Mobile Devices: Lite Theme Citroën: Citroën Trader | Saxo Trader | C2 Trader Peugeot: Peugeot Trader | 106 Trader Enthusiast: Saxperience


Go Back   Saxperience - Citroen Saxo Forum > Other... > Gaming, IT, Multimedia & Music

Gaming, IT, Multimedia & Music Please use this forum to discuss Gaming, IT, Multimedia & Music.

Reply
 
Thread Tools Display Modes
Old 1st February 2008, 21:37   #1
Adam_Q
Saxperience Post Whore
Central South Region MemberSouth East Region Member
 
Adam_Q's Avatar
 
Join Date: Mar 2007
Location: Worthing
Posts: 5,660
Car(s): Jap crap
iTrader Score: 21 (100%)
Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!
Default RootKit Revealer

I've been getting loads of spyware on my fooking computer and been advised by Alex to run Hijack this and RootKit Revealer

I've run the rootkit thingy, which brought up loads of stuff... but dont know what to do with it....

Can anyone help?
__________________
Quote:
Originally Posted by luke1988 View Post
i just schmidt myself!!
Adam_Q is offline   Reply With Quote
Old 1st February 2008, 22:03   #2
Alexp
Central South
Track / Motorsport Prep

Central South Region MemberSouth East Region Member
 
Alex's Avatar
 
Join Date: Jun 2006
Location: East Sussex
Posts: 3,105
Blog Entries: 9
Car(s): VTS :)
iTrader Score: 17 (100%)
Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!
Default

post it up, some stuff will come up that is ok tho.
__________________
Can I be your car fwrend??
Alex is offline   Reply With Quote
Old 1st February 2008, 22:15   #3
Adam_Q
Saxperience Post Whore
Central South Region MemberSouth East Region Member
 
Adam_Q's Avatar
 
Join Date: Mar 2007
Location: Worthing
Posts: 5,660
Car(s): Jap crap
iTrader Score: 21 (100%)
Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!
Default

Just scanning again
__________________
Quote:
Originally Posted by luke1988 View Post
i just schmidt myself!!
Adam_Q is offline   Reply With Quote
Old 1st February 2008, 23:00   #4
Adam_Q
Saxperience Post Whore
Central South Region MemberSouth East Region Member
 
Adam_Q's Avatar
 
Join Date: Mar 2007
Location: Worthing
Posts: 5,660
Car(s): Jap crap
iTrader Score: 21 (100%)
Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!
Default

Could only take screen shots so its in two parts


__________________
Quote:
Originally Posted by luke1988 View Post
i just schmidt myself!!
Adam_Q is offline   Reply With Quote
Old 2nd February 2008, 08:28   #5
Alexp
Central South
Track / Motorsport Prep

Central South Region MemberSouth East Region Member
 
Alex's Avatar
 
Join Date: Jun 2006
Location: East Sussex
Posts: 3,105
Blog Entries: 9
Car(s): VTS :)
iTrader Score: 17 (100%)
Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!
Default

The only one that looks suspicious to me is, "uduuiig.exe" and it's other files.
It does help if you close things such as firefox tho, will give less results.
__________________
Can I be your car fwrend??
Alex is offline   Reply With Quote
Old 2nd February 2008, 12:43   #6
Adam_Q
Saxperience Post Whore
Central South Region MemberSouth East Region Member
 
Adam_Q's Avatar
 
Join Date: Mar 2007
Location: Worthing
Posts: 5,660
Car(s): Jap crap
iTrader Score: 21 (100%)
Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!
Default

Quote:
Originally Posted by Alex View Post
The only one that looks suspicious to me is, "uduuiig.exe" and it's other files.
It does help if you close things such as firefox tho, will give less results.
Oh ok... will run it again and try to close as much as possible

But how do I remove the suspicious files? Would I need to find the source and remove it that way?
__________________
Quote:
Originally Posted by luke1988 View Post
i just schmidt myself!!
Adam_Q is offline   Reply With Quote
Old 2nd February 2008, 20:10   #7
Alexp
Central South
Track / Motorsport Prep

Central South Region MemberSouth East Region Member
 
Alex's Avatar
 
Join Date: Jun 2006
Location: East Sussex
Posts: 3,105
Blog Entries: 9
Car(s): VTS :)
iTrader Score: 17 (100%)
Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!
Default

See if you can modify them in safe mode, just try renaming the exe file first incase it's required.
Or hook your HD up to another PC and modify.
__________________
Can I be your car fwrend??
Alex is offline   Reply With Quote
Old 3rd February 2008, 11:40   #8
Adam_Q
Saxperience Post Whore
Central South Region MemberSouth East Region Member
 
Adam_Q's Avatar
 
Join Date: Mar 2007
Location: Worthing
Posts: 5,660
Car(s): Jap crap
iTrader Score: 21 (100%)
Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!
Default

Quote:
Originally Posted by Alex View Post
See if you can modify them in safe mode, just try renaming the exe file first incase it's required.
Or hook your HD up to another PC and modify.
Not something I feel comfortable about doing..... dont suppose you wanna come give it a go somewhen?
__________________
Quote:
Originally Posted by luke1988 View Post
i just schmidt myself!!
Adam_Q is offline   Reply With Quote
Old 3rd February 2008, 15:15   #9
Alexp
Central South
Track / Motorsport Prep

Central South Region MemberSouth East Region Member
 
Alex's Avatar
 
Join Date: Jun 2006
Location: East Sussex
Posts: 3,105
Blog Entries: 9
Car(s): VTS :)
iTrader Score: 17 (100%)
Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!
Default

after abit of digging around it looks like your infected with MessengerSkinner, Some crappy malware that hides itself with a rootkit.

Your a bit far for me to come (Would have to charge) but give this ago to, ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe

It should give you the option to remove those files.
__________________
Can I be your car fwrend??
Alex is offline   Reply With Quote
Old 3rd February 2008, 15:33   #10
Adam_Q
Saxperience Post Whore
Central South Region MemberSouth East Region Member
 
Adam_Q's Avatar
 
Join Date: Mar 2007
Location: Worthing
Posts: 5,660
Car(s): Jap crap
iTrader Score: 21 (100%)
Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!
Default

Quote:
Originally Posted by Alex View Post
after abit of digging around it looks like your infected with MessengerSkinner, Some crappy malware that hides itself with a rootkit.

Your a bit far for me to come (Would have to charge) but give this ago to, ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe

It should give you the option to remove those files.
ok bud. I'm running f-secure now. So will that find any mailware and spyware? then remove it?
__________________
Quote:
Originally Posted by luke1988 View Post
i just schmidt myself!!
Adam_Q is offline   Reply With Quote
Old 3rd February 2008, 15:36   #11
Alexp
Central South
Track / Motorsport Prep

Central South Region MemberSouth East Region Member
 
Alex's Avatar
 
Join Date: Jun 2006
Location: East Sussex
Posts: 3,105
Blog Entries: 9
Car(s): VTS :)
iTrader Score: 17 (100%)
Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!Alex is absolutely fabulous!
Default

Hopefully, Iv'e never used it but it did say on there site it has a removal engine.
__________________
Can I be your car fwrend??
Alex is offline   Reply With Quote
Old 3rd February 2008, 15:41   #12
Adam_Q
Saxperience Post Whore
Central South Region MemberSouth East Region Member
 
Adam_Q's Avatar
 
Join Date: Mar 2007
Location: Worthing
Posts: 5,660
Car(s): Jap crap
iTrader Score: 21 (100%)
Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!
Default

Its scanning now, but does have a cleaning process after... so hopefully that fixes it

Thanks for your help dude!
__________________
Quote:
Originally Posted by luke1988 View Post
i just schmidt myself!!
Adam_Q is offline   Reply With Quote
Old 3rd February 2008, 15:43   #13
Adam_Q
Saxperience Post Whore
Central South Region MemberSouth East Region Member
 
Adam_Q's Avatar
 
Join Date: Mar 2007
Location: Worthing
Posts: 5,660
Car(s): Jap crap
iTrader Score: 21 (100%)
Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!Adam_Q is absolutely fabulous!
Default

F-secure didn't actually find any hidden files... will run it again though
__________________
Quote:
Originally Posted by luke1988 View Post
i just schmidt myself!!
Adam_Q is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:11.