Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
WARNING - DO NOT TRUST TRON
   
BullGuard Antivirus Forum > General Security > Updates and Patches > WARNING - DO NOT TRUST TRON  
Forum Quick Jump
 
New Topic Locked Topic Printable version of : WARNING - DO NOT TRUST TRON
[ << Previous Thread | Next Thread >> ]

Jintan
New Member


Date Joined Dec 2006
Total Posts : 28
 
   Posted 12-30-2006 4:51 (GMT +1)    Quote: WARNING - DO NOT TRUST TRONAlert an admin about: WARNING - DO NOT TRUST TRON
I see it would be a good time to post in these forums a warning, about a person who uses the user names Tron and Powertron. I assist in many forums such as this; forums where trained individuals who have been certified to provide anti-malware assistance give good advice and bring about positive solutions. At one of these forums a Member named Powertron had been requesting assistance frequently with infection on his system. So I was surprised when recently in a Google search I saw Tron and his posting links to his Powertron site, posting here, not requesting assistance like he usually does, but pretending to provide assistance, as if he were another trained expert. If anyone would like to check on that, just do a Google search using these two words together "powertron hijackThis". Ignore any Bullguard links, and what you find are the many posts by this person not providing assistance, but receiving assistance. Many posts.



I checked here further, and sadly enough, I find he not only is pretending to have the knowledge to assist, he is providing bad and system damaging advice, or mistakenly telling people their still infected systems are cleaned.


As I posted in the thread below, Tron gave some terrible advice, which has caused this person to do damage to their delicate Winsock layer (the part of the system where communications with the internet are transferred).

www.bullguard.com/forum/12/Ctrl-alt-del-wont-work_40947.html


As Tron/Powertron has no training of any kind, he apparently is using one of those HijackThis Analyzer programs, which of course only provide minimal, general guidelines about infections or valid processes. In the thread below, once the HijackThis Analyzer would not provide the information necessary to understand that there was an infected explorer.exe file in the running processes, Tron abandoned the request. Fortunately Touch, the forum Moderator, has stepped in to fix the mess Tron left.

www.bullguard.com/forum/10/Computer-sending-out-spam-with_40941.html

You will notice Touch immediately requested a ComboFix scan, which Tron cannot ask for, because he has no idea how to interpret it's results.

In the following request, he has now told the person their system is clean:

www.bullguard.com/forum/12/VirusBurster-adware_39447.html


Yet very visible in their HijackThis log is evidence of the untreated SmitFraud infection:

O21 - SSODL: featherweed - {ab340860-fd81-4a65-b345-82eb77a66b5e} - C:\WINDOWS\system32\jbtazy.dll (file missing)

See here:

www.castlecops.com/o22list-40.html


And even worse, an active backdoor Trojan infection:

O4 - HKLM\..\Run: [windows] C:\Windows\System32\Security\WindowsMediaPlayer\Auto-Update\WindowsMediaPlayer.exe

See here:

www.bleepingcomputer.com/startups/windows-14938.html


This Tron/Powertron individual also provides links to his domain, where he has a download for what he calls his "Personal Tronbar".

Here (link not active to avoid someone accidentally downloading this garbage)

http://www.freewebs.com/1089downloads/Home.html

Powertron does not provide any details or EULA for this download, which on further investigation is a thinly veiled copy of the EBToolbar search hijacker, which shares server space with the providers of the UCMore infection. Tron/Powertron knows this thing is infection all too well, as he had to get assistance at the following site to have his own infected toolbar removed from his own system

forums.techguy.org/security/504164-solved-h-e-l-p.html


if you have had the misfortune to have this impostor give you repair suggestions and steps, it is best that you stopp immediately following any advice he has given, and start a new request thread, linking back to the one where Tron was getting ready to assist in damaging your system. If this information still has you wondering if this Tron/Powertron person has any malware removal skills whatsoever, simply ask him to provide you with links to where he received his training, and a contact name there. Be very sure the name is of a person who is in a Moderator position, to avoid getting a link to Tron using a different name at a different forum.
Back to Top
 
New Topic Locked Topic Printable version of : WARNING - DO NOT TRUST TRON
 
Forum Information
Currently it is Thursday, November 20, 2008 9:36 AM (GMT +1)
There are a total of 63.919 posts in 15.821 threads.
In the last 3 days there were 34 new threads and 147 reply posts. View Active Threads
Who's Online
This forum has 27172 registered members. Please welcome our newest member, Kenku.
38 Guest(s), 1 Registered Member(s) are currently online.  Details
Touch
5 Latest Threads
Generic.PWS.WoW.B7078E0 (11)20-11-2008 08:33:19 (Touch)
Google and Yahoo redirect and associated malfunctions (9)20-11-2008 08:31:46 (Touch)
Performance dive (6)20-11-2008 06:40:36 (Touch)
Internet Redircet Virus on Vista (7)20-11-2008 05:56:10 (Touch)
Win 32-trojan-gen (11)20-11-2008 05:52:16 (Touch)