![]() |
|
#1
|
||||
|
||||
|
This is the log that posted in my NOD32
Quote:
Quote:
Quote:
Quote:
Can anyone help me how to clean this trojan from my system? |
|
#2
|
|||
|
|||
|
have u rebooted yet so that nod32 may clean/delete the trojan?
__________________
|
|
#3
|
||||
|
||||
|
The first log looks like it was just a scan, not a scan & clean - please try this.
After you restarted the PC were the detections in the second log gone? Third and fourth logs are on their own quite normal. Cheers ![]()
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#4
|
|||
|
|||
|
how do i properly paste a log of NOF32? is that the rigght way?
Code:
Last edited by Blackspear : July 19th, 2006 at 02:13 AM. Reason: Disabled link |
|
#5
|
||||
|
||||
|
Quote:
Some of the entries are there from when ewido and other have attempted to check a file and NOD32 has checked it first on access...
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#6
|
|||
|
|||
|
ok this is my log
Code:
how do i know my trojan.zlob.zb is leaned frm my system? ewido software doest detect anything |
|
#7
|
||||
|
||||
|
ewido is not detecting anything because NOD32 is preventing anything from accessing the detected files.
Please scroll up a bit to posts #2, #3 and #5 and let us know how you go after that... ...or if post#6 is after you have rebooted your PC already then it should now be just fine ![]() Cheers ![]()
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) Last edited by NOD32 user : July 19th, 2006 at 02:01 AM. Reason: or if post#6 is after... |
|
#8
|
|||
|
|||
|
done.
if nod32 doesnt led anything access..so whats the use of ewido to me now? |
|
#9
|
||||
|
||||
|
Quote:
If you wish to use ewido to double check your system I would suggest the following
That is really all that is necessary since after having first run a full scan anything NOD32 would prevent access to because of detection should already be gone anyway... Also, you may wish to verify that some registry cleaner hasn't removed the entry for the NOD32 Quarantine folder - if it has I'd suggest restoring it. Cheers ![]()
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#10
|
|||
|
|||
|
Quote:
thanks for the reply anyway, how do i done that im using registry mechanic |
|
#11
|
||||
|
||||
|
Not entirely familiar with registry mechanic, but you should be able to restore it as follows:-
Cheers ![]()
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#12
|
|||
|
|||
|
where can i get passowrd and username for nod32
|
|
#13
|
||||
|
||||
|
You can buy a username and password (licence) for NOD32 from pretty much any reseller worldwide, but unless there was a special reason I would suggest your local reseller...
What part of the world are you in?
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#14
|
|||
|
|||
|
im in singapore.
anyway, when i opened my internet explorer, it direct me to www,sysprotectionpage.net (if im nt wrong) and also is it safe to remove HKLM\SOFTWARE\Microsoft\Windows\CurrentWindows\policies\explorer\run\\kernel32.dll Which Infected wit Trojan.Small and C:\Windows\System32\isnotify.exe which infected with Downloader.Zlob.zd can i remove both of this file which is in my quarantine now? Last edited by Bubba : July 19th, 2006 at 09:11 AM. Reason: modified URL to not be linkable....CWS.VCodec group |
|
#15
|
||||
|
||||
|
Singapore - you should be able to find a local reseller that pleases you -->HERE<--
Yes - clean out your quarantine any time you choose. Cheers ![]()
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#16
|
|||
|
|||
|
Quote:
Please , check your Private Messages ! |
|
#17
|
|||
|
|||
|
my internet explorer still redirects me to www,sysprotectionpage.net , no matter how many thousand times i sca with ewido or nod32. not that i also use software like
HijackThuis SmitFraud UnDLL for NOD32 FixReg.req SmitREm bla bla bla.... and also online scan...panda software.. but my IE still redirects me to www,sysprotectionpage.net and also in my C:\ theres alot of sqmdata0x *x = number pls pls help.im begging. Last edited by Bubba : July 19th, 2006 at 10:19 PM. Reason: modified URL to not be linkable....CWS.VCodec group |
|
#18
|
||||
|
||||
|
Hello sLapshock,
As I have noted in 2 of your posts I have edited....that clickable link is a known CWS.VCodec group of badware folks. If you don't mind....if you feel you need to post those links in the future in this thread....Please make them non-clickable. Thanks, Bubba As for your problem....it appears you recognize that it is a possible Smitfraud problem. As such....that would normally require running a special tool and for that reason I suggest you post a HijackThis log at one of the below Forums that deal with this sort of thing. http://gladiator-antivirus.com/forum...?showforum=170 http://bfccomputerhelp.com/index.php?showforum=5 http://forums.subratam.org/index.php?showforum=7 Just select one Forum to post to. Your problem probably needs special attention since I don't think regular scanners will deal with it. Last edited by Bubba : July 19th, 2006 at 10:24 PM. |
|
#19
|
||||
|
||||
|
Hi sLapshock,
Please be careful when posting reference to a potentially malicious web address that you use the advanced method to make your post and uncheck the box below that says 'Automatically parse links in text', or use commas or something instead of the dots - the mods have helped you with this a couple of times so far. (OK Bubba - you beat me to it )Have you reset your homepage to something you like and it is automatically being changed back? Or do you need some help to change it?
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) Last edited by NOD32 user : July 19th, 2006 at 10:21 PM. Reason: as Bubba said... |
|
#20
|
|||
|
|||
|
sorry guys, i will not pose malicious links.
whats about the sqmdata01.sqm theres' alot in my c:\ |
|
#21
|
||||
|
||||
|
Quote:
Or Windows Live Massenger ?
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#22
|
||||
|
||||
|
Please download VundoFix.exe to your desktop.
1 Reboot your PC into "Safe Mode". 2. Double click on VundoFix.exe 3. Place a tick next to "Run VundoFix" as a task. 4. You will receive a message saying VundoFix will close and re-open in a minute or less. 5. Click "OK". 6. When VundoFix re-opens, click the "Scan for Vundo" button. 7. Once it's done scanning, click the "Remove Vundo" button. 8. You will receive a prompt asking if you want to remove the files, click "Yes". 9. Once you click yes, your desktop will go blank as it starts removing Vundo. 10. When completed, it will prompt that it will shutdown your computer, click "Ok". 11. Turn on your computer. Let us know how you go... Cheers ![]()
__________________
"Illegitimis non carborundum"
translation: "Don't let the bastards grind you down" U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946) Two Photographers |
|
#23
|
|||
|
|||
|
what is that software?
nope. |
|
#24
|
||||
|
||||
|
Quote:
Cheers ![]()
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#25
|
|||
|
|||
|
okay, i will try it. im at school now. is there any other methods avail?
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|