Member Panel


Sponsors and Ads

Noticeboard

[Fixed] Hijackthis! Logs - [Closed] Rundll32.exe posted in the Security & Safety forums; Yep, you got it right. It will open the process information window. I will need the type of file, description and location....

JOIN US NOW to remove these Ads

Post New Thread  Closed Thread
  #8  
Old 02-24-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,752
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Yep, you got it right. It will open the process information window. I will need the type of file, description and location.


  #9  
Old 02-24-2007
Blackjack925's Avatar
Bronze Member
My PC
 
Join Date: Feb 2007
Posts: 9
Blackjack925 - See this Members User comments on their Profile page
Default

I actually cant get it to show up anymore but if it does ill post the info here. I also had a question. My Idiot friend installed a backdoor on my computer called Posion Ivy. He says he uninstalled it but im not sure i belive him, any way i can make sure. Apparantly its injected into the winlogon process and is undetected by bitdefender, nod32 and any adware software i have used. any ideas?


  #10  
Old 02-24-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,752
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

I've done a bit of reading on this on the web.
  • Run Registry Editor (Start Button -> Run, then type 'regedit' and click OK) and find the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components
  • .. and look for any sub-Key(s) that have only a StubPath entry in the Name column (legitimate entries typically have Version, Locale, or ComponentID at the very least).
  • Make note of the name & location of any files that are pointed to in the 'Data' column of the StubPath, typically in either the C:\Windows\System32 directory (default), or in C:\Windows)
  • Do a file Search, locate and verify the authenticity of any file(s) mentioned in the above StubPath
  • Look for a similar filename to the above, but with no file extension (this is typically the keylogging/activity-tracking data file)
tip: Sort your files by 'Type', and then look for files of the generic 'File' type (no extension). Though the server (& logfile) could use *any* filename, confirmed reported filenames have included: - RegMen.exe - lssas.exe (Note: do not confuse with legitimate file, 'lsass.exe') - svlchost.exe (Note: do not confuse with legitimate file, 'svchost.exe')

Did you find anything?


Note:
This Trojan may open a port on your computer that may enable one to gain remote control of your computer. It is recommended that you change all of your passwords even if it was your friend who put it in. If you bank online, you might consider changing your credit card and bank account numbers. You should also monitor your credit card and bank statements carefully over the next several months for signs of fraudulent activity.


  #11  
Old 02-26-2007
Blackjack925's Avatar
Bronze Member
My PC
 
Join Date: Feb 2007
Posts: 9
Blackjack925 - See this Members User comments on their Profile page
Default

RunDLL32 is back and i got the properties from hijack this:

Process Name: rundll32.exe
Type of File: Application
Description: Run a DLL as an app
Location: C:/WINDOWS/System32

And as for the Backdoor i followed those instructions before and i thinki got rid of it i just wanted to knwo if there was any other way to make sure.


  #12  
Old 03-01-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,752
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Looks good to me.

If you want to check if there are any remnants of the backdoor I would suggest running some online scanners. You will not have to install any new programs on your computer.

Here are a few online scanners that you can possibly run:
Panda ActiveScan – Free online antivirus to combat viruses, spyware and other Internet threats.
Trend Micro - Free online virus Scan



If they detect anything other than the typical tracking cookies, I'll be happy to have a look at it. I'll keep this thread open for now.


  #13  
Old 03-01-2007
Blackjack925's Avatar
Bronze Member
My PC
 
Join Date: Feb 2007
Posts: 9
Blackjack925 - See this Members User comments on their Profile page
Default

alright thanks alot



Closed Thread
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 01:54 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top