Gizmos Freeware Reviews  

Go Back   Gizmo's Freeware Forum > Debating Chamber > Security

Reply
 
Thread Tools Display Modes
Old 26. Jul 2010, 08:50 PM   #11 (permalink)
Senior Member
 
emmjay's Avatar
 
Join Date: Dec 2009
Posts: 226
Default

Quote:
Originally Posted by emmjay View Post
Hi Aunupam.


After much searching I found a post on MBAM from a user who was infected. MBAM tried but could not help, however the user forged ahead. They posted their experience (a very involved and complicated process ... they provided a translation from German, so it is a little hard to follow). The user believes the bootkit was removed using a fix they got from another source. They provided a link to the fix (it is a rar). I can provide a link to it, if it is allowed here at Gizmo (not sure where you stand on these types of links). Hopefully it will help if one of our members or guests get infected, let me know. .
Did not get your advise on this. Here is the link http://www.esagelab.com

Download bootkit_remover.rar and use 7-zip to open it up.

Update: This bootkit is showing up now in North America (mostly within the past 2 weeks). It is hitting IE, however one AVG user stated that he only uses Chrome and Firefox and he is seeing adds from IE popping up on his browser screen.

I noticed that users of MSE have been hit too (MSE tech support is recommending a clean reinstall). I took a look at the Avast Forum today and there are quite a few instances there. The Avast Forum gurus are pointing their users to the above link (users are reporting success with this fix).
emmjay is offline   Reply With Quote
Old 26. Jul 2010, 09:21 PM   #12 (permalink)
Moderator
 
Join Date: Jul 2008
Location: India
Posts: 9,484
Default

Sorry emmjay, I forgot to reply to that post of yours. It slipped my mind.

Thanks a lot for the link. It is really useful. I downloaded both Bootkit Remover, and TDSS Remover from there. I think such tools should be with everyone.

The site offers other research papers for reading too. That also looks interesting, and I would read them when I have sometime. Thanks a lot for the link again.

About our policy, we do not allow direct link to exe, or zip files, but a link to the download page is OK.
__________________
Anupam
Anupam is online now   Reply With Quote
Old 27. Jul 2010, 11:36 AM   #13 (permalink)
Site Manager
 
MidnightCowboy's Avatar
 
Join Date: Aug 2008
Location: South American Banana Republic, third bunch from the left
Posts: 9,250
Default

I installed and ran both the tools from emmjays's link without any problems on Windows 7 Ultimate x32.

Please though note the following which applies to the TDSS Remover:

"Currently we are aware of the following false positives:
- Microsoft Windows 7 license files. The files look like this:
C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
DO NOT REMOVE THEM!"

We shouldn't need to keep reminding folks to digest the "read me" files before using software, especially security apps, but a failure to do so here will be a painful lesson if you then choose to "clean" this "infection" LOL

Thanks emmjay
__________________
Knows nothing and cares even less
MidnightCowboy is online now   Reply With Quote
Old 03. Feb 2012, 08:27 PM   #14 (permalink)
Member
 
Join Date: Feb 2012
Posts: 3
Cool Thanx Ive been trying to find out what those were

Quote:
Originally Posted by MidnightCowboy View Post
"Currently we are aware of the following false positives:
- Microsoft Windows 7 license files. The files look like this:
C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-3D-8115-601632D005A0
DO NOT REMOVE THEM!"
-I know this is an old post - but I've been seeing these files for a long time not knowing what they were - As I use TDSSkiller all the time, now that I know, I'll leave them alone.

Sometimes, files show up in my Windows folder that have nonsense letters, usually they are some kind of Virus. But once in a while they have to do with a program I have installed... For Example, when I use Digidesign Pro Tools, each time I use a Bomb Factory Plug in, it generates an Aladdin Key, which is always a bunch of nonsense letters and numbers. These you can actually delete, cos the Aladdin program generates new keys each time you use it.

Anyway, I can determine what these files are a lot easier now, I suggest to everyone install Foolish IT D7, it has a shell extension that allows you to right click on any file and google it. That's how I found this post!

Than you so much for the information, it is rare I find someone who knows what this stuff actually IS and can give a definitive answer. Most of the time, people generate long posts which mean "I don't know what this is" - Your answer was straight at to the point!
XweAponX is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT +1. The time now is 09:37 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2