![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#41 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Hmmmmmmmmmmm did that but nothing I think: -
________________________________________________________________ HAXFIX logfile - by Marckie ______________ version 3.01 18/06/2006 14:28:57.37 checking for haxdoor -------------------- checking for a3d files.... a3d files not found checking for matching notify keys.... no matching notify keys found checking for matching services.... matching services found Aspi32 checking for matching safeboot services.... matching safeboot services found drtw6a.sys Checking for goldun ------------------- checking for notify keys.... no notify keys found checking for services.... no services found Finished ________________________________________________________________ So ok tell me you thought that lol! But now for your strategy as mine don't seem to work haha! Tell me what order to things and I will go for it! Ruth XXX |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#43 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,422
OS: N/A
|
drtw6a.sys - It did find something. Let's work on that for the moment. Considering what happened yesterday, I'm more inclined to tread carefully
Download & extract this file to it's own folder - Registry Search Launch Registry Search In the search box, enter drtw6a.sys & click "Ok". Notepad will open with some text in it (the file will also be saved in the program's folder as well). Post this text in your next reply
__________________
Question - what have you done for the community today? |
|
|
|
|
#44 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Ok done that here is the results: -
__________________________________________________________ REGEDIT4 ; Registry Search 2.0 by Bobbi Flekman © 2005 ; Version: 2.0.1.0 ; Results at 18/06/2006 14:53:10 for strings: ; 'drtw6a.sys' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\drtw6a.sys] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\drtw6a.sys] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Control\SafeBoot\Minimal\drtw6a.sys] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Control\SafeBoot\Network\drtw6a.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\drtw6a.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\drtw6a.sys] ; End Of The Log... ________________________________________________________________ But what about the other - Aspi32 ?? Ruth |
|
|
|
|
#45 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,422
OS: N/A
|
Ruth,
I've attached a batch file to this post. Double click on it & it shall remove those reg entries you posted. It shall also produce a log on your Desktop - report.txt Please post the contents of that log.
__________________
Question - what have you done for the community today? Last edited by sUBs; 06-18-2006 at 01:37 PM. |
|
|
|
|
#48 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,422
OS: N/A
|
Sorry about that. If you look at the contents of the batch, you would see that I made a minor error with the variable userprofile. It should be %userprofile%.
No worry though, that wouldnt delete any files. Please do another Regsearch & let me know if those drtw6a.sys still exist.
__________________
Question - what have you done for the community today? |
|
|
|
|
#49 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Ok done that and from the following, I don't think it exists anymore, whatever it deleted lol!
_______________________________________________________________ REGEDIT4 ; Registry Search 2.0 by Bobbi Flekman © 2005 ; Version: 2.0.1.0 ; Results at 18/06/2006 16:01:01 for strings: ; 'drtw6a.sys' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS ; End Of The Log... _______________________________________________________________ I don't know anything about batch files I'm afraid, so I haven't done anything with it I'm afraid. So what's next? - do we assume the Haxdoor vaiant has been destroyed now and hopefully I won't get the BSOD's? - we could always try running gmer again to see if that invokes a crash again, but I'm going to wait for you now, I'm in your hands now lol! XX Ruth |
|
|
|
|
#50 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,422
OS: N/A
|
Okay...that removed the Haxdoor entry.
Please reboot once so that the reg deletions may take effect. Then try gmer again Dont get your hopes too high though. Haxdoor isnt known to be a mailbot
__________________
Question - what have you done for the community today? |
|
|
|
|
#53 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Thing is with this fault, I don't understand why it's saying check my disc space - there's plenty, it also suggests to check my drivers - no exclamation marks in Device Manager and it also suggest checking my BIOS - it's up to date to, I think.
Ruth |
|
|
|
|
#54 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,422
OS: N/A
|
It looks likely that we have to use the gmer game plan. But let's give it one more chance & try out another rootkit scanner.
Download and run Blacklight Note that you must have local administrative privileges to run the program. Click Scan. BlackLight will use Windows Explorer (the desktop process) to scan for hidden items. Your anti-virus software or personal firewall might display a warning that says Blacklight (blbeta.exe) is trying to manipulate the Windows Explorer process (explorer.exe). If you want to continue the scan, you should allow BlackLight to do this When it finishes, click Next. You may get a screen similar to the picture below. Click on Close BlackLight beta would create a log file "fsbl-<date-and-time>.log". By default, the log file is in the same directory as the executable. Please post the log
__________________
Question - what have you done for the community today? |
|
|
|
|
#55 (permalink) | |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,422
OS: N/A
|
Quote:
Go to Start > Run - type in control sysdm.cpl & click OK In the new window, under 'Startup & Recovery', click 'Settings' Untick 'Automatically Restart' & click OK That should give you plenty of time to read the entire message.
__________________
Question - what have you done for the community today? |
|
|
|
|
|
#56 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Yes the program cannot get the required priviledges to run. It says it could be that these have been altered maliciously. Can you advise what to do to change them back if at all? - under User Accounts in control-panel, it shows Ruth and Administrator - and Ruth has administrator rights!
Ruth XX |
|
|
|
|
#57 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,422
OS: N/A
|
Please show me the complete error message. Does it say something about SeDeBug Privileges?
__________________
Question - what have you done for the community today? |
|
|
|
|
#58 (permalink) | |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Quote:
Ruth |
|
|
|
|
|
#59 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,422
OS: N/A
|
Yes..that's what I wanted.
I left out the part where I wanted you to click the 'Advanced' tab.
__________________
Question - what have you done for the community today? |
|
|
| Thread Tools | |
|
|