943,678 Members | Top Members by Rank

Ad:
You are currently viewing page 2 of this multi-page discussion thread; Jump to the first page
Sep 18th, 2009
0

Re: trojan.conficker.H

The server is MOST DEFINITELY infected, 7 out of 11 say so. But jotti uses 22 scanners, why are there only 11 showing?
They are all showing, Judy - look more closely

That rules out any sort of false-positive.
Frankly, MBA-M should remove this, so something is restoring it: either the drive is infected or you have an infected pen drive(s).

There are a number of different ways to attack this - I'm sure Judy or tiger86 can help you on that front.

Best Luck
PP
Moderator
Reputation Points: 169
Solved Threads: 106
Central Scrutinizer
PhilliePhan is offline Offline
1,575 posts
since Dec 2006
Sep 18th, 2009
0

Re: trojan.conficker.H

They are all showing, Judy - look more closely

That rules out any sort of false-positive.
Frankly, MBA-M should remove this, so something is restoring it: either the drive is infected or you have an infected pen drive(s).

There are a number of different ways to attack this - I'm sure Judy or tiger86 can help you on that front.

Best Luck
PP
I have never seen a jotti log look like that. No scanner names, just a header Scanner then just dates. 11 lines.
Last edited by jholland1964; Sep 18th, 2009 at 4:07 pm.
Moderator
Featured Poster
Reputation Points: 725
Solved Threads: 339
Posting Expert
jholland1964 is offline Offline
5,497 posts
since Jul 2008
Sep 22nd, 2009
0

Re: trojan.conficker.H

The server is MOST DEFINITELY infected, 7 out of 11 say so. But jotti uses 22 scanners, why are there only 11 showing?
it is actually 22 scanner, left and right...

i realign it as below.
2009-09-17 Worm.Kido.ix
2009-09-18 Worm.Autorun.VHG
2009-09-18 Worm.Win32.Conficker!IK
2009-09-18 Worm.Win32.Conficker
2009-09-17 BV:AutoRun-S
2009-09-18 Net-Worm.Win32.Kido.ix
2009-09-17 Worm/Generic_c.ZS
2009-09-17 Found nothing
2009-09-17 WORM/Kido.IX
2009-09-17 Found nothing
2009-09-18 Worm.Autorun.VHG
2009-09-17 W32/Conficker.C.worm
2009-09-17 Worm.Autorun-1838
2009-09-17 Found nothing
2009-09-18 W32.Net.W.Kido.ix 2
009-09-18 Mal/ConfInf-A
2009-09-17 Win32.HLLW.Autoruner.5601
2009-09-17 Found nothing
2009-09-17 JS/AutoRun
2009-09-17 INF.Conficker.F
2009-09-18 Worm:W32/Downaduprun.A

since identify the server infected, what should i do next
Reputation Points: 10
Solved Threads: 0
Newbie Poster
syswee is offline Offline
6 posts
since Sep 2009
Sep 23rd, 2009
0

Re: trojan.conficker.H

Hey sorry I haven't posted in a while. I did some quick research. Your log is very, well bad. You appear to be confickered majorly. If the conficker virus doesn't stop you from going to microsofts support page please follow the link http://support.microsoft.com/kb/962007 also on that page to see if your clean of conficker theres a link to http://safety.live.com and here is the Manual... yes a manual on removing conficker http://support.microsoft.com/kb/962007#Manualsteps
I hope that is helpful.
Reputation Points: 48
Solved Threads: 11
Posting Pro
tiger86 is offline Offline
540 posts
since Feb 2008

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: HijackThis & MBAM logs | MBAM keeps blocking infected ip numbers "infection detected"
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: cant access C drive by double click





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC