Infection kernel32.sys [Radow]

Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -  
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Continue here.

It's the continuation of this post:
uc help ccapp exe120 mo#2007 06 19%2004%3A18%3A14

Last message:
About new topic - I think I may do smth wrong and only add some new trash to this site. Can you create it and move messages from 161 to 173 there?
For the mémmory, you pc bugg when AVG starting? -> Guard.exe is eating 10mb of my memmory. It's not lagging my computer, but I already have another anti-spam programs and firewall activated, so AVG is unnecessary.
Don't speack cracks, keygen here ! They are all infected ! -> well, not all. I think if you know where search them - you'll find clean cracks, keygens etc. If I'll find some working serial for AVG v7.5 I can give it to You, of course if you need it.
Put me a new rapport of Hijackthis and have you got a report of AVG 7.5?
Here's new log from Hijackthis http://radow.narod.ru/Hijackthis2.txt
About AVG report - at 'Analysis' window there is now 'Actions recommended' or 'Select Quarantine' option. There are only 'processes', 'connections', 'autostart', 'browser plugins' and 'lsp viewer'. Can you send me screen of that option?
P.S. At last I could delete file kernel32.dll in *\system32\ directory.
P.P.S. Sorry for my english one more time.


My answer:

- AVG isn't in real time. It scan and remove the infections. You can delete it when your probleme will be solved.
- It's not necessary to have crack and keygen for AVG AS 7.5 because it's free.

- The option delete is at the end of the scan. Do you see that?
Have you got the report of AVG AS 7.5?

A+

13 réponses

Radow Messages postés 9 Date d'inscription   Statut Membre Dernière intervention  
 
- The option delete is at the end of the scan. Do you see that? -> I've already scaned all hard disks and deleted ~30cookies - AVG couldn't find nothing more. However for trojan and worm search I use NOD and XoftSpy.
Have you got the report of AVG AS 7.5? -> I still can't find how to make AVG report :(.
Plz check in your system32 folder - is there a file 'krnl386'?
p.s. what means 'A+' )) ?
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Hello

Yes, i have krnl386.exe in my PC.
What are your soucy actually? Have you got questions or problems? The infection is already present?

PS: a+ = has soon / has the next one / at a next moment in the day, you understand?
0
Radow Messages postés 9 Date d'inscription   Statut Membre Dernière intervention  
 
No, I just thought that it might be one of files created by kernel32.sys .
PS: a+ = has soon / has the next one / at a next moment in the day, you understand? -> not quite
p.s. avg->analysis->connections... how many system processes there are normal?
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Hello,

A+ means has later. When i comunicate to you, i don't know when you will answer me. So i say, has soon.

It's normal for the system process ;)

What can I for you?

Regards.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Radow Messages postés 9 Date d'inscription   Statut Membre Dernière intervention  
 
Good morning...
'A+ means has later. When i comunicate to you, i don't know when you will answer me. So i say, has soon.' -> I think I catched it's meaning.
kernel32.dll|sys don't appear anymore. I think the virus died a brutally and violent death :). Thank you for active support. Without it I would break my computer and throw it out from the window. You'd save it's life )) .
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
lol i have safe your pc lol

If you have got in help, contact me :)

Good night amigo !
0
moK´s@ Messages postés 4399 Date d'inscription   Statut Membre Dernière intervention   89
 
Regis,

tu parle anglais maintenant? LOL

@+
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Salut mok's,

J'essaie oui :)
Je suis pas particulierement bon mais j'essaie de me faire comprendre ;)

A+
0
moK´s@ Messages postés 4399 Date d'inscription   Statut Membre Dernière intervention   89
 
Yes ;-)
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Et toi, do you speack english?
0
moK´s@ Messages postés 4399 Date d'inscription   Statut Membre Dernière intervention   89
 
re,

course i do, lived in london for almost 5 years...

je donne des cours, si tu veux LOL

Bonne soirée a toi.

Et la fete de la zik?

Chez moi y connaissent pas :-( j´habite a helsinki>finlande)

@+
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Ah oué, t es finlandais? Je savais pas ! ;)

Ben c'est tres interressant de savoir parlé anglais, au besoin tu me donneras des cours lol
La musique? Pouah, il pleut.... et toi?

A+
0
moK´s@ Messages postés 4399 Date d'inscription   Statut Membre Dernière intervention   89
 
re,

et oui je suis finois...

pas de fete de la zik par ici, c´est demain la grande fete (la saint jean).

mais bon y va surement pleuvoir aussi...

Ps : au prochain post en anglais je ferais la traduction :D

Bonne soirée a toi.

@+
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
ah cool, je te contactes au prochain anglais ;)

A9+
0