InterviewSolution
| 1. |
Solve : Help with trojan! No Internet Records? |
|
Answer» On my computer I run Kaspersky and I get this problem: when I start looking for daml9.sys What is daml9.sys? Not to be rude, it is good that you are trying to fix this but please stick to my instructions. Doing things outside of them will just confuse me and make this much harder in the long run. I need the Hijackthis log.Sorry for the confusion. I thought I'd give you all the logs I have.. Just to refresh what my problem is: On my computer I run Kaspersky and I get this problem: detected: Trojan program Trojan-Downloader.Win32.Hmir.alm File: c:\windows\system32\drivers\daml9.sys Kaspersky has deleted the file a couple of times but it comes back, when I try to open it in notepad, copy, paste, or anything it tells me that the file is being used. The hijackthis log is on the first post. Also, whenever I start looking for it on the registry the computer reboots, or when I set it to be deleted with Kaspersky it reboots without notice. I've been pretty successful with other malware until now. I've also looked for this trojan-downloader strand with only hits in an asian language.I need a new Hijackthis log from after RUNNING the other tools.Is Kaspersky updated? Do you have two antivirus installed? daml9.sys is a driver. C:\WINDOWS\system32\DRIVERS\daml9.sys Do you have an XP CD? If so, place it in your CD ROM drive and follow the instructions below:
If you want to see what was replaced, right-click My Computer and click on Manage. In the new window that appears, expand the Event Viewer (by clicking on the + symbol next to it) and then click on System. Thanks.. this is a work computer and I'll run that tomorrow, thanks alot!You gotta help me here. Quote from: evilfantasy on April 07, 2008, 03:45:19 PM What is daml9.sys? Quote from: evilfantasy on April 07, 2008, 04:08:10 PM Is Kaspersky updated? Do you have two antivirus installed? daml9.sys appeared out of nowhere, it's stuck onto the /windows/system32/drivers/ folder. I've looked it up online and have found nothing on it. All I know it's linked to this trojan downloader hmir.alm which in turn i've only seen on asian sites. I've been trying to see what it is linked to in the registry but as SOON as I get close to finding it the computer crashes. I've uninstalled AVG and any other anti-virus and kaspersky is up to date.OK, lets try this. Scan Suspicious File(s) Please visit one of the following: (Multiple sites are given in case one is not working) (If more than one file needs scanned they must be done separately and logs posted for each one) Copy the file path in the code box below. Code: [Select]C:\WINDOWS\system32\DRIVERS\daml9.sys
I haven't had a chance to run sfc.exe, does it matter if I have windows sp1? Quote from: lefloresg80 on April 08, 2008, 02:14:25 PM
Possibly, there have been loads of service packs released since SP1. Why don't you have SP2? |
|