Forum Home
Press F1
 
Thread ID: 96058 2008-12-27 20:43:00 I would like to know about these threats JOEJG (10295) Press F1
Post ID Timestamp Content User
732865 2008-12-27 20:43:00 I've wasted over 7 hours trying to figure out why my computer was having problems. It seems after using Hijackthis, 3 files stood out as Unknown owners. After deleting in safe mode, they appeared back after a reboot. Then after I manually deleted them, they could not be found in the windows search, just for me to find them in the admin tools menu, so I disabled them. Yet even after a Ad-Aware scan and my Norton virus checker, the files or programs would still bypass and would not be found.

The trojans are called CbEvtSvc, bEvtService and bEvtSvcE.

Any possible way of deleting them, and where they could've came from? Otherwise I'll have to fresh install XP as they've gone and created and modified spam topics.

Thanks.
JOEJG (10295)
732866 2008-12-27 20:48:00 Disable system restore, if its XP.

Get trojan remover and malwarebytes in my sig below

Update both then scan

Then select all options under utilities in Trojan remover
Speedy Gonzales (78)
732867 2008-12-27 20:54:00 Thanks, Speedy Gonzales, you are fast lol. I would've posted my Hijackthis but I couldn't get online at the time since at the time I was in safe mode and my connection wasn't active. Plus the CPU was acting very slow.

Perhaps tommorow if I have trouble I'll save to a disc and then use my laptop, and post here.
JOEJG (10295)
732868 2008-12-27 20:58:00 Theyre probably running in the background. Disable system restore

If you have XP, boot into safe mode / networking

Then get the 2 programs I posted before. Come back here. And click on the links belw
Speedy Gonzales (78)
732869 2008-12-27 21:02:00 I will do, thank you. I wondered why they weren't going even after manually looking for them and deleting. They even created topics like finance with a bit of spam text, as I looked through my comp via last modified and observed as such. Just a real pain to be honest.

Edit: I didn't know that Trojan Remover and the other costed money. I don't think I can afford right now...
JOEJG (10295)
732870 2008-12-27 21:07:00 Looks like this is what it belongs to (vil.nai.com)

I would get off the net right now. Because its a backdoor trojan

Trojan remover is a trial for 30 days. Malwarebytes is free
Speedy Gonzales (78)
732871 2008-12-27 21:20:00 The most serious of all? I've noticed it was modifying and creating those topics like I said, but I deleted what I could see was from them and created today.

Do they go as far as taking money or playing with card details? My dad orders rarely, but this is scary! Should I just fresh install XP and be done with it? Or will it not go? I've little on it worth worrying about.

By the way I'm using another computer now. This is not the one. So I will download them to a disc here without needing the Internet on the trojan comp.
JOEJG (10295)
732872 2008-12-27 21:44:00 A backdoor trojan can do whatever it wants to.

It'll probably steal cc info as well. So, DONT do online banking on it, till its fixed
Speedy Gonzales (78)
732873 2008-12-27 23:46:00 Not a human hack? Those folders it created where all just common reference text, looked a bit like a bot to me.

I've fresh installed reformated my C drive after running Trojan Remover, it picked up 4 of them. I will post Hijackthis when more gets sorted.
JOEJG (10295)
732874 2008-12-27 23:54:00 If you did a clean install, (it wipes everything) it wouldnt be there.

It sounds like you reinstalled windows over windows.

That wont get rid of it. It just overwrites whats on the hdd, then reinstalls windows.

Did you tell Trojan remover to remove them?? Then reboot?
Speedy Gonzales (78)
1 2