
05-20-2008, 01:58 AM
|
|
Registered User
|
|
Join Date: Jan 2005
Location: Palmdale
Posts: 283
|
|
|
unknown trojan ...
vtUlMfFX.dll
thats what is calls itself ...
it keeps regenerating itslef ... and its really annoying ...
i researched it briefly but found nothing ...
someone help?
__________________
adoBo` Justin [pnoy]
|

05-20-2008, 03:06 AM
|
|
Registered User
|
|
Join Date: Jan 2005
Location: Palmdale
Posts: 283
|
|
|
this problem occurs everytime that i start up my computer from shut down, hibernate, sleep, restart .... after that ... it doesnt bother .... atleast i dont think so ...
__________________
adoBo` Justin [pnoy]
|

05-20-2008, 06:32 AM
|
 |
Registered User
|
|
Join Date: Jan 2007
Location: Australia
Posts: 1,868
|
|
What antivirus/antispyware software are you using? Download http://www.superantispyware.com/ and install and update, boot into safe mode and run a full scan.
__________________
http://www.doddpc.com
MCP
MCDST
|

05-20-2008, 07:06 PM
|
|
Registered User
|
|
Join Date: Jan 2005
Location: Palmdale
Posts: 283
|
|
|
i have Avast Professional and i have ran MANY tests ... it catches it everytime , but it still comes back up ...
but its weird ... i tried to delete the file in safe mode ... and now its gone ...
is that a good thing?
__________________
adoBo` Justin [pnoy]
|

05-20-2008, 09:59 PM
|
|
Registered User
|
|
Join Date: Jan 2005
Location: Palmdale
Posts: 283
|
|
|
stay on topic please ...
i have new viruses to talk about ...
along with
vtUlMfFX.dll
there is also ...
mlJDutqq.dll
wvUnoppO.dll
these just poped up ....
what can i do!!!!
they keep poping up !!!! AHHH
__________________
adoBo` Justin [pnoy]
|

05-20-2008, 10:17 PM
|
 |
Temporary Ban
|
|
Join Date: Sep 2002
Location: In a plasma conduit
Posts: 1,625
|
|
Quote:
|
Originally Posted by animefreak
stay on topic please ...
|
I'm just having a go at the spammer above mate. I reported him.
Ok, it looks like what you have is generating random names to evade removal or something.
You could try hijackthis:
http://www.trendsecure.com/portal/en...ols/hijackthis.
Maybe post a log. See what we can see:
Try Monty's suggestion: http://www.superantispyware.com/
Or Ewido online scan. When you go here it will install the scanner, automatically it seems. http://www.ewido.net/en/onlinescan/
__________________
Where there's a will, There's a way.
Pay developers, not Rapidshare!
I know nowt, but at least I'm trying. 
Quality, not quantity.
Prevention is better than cure.
Last edited by Disk_Contented : 05-20-2008 at 10:24 PM.
|

05-20-2008, 11:14 PM
|
|
Registered User
|
|
Join Date: Jan 2005
Location: Palmdale
Posts: 283
|
|
|
i forgot about hijackthis ...
ill try it ... but a new one came up ... AGAIN
name : efcDTKef.dll
__________________
adoBo` Justin [pnoy]
|

05-20-2008, 11:29 PM
|
|
Registered User
|
|
Join Date: Jan 2005
Location: Palmdale
Posts: 283
|
|
|
what is MSServer ....
that runs in my processes when i start the task manager ....
and a ton of Rundll32 crap ....
__________________
adoBo` Justin [pnoy]
|

05-20-2008, 11:31 PM
|
|
Registered User
|
|
Join Date: Jan 2005
Location: Palmdale
Posts: 283
|
|
|
so i used hijack this ... and when i tried to delete ... a new trojan poped up
C:\Users\marissa\Documents\things\Programs\Program Installations\backups\backup-20080520-203005-466.dll
and the trojans are still there ...
__________________
adoBo` Justin [pnoy]
|

05-22-2008, 01:34 AM
|
|
Registered User
|
|
Join Date: Jan 2005
Location: Palmdale
Posts: 283
|
|
|
in Run i found that this NEW program runs on startup ...
and i have never heard or seen it running ... ever
it goes under the name .... MSServer and the file name is oppnljIB.dll
when i try to disable auto startup, it starts up still ....
and when i check it again, its like it forces itself to be on the startup list...
__________________
adoBo` Justin [pnoy]
|

05-22-2008, 04:35 AM
|
 |
Temporary Ban
|
|
Join Date: Sep 2002
Location: In a plasma conduit
Posts: 1,625
|
|
You best read this: http://www.auditmypc.com/process/mssvr.asp
May not be the same thing. Post a Hijackthis log
__________________
Where there's a will, There's a way.
Pay developers, not Rapidshare!
I know nowt, but at least I'm trying. 
Quality, not quantity.
Prevention is better than cure.
|

05-22-2008, 06:38 PM
|
|
Registered User
|
|
Join Date: Jan 2005
Location: Palmdale
Posts: 283
|
|
|
hahaha
i stopped it from happening ... but i did not kill it ...
i opened the file in safe mode with notepad .... and i deleted the content and saved it lol
there is an error that pops up when i start up, but ... nothing is running slower now!!!
__________________
adoBo` Justin [pnoy]
|

05-22-2008, 06:49 PM
|
|
Registered User
|
|
Join Date: Jan 2005
Location: Palmdale
Posts: 283
|
|
|
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 3:49:05 PM, on 5/22/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
Boot mode: Normal
Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\FirefoxPortable\App\firefox\firefox.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\marissa\Documents\things\Programs\Program Installations\HiJackThis_v2.exe
O2 - BHO: (no name) - {2AA0726C-95B7-4216-AA43-B5BDD524892F} - C:\Windows\system32\jkkJbArp.dll
O2 - BHO: (no name) - {DD231873-E3A9-498F-8580-CE1847D4FAF0} - C:\Windows\system32\vtUlMfFX.dll (file missing)
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\jkkJbArp.dll,#1
O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\Windows\system32\hasplms.exe
--
End of file - 1043 bytes
__________________
adoBo` Justin [pnoy]
|

05-23-2008, 07:22 AM
|
 |
Registered User
|
|
Join Date: May 2008
Posts: 71
|
|
vista trojans and malware/spyware
There are several new Trojans for vista and you can do several things to eliminate them.
run hijackthis and generate a report,this can be assessed and you may get help here or at bulldog antivirus forums forums (Touch would help you there amongst others and he is good).
From practical experience with Vista which seems to be the most targeted of the windows systems at the moment,I know Nortons/symnatec have come out with some new definitions in regard to Vista Trojans just recently and although not my favorite anti virus would update it if you have it.
I personally wouldn't touch Vista with a big pole until they have worked out all the teething problems with it as they have with xp and it`s only taken them 9 years to get that right.
The next windows release will probably be in conjunction with Linux as they are collaborating now in that regard,then it might be worth more than its inflated price and vulnerabilities.
Also read what disk contented had to say and check this link http://www.auditmypc.com/process/mssvr.asp from your description it does sound like ms server issue as link describes,although may be renamed to appear that way as well.
Last edited by Embolism : 05-23-2008 at 07:33 AM.
|

05-23-2008, 09:01 AM
|
 |
Temporary Ban
|
|
Join Date: Sep 2002
Location: In a plasma conduit
Posts: 1,625
|
|
Quote:
|
Originally Posted by animefreak
hahaha
i stopped it from happening ... but i did not kill it ...
i opened the file in safe mode with notepad .... and i deleted the content.
|
Now you lost me. What file?
Seriously, this is one case where I would wipe the lot and start from new.
You have no idea what this is and as you've seen. It's clever.
Shut down the PC for several minutes before the reinstall just to make sure there's no soft reset surviving resident stuff hanging about.
If these files are remote logs your treading on possibly dangerous waters.
Paranoid? Not these days.
Quote:
There are several new Trojans for vista and you can do several things to eliminate them.
run hijackthis and generate a report,this can be assessed and you may get help here or at bulldog antivirus forums forums (Touch would help you there amongst others and he is good).
From practical experience with Vista which seems to be the most targeted of the windows systems at the moment,I know Nortons/symnatec have come out with some new definitions in regard to Vista Trojans just recently and although not my favorite anti virus would update it if you have it.
I personally wouldn't touch Vista with a big pole until they have worked out all the teething problems with it as they have with xp and it`s only taken them 9 years to get that right.
The next windows release will probably be in conjunction with Linux as they are collaborating now in that regard,then it might be worth more than its inflated price and vulnerabilities.
Also read what disk contented had to say and check this link http://www.auditmypc.com/process/mssvr.asp from your description it does sound like ms server issue as link describes,although may be renamed to appear that way as well.
|
A man after my own heart.
Windows probably will one day be linux, with a windows emulator for the "legacy" windows OS 
__________________
Where there's a will, There's a way.
Pay developers, not Rapidshare!
I know nowt, but at least I'm trying. 
Quality, not quantity.
Prevention is better than cure.
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Rate This Thread |
Linear Mode
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
All times are GMT -5. The time now is 03:38 AM. |
|
|
|