I would really appreciate it if someone could take a look at the logs. I know these damn trojans have a habit of infecting systems on the same network especially when, as in this case, there is extensive use of network shares. As we believe the infected machine is now clear one I would like to be reasonably sure about the others but Bruce's time is very precious and he needs to concentrate on other things.
Attached is the HiJack this log file from Sleuth.
This machine is sometimes extremely slow but I have no solid reason for believing it is infected. However it has a notification error after login:
Keyhook.exe - Entry point not found
The procedure entry point ? DDrawSupportGetDriverName@CSISEsc@@QAEHPADH@Z could not be located in the dynamic link library SiSApCom.dll
There are also notices ofthe following type in the event log:
Source Windows Search Service
Event ID 1015
Time 5:47:26 AM
Event ID 3013 for the Windows search service has been suppressed 100 times since
5:26:32 AM. This event is used to suppress Windows search events that have incurred frequently withinm a short period........
Event ID 3013
(NB the system is on drive E:\ not C:\)
The entry <E:\CONFIG.MSI\77DAE.RBF> in the hash map cannot be updated.
Context: Application, SystemIndexCatalog
Details
A device attached to the system is not functioning (0x8007001f)
I am sorry to say I know more about administering Unix systems than MS$ so am not certain what to do about this... if I were to rely on instinct alone I would say this is not a malware related problem -- but instincts need to be disabused from time to time!!! <chuckles>
Thanks
David
Sign In
Create Account
This topic is locked

Back to top










