Reply to thread

Re: Do you recognise this malware?


From: "Newell White" <NewellWhite@discussions.microsoft.com>




| Thanks for swift response, David.


| Mcafee AV 7.0 was installed.

| I attempted to install 8.0i after uninstalling 7.0. Plan was to update 8.0i

| from the McAfee web-site.


| I omitted to say in my previous post that the first thing that aroused my

| suspicion was that Start.. Run.. msconfig didn't work.

| This or an inability to run regedit are classic symptoms of malware infection.


| Machine is off the LAN while I investigate.

| Having reviewed use of the machine (domain logon and logoff scripts write to

| a log-file for each computer on the LAN) I believe that the most likely time

| and source of infection was the installation of the machinery control

| software by the supplier's field technicians.


| But I must be able to identify the malware to deduce date/time of infection

| before I can take this issue further.


| Is there any detection software which can run from a Bart PE disk?

| --

| Regards,

| Newell White


Not using the BartPE but you can try the following...


Read the included PDF Help File on oh to use a one PC to download signature and port the

Multi-AV to the affected PC.


Download MULTI_AV.EXE from the URL --

http://www.pctipp.ch/ds/28400/28470/Multi_AV.exe


http://www.pctipp.ch/downloads/dl/35905.asp


English:

http://www.raymond.cc/blog/archives/2008/01/09/scan-your-computer-with-multiple-anti-virus-for-free/


To use this utility, perform the following...

Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }

Choose; Unzip

Choose; Close


Execute; C:\AV-CLS\StartMenu.BAT

{ or Double-click on 'Start Menu' in C:\AV-CLS }


NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your

FireWall to allow it to download the needed AV vendor related files.


C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}

This will bring up the initial menu of choices and should be executed in Normal Mode.

This way all the components can be downloaded from each AV vendor's web site.

The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.


You can choose to go to each menu item and just download the needed files or you can

download the files and perform a scan in Normal Mode. Once you have downloaded the files

needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key

during boot] and re-run the menu again and choose which scanner you want to run in Safe

Mode.  It is suggested to run the scanners in both Safe Mode and Normal Mode.


When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help

file.


Additional Instructions:

http://pcdid.com/Multi_AV.htm



* * *   Please report back your results  * * *





--

Dave

http://www.claymania.com/removal-trojan-adware.html

Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Back
Top