Scan your PC for Errors

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Starware popups again!

[Fixed] Hijackthis! Logs - [Fixed] Starware popups again! posted in the Security & Safety forums; OK, here are the latest logs form AdAware and Ewido. Spybot found no immediate threts. Let me know if you need anything else. Thanks....

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #22  
Old 02-23-2006
Bronze Member
 
Join Date: Feb 2006
Posts: 14
bmit - See this Members User comments on their Profile page
Default

OK, here are the latest logs form AdAware and Ewido. Spybot found no immediate threts. Let me know if you need anything else. Thanks.
Attached Files
File Type: txt Ad-Aware SE log.TXT (49.9 KB, 2 views)
File Type: txt Scan report_20060223.txt.txt (3.4 KB, 4 views)


  #23  
Old 02-24-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hmm , the Ewido log shows something very interesting. There is/was some malware on youre pc pretending to be "Adobe Gamma Loader.exe". And i dont know if Ewido removed all of it already .

Since you obviously also have legit Adobe software installed , and there is infact an legit Adobe file with the same name aswell , we need to check wich is wich first.

Can you post a new hjt log to see what is stil present?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #24  
Old 02-24-2006
Bronze Member
 
Join Date: Feb 2006
Posts: 14
bmit - See this Members User comments on their Profile page
Default

Yes, I have noticed that too. In the meantime Spy Sweeper Startup Program Shield gave me an alert regarding this and prompted to eliminate it from the startup programs. I agreed and as a result haven's noticed anything unusual since.

"_delete_on_reboot_Adobe Gamma Loader.exe" is now shown in Spy Sweeper startup program list as unchecked. There is also another one - Adobe Gamma Loader.ink, but this one is still active. How can I permanently delete the frst file this from my computer (assuming the second one is legit)?

Here is the latest HJT log.
Attached Files
File Type: log hijackthis.log (11.8 KB, 1 views)


  #25  
Old 02-24-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

It isn't showing up in the hjt log anymore , so to get rid of it completly first eneble it again in spysweeper. Then fix this line with hjt in safemode (hit f8 when booting up):

O4 - Startup: Adobe Gamma Loader.exe

And manually delete the file from these two places if present:

C:\Documents and Settings\{username}\Start Menu\Programs\Startup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup




And then to double check , upload this file:

C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

to this site to check:

http://www.virustotal.com/flash/index_en.html

And report back if it finds anything please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #26  
Old 02-24-2006
Bronze Member
 
Join Date: Feb 2006
Posts: 14
bmit - See this Members User comments on their Profile page
Default

So far so good. I also checked the file over at virustotal.com and they didn't find anything bad either.

Thanks for your help. I appreciate it.


  #27  
Old 02-24-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Sounds great. The little ****** had us fooled for a bit but it seems like we got it.

Marked as Fixed for the second time.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 09:01 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top