My downfall, lulDr. kitteny berk wrote: keygens
Trojan DD:
Moderator: Forum Moderators
-
- Shambler In Drag
- Posts: 780
- Joined: March 16th, 2007, 20:22
- Location: on the sofa
- Contact:
-
- Morbo
- Posts: 19676
- Joined: December 10th, 2004, 21:53
- Contact:
-
- Morbo
- Posts: 19676
- Joined: December 10th, 2004, 21:53
- Contact:
If it's smart enough to lurk in system restore, it's quite possible it's lurking elsewhere too, but it might not be - Unless you're doing a full format of all your currently connected storage, it's probably not worth doing.TezzRexx wrote:Well the Trojans have been removed allegedly, they were in my system restore folder.
I'm still nervous and tempted to format, I'm just unsure if that would be of use or would the Trojan still be lurking?
My usual course of action is to get the machine as clean as possible, reboot, scan again, clean (if needed) and repeat.
Using different AV apps can help a little, but I'd honestly just use nod32, then buy it off mr. ham.
Last edited by Dr. kitteny berk on August 13th, 2008, 23:40, edited 1 time in total.
-
- Shambler In Drag
- Posts: 780
- Joined: March 16th, 2007, 20:22
- Location: on the sofa
- Contact:
-
- Morbo
- Posts: 19676
- Joined: December 10th, 2004, 21:53
- Contact:
-
- Shambler In Drag
- Posts: 780
- Joined: March 16th, 2007, 20:22
- Location: on the sofa
- Contact:
Remember this
http://www.5punk.co.uk/wiki/index.php?t ... quest_Help
If you do reformat, get yourself an imaged up. And take an image before doing anything risky.
Forget my last comment, an image is the ultimate sandbox
http://www.5punk.co.uk/wiki/index.php?t ... quest_Help
If you do reformat, get yourself an imaged up. And take an image before doing anything risky.
Forget my last comment, an image is the ultimate sandbox
-
- Shambler In Drag
- Posts: 780
- Joined: March 16th, 2007, 20:22
- Location: on the sofa
- Contact:
-
- Morbo
- Posts: 19676
- Joined: December 10th, 2004, 21:53
- Contact:
-
- Site Owner
- Posts: 9597
- Joined: May 16th, 2005, 15:31
- Location: Coventry, UK
- Contact:
I think it could potentially still write to the ..//xphost or whatver the default share is called, and perhaps mess with the VM tools if they're installed.cheeseandham wrote: If you switch off the virtual network adapter once moving said risky items to it then I can't imagine any way that it could.
Maybe osmosis?
-
- Shambler In Drag
- Posts: 780
- Joined: March 16th, 2007, 20:22
- Location: on the sofa
- Contact:
-
- Morbo
- Posts: 19676
- Joined: December 10th, 2004, 21:53
- Contact:
Fire up this:
http://technet.microsoft.com/en-us/sysi ... 63902.aspx
then go to options up the top and hide Microsoft Entries and then scour the remaining list. If there is anything fishy there or claiming to be MS stuff, chances are it is a nasty. The majority of them will have a publisher listed which bad things won't (or not a legit one anyway) but that's not to say that ones without a publisher are bad (see: 7zip/winRAR)
http://technet.microsoft.com/en-us/sysi ... 63902.aspx
then go to options up the top and hide Microsoft Entries and then scour the remaining list. If there is anything fishy there or claiming to be MS stuff, chances are it is a nasty. The majority of them will have a publisher listed which bad things won't (or not a legit one anyway) but that's not to say that ones without a publisher are bad (see: 7zip/winRAR)