« CONSTITUTION Home | Email msg. | Reply to msg. | Post new | Board info. Previous | Home | Next

Re: Bugs

By: lkorrow in CONSTITUTION | Recommend this post (0)
Sat, 11 Aug 12 10:36 AM | 77 view(s)
Boardmark this board | Constitutional Corner
Msg. 19252 of 21975
(This msg. is a reply to 19246 by DueDillinger)

Jump:
Jump to board:
Jump to msg. #

Wowzer, to quote monkey!

None of those mods are running. I have a lsass.exe though.

Thanks for that info, I'm doing a module search now and I'll check out the links and Combofix tomorrow.

:shock

Hah, just ran spyzooka with the newly downloaded files and got the win21 worm autoIT and Win32 Trojan-proxy MSIL again, but not that third one. Now I'm going to run webroot and go to sleep.

Thanks again!
Linda




Avatar


- - - - -
View Replies (1) »



» You can also:
- - - - -
The above is a reply to the following message:
Re: Bugs
By: DueDillinger
in CONSTITUTION
Sat, 11 Aug 12 5:39 AM
Msg. 19246 of 21975

Tracking cookies are not dangerous, and if you continue to use older IE versions, they are gonna be ubiquitous.

The registry entries in and of themselves are not actually malware; ie; they aren't programs. What is probably happening is that the virus itself has been zapped, but not all of it's effects on the registry have been undone.

Look in your Webroot logs to see if these specific viruses have been removed.

Here's Microsoft's page on the HackTool malware:

Technical Information (Analysis)
HackTool:Win32/PWDump.A is a tool used to obtain password hashes from Windows NT and 2000 machines.

The tool is installed as a service, usually named pwservice.exe. It utilizes the files pwdump3.exe and lsaext.dll, and is designed to remotely obtain password hashes from the memory of the target machine.

http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=HackTool%3AWin32%2FPWDump.A#symptoms_link

So you can see if you have either of these files on your system and/or run Windows Task Manager to see if the service is running.

If you want to really ensure that your system is cleaned out, run ComboFix.

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Uploaded Image

∆∆


« CONSTITUTION Home | Email msg. | Reply to msg. | Post new | Board info. Previous | Home | Next