Forum Home
Press F1
 
Thread ID: 118837 2011-06-23 04:00:00 Malware Experts SolMiester (139) Press F1
Post ID Timestamp Content User
1211388 2011-06-23 08:40:00 If its 32 bit, run trojan remover scan then select all options under the utils menu Speedy Gonzales (78)
1211389 2011-06-23 09:05:00 Malware bytes normally gets the infection out, thats not the problem, its the damage it does that really screws things up.

From the XP ones I have done, it drops a couple of random named exe and other files files in the C:\Documents and Settings\UserName\Local Settings\Temp folder.
wainuitech (129)
1211390 2011-06-23 10:22:00 Combofix now restores your start menu shortcuts after removing the infection. First time I encountered it, I unhid the user folder but didn't notice the missing start menu shortcuts until after I had run ccleaner. Greven (91)
1211391 2011-06-23 11:00:00 That must have been since last Saturday (combofix) - that was when I did the last one, and while combo fix removed several infections the start menu was still toast.

The PC in question had 4 users accounts, each users start menu was in a different state of "disaster", ranging from completely blank to half there but not working :)
wainuitech (129)
1211392 2011-06-23 19:44:00 If its the same bug that I have had, a repair install doesn't work (tried it in XP)

Did for me. XP.
pctek (84)
1211393 2011-06-23 21:53:00 Did for me. XP. How many user accounts ??

The one I tried it on had four user accounts, and it didn't change any of them. Thats why I tried the repair install, LOTS of data between four accounts :waughh:
wainuitech (129)
1211394 2011-06-25 00:49:00 Sounds like a bastard. Luckily I have not encountered this one (yet) Agent_24 (57)
1211395 2011-06-25 05:21:00 Any ideas on how this one is getting picked up? Is it email attachments, image file payload, web-link or what?

It would be nice to know what to watch out for, especially since i picked up a similar nasty a while back and still have no idea how it got in.

I am usually super cautious, but clearly that is not going to help if the infection is by other than the commonly known and avoidable sources.

Cheers

Billy 8-{)
Billy T (70)
1211396 2011-06-25 05:36:00 Most of the time, these infections are installed by whats known as a Drive By Download (en.wikipedia.org) number 2 & 3 in that link explain it better. wainuitech (129)
1211397 2011-06-25 05:51:00 It may also happen if you dont keep windows up to date Speedy Gonzales (78)
1 2 3