1.

Solve : Trojan Rootkit problem?

Answer»

Hello

With RESPECT to the testfiles , yes I had created it for some perl program,
all three were created by me, it is not at all important so I can delete them if you PERCEIVE any ISSUE with these files

C:\test4
C:\test3
C:\test1

These two belong to different user profiles and was created previously not by me. Lisa was the previous
sys admin so hopefully this tmp file is clean .

c:\documents and settings\lisa\Start Menu\Programs\Startup\
prf1DE.tmp [2004-8-11 84]

c:\documents and settings\ranjitha.INFORSENSE\Start Menu\Programs\Startup\
prf32E.tmp [2004-8-11 84]

Thank you
Regards
dsgk
Quote

C:\test4
C:\test3
C:\test1

These are fine as long as you know what they are.

Quote
c:\documents and settings\lisa\Start Menu\Programs\Startup\
prf1DE.tmp [2004-8-11 84]

c:\documents and settings\ranjitha.INFORSENSE\Start Menu\Programs\Startup\
prf32E.tmp [2004-8-11 84]

Would you like to remove these? I don't think they should stay if they aren't being used.Hi

Thank you, sure I will delete those tmp files.

Thanks a lot for your timely help and wonderful support, before you helped me
out I was really STUCK, frustrated.

Have a great day !

Regards
dsgk
    OK but we aren't done yet

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Scan with
Panda ActiveScan 2.0

This scanner requires Internet Explorer

  • Once you are on the Panda SITE click the Scan your PC now button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Select the appropriate Yes or No to receiving marketing information
  • Click the Free Online Scan button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
.
Post the contents of the ActiveScan report in your next reply.


Discussion

No Comment Found