![]() ![]() |
17.08.2006 16:30
Post
#1
|
|
|
Advanced Member ![]() ![]() ![]() Group: Members Posts: 172 Joined: 17.08.2006 |
According to some sources on internet conime is a trojan. I found it on my computer and looks like a MS application of some kind (Console IME). I checked it with Kaspersky on line scanner, which didn't find anything wrong. I also checked it with Lavasoft Ad Aware, MS Antispyware and NOD32 antivirus (I plan to switch to Kaspersky 6 very soon
Can anyone explain me if this is actually a real trojan or just a application that could be potentially harmfull? Thanks in advance. |
|
|
|
17.08.2006 16:36
Post
#2
|
|
|
Advanced Member ![]() ![]() ![]() ![]() Group: Members Posts: 255 Joined: 14.04.2005 From: Запорожье, Украина |
Send it to newvirus@kaspersky.com for check.
-------------------- С уважением, Воронин Андрей aka Phoenix
![]() |
|
|
|
17.08.2006 16:50
Post
#3
|
|
|
Advanced Member ![]() ![]() ![]() Group: Members Posts: 172 Joined: 17.08.2006 |
|
|
|
|
17.08.2006 17:54
Post
#4
|
|
|
Advanced Member ![]() ![]() ![]() Group: Members Posts: 172 Joined: 17.08.2006 |
Response I got from Kaspersky:
QUOTE No malicious software was found in the attached file. Must be some application, which can be misused for gaining remote access to the computer. |
|
|
|
17.08.2006 18:51
Post
#5
|
|
|
Guest ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Gold beta testers Posts: 7775 Joined: 7.12.2005 From: Ring 0 |
QUOTE(JoeAverage @ 17.08.2006 18:54) Response I got from Kaspersky: Must be some application, which can be misused for gaining remote access to the computer. This is BFGhost, it's a Remote Administration Tool and it's dangerous. If you haven´t been administrating your computer remotely and find it on your computer, somebody has been using it to control your machine and could be spying on you. If that's the case you should take counter-measures immediatedly. You can either download SpySweeper (which is the safest option if you're not a power user). http://www.download.com/Webroot-Spy-Sweepe...4-10562248.html OR Follow the following instructions for manual removal: 1. Kill the following processes in the Task Manager: bfghost.exe, editmm.exe, conime.exe 2. Unregister service.dll in Windows\system\ How? Start - Run - copy and paste: REGSVR32 /u C:\Windows\System\service.dll Press Enter and REBOOT. 3. Remove the following files bfghost.exe, editmm.exe, read it.txt. conime.exe in Windows\ regsys.vxd, service.dll in Windows\system\ Paul Wynant Moscow, Russia This post has been edited by p2u: 17.08.2006 19:02 -------------------- Adblock Plus content blocking filter: * (= show text only anywhere)
Exception rule for all: @@*$stylesheet (= show style sheet only anywhere) Default exception rule for white-listed sites: domain name/$background,image (= images only from that domain only; no scripts, objects, or other elements) |
|
|
|
17.08.2006 19:31
Post
#6
|
|
![]() Global Moderator ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Global moderators Posts: 25601 Joined: 7.04.2005 |
Easy does it Paul, i have that one too and no app detects it including Spy Sweeper & SUPERAntiSpyware. As long as he doesn't have bfghost.exe.
-------------------- |
|
|
|
17.08.2006 19:38
Post
#7
|
|
|
Guest ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Gold beta testers Posts: 7775 Joined: 7.12.2005 From: Ring 0 |
QUOTE(Don Pelotas @ 17.08.2006 20:31) Easy does it Paul, i have that one too and no app detects it including Spy Sweeper & SUPERAntiSpyware. As long as he doesn't have bfghost.exe. Ok. Well, in that case, if JoeAverage doesn't want to see it and it starts up with Windows, then he could try Startup Control Panel (34 KB): http://www.mlin.net/StartupCPL.shtml Pick the Standalone verision. No install needed. Uncheck 'conime.exe' and done... Paul This post has been edited by p2u: 17.08.2006 19:38 -------------------- Adblock Plus content blocking filter: * (= show text only anywhere)
Exception rule for all: @@*$stylesheet (= show style sheet only anywhere) Default exception rule for white-listed sites: domain name/$background,image (= images only from that domain only; no scripts, objects, or other elements) |
|
|
|
17.08.2006 20:00
Post
#8
|
|
|
Advanced Member ![]() ![]() ![]() Group: Members Posts: 172 Joined: 17.08.2006 |
Thanks to all for your replies, I really appreciate it. I installed and run Spy Sweeper, which found nothing with the exception of 4 cookies.
Can anyone tell me which port does BFGhost use for its activity? So there's a trojan that uses conime.exe OS file to function properly? This post has been edited by JoeAverage: 17.08.2006 20:07 |
|
|
|
17.08.2006 20:04
Post
#9
|
|
|
Guest ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Gold beta testers Posts: 7775 Joined: 7.12.2005 From: Ring 0 |
QUOTE(JoeAverage @ 17.08.2006 21:00) Thanks to all for your replies, I really appreciate it. I installed and run Spy Sweeper, which found nothing with the exception of 4 cookies. So there's a trojan that uses conime.exe OS file to function properly? No. You're only in trouble if the mentioned combination (with bfghost.exe, editmm.exe) is present on your computer. You can relax. Paul Wynant Moscow, Russia -------------------- Adblock Plus content blocking filter: * (= show text only anywhere)
Exception rule for all: @@*$stylesheet (= show style sheet only anywhere) Default exception rule for white-listed sites: domain name/$background,image (= images only from that domain only; no scripts, objects, or other elements) |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 22.11.2009 01:36 |