BleepingComputer.com: Probable Rootkit infection

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • You cannot reply to this topic

Probable Rootkit infection Malware infection

#31 User is offline   erduggan 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 36
  • Joined: 01-May 11

Posted 08 May 2011 - 11:35 AM

Moments after typing the previous message, I got a NOD32 warning and the same Trojan as reported before quarantined.

5/8/2011 12:29:22 PM HTTP filter archive static.travelscream.com/scripts/TSWidget1.js?v=1.2 JS/Kryptik.AK trojan connection terminated - quarantined DH8J2091\Edward Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.

Odd. I never used to get these warnings so I guess I remain a little edgy.

Best,

Edward

This post has been edited by erduggan: 08 May 2011 - 05:31 PM


#32 User is offline   erduggan 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 36
  • Joined: 01-May 11

Posted 11 May 2011 - 03:30 PM

Three days in, and so far, so good. Are there any final stages that you need me to take,

Kind regards,

Edward

#33 User is offline   erduggan 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 36
  • Joined: 01-May 11

Posted 13 May 2011 - 06:05 PM

Hello Tea,


Is all well with you? I see no recent posts here or on Bleeping Computer, and I trust nothing is amiss?

The system appears to be stable, no anomalies to speak of, and I have hardened it considerably. I've instituted OpenDNS to help prevent such issues as my daughter's misadventure, and I've added to my malware armament.

I believe there may be a few tools you use still resident, and perhaps a couple of loose ends as you had indicated in your last communique.

Kind regards,

Edward

#34 User is offline   erduggan 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 36
  • Joined: 01-May 11

Posted 26 May 2011 - 06:55 PM

Hi Tea,

Got your message. I'm glad that you and your folks are all safe. What a terrible series of storms the mid-West has had. Don't feel pressured--when you get to it. All smooth here.

All good wishes,

Edward

Share this topic:


  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users