack 3, v.3311 Harddisk1\DR1 -> \Device\Scsi\nvgts2Port3Path0Target0Lun0 Hitachi_ rev.P21O
Running: i9yok70x.exe; Driver: D:\DOCUME~1\random\LOCALS~1\Temp\ugkoifob.sys


---- Kernel code sections - GMER 1.0.15 ----

.text D:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB60C43A0, 0x88C445, 0xE8000020]

---- EOF - GMER 1.0.15 ----

descriptionHelp I think my computer is infected - Page 1 EmptyRe: Help I think my computer is infected

more_horiz
Excellent. As far as I can see, your computer is CLEAN.

Help I think my computer is infected - Page 1 Clean_computer

====================

Time to uninstall used tools.

  • Go to Start > Run and type or copy/paste Combofix /uninstall (note the space before the "/").
  • Double click OTL.exe to run it again and click the CleanUp button.
  • If we used any other tools and they still remain on your desktop, please delete them manually.

====================

Do you have any more questions or do you want to see my ALORTKYCC (Awesome List Or Recommendations To Keep Your Computer Clean)?

descriptionHelp I think my computer is infected - Page 1 EmptyRe: Help I think my computer is infected

more_horiz
oh no. I tried to double click on OTL and i'm getting windows cannot access the specified file :S

descriptionHelp I think my computer is infected - Page 1 EmptyRe: Help I think my computer is infected

more_horiz
ok i removed OTL using inherit. Also i was going to ask you about something. I made another account on XP and can't get back to the administrator account. The account i'm using is admin. It's no biggie

descriptionHelp I think my computer is infected - Page 1 EmptyRe: Help I think my computer is infected

more_horiz
Mate you are a life saver. Thank you so much for taking the time to help me fix my computer and guiding me thru it all.

descriptionHelp I think my computer is infected - Page 1 EmptyRe: Help I think my computer is infected

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum