It's the first time some smartass broken into my computer, usually
AVAST had done it's job and sometimes I would do cleaning via
MAlwarebytes and superantivirus and Truesword, but now it's all gone
to some shithole.
...There are a few trojans and bacdoor agents, some guy , is very
pleased with the informations on my computer so he comes back here and
there.
What to do to clean it up...hijack report ?
...uff...
alwarebytes' Anti-Malware 1.38
Database version: 2358
Windows 5.1.2600 Service Pack 2
1.7.2009 21:01:43
mbam-log-2009-07-01 (21-01-43).txt
Scan type: Full Scan (G:\|)
Objects scanned: 131007
Time elapsed: 4 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 9
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Not
selected for removal.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ksi32sk
(Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\amd64si
(Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ati64si
(Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\securentm
(Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\antiwpa (Trojan.I.Stole.Windows) -> Not selected for
removal.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\acpi32
(Rootkit.Spamtool) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\i386si
(Rootkit.Spamtool) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ws2_32sik
(Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\netsik
(Rootkit.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Not
selected for removal.
I have trojan agents on windows WPA files also, but didn't deleted
them,as i think these are cracked files so program sees them as
trojans !?
thanks if so!
> snip complete waste of our time
>
> I have trojan agents on windows WPA files also, but didn't deleted
> them,as i think these are cracked files so program sees them as
> trojans !?
you should go take your stolen, infected, cracked arse up the road.
--
Virus Removal http://max.shplink.com/removal.html
Keep Clean http://max.shplink.com/keepingclean.html
Change nomail.afraid.org to gmail.com to reply by email.
nomail.afraid.org is specifically setup for use in USENET
Snip, snip...
Now, you may wish to follow with SAS:
<http://www.superantispyware.com/>
SAS is best run in the Safe Mode.
I'm sure that you can re-examine your security practices for increased
protection. Why aren't you at SP3? What other patches and fixes are
you missing? Are you using a good NAT router?
Please update this thread with your progress.
Pete
--
1PW @?6A62?FEH9:DE=6o2@=]4@> [r4o7t]
ad...Linux is a better operating system for you if you cannot clean
your craps...
solved....mostly ;)
Can we quote you on that?
> Max Wachtel" <maxwa...@nomail.afraid.org> wrote in message
> news:op.uweo60iwkzp3b8@max...
>> you should go take your stolen, infected, cracked arse up the road.
>
> Can we quote you on that?
>
you just did :)
There is no need to use stolen software. There's plenty of freeware
programs to choose from. Ask in alt.comp.freeware
What to do...cleaning registry...i have the list of files which to
delete, and to renew by system repair. But, how the heck on the first
place did i got all of these ? And whats the best way to protect the
computer from it ?
Thanks.
Respect!
[...]
... And whats the best way to protect the computer from it ?
Change your computing habits.
Give yourself restrictions, and exist within them.
Set strict policies, and abide by them.
Seems like you have an ASCII infection....... Try MASTURBATE