Oddthought Forums
vBookie Blogs Oddthought Arcade Dopewars Global Conflict Survival of Species

Go Back   Oddthought Forums > Oddthought Community Forums > Techie Section

Techie Section Geek Chat from Hardware to Software to Internet, Video Games, Pc and a load of "how the hell did I do that and how the hell do I stop it" Stuff!

Techie Section Thread, Malware problems in Oddthought Community Forums; don't use google - try yahoo or msn - I have actually seen that before Let me look through some ...
Reply
 
LinkBack Thread Tools Display Modes
  #31  
Old 4th September 2008, 08:43 PM
Red Dragon's Avatar
Tech Mod
 

Join Date: Apr 2006
Location: Florida
Posts: 903
Blog Entries: 2
Send a message via MSN to Red Dragon
Default

don't use google - try yahoo or msn - I have actually seen that before

Let me look through some change logs for your infection - I actually see it back in the combofix log and thought sdfix would have killed it but it didn't
__________________
Reply With Quote
  #32  
Old 5th September 2008, 03:10 AM
steff's Avatar
SofS Game Admin/Moderator
 
Join Date: Feb 2007
Location: UK
Posts: 3,515
Blog Entries: 1
Default

Dy wasn't kidding when he said I was a handful.

MBAM log 1 - quick scan in safemode
MBAM log 2 - full scan in safemode
MBAM log 3 - quick scan in regular mode
Misc file - the file that got created when the online Kaspersky virus scanner wouldn't work

It's also worth mentioning I have a process running called "conime.exe" which sounds bad. I just closed it there just now.

edit - and since I have said process... here's my hijackthis log too
Attached Files
File Type: txt mbam-log-9-4-2008 (19-12-00).txt (2.8 KB, 2 views)
File Type: txt mbam-log-9-5-2008 (01-05-05).txt (2.1 KB, 1 views)
File Type: txt mbam-log-2008-09-05 (01-52-55).txt (1.5 KB, 1 views)
File Type: txt hs_err_pid3208.txt (13.4 KB, 1 views)
File Type: txt hijackthis.txt (8.3 KB, 1 views)
__________________


Last edited by steff; 5th September 2008 at 04:00 AM.
Reply With Quote
  #33  
Old 5th September 2008, 04:01 AM
Red Dragon's Avatar
Tech Mod
 

Join Date: Apr 2006
Location: Florida
Posts: 903
Blog Entries: 2
Send a message via MSN to Red Dragon
Default

Run Smitfraudfix
  • Download Smitfraudfix by S!ri from HERE
  • Double-click SmitfraudFix.exe
  • Select 1 and hit Enter
  • The report can be found at the root of the system drive, usually at C:\rapport.txt

==============================================

Panda Online Scan
  • Please visit Panda Online Scanner
  • Click on "Scan your PC".
  • A new browser window will open with Panda ActiveScan.
  • Click the big "Check Now" button
  • Enter your Country, State/Province, e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
Note: If this is the first time you scanned your PC, youŽll have to download the ActiveX controls (8 MB). The time it takes to download these can vary depending on your connection
  • Click on "Local Disks" to start the scan
  • Save the log file to your desktop


Attach both here - looks like MBAM is finding it but may be having trouble removing some of the files - i have something for that after we see these reports
__________________
Reply With Quote
  #34  
Old 5th September 2008, 04:52 AM
Red Dragon's Avatar
Tech Mod
 

Join Date: Apr 2006
Location: Florida
Posts: 903
Blog Entries: 2
Send a message via MSN to Red Dragon
Default

I wouldn't be so sure. It's easy enough to upload it - and the legit version usually only is seen on Asian versions of windows


Upload a File to Virustotal
Please visit Virustotal found HERE
  • Click the Browse... button
  • Navigate to the file C:\Windows\system32\conime.exe
  • Click the Open button
  • Click the Send button
  • Copy and paste the results back here please.

now I wanna see virustotal, report.txt, and panda log
__________________
Reply With Quote
  #35  
Old 5th September 2008, 05:16 AM
steff's Avatar
SofS Game Admin/Moderator
 
Join Date: Feb 2007
Location: UK
Posts: 3,515
Blog Entries: 1
Default

MD5: abc9002269e569538901109441660dd2
First received: -
Date: 09.01.2008 17:58:45 (CET) [>3D]
Results: 0/36
Permalink: analisis/12c29d9080aa9f7693fa58c74f18af87

So apparently it isn't a virus... strange though since that is the first time I've ever seen that process running.

edit - and the whole google problem was a general "click on a link" problem but MAMB sorted it.
Attached Files
File Type: txt rapport.txt (5.5 KB, 2 views)
File Type: txt ActiveScan.txt (6.3 KB, 2 views)
__________________

Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
XicemanX Malware Thread Red Dragon Techie Section 168 3rd April 2008 05:41 PM
Guide to Removing Malware Red Dragon Tutorial Section 0 22nd February 2008 04:21 AM
Virus/malware/spyware removal... TraPStaR Techie Section 6 2nd December 2006 08:42 PM


All times are GMT +1. The time now is 04:20 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109