Found multiple infections: hldrrr.exe, srosa and more | Thread profile
Thread profile page for "Found multiple infections: hldrrr.exe, srosa and more" on http://www.devshed.com.
This report page is a snippet summary view from a single thread "Found multiple infections: hldrrr.exe, srosa and more", located on the Message Board at http://www.devshed.com.
This thread profile page shows the thread statistics for: Total Authors, Total Thread Posts, and Thread Activity, which are reported in a table below.
Additional thread profile information is also shown in the following ways:
Warning: These statistics are generated using 'best efforts' and can experience delays and reporting errors at times. Please note that such statistics do not constitute a thread's popularity and/or exact posting volumes at any given reporting period.
Title:
Found multiple infections: hldrrr.exe, srosa and more
Started 2 months, 1 week ago (2008-06-28 01:12:00)
by Trident18
A few days ago I downloaded a stupid file. My system had already been running slowly, but I immediately saw a huge slowdown, internet connections became sporadic and I was unable to open my A/V program [eset NOD32] at all. I found this site and tried running through the steps on the first sticky. The first two apps/directions wouldn't run at all. I was able to run Malwarebytes' Anti...
Started 2 months, 1 week ago (2008-06-28 01:17:00)
by Trident18
Changed http/https, .com, www to other stuff. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:50:19 PM, on 6/27/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\...
Started 2 months, 1 week ago (2008-06-28 01:23:00)
by Trident18
I should add that I'm very concerned about running some confidential software and opening files until this is resolved. I don't want the information from my Quickbooks files or confidential MSWord docs to be exposed if any damage will be done to them or if their data will be compromised. But I need to run them soon. I guess I need to know if it's OK to work with these files with ...
Started 2 months, 1 week ago (2008-06-28 02:40:00)
by Porthos
Welcome. Quote: I should add that I'm very concerned about running some confidential software and opening files until this is resolved. I don't want the information from my Quickbooks files or confidential MSWord docs to be exposed if any damage will be done to them or if their data will be compromised. But I need to run them soon. I guess I need to know if it's OK to...
Started 2 months, 1 week ago (2008-06-28 14:13:00)
by Trident18
I sort of messed up when I panicked yesterday- after reading this post, I clicked on the link to download ComboFix. When I tried browsing to another link, my connection was gone and AVG seemed disabled- it appeared to be running, but I couldn't open the GUI and couldn't repair or reinstall. After some messing around and running CF last night (but not having run HJT previously as ...
Started 2 months, 1 week ago (2008-06-28 14:18:00)
by Porthos
The more times you run Combofix I loose track of what it did. Do have the log form it. I need to see that before we go any further. Look for c\combofix.txt
Started 2 months, 1 week ago (2008-06-28 14:27:00)
by Trident18
Quote: Originally Posted by Porthos The more times you run Combofix I loose track of what it did. Do have the log form it. I need to see that before we go any further. Look for c\combofix.txt I did save the CF log last night. Here it is. Since then, I just ran HJT and only fixed the one item. ComboFix 08-06-20.4 - Owner 2008-06-27 23:51:33.1 - ...
Started 2 months, 1 week ago (2008-06-28 15:21:00)
by Trident18
Slightly OT: I can't seem to get my PC to allow my PPC/phone to sync using activesync. I have a feeling it's because of the AVG8 firewall, but might have something to do with the infection. If it is a result of the infection, is there a method for fixing it? If it's because of AVG, is someone familiar enough with the program to help me configure it properly?
Started 2 months, 1 week ago (2008-06-28 15:33:00)
by Porthos
First we need to move Combofix to the desktop. Quote: Running from: S:\Downloads \Combo-Fix.exe Make sure you follow all directions as to where to run the fixes I give you. * Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the Quote box below: Quote: ...
Size: 2,439 bytes
Customize:
Top contributing authors for Found multiple infections: hldrrr.exe, srosa and more
Name
Posts
Trident18
31
Porthos
21
Related threads on "Dev Shed Forums - Open Source web development":