housecall found trojan
Results 1 to 15 of 15

Thread: housecall found trojan

  1. #1
    Join Date
    Aug 2001
    Location
    Vancouver, Canada
    Posts
    1,002

    housecall found trojan

    Hi gang - am on roomie's pc and found ZA settings mysteriously changing and some other peculiar activity - Norton found nada.

    Ran Housecall which immediately found and said it cleaned a trojan, but unfortuantely I don't recall the name other than it "gig" something and included an underscore (_).

    All seams well, except I find a couple things in msconfig I don't understand - please take a look at the attachments and let me know what you think.

    TIA...
    Attached Images Attached Images
    Last edited by ^dAvEy^; July 24th, 2002 at 01:16 AM.
    ^dAvEy^

    Wow!!! Love at first byte. Ain't it grand.
    Scottlr

    Registered VDr (at 50+/- yrs): 10-03-1999
    Offline: 06-05-2002

  2. #2
    Join Date
    Aug 2001
    Location
    Vancouver, Canada
    Posts
    1,002

    attachment 2

    Here's the one from config.sys
    Attached Images Attached Images
    ^dAvEy^

    Wow!!! Love at first byte. Ain't it grand.
    Scottlr

    Registered VDr (at 50+/- yrs): 10-03-1999
    Offline: 06-05-2002

  3. #3
    Join Date
    Jul 2000
    Posts
    1,433
    Those seem fine. What are the programs in msconfig that seem strange.

  4. #4
    Join Date
    Oct 1999
    Location
    Whitby, Ontario, Canada
    Posts
    6,351
    Download and run StartupLog and post back the contents of StartUp.log.

    It is a good tool for evaluating what is starting at boot time, and whether all of the trojan has been ripped out.

  5. #5
    Join Date
    Aug 2001
    Location
    Vancouver, Canada
    Posts
    1,002
    thanks WhitPhil and Buffalo
    Originally posted by Buffalo
    Those seem fine. What are the programs in msconfig that seem strange.
    config.sys and autecec.bat are tabs in sytem configuration Utility. aka msconfig, n'est-ce pas?
    WhitPhil - good call! I'm on it...
    ^dAvEy^

    Wow!!! Love at first byte. Ain't it grand.
    Scottlr

    Registered VDr (at 50+/- yrs): 10-03-1999
    Offline: 06-05-2002

  6. #6
    Join Date
    Aug 2001
    Location
    Vancouver, Canada
    Posts
    1,002
    Here is the StartupLog, WhitPhil et al.
    StubPath.txt log to follow.
    TIA...
    Attached Files Attached Files
    Last edited by ^dAvEy^; July 23rd, 2002 at 10:28 PM.
    ^dAvEy^

    Wow!!! Love at first byte. Ain't it grand.
    Scottlr

    Registered VDr (at 50+/- yrs): 10-03-1999
    Offline: 06-05-2002

  7. #7
    Join Date
    Aug 2001
    Location
    Vancouver, Canada
    Posts
    1,002
    StubPath.txt
    Attached Files Attached Files
    ^dAvEy^

    Wow!!! Love at first byte. Ain't it grand.
    Scottlr

    Registered VDr (at 50+/- yrs): 10-03-1999
    Offline: 06-05-2002

  8. #8
    Join Date
    Aug 1999
    Location
    Hong Kong
    Posts
    2,289
    Hi ^dAvEy^...God, I hate the way the upload renders the StartLog. So hard to read. Looks clean as a whistle though. I wonder if the intercepted trojan was Gigger. Quite a nasty...

  9. #9
    Join Date
    Oct 1999
    Location
    Whitby, Ontario, Canada
    Posts
    6,351
    Looks clean to me.

    Hmmm, HKEd. Now there's a name that rings a bell!!
    How ya doin' lad?

    Got a link to Gigger?

  10. #10
    Join Date
    Aug 1999
    Location
    Hong Kong
    Posts
    2,289
    Hi Phil...thanks, but I've been a little poorly lately. Nothing serious, but it's just one of those times when nothing seems to go right.

    Ermmmm...the link to Gigger is in my previous post.

  11. #11
    Join Date
    Oct 1999
    Location
    Whitby, Ontario, Canada
    Posts
    6,351
    "one of those times"!!

    How have you been so lucky to only have ONE!!! LOL

    As for your link, thanks. I just thought you were highlighting it with an underline!! (it's getting past my sleepy time, as you can tell)

    Gigger is just another reason to be running a Script blocker like ScritpSentry and another reason why I have renamed Format.com and Deltree.exe
    Last edited by WhitPhil; July 23rd, 2002 at 11:03 PM.

  12. #12
    Join Date
    Aug 2001
    Location
    Vancouver, Canada
    Posts
    1,002
    Hi - Thanks for the input, HKEd - good news to hear!
    Ya, I prefer the txt fomat view myself, so I go the extra k and dl and open as such. Ya, gigger, that was it.

    Guess we just got lucky indeed over here, WhitPhil, as the site HKEd linked says coulda been tragic lickity split!
    Thanks for all, including the heads-up on ScriptSentry and Deltree.com.
    ^dAvEy^

    Wow!!! Love at first byte. Ain't it grand.
    Scottlr

    Registered VDr (at 50+/- yrs): 10-03-1999
    Offline: 06-05-2002

  13. #13
    Join Date
    Jul 2000
    Posts
    1,433
    WhitPhil,
    Those are still two great ideas.
    ^dAvEy,^
    config.sys and autecec.bat are tabs in sytem configuration Utility. aka msconfig, n'est-ce pas?
    I thought that you had something else in the Startup part of Msconfig that you didn't understand.
    WhitPhil very rarely gives out poor advice, except when it comes to ...---.... or %%@@@@@@@@@??????????.


  14. #14
    Join Date
    Aug 1999
    Location
    Hong Kong
    Posts
    2,289
    You're welcome, ^dAvEy^. I agree with WhitPhil...deltree.exe and format.com have no business being active on a system, unless you're using deltree in autoexec.bat to deltree Temp, TIFs, cookies etc. (which I don't really recommend - Spider is a better way to go, IMO). Either rename them or keep them on a diskette for use as and when required. It's really easy to write a little batch file that would append a format or deltree command to autoexec.bat. Not a nice way to start the day.
    Last edited by HKEd; July 23rd, 2002 at 11:53 PM.

  15. #15
    Join Date
    Oct 1999
    Location
    Whitby, Ontario, Canada
    Posts
    6,351
    If you have the need to use deltree in a batch file, just use the renamed name. Ie: if you changed it to MYDEL.exe then just use MYDEL instead of DELTREE.

    The only thing to be aware of is if you use Norton. Hopefully you then keep you Rescue disks updated. If you do, then rename these files back, or Norton will give an warning and (obviously) will not copy them to the disks.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •