View Full Version : trojan in system32 ????
greenfly
April 8th, 2007, 06:24 PM
My NOD32 with extra settings found a lot of trojan in system32 . what i can do???? take a look..............
http://img459.imageshack.us/img459/3259/lllzo0.th.jpg (http://img459.imageshack.us/my.php?image=lllzo0.jpg)
I can't end the process (winlogon.exe) to delete this files??????????
flyrfan111
April 8th, 2007, 06:53 PM
Reboot, seems like someof those log entries say the trojan will be deleted on rebooting. You should also try running the scan in safe mode, that makes it easier as not as many processes load and our easier to delete
greenfly
April 8th, 2007, 06:57 PM
I have do that---nothing
Get
April 8th, 2007, 07:15 PM
Best is to become a member here (http://www.castlecops.com/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html) and post a Hijackthislog.
greenfly
April 8th, 2007, 08:03 PM
GET
-{ Quote: "Best is to become a member here and post a Hijackthislog." }-
the guys here are too kind an helpful....They've helped me many time....::)
I have made a Hijack-thing...check the file for delete,,but they appear again???!!!???
ASpace
April 9th, 2007, 12:12 AM
Hello Greenfly .
Make sure your definition is up-to-date by pressing Control Center -> Update -> Update now.
Make sure your settings are the same as this tutorial (http://www.wilderssecurity.com/showthread.php?t=37509).
Boot in Safe Mode (http://support.microsoft.com/kb/315222)
Open NOD32's on-demand scanner from Start -> Programs-> ESET ->NOD32 ,make sure you use Control Center profiles and perforum full Scan&Clean over your hard drives . NOD32 will take care of these threats
You can also use Ewido Micro (http://download.ewido.net/ewido_micro.exe) for second opinion
If this still doesn't help , can you please also send a HijackThis log file to ESET Tech Support (support[at]eset.com) along with more information and a link to this thread.You might have something like trojan-downloader/dropper undetected by NOD32 . Let us know how you go. :thumb:
Email address edited to prevent it from being harvested by robots
Get
April 9th, 2007, 05:57 AM
-{ Quote: "I have made a Hijack-thing...check the file for delete,,but they appear again???!!!???" }-
Yes, but you shouldn't use hjt yourself. Post a log in a forum like CastleCops and people there will tell you what to do and that's in this case a lot more then just click "Fix" :), but by all means do it the way other wilders-people tell you if that makes you feel more comfortable.;)
FanJ
April 9th, 2007, 08:06 PM
-{ Quote: "My NOD32 with extra settings found a lot of trojan in system32 . what i can do???? take a look..............
" }-
Official complaint:
Posting pictures from other sites (http://www.wilderssecurity.com/showthread.php?t=171258)
clicx
April 10th, 2007, 02:09 AM
winlogon.exe is a windows system process
Marcos
April 10th, 2007, 02:43 AM
For instance, Wigon patches the system file winlogon.exe and some other trojans inject their dlls into it. I'd suggest Greenfly to email support[at]eset.com and enclose a link to this thread.
greenfly
April 10th, 2007, 06:33 AM
Get :
-{ Quote: " Best is to become a member here and post a Hijackthislog." }-
Thanks Man ,, the guys are great ...;D they solving my problem "in progres"
Get
April 10th, 2007, 06:47 AM
-{ Quote: "Thanks Man" }-
You're welcome. Good luck :).
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums