Computing.Net > Forums > Security and Virus > Any knowledgable folks here ?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Any knowledgable folks here ?

Reply to Message Icon

Name: JFPoitras
Date: August 11, 2004 at 19:34:01 Pacific
OS: Win XP Pro - SP1
CPU/Ram: P4 1.8 Mhz 512 Mb-Ram
Comment:

I just followed all the steps explained at http://www.greyknight17.com/spyware.htm and now i need help. I'm still afraid to be infected or to get infected again.

I'm doing this Spyware/Virus check cause i find my internet connection to be anormal ... i have way too many data uploading at all times. And also because i always fail to log in to my account at Hotmail.com, i get a blank page after confirming my handle and password. Yet i can access any other website (secure or not) !!!

My ZoneAlarm always warns me about "sysdrv.exe", "16winupdate32.exe" and the "Generic Host Process for Win32 Services", but if i stops those programs i have no acces to the web at all. What to do !?

I posted my most recent HTJ log file here ... http://greyknight17.com/bb/index.php?topic=63.0 ... if it can help

Thanx

Jean-Frédéric Poitras

jeanfredericpoitras@sympatico.ca



Sponsored Link
Ads by Google

Response Number 1
Name: EC
Date: August 11, 2004 at 20:29:00 Pacific
Reply:

These files are bad and must be dealt with now:

16winupdate32.exe is beagle variant

int114844.exe is spyware

SYSDRV.EXE Worm Then it connects to virus author site and downloads additional components to the local machine to e-mail automatically. The additional files will be stored in the name of SYSDRV.exe and SYSTMP.DLL in Windows directory - very bad

Go to www.housecall.antivirus.com and run their on-line AV scan

Download, install and run: AD AWARE, SPYBOT and TROJAN HUNTER from
http://www.trojanhunter.com/


These programs are responsible for all your upload activity. I'd suggest you address these immediately, or at least disconnect from the NET until you can.


0

Response Number 2
Name: kinghe
Date: August 11, 2004 at 22:08:39 Pacific
Reply:

Can you send these"sysdrv.exe,16winupdate32.exe"with compressed file to me?i will check them

Send suspecied file to me with compressed file.my email:virus@shanguo.com


0

Response Number 3
Name: BlueRaja
Date: August 12, 2004 at 00:27:45 Pacific
Reply:

kinghe wtf why are you going around collecting viruses?


0

Response Number 4
Name: EC
Date: August 12, 2004 at 14:41:46 Pacific
Reply:

"Collecting" viruses is hopefully just another name for studying them, as that's how it's done.
Get an older Windows box, with a Pentium 1 processor and some RAM and load up and there are some analytical programs that even assist in researching.


0

Response Number 5
Name: BlueRaja
Date: August 12, 2004 at 16:08:16 Pacific
Reply:

Well there are some people who collect viruses for...hell I dunno, sport, as one would collect stamps or coins...
There are others who collect them to use them against others...


0

Related Posts

See More



Response Number 6
Name: suzi
Date: August 12, 2004 at 22:04:36 Pacific
Reply:

EC, you said:
"some analytical programs that even assist in researching."

Do you have the names or links for any of those programs? I'd like to find something like that.

Thanks.



0

Response Number 7
Name: sc00pex
Date: August 15, 2004 at 00:27:19 Pacific
Reply:

http://ethereal.com/ nice free packet sniffer to analyse network traffic

http://sysinternals.com/ do a registry monitor, file monitor (log process name, command(open, create, read, write, queryvalue,close), file path or registry key, n other values n things. tcpview for viewing all open / connected / unconnected programs / ports / addresses, and a great process explorer (all free) process explorer can view all handles open by a process, and all dll's loaded by a process (some malware hides behind explorer.exe or/and iexplorer.exe)

http://hexworkshop.com/ for viewing binary files .. (

upx.com for unpacking ones packed with upx :d

http://datarescue.com/ for ida, interactive disassembler, to analyze program code

i've heard something about a vm for windows, emulating windows inside windows for safety when playing with evil programs .. havent looked for it yet


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Any knowledgable folks here ?

I think Ive Been Google 'Jacked www.computing.net/answers/security/i-think-ive-been-google-jacked/24739.html

Where can we post Hijack This Logs? www.computing.net/answers/security/where-can-we-post-hijack-this-logs/12239.html

Can this machine be saved? www.computing.net/answers/security/can-this-machine-be-saved/12549.html