Results 1 to 8 of 8
  1. #1
    Pc Wizkid & Programmer :)
    Overall activity: 3.0%

    Join Date
    Jun 2008
    Location
    Rotherham, United Kingdom
    Posts
    1,195
    Liked
    48 times
    Points
    12,033
    i had a problem few days ago with a pc infested with malware ,and by accident i came across this web site http://www.2-spyware.com/ which has a nice little analyzer for hijack this, all u to is run hijack this, do a system scan and save a log ,copy paste this log into the analyzer and bingo! saves sifting through the hijack this log or posting it to a forum .
    Out of my mind. I Haven't Lost My Mind, It's Backed Up On Disk Somewhere.

  2. #2
    Administrator
    Overall activity: 46.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,802
    Liked
    1656 times
    Points
    48,740
    Nice addition to http://www.raymond.cc/blog/archives/2008/02/25/5-ways-to-automatically-analyze-hijackthis-log-file/

  3. #3
    Experienced User
    Overall activity: 0%

    Join Date
    Jun 2008
    Posts
    136
    Liked
    1 times
    Points
    6,127
    Wow nice site for analysis:)

  4. #4
    Experienced User
    Overall activity: 0%

    Join Date
    Jul 2007
    Location
    XyberSpace
    Posts
    434
    Liked
    0 times
    Points
    11,322
    thumbs up @ tangomouse nice one :)

  5. #5
    Pc Wizkid & Programmer :)
    Overall activity: 3.0%

    Join Date
    Jun 2008
    Location
    Rotherham, United Kingdom
    Posts
    1,195
    Liked
    48 times
    Points
    12,033
    lol cheers :)

  6. #6
    Experienced User
    Overall activity: 0%

    Join Date
    Apr 2008
    Location
    Chandigarh, India
    Posts
    313
    Liked
    0 times
    Points
    5,176
    Thanks tangomouse. Knew 5 of them, now they are six.

  7. #7
    Experienced User
    Overall activity: 0%

    Join Date
    Jun 2008
    Posts
    136
    Liked
    1 times
    Points
    6,127
    The analyser didn't tell anything suspicious about this process
    F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\sembako-ckzjlli.exe

  8. #8
    Experienced User
    Overall activity: 0%

    Join Date
    Apr 2008
    Location
    Chandigarh, India
    Posts
    313
    Liked
    0 times
    Points
    5,176
    This is what I found about sembako-ckzjlli.exe
    Its a W32/Brontok-M worm.
    Category: Viruses and Spyware
    Type: Worm
    Affected operating systems: Windows
    Characteristics: Installs itself in the registry
    Command: C:\Windows\sembako-cfzjkmg.exe
    Startup Type: If you are running Windows 95/98/ME, this startup entry is being started via the Shell= line in the Windows\system.ini file.
    If you are running Windows NT/XP/Vista/2000/2003, this startup entry is being started via the Shell= line in the registry key:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
    Here's how to clean it.
    Looks like Sophos is best in removing it but its shareware.

    How to Clean brontok virus by Raymond: http://www.raymond.cc/blog/archives/2006/12/08/how-to-clean-brontok-virus/


    OR Try scanning with Kaspersky AVP Tool
    http://dnl-eu14.kaspersky-labs.com/devbuilds/AVPTool/setup_7.0.0.223_02.07.2008_17-46.exe

 

 

Similar Threads

  1. NPE File Analyzer v1.1.2.1
    By nivels in forum Security Bulletin
    Replies: 4
    Last Post: 03-22-2011, 06:15 AM
  2. NPE File Analyzer v1.0
    By nivels in forum Security Bulletin
    Replies: 4
    Last Post: 11-20-2010, 07:55 PM
  3. Hijack
    By Ceyfer √ in forum Spyware/Viruses
    Replies: 4
    Last Post: 11-19-2010, 06:41 AM
  4. Can someone take a look at this hijack log please?
    By LunarWolf in forum Spyware/Viruses
    Replies: 4
    Last Post: 06-05-2009, 06:33 PM
  5. Hijack Log?
    By saturn in forum Spyware/Viruses
    Replies: 6
    Last Post: 05-11-2009, 01:16 AM
All times are GMT +8. The time now is 05:08 AM.