Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Community » Unfinished Threads
Register for a Free Account

Unfinished Threads - Big spyware problems posted in the Community forums; i would like to try and clean it up...I dont do any important work on this computer such as banking...it is mainly school work, myspace, music, videos etc. Also, what ...


Reply
Recommended Driver Scanner
Old 09-17-2007   #8
Bronze Member
 
Join Date: Aug 2005
Posts: 61
Default Re: Big spyware problems

i would like to try and clean it up...I dont do any important work on this computer such as banking...it is mainly school work, myspace, music, videos etc. Also, what exactly can a rootkit do?
__________________
-Brent
brent is offline   Reply With Quote
Advertisement - Register to Remove

Old 09-17-2007   #9
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default Re: Big spyware problems

Rootkits have gotten a great deal of attention in the popular media lately as the "greatest threat to security" at the level of the individual system. For example, see:
http://www.computerworld.com/securitytopic...1,99843,00.html
PC World - Rootkits: Invisible Assault on Windows

Basically the defining characteristic of a rootkit is stealth. A rootkit hides its presence from the operating system. Then it usually does something else as well (since stealth for its own sake doesn't gain the rootkit author very much). This might include protecting/hiding other malware that spams or accepts remote access commands, opening a backdoor, or something slightly more mundane like enforcing digital rights management (Sony rootkit).

This can be dangerous for obvious reasons. Most of the interaction a user has with a system is through the "eyes" of the operating system. You never actually tell your hard drive to delete a file, for example --- you tell Windows to delete a file, and Windows in turn interprets your request and passes it down the driver chain until it reaches the physical device. Likewise, in the opposite direction, you never actually know what data (in the form of binary 1's and 0's) is present on your hard drive, or in your registry --- you only know the high-level interpretation of that data that Windows gives you. You see with the eyes of the operating system, and so a rootkit, which hides from the operating system, can make itself effectively undetectable by normal means.


Please download F-Secure BlackLight
  • Save BlackLight to your desktop.
  • Double-click blbeta.exe then accept the agreement.
  • Click > Scan then > Next
  • After the scan you'll see a list of all items found. Please click Next and exit. Don't choose to rename anything yet! I want to see the log first, because legitimate items can also be present there.
  • There will be a log on your desktop with the name fsbl.xxxxxxx.log (where the xxxxxxx are numbers) Please post the contents of this log in your next reply.
chiaz is offline   Reply With Quote
Old 09-19-2007   #10
Bronze Member
 
Join Date: Aug 2005
Posts: 61
Default Re: Big spyware problems


09/18/07 19:43:50 [Info]: BlackLight Engine 1.0.64 initialized
09/18/07 19:43:50 [Info]: OS: 5.1 build 2600 (Service Pack 2)
09/18/07 19:43:50 [Note]: 7019 4
09/18/07 19:43:50 [Note]: 7005 0
09/18/07 19:44:02 [Error]: 6024 1
09/18/07 19:44:02 [Error]: 6024 1
09/18/07 19:44:02 [Error]: 6024 1
09/18/07 19:44:02 [Error]: 6024 1
09/18/07 19:44:02 [Error]: 6024 1
09/18/07 19:44:02 [Error]: 6024 1
09/18/07 19:44:02 [Note]: 7006 0
09/18/07 19:44:02 [Note]: 7011 4336
09/18/07 19:44:02 [Note]: 7026 0
09/18/07 19:44:02 [Note]: 7026 0
09/18/07 19:44:03 [Error]: 6024 1
09/18/07 19:44:03 [Error]: 6024 1
09/18/07 19:44:03 [Error]: 6024 1
09/18/07 19:44:12 [Note]: FSRAW library version 1.7.1022
09/18/07 19:46:26 [Info]: Hidden file: c:\WINDOWS\SYSTEM32\KDHQP.EXE
09/18/07 19:46:26 [Note]: 7002 32
09/18/07 19:46:26 [Note]: 7003 1
09/18/07 19:46:38 [Note]: 2000 1012
09/18/07 19:46:38 [Note]: 2000 1012
09/18/07 19:54:28 [Note]: 7007 0
__________________
-Brent
brent is offline   Reply With Quote
Old 09-19-2007   #11
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default Re: Big spyware problems

Run a scan with Blacklight again.

When the file KDHQP.EXE is reported, select it, and then press Next.
Then click "Restart Now" to reboot the computer.


After the reboot, run a new scan with Blacklight. Is the file still being detected?
chiaz is offline   Reply With Quote
Old 09-20-2007   #12
Bronze Member
 
Join Date: Aug 2005
Posts: 61
Default Re: Big spyware problems

when i select it, and press next, the only option i get is "finish" and there is nothing that signals that that file was deleted. Also no option for a restart.
__________________
-Brent
brent is offline   Reply With Quote
Old 09-22-2007   #13
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default Re: Big spyware problems

Was there no option to rename the file?
chiaz is offline   Reply With Quote
Old 09-22-2007   #14
Bronze Member
 
Join Date: Aug 2005
Posts: 61
Default Re: Big spyware problems

ya there was an option to rename...is that what you wanted me to do?
__________________
-Brent
brent is offline   Reply With Quote

Reply

Bookmarks

Tags
big, problems, spyware
Similar discussions...
Thread Thread Starter Forum Replies Last Post
[Resolved] Mouse stops responding, leads to big problems... Bravo86 PSU and Overheating Issues 8 08-19-2007 10:22 PM
[Resolved] Spyware Problems Angelinaa [Fixed] Hijackthis! Logs 2 02-16-2007 12:35 AM
big time pc problems bigbren All other Hardware 3 10-23-2006 03:52 AM
[Fixed] spyware problems davesmith20 [Fixed] Hijackthis! Logs 13 05-22-2006 12:41 PM

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 01:14 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2