Member Panel


Sponsors and Ads

Noticeboard

[Fixed] Hijackthis! Logs - [Fixed] hjt log posted in the Security & Safety forums; Yes!!! Just glad thats over Yeah seems to be running fine, On housecall though about a week ago it did find DIALER_BT is this normal,I didn't let it delete incase ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #29  
Old 03-04-2007
jakedude182's Avatar
Gold Member
My PC
 
Join Date: Oct 2006
Posts: 337
PC Experience: Some Experience
jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page
Default

Yes!!! Just glad thats over

Yeah seems to be running fine, On housecall though about a week ago it did find DIALER_BT is this normal,I didn't let it delete incase it was somthing needed for the internet or somthing like that.. Is it safe to let trendmicro/housecall get rid of anything it finds?

Thanks, Jake


__________________
Prework works!



Last edited by jakedude182; 03-04-2007 at 10:03 PM.
  #30  
Old 03-05-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

I want you to do this; rename hjt.exe to lotus.exe, and run it again, and post another log. Some malware will spot hijackthis.exe and hide themselves accordingly. Then post another log, please.

Thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #31  
Old 03-05-2007
jakedude182's Avatar
Gold Member
My PC
 
Join Date: Oct 2006
Posts: 337
PC Experience: Some Experience
jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page
Default

Ok then, I did a full system scan with spysweeper of C for viruses and spyware I think, and it found nothing. Then I chose a custom scan of C for rootkits, system restore folder, direct disk sweeping, and verify excutable programs, and it found perfect keylogger again. I didn't quarantine and delete it becuase its just found it again after already having done that.


Thanks, Jake
Attached Files
File Type: txt Spy Sweeper Session Log 5.3.07.txt (39.0 KB, 0 views)


__________________
Prework works!


  #32  
Old 03-05-2007
jakedude182's Avatar
Gold Member
My PC
 
Join Date: Oct 2006
Posts: 337
PC Experience: Some Experience
jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page
Default

Should I turn off system restore? or should I do a system restore?
I think that it may be a rootkit becuase of the scan before. so far this is the only scanner of mine that picks it up, apart from spyware doctore which only scans, but I will scan with that. Would you reccomend I do Housecall?
Im going to try using pest patrl becuase it has perfect keylogger in the encyclopedia eTrustŪ PestPatrolŪ Anti-Spyware


__________________
Prework works!



Last edited by jakedude182; 03-05-2007 at 08:18 PM.
  #33  
Old 03-05-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

don't worry about system restore, for now (we'll create a new one once we get you clean) but yes, let's run a rootkit scan.

Download GMER from here:
GMER - Files

Unzip it to the desktop.

Open the program and click on the Rootkit tab.
Make sure all the boxes on the right of the screen are checked, EXCEPT for ‘Show All’.
Click on Scan.
When the scan has run click Copy and paste the results (if any) into this thread.


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #34  
Old 03-05-2007
jakedude182's Avatar
Gold Member
My PC
 
Join Date: Oct 2006
Posts: 337
PC Experience: Some Experience
jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page
Default

I have attached the hjt log with lotus.exe, and a normal one when called hjt.exe
I couldn't spot any difference apart from hjt name change.

this keylogger doesn't seem to be doing anything that I would sespect. Apart from one thing, Somtimes when I am looking through folders the icons all change to a different veiw, e.g it would change the nveiw from- files to thumbnails, or what it normall was to another.
I think it might of done this before I re-formatted ages ago because of a bad trojan.
Attached Files
File Type: log hjt with lotus 5.3.07.log (6.5 KB, 0 views)
File Type: log hijackthis 5.3.07.log (6.5 KB, 0 views)


__________________
Prework works!


  #35  
Old 03-05-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

did you run the gmer yet?


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 05:03 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top