Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 12th, 2005, 08:46 PM
rothen rothen is offline
Infrequent Poster
 
Join Date: Jan 2005
Posts: 3
Unhappy Something weird going on....

Somehow there is something going on inside my pc

I would really appreciate your help on this....

I use W2000 with Symantec AV + Sygate Firewall. At start-up Sygate reports "NT Kernel System has changed" with file identifier ntoskrnl.exe. Sygate asks whether that can access the internet and I say no. All seems fine but after five minutes or so IE denies I am connected. Mozilla the same. Outlook still runs as if nothing is the matter. Restart and the same happens again.

I ran spybot-search and for good measure installed Spyware blaster. No use. I uninstalled about everything not essential. No use. There still is something weird going on...

Any hint will help.
  #2  
Old January 12th, 2005, 08:56 PM
dog
 
Posts: n/a
PixelPup Re: Something weird going on....

Hi rothen,

Welcome to Wilders'

ntoskrnl.exe is a critical process in the boot-up cycle of your computer

Note: ntoskrnl.exe can be altered by the w32.bolzano and variants.

Info on : w32.bolzano -> http://securityresponse.symantec.com...2.bolzano.html

Quote:
W32.Bolzano has the chance to patch ntoskrnl.exe, the Windows NT kernel, located in the WINNT\SYSTEM32 directory. The virus modifies only 2 bytes in a security API called SeAccessCheck that is part of ntoskrnl.exe. This way Bolzano is able to give full access to all users to each file regardless of its protection, whenever the machine is booted with the modified kernel.

Norton will detect it ... try running an AV scan in "Safe" mode ... Tap F8 while booting ... Select option 1 "Safe Mode" ... When Norton finds it select "Repair"

Steve
  #3  
Old January 13th, 2005, 02:41 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: Something weird going on....

Hi Rothen, welcome to Wilders. If what Dog suggested doesn't work, I would suggest following the comprehensive steps found in General Cleaning.

If these steps do not resolve your situation, you will need to download and run “Hijack This” found here and post your log at one of the forums found at A-SAP. The two bigger forums for HijackThis log processing, (meaning they process more log threads each day than most others) are: SpywareInfo.com and CastleCops.com. Be sure to read their posting policy in the links at their log review forum sections prior to posting.

The steps mentioned in General Cleaning use software that ought to be part of your security, as an absolute minimum. Once your system is clean, please don’t hesitate to ask further about using these and other security software to protect your computer.

Hope this helps...

Let us know how you go.

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #4  
Old January 16th, 2005, 08:50 PM
rothen rothen is offline
Infrequent Poster
 
Join Date: Jan 2005
Posts: 3
Thumbs up Re: Something weird going on....

The treatment suggested, running Symantec AV in safe mode, worked wonders. I am eternally in debt.

What I do not know is how that little bugger got into my PC. I have a router making me invisible to the world (I hope), I have Sygate, Symantec AV and Spywareblaster running, I do a regular check with Spybot and yet I appear to be as vulnerable as the next guy.

Make me long for the good old EARN days...

Keep up the good work, you have been a real help.

Regards from the Dutch outback.
  #5  
Old January 17th, 2005, 07:28 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: Something weird going on....

Good to see Rothen, and thanks for keeping us up-to-date with your progress, You may want to take a look here for further discussion on security and how to make your system that much stronger and here for more.

This is what works really well for me, very simple to use and maintain.

Let us know how you go…

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #6  
Old January 17th, 2005, 05:34 PM
rothen rothen is offline
Infrequent Poster
 
Join Date: Jan 2005
Posts: 3
Default Re: Something weird going on....

Blackspear,

That seems a fairly comprehensive list of which I have at least half a dozen running. I will try the rest. Meanwhile Spybot found more W32.Bolzano's (That town has been a difficult place to live even in the best of times). Time to start making a donation to these guys !

And another little problem I have is that someone out there seems to be sending emails riddled with viruses under my email address (at least that's what I think is going on: unknown postmasters are sending me refusal notifications).

This really is a new world for me.
  #7  
Old January 17th, 2005, 05:40 PM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: Something weird going on....

Quote:
Originally Posted by rothen
That seems a fairly comprehensive list of which I have at least half a dozen running.
It is there as a guide, my system is set up like a fortress


Quote:
Originally Posted by rothen
Meanwhile Spybot found more W32.Bolzano's
I would suggest another run through General Cleaning until your system is clean, and if it keeps returning then download and run “Hijack This” found here and post your log at one of the forums found at A-SAP.


Quote:
Originally Posted by rothen
I have is that someone out there seems to be sending emails riddled with viruses under my email address (at least that's what I think is going on: unknown postmasters are sending me refusal notifications).
Once your system is clean you can safely ignore these sort of messages, but until then let’s work on confirming your system is actually clean

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:47 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums