Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Possible Trojan problem

Thread Tools
 
Search this Thread
 
Old 30 January 2003, 08:14 PM
  #1  
super_si
Scooby Regular
Thread Starter
 
super_si's Avatar
 
Join Date: Feb 2002
Location: Lurkin Somewhere
Posts: 7,951
Likes: 0
Received 0 Likes on 0 Posts
Post



500+ attacks since 10am.
The Remote + Local host is my IP.
So am i infected already?
What action should be taken?

thanks for any info

Si
Old 30 January 2003, 08:32 PM
  #2  
Fatman
Scooby Regular
 
Fatman's Avatar
 
Join Date: Aug 2002
Posts: 2,390
Likes: 0
Received 0 Likes on 0 Posts
Post

Can you check whether you have this in your registry...?

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run] "kernel16"="C:\\WINDOWS\\kernel16.exe"

I've not found much on the Web so far about this, but got the above from this site. It says:"...Transscout 1.1 +1.2... Copies to c:\windows\kernel16.exe..." i.e. suggesting that the kernel16.exe is the trojan executable.

I'll keep looking around...
Old 30 January 2003, 08:36 PM
  #3  
Fatman
Scooby Regular
 
Fatman's Avatar
 
Join Date: Aug 2002
Posts: 2,390
Likes: 0
Received 0 Likes on 0 Posts
Post

OK - this is fairly suggestive that the kernel16.exe binary is the trojan. I'd say - delete the above registry entry and the .exe and you'll be good to rock'n'roll.

Check also for kernel16.dl* as well as this NT Security article mentions a SubSeven trojan using the same file name.
Old 30 January 2003, 08:48 PM
  #4  
super_si
Scooby Regular
Thread Starter
 
super_si's Avatar
 
Join Date: Feb 2002
Location: Lurkin Somewhere
Posts: 7,951
Likes: 0
Received 0 Likes on 0 Posts
Post

Alrite mate , cheers for this.

But there is no Kernel16 in that folder im afraid.

Si
Old 30 January 2003, 08:49 PM
  #5  
Jye_0
BANNED
 
Jye_0's Avatar
 
Join Date: Dec 2002
Posts: 661
Likes: 0
Received 0 Likes on 0 Posts
Post

download 'Swatit' Si, good free trojan and bot remover, ps its not me
Old 30 January 2003, 08:49 PM
  #6  
super_si
Scooby Regular
Thread Starter
 
super_si's Avatar
 
Join Date: Feb 2002
Location: Lurkin Somewhere
Posts: 7,951
Likes: 0
Received 0 Likes on 0 Posts
Post

Thanks
Old 30 January 2003, 08:53 PM
  #7  
Jye_0
BANNED
 
Jye_0's Avatar
 
Join Date: Dec 2002
Posts: 661
Likes: 0
Received 0 Likes on 0 Posts
Post

Let us know how ye get on, hate script kiddies mesel like
Old 30 January 2003, 08:56 PM
  #8  
super_si
Scooby Regular
Thread Starter
 
super_si's Avatar
 
Join Date: Feb 2002
Location: Lurkin Somewhere
Posts: 7,951
Likes: 0
Received 0 Likes on 0 Posts
Post

Its just scanning at the moment. Off to clear the snow off the drive so might be done by the time im back.

Cheers


Si
Old 30 January 2003, 09:54 PM
  #9  
super_si
Scooby Regular
Thread Starter
 
super_si's Avatar
 
Join Date: Feb 2002
Location: Lurkin Somewhere
Posts: 7,951
Likes: 0
Received 0 Likes on 0 Posts
Post

NT Rebooter - C:\WINNT\Temp\~GL_2753.EXE


that what it found
Old 30 January 2003, 10:58 PM
  #10  
Jye_0
BANNED
 
Jye_0's Avatar
 
Join Date: Dec 2002
Posts: 661
Likes: 0
Received 0 Likes on 0 Posts
Post

Hmmm, nasty, least it found it, u really gotta stop dl'in that **** off Kazza Si
Old 30 January 2003, 11:05 PM
  #11  
super_si
Scooby Regular
Thread Starter
 
super_si's Avatar
 
Join Date: Feb 2002
Location: Lurkin Somewhere
Posts: 7,951
Likes: 0
Received 0 Likes on 0 Posts
Post

nope up to 602 now mate! Still there the damm thing
Old 31 January 2003, 12:27 AM
  #12  
Jye_0
BANNED
 
Jye_0's Avatar
 
Join Date: Dec 2002
Posts: 661
Likes: 0
Received 0 Likes on 0 Posts
Post

Did you update the definitions in Swatit and are you on a lan just looked at the IP and it looks like yer lan to me?

[Edited by Jye_0 - 1/31/2003 12:28:58 AM]
Old 31 January 2003, 07:31 AM
  #13  
super_si
Scooby Regular
Thread Starter
 
super_si's Avatar
 
Join Date: Feb 2002
Location: Lurkin Somewhere
Posts: 7,951
Likes: 0
Received 0 Likes on 0 Posts
Post

967 now, I am on a lan mate. ive 4pcs off the router.

Ill update it later got things to do.

Si
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Abx
Subaru
22
09 January 2016 05:42 PM
PetrolHeadKid
Driving Dynamics
10
05 October 2015 05:19 PM
T.K
General Technical
10
02 October 2015 11:35 AM
the shreksta
Other Marques
26
01 October 2015 02:30 PM
minguela
Wheels And Tyres For Sale
0
29 September 2015 11:28 AM



Quick Reply: Possible Trojan problem



All times are GMT +1. The time now is 11:17 AM.