Search:

Type: Posts; User: mchase; Keyword(s):

Search: Search took 0.01 seconds.

  1. Replies
    19
    Views
    7,394

    Yep, I think we are good. Some of the stuff was...

    Yep, I think we are good. Some of the stuff was just closed ports and processes that needed to be restarted.

    Thanks for the help. I owe you my first born.

    Just for my education could you give...
  2. Replies
    19
    Views
    7,394

    You were correct about the snapshot section: ...

    You were correct about the snapshot section:

    here is the comboFix file with the section removed:

    ComboFix 07-11-02.3 - MIA-KITTY 2007-11-04 8:17:12.3 - NTFSx86
    Microsoft Windows XP...
  3. Replies
    19
    Views
    7,394

    The comboFix file is very large 120,000...

    The comboFix file is very large 120,000 characters long. This posting program will only let me post upto 20,000 char how do I post? Or do I attach?

    Mean while the HJT file is:


    Logfile of...
  4. Replies
    19
    Views
    7,394

    looks like my VNC port has been closed as VNC...

    looks like my VNC port has been closed as VNC does not appear to be working any more.

    Mike
  5. Replies
    19
    Views
    7,394

    Is there anyway to find out what changes all of...

    Is there anyway to find out what changes all of this has done to my computer? It looks like I have to go back and re-setup some things.

    I notice that all of my secure ssh is no longer working....
  6. Replies
    19
    Views
    7,394

    What is the next step or have we finished? Mike

    What is the next step or have we finished?

    Mike
  7. Replies
    19
    Views
    7,394

    Here is the new HJT log file. How am I doing? ...

    Here is the new HJT log file. How am I doing?


    ***************************************

    New HJT LOG:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:59:19 PM, on 11/2/2007...
  8. Replies
    19
    Views
    7,394

    Ok had a bit of a snag with this one. I forgot to...

    Ok had a bit of a snag with this one. I forgot to disable script blocking in NAV. So on reboot while running ComboFix NAV sent me a warning and the system froze. I rebooted and got script blocking...
  9. Replies
    19
    Views
    7,394

    Ok I have rebooted after SuperAntiSpyware. The...

    Ok I have rebooted after SuperAntiSpyware. The resulting scan log is:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 11/02/2007 at 05:49 PM

    Application Version :...
  10. Replies
    19
    Views
    7,394

    Ok SuperAntiSpyWare has finished. It says I still...

    Ok SuperAntiSpyWare has finished. It says I still have 5 items of Vundo as well as some downloaders I will continue as per the instructions but here is the Scan log file:


    SUPERAntiSpyware Scan...
  11. Replies
    19
    Views
    7,394

    Thanks for the location of the VundoFix.txt file....

    Thanks for the location of the VundoFix.txt file. It contains the following:


    VundoFix V6.5.11

    Checking Java version...

    Java version is 1.5.0.7
    Old versions of java are exploitable and...
  12. Replies
    19
    Views
    7,394

    Ok I ran VundoFix It did not generat a text...

    Ok I ran VundoFix

    It did not generat a text file as far as I can tell bu it did list some files in its window:

    C:/windows/system32/exdramn.dll
    C:/windows/system32/qomkjjg.dll

    I clicked...
  13. Replies
    19
    Views
    7,394

    Ok here is the hijack this file: Logfile of...

    Ok here is the hijack this file:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:49:04 PM, on 11/2/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00...
  14. Replies
    19
    Views
    7,394

    virtumonde has got me

    Hi I believe I am having problems with with virtumonde and maybe others.

    I have tried Norton Symantic, and MS One care, virus scanners both have reported differing viruses which I removed.

    I...
Results 1 to 14 of 14