Reply

Join Date: Dec 2006
Posts: 922
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 43
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is online now Online
Posting Shark

Re: trojan.conficker.H

 
0
  #11
Sep 18th, 2009
Originally Posted by jholland1964 View Post
The server is MOST DEFINITELY infected, 7 out of 11 say so. But jotti uses 22 scanners, why are there only 11 showing?
They are all showing, Judy - look more closely

That rules out any sort of false-positive.
Frankly, MBA-M should remove this, so something is restoring it: either the drive is infected or you have an infected pen drive(s).

There are a number of different ways to attack this - I'm sure Judy or tiger86 can help you on that front.

Best Luck
PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 2,968
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 169
Moderator
Featured Poster
jholland1964 jholland1964 is online now Online
Posting Maven

Re: trojan.conficker.H

 
0
  #12
Sep 18th, 2009
Originally Posted by PhilliePhan View Post
They are all showing, Judy - look more closely

That rules out any sort of false-positive.
Frankly, MBA-M should remove this, so something is restoring it: either the drive is infected or you have an infected pen drive(s).

There are a number of different ways to attack this - I'm sure Judy or tiger86 can help you on that front.

Best Luck
PP
I have never seen a jotti log look like that. No scanner names, just a header Scanner then just dates. 11 lines.
Last edited by jholland1964; Sep 18th, 2009 at 4:07 pm.
Reply With Quote Quick reply to this message  
Join Date: Sep 2009
Posts: 6
Reputation: syswee is an unknown quantity at this point 
Solved Threads: 0
syswee syswee is offline Offline
Newbie Poster

Re: trojan.conficker.H

 
0
  #13
Sep 22nd, 2009
Originally Posted by jholland1964 View Post
The server is MOST DEFINITELY infected, 7 out of 11 say so. But jotti uses 22 scanners, why are there only 11 showing?
it is actually 22 scanner, left and right...

i realign it as below.
2009-09-17 Worm.Kido.ix
2009-09-18 Worm.Autorun.VHG
2009-09-18 Worm.Win32.Conficker!IK
2009-09-18 Worm.Win32.Conficker
2009-09-17 BV:AutoRun-S
2009-09-18 Net-Worm.Win32.Kido.ix
2009-09-17 Worm/Generic_c.ZS
2009-09-17 Found nothing
2009-09-17 WORM/Kido.IX
2009-09-17 Found nothing
2009-09-18 Worm.Autorun.VHG
2009-09-17 W32/Conficker.C.worm
2009-09-17 Worm.Autorun-1838
2009-09-17 Found nothing
2009-09-18 W32.Net.W.Kido.ix 2
009-09-18 Mal/ConfInf-A
2009-09-17 Win32.HLLW.Autoruner.5601
2009-09-17 Found nothing
2009-09-17 JS/AutoRun
2009-09-17 INF.Conficker.F
2009-09-18 Worm:W32/Downaduprun.A

since identify the server infected, what should i do next
Reply With Quote Quick reply to this message  
Join Date: Feb 2008
Posts: 462
Reputation: tiger86 is an unknown quantity at this point 
Solved Threads: 10
tiger86's Avatar
tiger86 tiger86 is offline Offline
Posting Pro in Training

Re: trojan.conficker.H

 
0
  #14
Sep 23rd, 2009
Hey sorry I haven't posted in a while. I did some quick research. Your log is very, well bad. You appear to be confickered majorly. If the conficker virus doesn't stop you from going to microsofts support page please follow the link http://support.microsoft.com/kb/962007 also on that page to see if your clean of conficker theres a link to http://safety.live.com and here is the Manual... yes a manual on removing conficker http://support.microsoft.com/kb/962007#Manualsteps
I hope that is helpful.
If I helped you I would appreciate it if you would give me some reputation.
read my actionscript to english blog
Currently developing what should be social network 2.0 offline.
Reply With Quote Quick reply to this message  
Reply

Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC