Re: Updateg Trojan

Nagareshwar Talekar <[email protected]> Mon, 31 Jan 2011 18:25:26 +0530
Newsgroups gmane.comp.security.virus
Message-ID <[email protected]>
you can try GMER (gmer.net) - antirootkit tool which can detect
generic anomalies !

If it uses any dll based injections then you can use SpyDllRemover
(http://securityxploded.com/spydllremover.php) to find such suspicious
dlls easily.

Tools like autoruns will help you to detect start up entries but these
advanced trojans will fix it for you again :)

Hope that helps !

Cheers
Nag

On Mon, Jan 31, 2011 at 5:36 AM, Jay Scalf <[email protected]> wrote:
> StartEdLite says one of my computers has Updateg Trojan set to start at
> Windows startup. Anyone know anything about this? MalwareBytes, Zone Alar=
ms,
> and Emmisoft failed to fine it. How do I locate it and get rid of it? (Th=
e g
> at the end is not a typo.) StartEdLite says it messes with the clock. I
> can't Goggle anything specific - please help.
>
> -------------------------------------------------------------------------=
--
> This list is sponsored by: Black Hat
>
> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier
> technical event for ICT security experts. Featuring 30 hands-on training
> courses and 90 Briefings presentations with lots of new content and new
> tools. =C2=A0Network with 4,000 delegates from 70 nations. =C2=A0Visit pr=
oduct
> displays by 30 top sponsors in a relaxed setting.
> http://www.blackhat.com
> -------------------------------------------------------------------------=
--
>
>

---------------------------------------------------------------------------
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier 
technical event for ICT security experts. Featuring 30 hands-on training 
courses and 90 Briefings presentations with lots of new content and new 
tools.  Network with 4,000 delegates from 70 nations.  Visit product 
displays by 30 top sponsors in a relaxed setting.  

http://www.blackhat.com
---------------------------------------------------------------------------