Sep 26, 2008, 11:24 PM // 23:24
|
#21
|
Banned
Join Date: Jun 2008
Location: Aussie Trolling Crew - Spah!
|
Quote:
Originally Posted by tarun
well i'm not going to leave you waiting for days.
i removed your screenshot of the nod result because that did show the link to malware. I'm going to drop it into a vm and see how it reacts.
|
score: 1 for the amateur!
|
|
|
Sep 27, 2008, 02:20 AM // 02:20
|
#22
|
Technician's Corner Moderator
Join Date: Jan 2006
Location: The TARDIS
Guild: http://www.lunarsoft.net/ http://forums.lunarsoft.net/
|
tinyproxy.exe is one of the processes that gets installed if the exe is allowed to run. Avast found and deleted it.
|
|
|
Sep 27, 2008, 07:15 AM // 07:15
|
#23
|
Jungle Guide
Join Date: Jun 2006
Location: Boise Idaho
Guild: Druids Of Old (DOO)
Profession: R/Mo
|
Quote:
Originally Posted by Tarun
Sir Seifus Halbred:
It looks like your NOD32 took care of the problem. It also looks like a website tried to pose as YouTube and wanted you to download some "codecs" that are actually malware.
What site are you encountering this issue on?
|
I managed to have malware installed from youtube just that way. But it was multi-part and the "codec" was a downloader that had a short field day. Both avast and Sypbot S&D missed it until I had another AV doing a scan.
Tarun, if you want the details I can provide most of them to you.
|
|
|
Sep 27, 2008, 09:06 AM // 09:06
|
#24
|
Banned
Join Date: Jan 2006
Location: Bermuda Triangle
Profession: W/
|
NOD32 is straight up G and I use it cuz it keeps the five-o off the block.
|
|
|
Sep 27, 2008, 04:06 PM // 16:06
|
#25
|
Technician's Corner Moderator
Join Date: Jan 2006
Location: The TARDIS
Guild: http://www.lunarsoft.net/ http://forums.lunarsoft.net/
|
Quote:
Originally Posted by KZaske
I managed to have malware installed from youtube just that way. But it was multi-part and the "codec" was a downloader that had a short field day. Both avast and Sypbot S&D missed it until I had another AV doing a scan.
Tarun, if you want the details I can provide most of them to you.
|
Please do.
The only scanner that found anything was avast; SAS, MBAM, and Spybot did not find anything.
|
|
|
Sep 28, 2008, 04:54 PM // 16:54
|
#26
|
Wilds Pathfinder
|
Update: Got Ad Aware 2008 to open, did a FULL scan last night, it found the same thing NOD 32 found and removed it. Haven't seen the pop up message from NOD 32. I think it's solved.
|
|
|
Sep 28, 2008, 05:42 PM // 17:42
|
#27
|
Technician's Corner Moderator
Join Date: Jan 2006
Location: The TARDIS
Guild: http://www.lunarsoft.net/ http://forums.lunarsoft.net/
|
Could you post the log from Ad-Aware 2008 please? Be sure to wrap it in a codebox.
|
|
|
Sep 29, 2008, 12:19 AM // 00:19
|
#29
|
Technician's Corner Moderator
Join Date: Jan 2006
Location: The TARDIS
Guild: http://www.lunarsoft.net/ http://forums.lunarsoft.net/
|
I just had to install it into a VM and I must say wow is it ever garbage. Even after cleaning out tracking cookies, I can't see a log through the program. Instead, you have to navigate to...
If installed for All Users:
Code:
C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\logs\
If installed for just your account:
Code:
C:\Documents and Settings\USERNAME\Application Data\Lavasoft\Ad-Aware\logs\
On Vista it will be slightly different.
My log was named: Ad-Aware 20080928 20-12-21.log.xml
You can copy it to the desktop, zip it and host it with a file sharing service like Rapidshare or Mediafire.
|
|
|
Thread Tools |
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT. The time now is 01:40 AM // 01:40.
|