Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Pending] Hidden Radio/Tv program?

[Fixed] Hijackthis! Logs - [Pending] Hidden Radio/Tv program? posted in the Security & Safety forums; Hello, I'm new to a lot of this personal protection stuff. I have Spybot and Ad-Aware and run these often. At the moment, on occasion, random audio files play on ...

JOIN US NOW to remove these Ads

PC Help Forum, the number one FREE computer support website in the search engines
Post New Thread  Reply
  #1  
Old 06-24-2007
hemingsoft's Avatar
Bronze Member
 
Join Date: Jun 2007
Posts: 3
hemingsoft - See this Members User comments on their Profile page
Default [Pending] Hidden Radio/Tv program?

Hello,
I'm new to a lot of this personal protection stuff. I have Spybot and Ad-Aware and run these often. At the moment, on occasion, random audio files play on my computer. This happens at random occasions and are not my audio files. There are no new applications which show on my task manager and I do not believe that any new processes are running. I notice that spool is runnning even though I have no printing needs at the moment. Does anyone know about these problems or ways of fixing it?

Bryan


  #2  
Old 06-24-2007
AMDPhenomX4's Avatar
Banned
My PC
 
Join Date: Mar 2007
Location: Charlton,Massachusetts
Posts: 634
PC Experience: Very Experienced
AMDPhenomX4 - See this Members User comments on their Profile page AMDPhenomX4 - See this Members User comments on their Profile page AMDPhenomX4 - See this Members User comments on their Profile page AMDPhenomX4 - See this Members User comments on their Profile page AMDPhenomX4 - See this Members User comments on their Profile page AMDPhenomX4 - See this Members User comments on their Profile page
Send a message via AIM to AMDPhenomX4 Send a message via MSN to AMDPhenomX4
Default

please do the prework in my signature.


  #3  
Old 06-25-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,502
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Hello, this sounds like the work of malware.
I'll be happy to help you once you have completed the Prework as AMDAthlon64X2 directed.


  #4  
Old 06-25-2007
hemingsoft's Avatar
Bronze Member
 
Join Date: Jun 2007
Posts: 3
hemingsoft - See this Members User comments on their Profile page
Default

Ok so these are my logs from those steps. Thanks for the help.

Bryan
Attached Files
File Type: log SUPERAntiSpyware Scan Log - 06-25-2007 - 11-38-13.log (6.8 KB, 3 views)
File Type: log hijackthis.log (5.1 KB, 3 views)


  #5  
Old 06-25-2007
hemingsoft's Avatar
Bronze Member
 
Join Date: Jun 2007
Posts: 3
hemingsoft - See this Members User comments on their Profile page
Default

Well the other log was too large so here is some parts.
Attached Files
File Type: txt Scan1.txt (51.5 KB, 2 views)
File Type: txt Scan2.txt (33.1 KB, 2 views)
File Type: txt Scan3.txt (57.9 KB, 0 views)
File Type: txt Scan4.txt (43.6 KB, 1 views)


  #6  
Old 06-26-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,502
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Please run HijackThis and place a checkmark by the following entries:
O2 - BHO: (no name) - {6F481F80-D133-AA9D-4F60-FC8DCC2783E8} - (no file)
O2 - BHO: BHOAd - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\xmlhelper2.dll
O2 - BHO: (no name) - {95D9B540-90F9-413B-85D5-646824820D33} - (no file)
O4 - HKLM\..\Run: [SecureWeb] C:\WINDOWS\system32\v2q44o0O.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


If you don't use a proxy, please tick:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 168.94.74.68:8080


Close all other windows except HijackThis and press "Fix Checked". Then close HijackThis and restart the computer.

Next clear your recycle Bin.


Then download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please attach the content of that report into your next reply, along with a new HijackThis log.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm



Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 08:21 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top