Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the HijackThis Log Help forum, or the "First Steps" link at the top right of each page.

Reply
 
Thread Tools
Old 02-01-2007, 08:09 PM   #1 (permalink)
Registered User
 
Join Date: Feb 2007
Posts: 2
OS: winxp pro


does anyone know what this is

i use kerio as my firewall and it keeps bringing this up can someone help me ive scanned my system and cant find the file

Technical details about the intrusion attempt:

Injector application: C:\windows\system32\kaxmcyvlqg.exe
Description: kaxmcyvlqg
File version:
Product name:
Product version:
Created: 2007/1/25, 21:58:23
Modified: 2007/1/25, 21:58:23
Accessed: 2007/2/2, 02:46:39

Target application: C:\WINDOWS\Explorer.EXE
Description: Windows Explorer
File version: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
Product name: Microsoft® Windows® Operating System
Product version: 6.00.2900.2180
Created: 2004/10/8, 12:01:47
Modified: 2004/10/8, 12:01:47
Accessed: 2007/2/2, 02:46:37

Address of injection: 0x00A60123
ibgrinchiest is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 02-01-2007, 09:22 PM   #2 (permalink)
Registered User
 
Join Date: Oct 2006
Posts: 367
OS: XP


i use kerio 2.1.5, but i am not an expert. i suggest you try dslreports. Ed James
ejames82 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 02-02-2007, 08:47 AM   #3 (permalink)
Registered User
 
Join Date: Feb 2007
Posts: 2
OS: winxp pro


dsl reports? for one i not have a dsl and two there is nothing on this page that refers to dsl.....thank you for you reply....
ibgrinchiest is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 02-02-2007, 09:26 AM   #4 (permalink)
Registered User
 
Join Date: Oct 2006
Posts: 367
OS: XP


http://www.dslreports.com/forum/kerio

it's hard to find help with the firewall that i have, 2.1.5. you didn't say which version that you have. this is not specifically a website geared toward dsl. this is the best kerio help that i can find.
ejames82 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 02-02-2007, 01:53 PM   #5 (permalink)
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 20,885
OS: Win XP Pro SP3

My System

Blog Entries: 9
Send a message via MSN to Glaswegian
Hi ibgrinchiest and welcome to TSF.

No need to go anywhere else - we have the best Security Team on the web! This is undoubtedly malware - the random name is a giveaway - and looks as though it's trying to inject itself into IE. I suggest you follow these instructions as it's possible it has asked other malware to join it on your system.

Please download HijackThis - this program will help us determine if there is any spyware/malware on your computer.
  • Create a folder at C:\HJT and move HijackThis.exe there.
  • Make sure you close down EVERY open window and close ALL browser windows. The only thing that should be open is the HijackThis program.
  • Run a scan and save the log file.
  • Copy the text file (Ctrl+A then Ctrl+C) and paste it (Ctrl+V) in a new thread in the HJT Forum (do not attach it or post it here).
  • Do not fix any entries in HijackThis since they may be harmless.
  • Make sure to include the System information at the top of the log as well.

We'll then have a look and provide instructions to clean your system, if required. Please note that the HJT forum is constantly busy, so I would ask that you be patient while waiting for a reply.
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.



Ad-Aware::SpywareBlaster::SpyBot::SpywareGuard::SnoopFree::AVG Free::HOSTS File::HijackThis::Donate::5 Steps For Infected PCs
Glaswegian is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 08:22 PM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81