Recommended Driver Scanner

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Malware and system restore errors

[Fixed] Hijackthis! Logs - [Resolved] Malware and system restore errors posted in the Security & Safety forums; Can anyone shed any light on the logs?...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #15  
Old 02-22-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 16
kohl - See this Members User comments on their Profile page
Default

Can anyone shed any light on the logs?


  #16  
Old 02-22-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

yes, you've got a root trojan that needs to come out....let me forumulate a fix for you and I'll post one shortly.

Car went south today, having to deal with tow trucks and rental cars, so my time is sort of scattered now, but I'll be on this as soon as I can.....thanks for your patience....

v


__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

  #17  
Old 02-22-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 16
kohl - See this Members User comments on their Profile page
Default

Your time's much appreciated - I'll await any fixes you can provide


  #18  
Old 02-22-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

I'm getting a lot of mixed responses on the below file. If you could go to Online malware scan and upload that file (click the browse button at the top and navigate to it, then click upload) and post back the results, it would be helpful. I don't want to delete something that is supposed to be there, but I've seen rootkits with that name as well.

C:\WINDOWS\SYSTEM32\DRIVERS\OREANS32.SYS

Also, go to start > search > for files or folders > advanced options, make sure the top 3 options are checked (system folders, hidden files, and subfolders) and search for the following three items:

ctx.exe, eclabm13.exe, fineprint.exe


If they are on your machine, let me know.



Thanks,

v



__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

  #19  
Old 02-23-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 16
kohl - See this Members User comments on their Profile page
Default

Hmm I navigated into my drivers file on the online malware scan page, but can't find that file in the folder?

I did a search for those other three and it came up with nothing.


  #20  
Old 02-23-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

that's a very good sign indeed. Let's try another online scan. If it hangs on a file, wirte down the location (if possible) and if it gives a log, be sure to post it.

TrendMicro™ HouseCall Java Scan
  • Please go HERE to run the Trend Micro™ HouseCall Scan.
  • Click Scan now. It's free!
  • Read and put a Check next to Yes I accept the terms of use.
  • Click the Launching HouseCall>> button.
  • Under Using Java-based HouseCall kernel click the Starting HouseCall>> button.
  • You may receive a Security Warning about the TrendMicro Java applet, click YES.
  • Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button.
  • Please be patient while it installs, updates, and scans your system.
  • Once the scan is complete, it will take you to the summary page.
  • Under Cleanup options, choose clean all detected infections automatically.
  • Click the Clean now>> button.
  • If anything was found you may be prompted to run the scan again, you can just close the browser window.

Thanks,

v


__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

  #21  
Old 02-23-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 16
kohl - See this Members User comments on their Profile page
Default

Uh oh, something's not right! I started up the scan, and it started scanning the files and folders, with an estimated time it'd take, but then Firefox suddenly closed itself.



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 08:50 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top