Ping David Lipman

Ping David Lipman

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Ping David Lipman Martin Goreing 04-01-2008
Posted by Martin Goreing on April 1, 2008, 10:44 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi there

Have you any experience with this particular crittur?

I have started a thread with more info here:
http://forums.spybot.info/showthread.php?t=26236

If you are able to assist, I would appreciate your advice.

Cheers

Martin
aussiebloke@<NOSPAM>hotmail.com





> G'day all
>
> I have manually edited the registry item:
>
> HKEY_Local_Machine\SOFTWARE\Microsoft\Windows NT\Current
> Version\Winlogon\System=kdgru.exe
>
> deleting this: System=kdgru.exe
>
> on reboot it is back in the registry.
>
> A file search does not find kdgru.exe
>
> Spybot identifies it as Zlob.DNSChanger.rtk
>
> When I attempt to 'fix Problem' in Spybot it crashes.
>
> Windows Malicious Software Remover Tool finds nothing on quick scan, and
> crashes on full scan.
>
> Norton finds nothing...
>
> Any suggestions would be appreciated - TIA.
>
>
> Cheers
>
> Martin
>
>
> aussiebloke@<NOSPAM>hotmail.com
>



Posted by David H. Lipman on April 1, 2008, 3:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hi there
|
| Have you any experience with this particular crittur?
|
| I have started a thread with more info here:
| http://forums.spybot.info/showthread.php?t=26236
|
| If you are able to assist, I would appreciate your advice.
|
| Cheers
|
| Martin
| aussiebloke@<NOSPAM>hotmail.com
|

Hi Martin:

I sent a ping to SpyBot personnel so someone will help you shortly.

You ran the VundoFix utility which is associated with a different malware family.
You have a ZLob Trojan associated with the SmitFraud family of malware.

However, I must note that you are using a very old and vulnerable version of Sun
Java. A
version well known for its exploitation leading to infection.

It is highly suggested that you update to the latest version which is Sun Java
JRE/JSE
Version 6.0 update 5 (jre 6u5)

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version. All older
versions should
be deleted.

Such as...
C:\Program Files\Java\jre1.6.0_05

http://java.sun.com/javase/downloads/index.jsp
http://www.java.com/en/download/manual.jsp

Additionally there is; O21 - SSODL: bokpkov
Which may be the peer protecting the Winlogon/System parameter.

I won't look any further. I let you get your peresonal assistance in the SpyBot
forum.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Martin Goreing on April 1, 2008, 6:46 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thank you David, I appreciate your assistance.

I have to rush off to work now, but will follow up on your advice later.


Cheers

Martin


>
> | Hi there
> |
> | Have you any experience with this particular crittur?
> |
> | I have started a thread with more info here:
> | http://forums.spybot.info/showthread.php?t=26236
> |
> | If you are able to assist, I would appreciate your advice.
> |
> | Cheers
> |
> | Martin
> | aussiebloke@<NOSPAM>hotmail.com
> |
>
> Hi Martin:
>
> I sent a ping to SpyBot personnel so someone will help you shortly.
>
> You ran the VundoFix utility which is associated with a different malware
> family.
> You have a ZLob Trojan associated with the SmitFraud family of malware.
>
> However, I must note that you are using a very old and vulnerable version
> of Sun Java. A
> version well known for its exploitation leading to infection.
>
> It is highly suggested that you update to the latest version which is Sun
> Java JRE/JSE
> Version 6.0 update 5 (jre 6u5)
>
> Simple check, look under...
> C:\Program Files\Java
>
> The only folder under that folder should be the latest version. All older
> versions should
> be deleted.
>
> Such as...
> C:\Program Files\Java\jre1.6.0_05
>
> http://java.sun.com/javase/downloads/index.jsp
> http://www.java.com/en/download/manual.jsp
>
> Additionally there is; O21 - SSODL: bokpkov
> Which may be the peer protecting the Winlogon/System parameter.
>
> I won't look any further. I let you get your peresonal assistance in the
> SpyBot forum.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



Posted by Ben on April 1, 2008, 8:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
> | Hi there
> |
> | Have you any experience with this particular crittur?
> |
> | I have started a thread with more info here:
> | http://forums.spybot.info/showthread.php?t=26236
> |
> | If you are able to assist, I would appreciate your advice.
> |
> | Cheers
> |
> | Martin
> | aussiebloke@<NOSPAM>hotmail.com
> |
>
> Hi Martin:
>
> I sent a ping to SpyBot personnel so someone will help you shortly.
>
> You ran the VundoFix utility which is associated with a different malware
> family.
> You have a ZLob Trojan associated with the SmitFraud family of malware.
>
> However, I must note that you are using a very old and vulnerable version
> of Sun Java. A
> version well known for its exploitation leading to infection.
>
> It is highly suggested that you update to the latest version which is Sun
> Java JRE/JSE
> Version 6.0 update 5 (jre 6u5)
>
> Simple check, look under...
> C:\Program Files\Java
>
> The only folder under that folder should be the latest version. All older
> versions should
> be deleted.
>
> Such as...
> C:\Program Files\Java\jre1.6.0_05
>
> http://java.sun.com/javase/downloads/index.jsp
> http://www.java.com/en/download/manual.jsp
>
> Additionally there is; O21 - SSODL: bokpkov
> Which may be the peer protecting the Winlogon/System parameter.
>
> I won't look any further. I let you get your peresonal assistance in the
> SpyBot forum.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>
I updated to Java ver.6 update 5, and it put a program on my
computer..........Puzzle Pirates........... Now, how do I get it out? I
have tried to uninstall it with out any success. It showed to be
uninstalled in Add/Remove Programs (does not appear). But it is still in
the Start > All Programs list, and when I click on it, it will still open.
I do a search for files, they appear, but will not allow me to delete them.



Posted by David H. Lipman on April 1, 2008, 8:57 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


| I updated to Java ver.6 update 5, and it put a program on my
| computer..........Puzzle Pirates........... Now, how do I get it out? I
| have tried to uninstall it with out any success. It showed to be
| uninstalled in Add/Remove Programs (does not appear). But it is still in
| the Start > All Programs list, and when I click on it, it will still open.
| I do a search for files, they appear, but will not allow me to delete them.
|

I don't know where "Puzzle Pirates" came from but it didn't come from Sun.

http://forums.puzzlepirates.com/community/mvnforum/viewthread?p=66863

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Similar ThreadsPosted
David Lipman September 11, 2007, 6:34 am
MULTI_AV.EXE for David H. Lipman December 27, 2005, 10:11 am
Mult_av for David lipman January 3, 2006, 7:05 pm
Kaspersky for David Lipman January 10, 2006, 4:34 pm
Attn::::David H Lipman March 14, 2007, 5:14 pm
Attn:David Lipman October 3, 2007, 1:04 pm
Re: Multi_VA trashed my system (Can David H Lipman please look a this) May 15, 2006, 1:12 pm
Re: Has David Lipman been providing malware to known malware criminals? March 24, 2007, 7:10 pm
Re: Has David Lipman been providing malware to known malware criminals? March 24, 2007, 7:15 pm
Re: Has David Lipman been providing malware to known malware criminals? March 26, 2007, 8:28 am

The site map in XML format XML site map

Contact Us | Privacy Policy