Re: ***NEED HELP PLEASE***
- From: "David H. Lipman" <DLipman~nospam~@Verizon.Net>
- Date: Sat, 14 Oct 2006 15:53:59 -0400
From: "Emily" <Emily@xxxxxxxxxxxxxxxxxxxxxxxxx>
| So that means this very newsgroup can NOT do much in helping people with
| their malware problems if all we could do is suggest scanners for them to
| use.
| Looking at a hijackthis log would give us all the details of the problem and
| we would know then the right tool to use instead of suggesting scanners that
| will not fix their problem.
|
| We might as well save them the time and trouble of installing unnecessary
| programs and just point them straight to those forums. Unless of course the
| problem is very obvious and we know the exact scanner that fixes the problem.
|
I am putting the following in this thread for ALL readers !
There is now a nastry Trojan called "Downloader.agent.awf" and is making HIJack This logs
even LESS effective as ever.
This Trojan is REPLACING legitimate files with the same named file but is infact the Trojan.
From a HJT analysis POV you would NOT know the difference between the legitimate file andthe replacement file. You need to comapre the file sizes and/or file CheckSum values.
Here is an example...
One knows that this would be a Logitech Mouse software driver...
C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
However, this Trojan is replacing EM_EXEC.EXE with a Trojan. A HJT log will NOT show this
fact and ONLY an anti virus scanner will detect and remove the malware.
At this time I am NOT sure of the validity of the statement that the Trojan creates a backup
of the legitimate file prior to replacing it with the Trojan file.
--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
.
- References:
- Re: ***NEED HELP PLEASE***
- From: Joec148
- Re: ***NEED HELP PLEASE***
- From: TomC
- Re: ***NEED HELP PLEASE***
- From: Emily
- Re: ***NEED HELP PLEASE***
- From: David H. Lipman
- Re: ***NEED HELP PLEASE***
- Prev by Date: Re: *PLS HELP*
- Next by Date: Re: Norton and home network
- Previous by thread: Re: ***NEED HELP PLEASE***
- Next by thread: Re: ***NEED HELP PLEASE***
- Index(es):
Relevant Pages
|