Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > Trojan Defence Suite
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 22nd, 2003, 07:34 PM
Q Section's Avatar
Q Section Q Section is offline
Frequent Poster
 
Join Date: Feb 2003
Location: Headquarters - London & Field Offices - Worldwide
Posts: 679
Default Alert question

Hello Everyone

Upon doing a scan with TDS3 the report was basically everything was OK except
- Alert - File has changed : C:\WINDOWS\win.ini
- Alert - File has changed : C:\WINDOWS\system.ini

Now when we look at win.ini and system.ini via msconfig what are we supposed to look for? Nothing is obvious as being wrong but it would take quite some time to check both those ini files completely. What did we miss?

Thank you for your assistance.
__________________
HMSS Q Section
Visualise World Righteousness
Semper Ad Fundum
Careers in the SECRET INTELLIGENCE SERVICE <--Click link for more information
  #2  
Old May 23rd, 2003, 12:08 AM
Dan Perez's Avatar
Dan Perez Dan Perez is offline
Global Moderator
 
Join Date: May 2003
Location: Sunny San Diego
Posts: 1,495
Default Re:Alert question

Hey Q,

The most important things to check are the

Load=

and

Run=

statements in the win.ini. Anything on the same line as those (assuming there is no "rem" or ";" at the start of that line) is set to start automatically when Windows launches.

__________________
"Whan alle tresors arn tried, Treuthe is the beste." Piers Plowman (William Langland)
  #3  
Old May 23rd, 2003, 12:21 AM
Q Section's Avatar
Q Section Q Section is offline
Frequent Poster
 
Join Date: Feb 2003
Location: Headquarters - London & Field Offices - Worldwide
Posts: 679
Default Re:Alert question

Hello David

In the win.ini we have no Run & Load in the left column. See screenshot.
Attached Images
 
__________________
HMSS Q Section
Visualise World Righteousness
Semper Ad Fundum
Careers in the SECRET INTELLIGENCE SERVICE <--Click link for more information
  #4  
Old May 23rd, 2003, 12:22 AM
Q Section's Avatar
Q Section Q Section is offline
Frequent Poster
 
Join Date: Feb 2003
Location: Headquarters - London & Field Offices - Worldwide
Posts: 679
Default Re:Alert question

List continued
Attached Images
 
__________________
HMSS Q Section
Visualise World Righteousness
Semper Ad Fundum
Careers in the SECRET INTELLIGENCE SERVICE <--Click link for more information
  #5  
Old May 23rd, 2003, 12:36 AM
Wayne - DiamondCS's Avatar
Wayne - DiamondCS Wayne - DiamondCS is offline
Security Expert
 
Join Date: Jul 2002
Location: Perth, Oz
Posts: 1,533
Default Re:Alert question

Quote:
Fully Layered - 98SE, IE5.5, Outpost FW, NOD32 AV, TDS3 AT, WormGuard AW, RegistryProt RP, Port Explorer PT, Spybot S&D and more!

Now seems like a good time to add another weapon to your arsenal ...
Autostart Viewer is available for free at http://www.diamondcs.com.au/index.php?page=asguard
It shows you all programs that have the capability of autostarting before and after Windows loads

Best regards,
Wayne
__________________
DiamondCS (Est. 1986) - Celebrating 20 Years ...
Home of Port Explorer, ProcessGuard, and check out all our other freeware security tools!
  #6  
Old May 23rd, 2003, 01:17 AM
Q Section's Avatar
Q Section Q Section is offline
Frequent Poster
 
Join Date: Feb 2003
Location: Headquarters - London & Field Offices - Worldwide
Posts: 679
Default Re:Alert question

Hello Wayne

Sounds good but tried to get it in April and it would not work. Just now deleted it and re-downloaded it. Still no go. Do you have any ideas? We get a popup that says, "Cannot find the file 'asviewer (or one of its components). Make sure the path and filename are correct and that all required libraries are available."

We do believe we possibly have an ActiveX problem as SpywareGuard has a runtime error 429 (something about ActiveX unable to create object). All else seems to be running correctly. :'(
__________________
HMSS Q Section
Visualise World Righteousness
Semper Ad Fundum
Careers in the SECRET INTELLIGENCE SERVICE <--Click link for more information
  #7  
Old May 23rd, 2003, 03:25 AM
Dan Perez's Avatar
Dan Perez Dan Perez is offline
Global Moderator
 
Join Date: May 2003
Location: Sunny San Diego
Posts: 1,495
Default Re:Alert question

Not sure about the the ASViewer problem you are having but the stuff you showed was not the win.ini but merely msconfig's parsing of win.ini. If you do a file search for win.ini and open it it up in notepad.exe you will see what I mean. I am not too familiar with msconfig so I am not sure where it would "put" the statements I mentioned but my guess would be in the "programs" section.

Hope this helps,

Dan
__________________
"Whan alle tresors arn tried, Treuthe is the beste." Piers Plowman (William Langland)
  #8  
Old May 23rd, 2003, 03:49 AM
Dan Perez's Avatar
Dan Perez Dan Perez is offline
Global Moderator
 
Join Date: May 2003
Location: Sunny San Diego
Posts: 1,495
Default Re:Alert question

On further thought...

the issue with AutoStart Viewer is puzzling since it is only a single executeable. I doubt ActivX has anything to do with it but perhaps some other security software is interfering (maybe SpyWare guard?). ASViewer is a very handy tool so I would recommend you try to temporarily exit from other software to see what is the point of "obstruction".

Regards,

Dan
__________________
"Whan alle tresors arn tried, Treuthe is the beste." Piers Plowman (William Langland)
  #9  
Old May 23rd, 2003, 04:00 AM
LowWaterMark LowWaterMark is offline
Administrator
 
Join Date: Aug 2002
Location: New England
Posts: 15,525
Default Re:Alert question

I agree with you Dan. It's much easier (for me at least) to open these .ini files in Notepad then it is to look at their entries with msconfig. (I just never got used to msconfig )

And I think it's easier to save off copies of these .ini files to a safe place so that at a future point, if you think they've been changed, you can go back and see what they were before - comparing them side-by-side in Notepad screens.
  #10  
Old May 23rd, 2003, 06:19 AM
Q Section's Avatar
Q Section Q Section is offline
Frequent Poster
 
Join Date: Feb 2003
Location: Headquarters - London & Field Offices - Worldwide
Posts: 679
Default Re:Alert question

These were right at the beginning of the file (as found in C:\Windows)

[windows]
load=
run=
NullPort=None

So that does not seem to be a problem but something had changed. We doubt there is a trojan or virus or malware in the computer just now. We have been doing a considerable amount of downloading (updates etc.).
__________________
HMSS Q Section
Visualise World Righteousness
Semper Ad Fundum
Careers in the SECRET INTELLIGENCE SERVICE <--Click link for more information
  #11  
Old May 23rd, 2003, 06:30 AM
Patrice Patrice is offline
Frequent Poster
 
Join Date: Apr 2003
Location: Antarctica
Posts: 571
Default Re:Alert question

Hi QSection,

sometimes this appears if you have done a Windows Update for example. Just check it throughly when it appears, but when you are sure that you have installed something which needed to restart it's probably that one.

Regards,

Patrice
__________________
I know nothing except the fact of my ignorance. (Socrates 470-399 bc)
  #12  
Old May 23rd, 2003, 06:31 AM
Q Section's Avatar
Q Section Q Section is offline
Frequent Poster
 
Join Date: Feb 2003
Location: Headquarters - London & Field Offices - Worldwide
Posts: 679
Default Re:Alert question

Quote:
quoting: QSection link=board=5;threadid=9546;start=0#msg62522 date=1053667041]
"Cannot find the file 'asviewer (or one of its components). Make sure the path and filename are correct and that all required libraries are available."

It really seems like it would be a great idea to learn which libraries are required for Autostartviewer.

Thank you.
__________________
HMSS Q Section
Visualise World Righteousness
Semper Ad Fundum
Careers in the SECRET INTELLIGENCE SERVICE <--Click link for more information
  #13  
Old May 23rd, 2003, 06:51 AM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re:Alert question

Hi QSection,
I unzipped the ASViewer in a folder created for that and ran it from the same place, or from there a shortcut to the desktop, no libraries missing here....... There is nothing to install, just run the file.
__________________
Jooske
"o_o"
  #14  
Old May 23rd, 2003, 06:52 AM
Dan Perez's Avatar
Dan Perez Dan Perez is offline
Global Moderator
 
Join Date: May 2003
Location: Sunny San Diego
Posts: 1,495
Default Re:Alert question

It may be different for Win98 but for Win2K the dependencies seem to be

advapi32.dll
comctl32.dll
comdlg32.dll
gdi32.dll
kernel32.dll
ole32.dll
oleaut32.dll
shell32.dll
shfolder.dll
user32.dll
__________________
"Whan alle tresors arn tried, Treuthe is the beste." Piers Plowman (William Langland)
  #15  
Old May 23rd, 2003, 07:10 AM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re:Alert question

4dmain.exe (mouse program, can differ)
asviewer.exe
windows\system:
4dhook32.dll
comdlg32.dll *
shfolder.dll *
comctl32.dll *
shlwapi.dll
msvcrt.dll
oleaut32.dll *
ole32.dll *
user32.dll *
gdi32.dll *
advapi32.dll *
kernel32.dll *

This is what i get via TDS looking in Process list and the modules behind the asviewer
The * are the same in Dan's list, running win98SE too.
__________________
Jooske
"o_o"
  #16  
Old May 23rd, 2003, 07:16 AM
Dan Perez's Avatar
Dan Perez Dan Perez is offline
Global Moderator
 
Join Date: May 2003
Location: Sunny San Diego
Posts: 1,495
Default Re:Alert question

Hey Jooske,

If I am not mistaken that list equates to what modules the process has open, but as the presence of your mouse modules indicates, this doesn't necessarily indicate any dependency (as I am sure you are aware). I got my list by using the Faber Toys "examine file" function on the asviewer.exe and listed the ones shown in the bottom left "Imported Modules" window.
__________________
"Whan alle tresors arn tried, Treuthe is the beste." Piers Plowman (William Langland)
  #17  
Old May 23rd, 2003, 03:24 PM
Q Section's Avatar
Q Section Q Section is offline
Frequent Poster
 
Join Date: Feb 2003
Location: Headquarters - London & Field Offices - Worldwide
Posts: 679
Default Re:Alert question

Thanks Dan
Hello Jooske

Well we did a check to make sure we had all the files mentioned and we do. So that leaves two possibilities, right? Either one or more of the Windows files are corrupted or there is a conflict with some other program. Any further suggestions? BTW - Start>Run>asviewer does not do anything.
__________________
HMSS Q Section
Visualise World Righteousness
Semper Ad Fundum
Careers in the SECRET INTELLIGENCE SERVICE <--Click link for more information
  #18  
Old May 23rd, 2003, 03:44 PM
Patrice Patrice is offline
Frequent Poster
 
Join Date: Apr 2003
Location: Antarctica
Posts: 571
Default Re:Alert question

Hi QSection,

Could you once start Windows 98SE in Safe Mode (press F8 during startup) and try to load Autostart Viewer then? When you start up Windows in that mode, all other processes and libraries are not started -just the Windows components are started. Then you know if it's a Windows problem or an incompatibility with another software on your computer.

Best regards,

Patrice
__________________
I know nothing except the fact of my ignorance. (Socrates 470-399 bc)
  #19  
Old May 23rd, 2003, 05:18 PM
Q Section's Avatar
Q Section Q Section is offline
Frequent Poster
 
Join Date: Feb 2003
Location: Headquarters - London & Field Offices - Worldwide
Posts: 679
Default Re:Alert question

Hello Patrice

We tried Safe mode and its a no-go with Start>Run>asviewer as we got the same popup as listed above. Tried Explorer>Program Files>Autostartviewer>asviewer.exe and it worked. Next we will try stopping programs one by one from the Task Manager. We will get to the bottom of this yet!
__________________
HMSS Q Section
Visualise World Righteousness
Semper Ad Fundum
Careers in the SECRET INTELLIGENCE SERVICE <--Click link for more information
  #20  
Old May 23rd, 2003, 06:38 PM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re:Alert question

No matter where you extracted the download, i did in a special folder, there is a file asviewer.exe
You might like to create a shortcut to that on your desktop.
Doubleclick the thing and it should just run.
Or dig via windows explorer for the file and click to run it as you did and it is the same effect.
__________________
Jooske
"o_o"
  #21  
Old May 23rd, 2003, 06:52 PM
Q Section's Avatar
Q Section Q Section is offline
Frequent Poster
 
Join Date: Feb 2003
Location: Headquarters - London & Field Offices - Worldwide
Posts: 679
Default Re:Alert question

Dear Jooske

We already had a shortcut and that was the first place we tried. It did not work. Did? Ha we found the problem. We tried the Taskmanager delete one at a time routine and when we closed the second program we found the answer. We had a program that was not yet in Beta stage and closing that did the trick. (We restarted the first program) Now Autostart Viewer works perfectly. What was that second program you say? It was Spybot S&D Resident (Beta). This is NOT the same application found in Spybot S&D>Tools>Resident. That last one is alright and should be used if one has Spybot S&D.

Thank you and Everyone for the assistance.
__________________
HMSS Q Section
Visualise World Righteousness
Semper Ad Fundum
Careers in the SECRET INTELLIGENCE SERVICE <--Click link for more information
  #22  
Old May 23rd, 2003, 06:52 PM
Dan Perez's Avatar
Dan Perez Dan Perez is offline
Global Moderator
 
Join Date: May 2003
Location: Sunny San Diego
Posts: 1,495
Default Re:Alert question

Ah, it was a pathing issue.

If you prefer to run it from the Start-Run command you will need to place the single exe somewhere in your PATH such as in the root of your windows folder
__________________
"Whan alle tresors arn tried, Treuthe is the beste." Piers Plowman (William Langland)
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > Trojan Defence Suite « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:35 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums