Austech



iTrader Today's Posts Donate My Posts Classifieds Site Rules FAQ's
Go Back   Austech > Technology > Security and Privacy
Register Members List Upgrade Account Search Today's Posts Mark Forums Read

Security and Privacy Spyware , Proxies , all security and privacy issues and software.

Reply
 
LinkBack (2) Thread Tools Search this Thread Display Modes
Old 01-09-08, 05:41 PM   #21 (permalink)
Super Moderator
 
ssrattus's Avatar
 

iTrader: (0)
Join Date: Jan 2008
Posts: 1,233
Spent time on board: 3 Weeks, 6 Days and 6:42:58
ssrattus is on a distinguished road
Default

Gawd... routing.exe looks hard to remove see

BleepingComputer.com > Routing.exe Removal
ssrattus is offline   Reply With Quote
Sponsored Links
Old 01-09-08, 05:41 PM   #22 (permalink)
Premium Member
 

iTrader: (-1)
Join Date: Jan 2008
Location: newcastle nsw
Posts: 369
Spent time on board: 1 Week, 2 Days and 6:28:43
hamguy2 is on a distinguished road
Default

that worked i still have access to explorer emails etc ,but its still bringing up virus alert plus all of the other things wrong, i cannot see anything differnt in add or remove programs here ,
hamguy2 is offline   Reply With Quote
Old 01-09-08, 05:47 PM   #23 (permalink)
Super Moderator
 
ssrattus's Avatar
 

iTrader: (0)
Join Date: Jan 2008
Posts: 1,233
Spent time on board: 3 Weeks, 6 Days and 6:42:58
ssrattus is on a distinguished road
Default

Looks like this is a start for removing routing.exe from the link above

Please download Malwarebytes' Anti-Malware to your desktop.

http://www.besttechie.net/tools/mbam-setup.exe

Double-click mbam-setup.exe and follow the prompts to install the program.

At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded, select Perform quick scan, then click Scan.

When the scan is complete, click OK, then Show Results to view the results.

Be sure that everything is checked, and click Remove Selected.

When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
ssrattus is offline   Reply With Quote
Old 01-09-08, 06:06 PM   #24 (permalink)
Premium Member
 
fandtm666's Avatar
 

iTrader: (19)
Join Date: Jan 2008
Posts: 1,297
fandtm666 is on a distinguished road
Default

noxtcyr.exe also seems like an issue
Trend Security Vendor Chart
fandtm666 is offline   Reply With Quote
Sponsored Links
Old 01-09-08, 06:16 PM   #25 (permalink)
Premium Member
 

iTrader: (-1)
Join Date: Jan 2008
Location: newcastle nsw
Posts: 369
Spent time on board: 1 Week, 2 Days and 6:28:43
hamguy2 is on a distinguished road
Smile its fixed thanks very much members

hi everyone, the computers back to normal id like to thank all the members of the forum and i reckon ill join to become a premium member,also can anyone tell me or can provide me with a working copy of my theatre im told that is the best to use with my twinhan satcard with the ci interface, thanks hamguy2 nsw
hamguy2 is offline   Reply With Quote
Old 01-09-08, 06:27 PM   #26 (permalink)
Premium Member
 

iTrader: (-1)
Join Date: Jan 2008
Location: newcastle nsw
Posts: 369
Spent time on board: 1 Week, 2 Days and 6:28:43
hamguy2 is on a distinguished road
Smile yeah i removed that the otherday

hi i remove the second 1 you just told me about in safemode but it has returned, thanks hamguy2
hamguy2 is offline   Reply With Quote
Old 04-09-08, 01:28 PM   #27 (permalink)
Premium Member
 

iTrader: (0)
Join Date: Jan 2008
Posts: 98
Spent time on board: 1 Day and 5:54:12
bucket is on a distinguished road
Default

HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System, DisableRegedit=1

Regedit may have been disabled by your AV software though.

C:\WINDOWS\system32\
sobicyt.exe, tdxdowkc.exe, wserving.exe, wsldoekd.exe, avgrsstx.dll, afinding.exe, afisicx.exe, macidwe.exe, Nobicyt.exe, noxtcyr.exe, perfs.exe, roxtctm.exe, sotpeca.exe

All look suss to me. I'd be checking the system32 folder, arrange files by modified and I'm willing to bet they are all around the same date. Or just google them.

C:\WINDOWS\portsv.exe

Also looks like a problem to me.
bucket is offline   Reply With Quote
Sponsored Links
Old 04-09-08, 02:31 PM   #28 (permalink)
Senior Member
 

iTrader: (0)
Join Date: Jan 2008
Posts: 162
Spent time on board: 5 Days and 20:20:58
Al Bundy is on a distinguished road
Default

You have been infected with either
Windows Antivirus 2008 or
Vista Antivirus 2008 do a search on those 2 terms and see what comes up.

I had to get my machine back to a stage where I could recover the info I wanted off the Hard Drive and then wiped it and re installed my OS, its a c@#t of a thing.
__________________
Cheers

Ted (Al)
Al Bundy is online now   Reply With Quote
Old 04-09-08, 02:43 PM   #29 (permalink)
Senior Member
 
Jaz808's Avatar
 

iTrader: (0)
Join Date: Jan 2008
Location: Hell
Posts: 270
Spent time on board: 4 Days and 5:46:17
Jaz808 is on a distinguished road
Default

My bro-inlaw had the MS Antivirus similar to the Xp Antivirsalso had the missing C drive, nothing it the start menu, no run, control panel ect, what a bitch to remove, had to restore policies, run more than half a dozen different fixes, inculing Melwarebytes, SmitFraud, Dail'a'Fix HijackThis ect
Jaz808 is offline   Reply With Quote
Old 04-09-08, 05:05 PM   #30 (permalink)
Senior Member
 
Woodstock's Avatar
 

iTrader: (14)
Join Date: Jan 2008
Location: Mt Gambier
Posts: 727
Spent time on board: 2 Weeks, 4 Days and 10:14:37
Woodstock is on a distinguished road
Default

Sounds like the one I removed from customers PC yesterday .. 3 hrs laters ... it had them all ! c: and d: missing in my computer and icon from start menus - VIRUS ALERT! in systray next to clock .... Malwarebytes.. AVG ... CCleaner and del there and there .. all fixed !
__________________
Trust thyself only, and another shall not betray thee.
Woodstock is online now   Reply With Quote
Sponsored Links
Reply


LinkBacks (?)
LinkBack to this Thread: http://www.austech.info/security-privacy/10574-computer-problem-reemoving-trojan-virus.html
Posted By For Type Date
Security and Privacy [Archive] - Austech This thread Refback 05-09-08 09:22 PM
Austech - Powered by vBulletin This thread Refback 01-09-08 04:56 PM

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


server monitor
All times are GMT +10. The time now is 08:08 AM.


Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.

Ad Management by RedTyger