1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

HELP ! My PC has been compromised !!

Discussion in 'General Malware And Security' started by penang@freemail.c3.hu, Mar 8, 2008.

  1. On Mon, 10 Mar 2008 11:35:37 -0400, "Lanwench [MVP - Exchange]"
    <lanwench@heybuddy.donotsendme.unsolicitedmailatyahoo.com> wrote:
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    >Straight Talk <b__nice@hotmail.com> wrote:<!--colorc--><!--/colorc-->
    <!--coloro:blue--><span style="color:blue <!--/coloro--><!--coloro:green--><span style="color:green <!--/coloro-->
    >> Trial and error against malware is a common but very stupid approach.<!--colorc--><!--/colorc-->
    >
    >Nonsense. <!--colorc--><!--/colorc-->

    Not really.
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    >It depends entirely on the severity of the infestation. <!--colorc--><!--/colorc-->

    Precisely. A severity you cannot determine without having a baseline.
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    >I won't spend hours and hours on a troubled workstation, but if I can pretty easily
    >remove a not-very-invasive piece of malware or two, I simply do so. <!--colorc--><!--/colorc-->

    And how exactly do you verify that the machine is now back in a
    reliable state?
     
  2. Straight Talk <b__nice@hotmail.com> wrote:<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > On Mon, 10 Mar 2008 11:35:37 -0400, "Lanwench [MVP - Exchange]"
    > <lanwench@heybuddy.donotsendme.unsolicitedmailatyahoo.com> wrote:
    ><!--coloro:green--><span style="color:green <!--/coloro-->
    >> Straight Talk <b__nice@hotmail.com> wrote:<!--colorc--><!--/colorc-->
    ><!--coloro:green--><span style="color:green <!--/coloro--><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> Trial and error against malware is a common but very stupid
    >>> approach.<!--colorc--><!--/colorc-->
    >>
    >> Nonsense.<!--colorc--><!--/colorc-->
    >
    > Not really.
    ><!--coloro:green--><span style="color:green <!--/coloro-->
    >> It depends entirely on the severity of the infestation.<!--colorc--><!--/colorc-->
    >
    > Precisely. A severity you cannot determine without having a baseline.
    ><!--coloro:green--><span style="color:green <!--/coloro-->
    >> I won't spend hours and hours on a troubled workstation, but if I
    >> can pretty easily remove a not-very-invasive piece of malware or
    >> two, I simply do so.<!--colorc--><!--/colorc-->
    >
    > And how exactly do you verify that the machine is now back in a
    > reliable state?<!--colorc--><!--/colorc-->

    Because it works and has no further symptoms when I run thorough scans.
    That's generally good enough for a home user. Sorry, I'm bored now - done
    with this thread. Have fun storming the castle.
     
  3. On Tue, 11 Mar 2008 12:13:12 -0400, "Lanwench [MVP - Exchange]"
    <lanwench@heybuddy.donotsendme.unsolicitedmailatyahoo.com> wrote:
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    >Straight Talk <b__nice@hotmail.com> wrote:<!--coloro:green--><span style="color:green <!--/coloro-->
    >> On Mon, 10 Mar 2008 11:35:37 -0400, "Lanwench [MVP - Exchange]"
    >> <lanwench@heybuddy.donotsendme.unsolicitedmailatyahoo.com> wrote:
    >><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> Straight Talk <b__nice@hotmail.com> wrote:<!--colorc--><!--/colorc-->
    >><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>>> Trial and error against malware is a common but very stupid
    >>>> approach.
    >>>
    >>> Nonsense.<!--colorc--><!--/colorc-->
    >>
    >> Not really.
    >><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> It depends entirely on the severity of the infestation.<!--colorc--><!--/colorc-->
    >>
    >> Precisely. A severity you cannot determine without having a baseline.
    >><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> I won't spend hours and hours on a troubled workstation, but if I
    >>> can pretty easily remove a not-very-invasive piece of malware or
    >>> two, I simply do so.<!--colorc--><!--/colorc-->
    >>
    >> And how exactly do you verify that the machine is now back in a
    >> reliable state?<!--colorc--><!--/colorc-->
    >
    >Because it works and has no further symptoms when I run thorough scans. <!--colorc--><!--/colorc-->

    This coming from someone bragging to be an MVP. Very sad.
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    >That's generally good enough for a home user. <!--colorc--><!--/colorc-->

    That's very good news for malware writers.
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    >Sorry, I'm bored now - done
    >with this thread. Have fun storming the castle.<!--colorc--><!--/colorc-->

    Oh, yes. Go back to sleep, MVP bragger.
     
  4. "Straight Talk" <b__nice@hotmail.com> wrote in message
    news:9u5ct3pf7c04vnkkj3ut9k0f5ft72kfqj0@4ax.com...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > On Mon, 10 Mar 2008 11:35:37 -0400, "Lanwench [MVP - Exchange]"
    > <lanwench@heybuddy.donotsendme.unsolicitedmailatyahoo.com> wrote:
    ><!--coloro:green--><span style="color:green <!--/coloro-->
    >>Straight Talk <b__nice@hotmail.com> wrote:<!--colorc--><!--/colorc-->
    ><!--coloro:green--><span style="color:green <!--/coloro--><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> Trial and error against malware is a common but very stupid approach.<!--colorc--><!--/colorc-->
    >>
    >>Nonsense.<!--colorc--><!--/colorc-->
    >
    > Not really.
    ><!--coloro:green--><span style="color:green <!--/coloro-->
    >>It depends entirely on the severity of the infestation.<!--colorc--><!--/colorc-->
    >
    > Precisely. A severity you cannot determine without having a baseline.
    ><!--coloro:green--><span style="color:green <!--/coloro-->
    >>I won't spend hours and hours on a troubled workstation, but if I can
    >>pretty easily
    >>remove a not-very-invasive piece of malware or two, I simply do so.<!--colorc--><!--/colorc-->
    >
    > And how exactly do you verify that the machine is now back in a
    > reliable state?<!--colorc--><!--/colorc-->

    If you know what changes a malware made, you
    can often reverse those changes and get the system
    back to as reliable as it was before the malware hit.

    Yes...it is that 'if' that is the bugger. Many malwares
    allow communication outside the system so you no
    longer know exactly what changes were made and
    it is time to flatten and rebuild if you desire any sense
    of confidence in its integrity.
     
  5. On Tue, 11 Mar 2008 17:35:35 -0400, "FromTheRafters"
    <Erratic@ne.rr.com> wrote:
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    >
    >"Straight Talk" <b__nice@hotmail.com> wrote in message
    >news:9u5ct3pf7c04vnkkj3ut9k0f5ft72kfqj0@4ax.com...<!--coloro:green--><span style="color:green <!--/coloro-->
    >> On Mon, 10 Mar 2008 11:35:37 -0400, "Lanwench [MVP - Exchange]"
    >> <lanwench@heybuddy.donotsendme.unsolicitedmailatyahoo.com> wrote:
    >><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>>Straight Talk <b__nice@hotmail.com> wrote:<!--colorc--><!--/colorc-->
    >><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>>> Trial and error against malware is a common but very stupid approach.
    >>>
    >>>Nonsense.<!--colorc--><!--/colorc-->
    >>
    >> Not really.
    >><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>>It depends entirely on the severity of the infestation.<!--colorc--><!--/colorc-->
    >>
    >> Precisely. A severity you cannot determine without having a baseline.
    >><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>>I won't spend hours and hours on a troubled workstation, but if I can
    >>>pretty easily
    >>>remove a not-very-invasive piece of malware or two, I simply do so.<!--colorc--><!--/colorc-->
    >>
    >> And how exactly do you verify that the machine is now back in a
    >> reliable state?<!--colorc--><!--/colorc-->
    >
    >If you know what changes a malware made, you
    >can often reverse those changes and get the system
    >back to as reliable as it was before the malware hit.<!--colorc--><!--/colorc-->

    That's true. Which, as I said, requires a baseline and a thorough
    understanding. Most users don't have that.
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    >Yes...it is that 'if' that is the bugger. Many malwares
    >allow communication outside the system so you no
    >longer know exactly what changes were made and
    >it is time to flatten and rebuild if you desire any sense
    >of confidence in its integrity. <!--colorc--><!--/colorc-->

    Yup.
     
  6. Delta

    Delta Guest

    Ok, you are victim of a internet worm, that seem to spread by mail.
    a) kill all suspicious processes like "rcgvejmrg.exe" OR MISTYPED names like
    "explroer.exe".
    best would be making a hijackthis log and sending it to some people, known
    to handle them (or here).
     
  7. Sandy Mann

    Sandy Mann Guest

    "Delta" <bla@bla.net> wrote in message
    news:93B6E4D1-7E61-4E53-A4C3-6EC502809B7D@microsoft.com...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Ok, you are victim of a internet worm, that seem to spread by mail.
    > a) kill all suspicious processes like "rcgvejmrg.exe" OR MISTYPED names
    > like "explroer.exe".
    > best would be making a hijackthis log and sending it to some people, known
    > to handle them (or here).
    ><!--colorc--><!--/colorc-->

    I assume that Delta meant "(NOT here)"

    from a old post by Frank Saunders:

    ***************************************
    First eliminate any scumware. See Dealing with Unwanted
    Malware, Parasites, Toolbars and Search Engines
    especially



    Note that AdAware and SpyBot S & D will each catch some
    things the other won't. Also, each needs to be updated
    with the program's update function before every use, even
    when just downloaded. There's also a lot more to do than
    just those two programs. CWShredder is also available
    here:

    **Post your HijackThis log to
    or the Spyware forum at
    for expert analysis, not here.**
    Alternative download pages for Ad-Aware, Spybot,
    HijackThis and CWShredder may be found on this page:
    .


    If nothing there helps, please post back to this thread.


    ********************************************


    --
    HTH

    Sandy
     
  8. From: "Delta" <bla@bla.net>

    | Ok, you are victim of a internet worm, that seem to spread by mail.
    | a) kill all suspicious processes like "rcgvejmrg.exe" OR MISTYPED names like
    | "explroer.exe".
    | best would be making a hijackthis log and sending it to some people, known
    | to handle them (or here).

    No HJT logs posted in any Microsoft news group or posted to Usenet at large.

    --
    Dave

    Multi-AV -
     

Share This Page