View Single Post
Old 03-19-2005, 01:21 AM   #4 (permalink)
MicroBell
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
 
MicroBell's Avatar
 
Join Date: Sep 2004
Location: Carmichaels, PA-USA
Posts: 6,963
OS: Windows 7


Send a message via ICQ to MicroBell Send a message via MSN to MicroBell
I see none of that trojans files running on your system.

Go to My Computer->Tools->Folder Options->View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing/visible also. Then do a search for the following files and report back what you find and in which directorys...

6b69ae716f1e720091c9a782a9103e9e.exe
help.chm
keygen.exe
nuclearbot.dll
readme.txt
server.exe


Also post the following logs...

Download Silent runners.Vbs http://www.silentrunners.org/
1. Make sure you have any script blocking software disabled
2. Run the program. It will take a few minutes to complete.
3. Once complete it will produce a log named “StartupPrograms” with Your user and date in the filename. Open that txt file and posts it contents in your next post.

Download Find-qoologic.zip from my attachment here.
Umonitor among others
1. Unzip (It must be unzipped) the files to a folder on your desktop.
2. Open the qoologic folder, run qoologic.bat from there and wait for it to finish.
3. It will take awhile so wait until the dos window disappears and disk activity stops.
4. Then open the text file it created… found here c:\log.txt and paste the contents into your next post.

Download: StartDreck

Unzip to its own folder and start the program:
Press 'Config'
Press 'Mark All'

UN-Check the 'NT-Services & NT-Kernel...' boxes only:
Press 'Ok'

Press 'Save' and select the location to save the log file (default is the same folder as the application)

Post the log in this thread
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!





Spyware/Adware Removal Tools
Hijackthis
Ad-aware SE
Spybot Search&Destroy
SpywareBlaster
CWShredder
MicroBell is offline