Showing posts with label Adware/Malware. Show all posts
Showing posts with label Adware/Malware. Show all posts

Tuesday, November 28, 2006

How to Remove Trojan.winreg.LowZones.f

The following is a detail page of Virtual Grub Street's Adware & Malware Indentifier Index:

The information in the Adware & Malware Indentifier Index is the result of thousands of web searches. It can not, however, possibly be complete. The subject is vast and constantly changing. Moreover, vendor uninstall tools and other removal tools do not necessarily remove all of an infection from your computer. Vendor uninstall tools, for instance, may silently leave cookies or other tracking software installed. It is suggestible to follow up a removal with one or more adware scans and/or to do an inspection using a HijackThis log. The information on the page is not guaranteed correct and any use you may choose to make of it is entirely at your own risk.


Trojan.LowZones.f

  • Associated Worms/Trojans: Trojan.WinREG.LowZones.f is a.k.a. Downloader-QG; QLowZones-26; Trojan.WinREG.LowZones.f; Troj/LowZone-AL .
  • Executable Files: Temporary Internet Files\Content.IE5\[Random Alpha-Numeric]\lg[1].exekansup.reg; Temporary Internet Files\Content.IE5\[Random Alpha-Numeric]\lg[1].exe/kans.reg; [Random Alpha-Numeric].exe/kansup.reg; \[Random Alpha-Numeric].exe/kans.reg; temp\kansup.reg.
  • Dynamic Link Libraries: N/A.
  • Directory/Search Page: N/A.
  • Uninstall page URL: N/A.
  • Related Articles: Fighting Malware with Standard Windows Tools (February 25, 2007). You may have more in your bag of tricks than you realize. Important Removal Tool Note.
  • Notes: This trojan has also been used to download registry permissions and files for ISearchTech adware and Mirar Toolbar.
  • This infection can be removed by using Ewido Security Suite trialware.






VGS encourages you to post comments about the service it offers, and, in particular, about your experiences with the removal tools suggested in its pages. Removal tool comments will be most effective in helping those who come after you if you post them to the individual detail page for the malware item you used the tool to remove. Please be as clear and as detailed as possible. The most effective comments might include such information as: 1) What browser and operating system you are are running on your computer (i.e. Windows 98, NT, XP, Linux, Internet Explorer 6.0, Firefox); 2) What updates are installed (i.e. SP1, SP2); 3) What anti-virus/malware package(s) are resident in your computer

Sunday, August 06, 2006

A Word to the Wise.

I've been the target of a number of direct attacks against my computer over the last several months. I'm providing the relevant Norton logs below, including the "remote address" (the IP of the attacker). My own IP is x'd out for obvious reasons.


8/6/2006 @ 6:13:42 PM: Rule "Default Block NetBus Trojan horse" blocked (207.12.157.2, NetBus(12345)).
Inbound TCP connection.
Local address, service is (XXX.XXX.XX.XX), NetBus(12345).
Remote address, service is (207.12.157.2, 3018).
Process name is "N/A".

See: Wikipedia page User talk:207.12.157.2; DNS Stuff/WhoIs page.


8/4/2006 @ 9:42:57 PM: Rule "Default Block Backdoor/SubSeven Trojan horse" blocked (209.159.206.135, 27374).
Inbound TCP connection.
Local address, service is (XXX.XXX.XX.XX, 27374).
Remote address, service is (209.159.206.135, 2783).
Process name is "N/A".


7/11/2006 @ 8:07:05 PM: Rule "Default Block Senna Spy Trojan horse" blocked (206.165.215.13, 13000).
Inbound TCP connection.
Local address, service is (XXX.XXX.XX.XX, 13000).
Remote address, service is (206.165.215.13, 13000).
Process name is "N/A".


5/10/2006 @ 10:53:19 PM: Rule "Default Block NetBus Trojan horse" blocked (209.214.148.159, NetBus(12345)).
Inbound TCP connection.
Local address, service is (XXX.XXX.XX.X, NetBus(12345)).
Remote address, service is (209.214.148.159, 1123).
Process name is "N/A".


Although not many Wiki Watchdog pages are getting indexed by the search engines these days, I hope that the IPs will be of help to you should you Google one or more of them in relation to an attack on your own computer.



Related posts:


Saturday, May 06, 2006

How to Remove ISearchTech.SideFind

The following is a detail page of Virtual Grub Street's Adware & Malware Indentifier Index:

The information in the Adware & Malware Indentifier Index is the result of thousands of web searches. It can not, however, possibly be complete. The subject is vast and constantly changing. Moreover, vendor uninstall tools and other removal tools do not necessarily remove all of an infection from your computer. Vendor uninstall tools, for instance, may silently leave cookies or other tracking software installed. It is suggestible to follow up a removal with one or more adware scans and/or to do an inspection using a HijackThis log. The information on the page is not guaranteed correct and any use you may choose to make of it is entirely at your own risk.


ISearchTech.SideFind



Also See: