📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

IMPORTANT! Have you received an email to your forum username?

1878890929395

Comments

  • joe134
    joe134 Posts: 3,336 Forumite
    edited 26 November 2010 at 7:57PM
    DeltaTwo wrote: »
    I agree with some of what you're saying, but just to give you some idea of the difficulties.
    This particular Trojan does real damage to a couple of System files.
    I have cleared up an infection using various scans and manually replacing the files.

    The particular variant i looked at (and i have the md5 checksums) works like this:
    It infects the Explorer.exe Winlogon.exe or Wininit.exe
    also infects the backups of those files in dllcache
    adds a file called memory.tmp to the User Account's Templates folder
    Creates a new folder called Server in 'All Users\Documents'
    adds a couple of files to that folder called admin.txt and hlp.dat
    also adds a couple of dat files to the Windows\Temp folder, but they disappear, don't expect to see them.

    If you do a file search and find that Server folder with the two files, then you're definitely infected.

    SuperAntiSpyware, MalwareBytes, Avira, HijackThis, and others are all good progs but can't resolve this one.

    The reason is that the previous mentioned System files are infected and probably need to be replaced with clean ones from another source, such as instal disk.
    If scans are carried out identifying those System files as 'infected', quarantining or deleting them, then the pc will no longer boot up!!!
    For me, it's not a problem, i have a range of tools to recover from those situations, but the average pc user could REALLY struggle, particularly if no other pc is available.

    I see StumpyPumpy has tried Hit_man_pro. Well done for posting the advice.
    Not tried it myself but would be very interested to know how it handles the infected System files?
    Does it ask the user for an instal disk or clean alternative location?

    It can't ignore those files, this is fundamental to this particular Trojan, so it has to take some action, which is probably in the log it created.
    If unsure i can dl Hit_man and maybe give it a go myself.
    Hi, Thanks very much for your very informative post.As you and Stumpy say, this is a serious Trojan, not to be ignored.I have just trawled everything from MSE regarding it, and Cannot find anywhere they mention seeking professional advice if Trojan is found:doesn,t mean it,s not there.That,s my main gripe, no info, other than what forumites like you et.al have given.WHY? There,s no onus on them to have id,d it in their first alert.a Trojan is a very generic term.As you say, the untechie person would need professional advice, Me, I would have gone direct to the Techie site, as Browntoa suggested, MSE could have given that advice, without any comeback.that,s the most likely place to get GOOD advice.without recourse to speculating in "pro"s, who I personally would not go near, unless reccommended by one of the Techies like you and Stumpy et.al.It's bad enough having ones e-mail being hacked, if that,s the case, but to be left without any advice, to me is worse.Lets just hope there are not too many need advice, but if they do,and I bet there are several that do not know they are infected do, this is not the place.the TECHIE site is,:beer:
  • RAS
    RAS Posts: 35,832 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    It is quite possible to contact abuse and have all your posts removed from MSE, if that is what you want.

    Martin

    Is it not about time this thread was closed? I doubt if you guys are learning anything new or even useful and the few remaining participants seem to have bees in their bonnets unrelated to the issue.
    If you've have not made a mistake, you've made nothing
  • nilrem_2
    nilrem_2 Posts: 2,188 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    RAS wrote: »

    Is it not about time this thread was closed? I doubt if you guys are learning anything new or even useful and the few remaining participants seem to have bees in their bonnets unrelated to the issue.

    Personally I feel it should be left open for any people who perhaps are not frequent visitors find the message and may wish to ask a question about the issue and seek help from others.

    I think most people here have enough common sense to sort the 'wheat from the chaff'. :)
  • meher
    meher Posts: 15,910 Forumite
    10,000 Posts Combo Breaker
    Actually I got the feeling too, there's far too much publicity and far too long even though there isn't a shred of evidence of breach. People would hesitate to sign up or use links or downloads if any site is publicised as having security issues. Imagine John Lweis showing up as having a security breach and then asking for email address to sign up for offers. I'd think long and hard before I sign up and certainly won't shop. The opportunity to post or give evidence has been offered. There's no evidence. So, imo, no need for banners on top. Since I like a little bit of thrill, i like :snow_grin this thread though.
  • ploddingalong_2
    ploddingalong_2 Posts: 31 Forumite
    edited 27 November 2010 at 12:31PM
    meher wrote: »
    Actually I got the feeling too, there's far too much publicity and far too long even though there isn't a shred of evidence of breach. People would hesitate to sign up or use links or downloads if any site is publicised as having security issues. Imagine John Lweis showing up as having a security breach and then asking for email address to sign up for offers. I'd think long and hard before I sign up and certainly won't shop. The opportunity to post or give evidence has been offered. There's no evidence. So, imo, no need for banners on top. Since I like a little bit of thrill, i like :snow_grin this thread though.

    Have you read the thread meher??? There is abundant evidence there has been a breech. Martin Lewis admits there has been a breech, although they cannot identify exactly how/ when. Users who use an email address dedicated to this site have received emails addressed to their username using the email addy for this site, and this site alone. I'm not out to persecute Martin Lewis or the site.
  • joe134
    joe134 Posts: 3,336 Forumite
    edited 27 November 2010 at 10:08AM
    Have you read the thread meher??? There is abundant evidence there has been a breech. Martin Lewis admits there has been a breech, although they cannot identify exactly how/ when. Users who use an email address dedicated to this site have received emails addressed to their username using the email addy for this site, and this site alone. I'm not out to persecute Martin Lewis or the site, but for goodness sake, get real, or keep quiet :D
    There are some, like me who got my e-mail via domain not linked to this site but with username correct;?and others.
  • torbrex
    torbrex Posts: 71,340 Forumite
    10,000 Posts Combo Breaker Rampant Recycler Hung up my suit!
    I feel a bit left out that I have not received an email :(:p
  • nilrem_2
    nilrem_2 Posts: 2,188 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    edited 27 November 2010 at 2:19PM
    but for goodness sake, get real, or keep quiet :D

    Don't you think that is a little unkind? This is a forum for people to discuss their views and opinions even if others disagree with those opinions, if everyone who had a different view took your advice to keep quiet it would soon become a bit boring here! :)

    Have edited my post, for some reason (I am going senile) I attributed the quote to Joe which was incorrect, sorry for any confusion and sorry to Joe who did not make the quote.
  • nilrem_2
    nilrem_2 Posts: 2,188 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    torbrex wrote: »
    I feel a bit left out that I have not received an email :(:p

    For a small fee I would be more than happy to send you mine! :D
  • meher
    meher Posts: 15,910 Forumite
    10,000 Posts Combo Breaker
    but for goodness sake, get real, or keep quiet :D
    No to both :snow_grin
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.4K Banking & Borrowing
  • 253.3K Reduce Debt & Boost Income
  • 453.8K Spending & Discounts
  • 244.4K Work, Benefits & Business
  • 599.7K Mortgages, Homes & Bills
  • 177.2K Life & Family
  • 258K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.