Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Log check please

[Fixed] Hijackthis! Logs - [Fixed] Log check please posted in the Security & Safety forums; Hey I gotta problem...spyware. Adaware doesn't detect it...its in the notification area, an upside-down yield sign with an exclamation point in it that blinks and occasionally notifies me that I ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 07-31-2006
Bronze Member
 
Join Date: Oct 2005
Posts: 49
gmsdrmmrboi - See this Members User comments on their Profile page
Send a message via AIM to gmsdrmmrboi
Default [Fixed] Log check please

Hey I gotta problem...spyware. Adaware doesn't detect it...its in the notification area, an upside-down yield sign with an exclamation point in it that blinks and occasionally notifies me that I have a virus...like I didn't figure that out already. It also has pop-ups! Yay! Anyway, HJT log attatched
Attached Files
File Type: log hijackthis.log (5.4 KB, 3 views)


  #2  
Old 07-31-2006
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 3,054
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default

Hi gmsdrmmrboi

You will need to uninstall this folder.Check for it in Add/Remove first.

F:\Program Files\IntCodec


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #3  
Old 07-31-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hi guys.

That Intcodec folder should be targeted and removed by the Smitfraudfix, manual removal could proove to be difficult.


Please download SmitfraudFix (by S!Ri)

Extract the content (a folder named SmitfraudFix) to your Desktop.
Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consultin...rocessutil.htm


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #4  
Old 07-31-2006
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 3,054
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default

It was a bit of an experiment.I wanted to see if it would remove by uninstalling.If not I was then going to hit it with Smit.


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #5  
Old 07-31-2006
Bronze Member
 
Join Date: Oct 2005
Posts: 49
gmsdrmmrboi - See this Members User comments on their Profile page
Send a message via AIM to gmsdrmmrboi
Default Next reply

Well, here it is.
Attached Files
File Type: txt rapport.txt (1.4 KB, 2 views)


  #6  
Old 07-31-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Sorry about that PC.


@Gmsdrmmrboi, have you tried the uninstaller in add/remove programs as PC mentioned before making this log?



Please print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Please reboot your computer in Safe Mode. (hit f8 before Windows loads when booting up)

Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.

The report can also be found at the root of the system drive, usually at C:\rapport.txt


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 06:13 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
News
News and information from the Mirror.

Loans
Loans information and advice from Thisismoney.

vBulletin
Unofficial support forum for vBulletin forum administrators