Page 1 of 3 123 LastLast
Results 1 to 10 of 22
  1. #1
    Newbie
    Overall activity: 0%

    Join Date
    May 2010
    Posts
    4
    Liked
    0 times
    Points
    1,782

    for raymond & experts

    help on security.
    Last edited by syracuse; 09-03-2011 at 11:00 AM.

  2. #2
    Senior Techie
    Overall activity: 0%

    Join Date
    Oct 2009
    Posts
    223
    Liked
    1 times
    Points
    3,704
    do u download crackwarez? Perhaps you can try malwarebytes and Superantispyware to do a malware scan .Weirdly, this two always detect malicious codes that are not detected by many antiviruses. If you like and since you already detected the process id, you can try killbox to terminate the process then forcefully delete it from your computer. you can download killbox from softpedia, it's free. Besides, you can try too virus effect remover that will scan vulnerabilities of your registry and fix it.But aware of those tools above as it could end up damage your system.

  3. #3
    Supernova
    Overall activity: 76.0%

    Join Date
    Feb 2010
    Location
    Calcutta, India, India
    Posts
    3,730
    Liked
    667 times
    Points
    48,426
    Kaspersky always detected my touchpad driver as keylogger..PDM.Keylogger kernel mode memory patch..
    @syracuse: you need to dig into the advanced reports to see what is the name of that file that is detected as keylogger.
    Every day brings a chance for you to draw in a breath, kick off your shoes, and dance.

  4. #4
    Whiz Kid
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    Albania
    Posts
    1,771
    Liked
    80 times
    Points
    20,857
    Post a HijackThis log and you might consider sujays answer!

    Screw Google! Ask me!


  5. #5
    Senior Techie
    Overall activity: 0%

    Join Date
    Oct 2009
    Posts
    223
    Liked
    1 times
    Points
    3,704
    like what sujay said, it's a very normal thing happens in KIS and KAV. I used to have this problem and the way I solved it is to run a registry cleaner like Glary utilities or Advanced System Care.just try this.Furthermore, this won't harm your pc.if this couldn't help, just post a hijackthis log here. I believe the others like leofelix,hellnoire will likely to help u.

  6. #6
    Supernova
    Overall activity: 76.0%

    Join Date
    Feb 2010
    Location
    Calcutta, India, India
    Posts
    3,730
    Liked
    667 times
    Points
    48,426
    @dredge: no registry cleaners please. It will remove many valid things as well....

  7. #7
    acr
    acr is offline
    Banned
    Overall activity: 0%

    Join Date
    Jul 2009
    Posts
    563
    Liked
    2 times
    Points
    9,798
    I agree with the above statements about you being careful as KAV/KIS can throw up a false positive, especially in regards to keyloggers. If I were you I would go to the kaspersky forum and make a post about your issue. There is usually a fairly fast response to questions. If you think you have a rootkit, I would download and scan with Prevx free version as they will remove some rootkits free of charge.

  8. #8
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    Code:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{428c6eeb-3fc3-4109-b19f-108e177721ac}: NameServer = 158.43.240.4  4.2.2.3	
    O17 - HKLM\System\CCS\Services\Tcpip\..\{70A724C1-EA21-41A5-88D4-B5F866D2B40A}: NameServer = 158.43.240.4,4.2.2.3 
    O17 - HKLM\System\CS1\Services\Tcpip\..\{428c6eeb-3fc3-4109-b19f-108e177721ac}: NameServer = 158.43.240.4 4.2.2.3
    if you don't know those IPs I'd do something about that, otherwise, looks clean to me. You might want to report a FP to Kaspersky. If you don't use any warez or anything like that, and your stuff is all legal, it should be nothing more then a false positive. However, I know EvilFantasy would like to see a different log... but I forget what it's called that looks for rootkits.'

    EDIT: I just noticed you had a second post, one I had to manually approve... that is very odd. It sounds like a rootkit infection, but I forget how he was able to tackle them. It would be best to wait for him if you can, or if you can't and need to have an urgent fix, you could do the classic "nuke and install"... but that's overkill and I'm sure he'd be able to solve your issue without going that far.
    Last edited by hellnoire; 05-07-2010 at 02:17 AM.
    pacman -Syyu life not found in sync db

  9. #9
    Senior Techie
    Overall activity: 0%

    Join Date
    Oct 2009
    Posts
    223
    Liked
    1 times
    Points
    3,704
    perhaps you should run GMER or rootkit revealer to post a scan log here, so that we would know what rootkit that is running on your system. Besides, icesword is a great tool to terminate the process and delete the said file, but I couldn't find anything to indicate that it supports windows 7.

  10. #10
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    If you used a keygen or patch, there's not much we can tell you: chances are good it's infected.

    This is why you shouldn't use warez, because there are a lot out there that will infect you if you don't know what you're doing. This is why we have the rules against warez.

    Now that you've admitted to using warez, there's even less we can do now. Not because of the rules but because it's hardcoded into your programs. That patch and keygen are probably infected to the teeth.

 

 
Page 1 of 3 123 LastLast

Similar Threads

  1. Top hacker 'retires'; experts brace for his return
    By johnshaw1917 in forum General Forum
    Replies: 9
    Last Post: 11-01-2010, 10:58 AM
  2. for the attention of experts like Raymond...!
    By badboy2009 in forum General Forum
    Replies: 7
    Last Post: 11-30-2009, 08:32 PM
  3. for the attention of experts like Raymond...!
    By badboy2009 in forum Freebies!
    Replies: 7
    Last Post: 11-29-2009, 10:02 PM
  4. Replies: 6
    Last Post: 06-25-2009, 07:00 PM
All times are GMT +8. The time now is 08:56 AM.