![]() |
|
|||||||
| [Fixed] Hijackthis! Logs - Antivirus 2008 posted in the Security & Safety forums; ok thanks... |
|
|
|
#8 |
|
PCHF VIP
![]() Join Date: Jun 2008
Location: Dover, Kent
Posts: 83 PC Experience: Beginner
|
ok thanks
|
|
|
|
| Advertisement - Register to Remove | |
|
|
|
#9 |
|
Tech Support Team
![]() Join Date: Sep 2008
Location: Caldwell, New Jersey
Posts: 10,112 PC Experience: Always Learning New Things
|
Let's start from the beginning again. Please run these:
Run both these programs. Please download Malwarebytes' Anti-Malware from one of these places: |MG| Malwarebytes Anti-Malware 1.31 http://www.besttechie.net/tools/mbam-setup.exe Double Click mbam-setup.exe to install the application. * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, navigate to the Update tab and click Check For Updates. It will then download the latest updates for you * Now navigate back to the Scan tab * Select "Perform Full Scan", then click Scan. * The scan may take some time to finish,so please be patient. * When the scan is complete, click OK, then Show Results to view the results. * Make sure that everything is checked, and click Remove Selected. * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note) * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. * Copy&Paste the entire report in your next reply along with a fresh HijackThis log. Please Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately. ================================================== =================================== ================================================== =================================== Ok.Lets download ComboFix.exe. This will give me a better view to the files running and also hidden on your computer and also those in the registry..Please download from one of these webpages . http://download.bleepingcomputer.com/sUBs/ComboFix.exe http://www.forospyware.com/sUBs/ComboFix.exe http://subs.geekstogo.com/ComboFix.exe * IMPORTANT !!! Save ComboFix.exe to your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right-click on the System Tray icon. They may otherwise interfere with our tools. Double-click on ComboFix.exe & follow the prompts. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.Recovery Console can be installed from your disc if you have Vista if you wish. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes to continue scanning for malware. When finished, it shall produce a log for you. Please include the C:\ComboFix.txt and MBAM logs in your next reply.
__________________
Crush aka Chris [Prework][Afterwork][PCHF Rules][BSOD's][SFC][Screenshots][PC Specs][Donate] I am in fact, quite cool. My graphing calculator confirms this |
|
|
|
|
|
#10 |
|
PCHF VIP
![]() Join Date: Jun 2008
Location: Dover, Kent
Posts: 83 PC Experience: Beginner
|
Malwarebytes' Anti-Malware 1.31
Database version: 1511 Windows 5.1.2600 Service Pack 3 2008-12-17 16:40:30 mbam-log-2008-12-17 (16-40-30).txt Scan type: Quick Scan Objects scanned: 60496 Time elapsed: 15 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I can't get combofix, it says some files are corrupt and to download a fresh copy... |
|
|
|
|
|
#11 |
|
Tech Support Team
![]() Join Date: Sep 2008
Location: Caldwell, New Jersey
Posts: 10,112 PC Experience: Always Learning New Things
|
Did you try downloading it again and running it?
__________________
Crush aka Chris [Prework][Afterwork][PCHF Rules][BSOD's][SFC][Screenshots][PC Specs][Donate] I am in fact, quite cool. My graphing calculator confirms this |
|
|
|
|
|
#12 |
|
PCHF VIP
![]() Join Date: Jun 2008
Location: Dover, Kent
Posts: 83 PC Experience: Beginner
|
I tried a couple of times...
|
|
|
|
|
|
#13 |
|
PCHF VIP
![]() Join Date: Jun 2008
Location: Dover, Kent
Posts: 83 PC Experience: Beginner
|
I just tried again and it worked, here is the log...
ComboFix 08-12-18.01 - Owner 2008-12-18 23:47:13.10 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.447.154 [GMT 0:00] Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Owner\Application Data\FunWebProducts c:\program files\Internet Explorer\msimg32.dll c:\program files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_MYWEBSEARCHSERVICE ((((((((((((((((((((((((( Files Created from 2008-11-18 to 2008-12-18 ))))))))))))))))))))))))))))))) . 2008-12-17 17:18 . 2008-12-17 17:23 <DIR> d-------- c:\documents and settings\Owner\Application Data\Uniblue 2008-12-17 17:18 . 2008-12-17 17:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\DriverScanner 2008-12-13 19:38 . 2008-12-13 19:41 <DIR> d-------- c:\program files\Microsoft LifeCam 2008-12-13 19:30 . 2007-04-10 21:46 1,966,312 -ra------ c:\windows\system32\drivers\VX1000.sys 2008-12-13 19:30 . 2007-04-10 21:46 709,992 -ra------ c:\windows\vVX1000.exe 2008-12-13 19:30 . 2007-04-10 21:46 476,520 -ra------ c:\windows\vVX1000.dll 2008-12-13 19:30 . 2007-04-10 21:46 202,088 -ra------ c:\windows\system32\LCCoin14.dll 2008-12-13 19:30 . 2007-04-10 21:46 185,704 -ra------ c:\windows\system32\cVX1000.dll 2008-12-13 19:30 . 2007-04-10 21:46 111,976 -ra------ c:\windows\VX1000.dll 2008-12-13 19:30 . 2007-04-10 21:46 15,498 -ra------ c:\windows\VX1000.ini 2008-12-13 19:30 . 2007-04-10 21:46 13,023 -ra------ c:\windows\VX1000.src 2008-12-12 23:08 . 2008-12-12 23:08 <DIR> d-------- c:\program files\MSXML 4.0 2008-12-12 23:04 . 2008-10-23 12:36 286,720 --------- c:\windows\system32\dllcache\gdi32.dll 2008-12-12 22:58 . 2008-10-24 11:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys 2008-12-12 22:57 . 2008-09-04 17:15 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll 2008-12-12 22:57 . 2008-10-03 10:02 247,326 --------- c:\windows\system32\dllcache\strmdll.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2008-12-18 23:53 --------- d-----w c:\program files\Common Files\Symantec Shared 2008-12-18 23:52 --------- d-----w c:\documents and settings\All Users\Application Data\Kontiki 2008-12-18 23:51 --------- d-----w c:\documents and settings\Owner\Application Data\Skype 2008-12-18 22:51 --------- d-----w c:\documents and settings\Owner\Application Data\OpenOffice.org2 2008-12-18 22:33 --------- d-----w c:\documents and settings\Owner\Application Data\skypePM 2008-12-15 17:05 --------- d-----w c:\program files\VirtualDJ 2008-12-13 06:40 3,593,216 ------w c:\windows\system32\dllcache\mshtml.dll 2008-12-12 23:46 --------- d-----w c:\program files\Malwarebytes' Anti-Malware 2008-12-12 23:28 --------- d-----w c:\program files\Norton 360 2008-12-03 19:52 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-03 19:52 15,504 ----a-w c:\windows\system32\drivers\mbam.sys 2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll 2008-10-23 04:04 --------- d-----w c:\program files\Microsoft Silverlight 2008-10-16 14:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 14:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll 2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll 2008-10-16 14:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 14:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll 2008-10-16 14:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 14:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll 2008-10-16 14:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll 2008-10-16 14:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 14:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 14:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe 2008-10-16 14:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 14:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 14:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll 2008-10-16 14:06 268,648 ----a-w c:\windows\system32\mucltui.dll 2008-10-16 14:06 208,744 ----a-w c:\windows\system32\muweb.dll 2008-10-16 13:11 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe 2008-10-16 13:11 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe 2008-10-15 16:34 337,408 ------w c:\windows\system32\dllcache\netapi32.dll 2008-10-15 07:06 633,632 ------w c:\windows\system32\dllcache\iexplore.exe 2008-10-15 07:04 161,792 ------w c:\windows\system32\dllcache\ieakui.dll 2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-09-30 16:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-03-06 19:27 13,123 ----a-w c:\documents and settings\Smart PC\unins000.dat 2008-02-28 18:58 11,915,264 ----a-w c:\documents and settings\Smart PC\SmartPC.exe 2008-02-28 18:01 360,448 ----a-w c:\documents and settings\Smart PC\SmartPCSchedule.exe 2008-01-11 15:39 774,144 ----a-w c:\program files\RngInterstitial.dll 2007-11-16 00:13 212,992 ----a-w c:\documents and settings\Smart PC\SmartPCBoost.exe 2007-03-01 22:00 53,248 ----a-w c:\documents and settings\Smart PC\SmartPC.dll 2007-01-23 21:54 152,064 ----a-w c:\documents and settings\Smart PC\Uninst.exe 2008-06-30 12:44 324,976 ----a-w c:\program files\mozilla firefox\components\coFFPlgn.dll 2008-08-18 02:55 16,384 --sha-w c:\windows\system32\config\systemprofile\Cookies\i ndex.dat 2008-08-18 02:55 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat 2008-08-18 02:54 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008081820080 819\index.dat 2008-08-18 02:55 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\Ov erlayExcluded] @="{4433A54A-1AC8-432F-90FC-85F045CF383C}" [HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}] 2008-10-31 12:24 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\Ov erlayPending] @="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}" [HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}] 2008-10-31 12:24 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\Ov erlayProtected] @="{476D0EA3-80F9-48B5-B70B-05E677C9C148}" [HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}] 2008-10-31 12:24 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704] "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2008-09-02 716800] "kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392] "THGuard"="c:\program files\TrojanHunter 5.0\THGuard.exe" [2008-03-25 1047712] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048] "osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-08-12 144792] "4oD"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640] "VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992] "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912] "VTTimer"="VTTimer.exe" [2004-03-26 c:\windows\system32\VTTimer.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce] "nltide_3"="advpack.dll" [2008-10-16 c:\windows\system32\advpack.dll] c:\documents and settings\Owner\Start Menu\Programs\Startup\ OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216] c:\documents and settings\All Users\Start Menu\Programs\Startup\ TrayMin220.lnk - c:\program files\Philips\Philips SPC220NC Webcam\TrayMin220.exe [2008-05-09 278528] [HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer] "ForceClassicControlPanel"= 1 (0x1) "NoSMConfigurePrograms"= 1 (0x1) [HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\explorer] "ForceClassicControlPanel"= 1 (0x1) "NoSMConfigurePrograms"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"= "c:\\Program Files\\ICQ6\\ICQ.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Zapu\\Zapu\\wDivi.exe"= "c:\\Program Files\\VirtualDJ\\virtualdj.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"= "c:\\Program Files\\Kontiki\\KService.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [2008-02-18 149352] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\pro gram files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-03 99376] R3 SbieDrv;SbieDrv;\??\c:\program files\Sandboxie\SbieDrv.sys [2008-09-02 100352] S2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2004-08-12 14336] S3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\CO H_Mon.sys [2008-01-13 23888] S3 SPC220NC;Philips SPC220NC Webcam;c:\windows\system32\DRIVERS\SPC220NC.SYS [2008-05-09 507136] *Newly Created Service* - COMHOST . Contents of the 'Scheduled Tasks' folder 2008-12-18 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 17:20] 2008-12-13 c:\windows\Tasks\Microsoft_Hardware_Launch_setup_e xe.job - D:\setup.exe [] 2008-12-13 c:\windows\Tasks\Microsoft_Hardware_Launch_vVX1000 _exe.job - c:\windows\vVX1000.exe [2007-04-10 21:46] 2008-12-18 c:\windows\Tasks\PCConfidential.job - c:\program files\Winferno\PC Confidential\PCConfidential.exe [] 2008-10-24 c:\windows\Tasks\rpc.job - c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean. exe [] . . ------- Supplementary Scan ------- . uStart Page = hxxp://uk.yahoo.com/ uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ie/defaults/su/msgr8/*Yahoo! Search - Web Search IE: &Search IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm IE: Add to Windows &Live Favorites - Add to Windows Live Favorites IE: {{3015DB92-158E-4b77-9020-85C8E311FBB5} - c:\progra~1\CASINO~1\casino.exe IE: {{3015DB92-158E-4b77-9020-85C8E311FBB5} - c:\progra~1\CASINO~1\casino.exe - c:\windows\Downloaded Program Files\oscan81.ocx_x - c:\windows\bdoscandellang.ini c:\windows\bdoscandel.exe c:\windows\Downloaded Program Files\live.ini c:\windows\Downloaded Program Files\scanoptions.tsi c:\windows\Downloaded Program Files\lang.ini c:\windows\Downloaded Program Files\ipsupd.dll c:\windows\Downloaded Program Files\bdupd.dll c:\windows\Downloaded Program Files\libfn.dll c:\windows\Downloaded Program Files\bdcore.dll c:\windows\Downloaded Program Files\oscan8.ocx O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} hxxp://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab c:\windows\Downloaded Program Files\oscan8.inf FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\rh1gboyr.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT188012&SearchSource=3&q= FF - prefs.js: browser.search.selectedEngine - ICQ Search FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q= FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\rh1gboyr.default\ext ensions\{90c39cb5-4269-45fb-9e41-7a2e5c34995b}\components\FFAlert.dll FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMyWebS.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dl l FF - plugin: c:\program files\TV JOJ Media Player\np_JOJ_netscape_player.dll FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll . ************************************************** ************************ catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-18 23:54:23 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************** ************************ . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Symantec Shared\ccProxy.exe c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Kontiki\KService.exe c:\program files\Microsoft LifeCam\MSCamS32.exe c:\program files\CDBurnerXP\NMSAccessU.exe c:\program files\Sandboxie\SbieSvc.exe c:\program files\OpenOffice.org 2.4\program\soffice.exe c:\program files\OpenOffice.org 2.4\program\soffice.bin c:\program files\Skype\Plugin Manager\skypePM.exe c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe . ************************************************** ************************ . Completion time: 2008-12-19 0:02:38 - machine was rebooted ComboFix-quarantined-files.txt 2008-12-19 00:02:13 ComboFix2.txt 2008-09-12 06:38:22 Pre-Run: 57,423,220,736 bytes free Post-Run: 57,395,941,376 bytes free 249 --- E O F --- 2008-12-18 22:46:21 |
|
|
|
|
|
#14 |
|
Tech Support Team
![]() Join Date: Sep 2008
Location: Caldwell, New Jersey
Posts: 10,112 PC Experience: Always Learning New Things
|
Looks like that removed some stuff. How are you running now?
__________________
Crush aka Chris [Prework][Afterwork][PCHF Rules][BSOD's][SFC][Screenshots][PC Specs][Donate] I am in fact, quite cool. My graphing calculator confirms this |
|
|
|
![]() |
| Bookmarks |
| Tags |
| 2008, antivirus, question, Question:, [Question] |
Similar discussions...
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Please Help-Virtumonde | Metalhead1126 | [Pending] HJT Logs | 6 | 04-03-2009 05:45 PM |
| XP Antivirus 2008... | Pipboy3000 | [Pending] HJT Logs | 2 | 04-03-2009 07:29 AM |
| please help with pop ups!!!!! | khaosmage | [Pending] HJT Logs | 23 | 04-02-2009 11:59 PM |
| Fixed: Extreme virus problem | t-kayz | [Fixed] Hijackthis! Logs | 23 | 06-30-2008 12:56 AM |
| Pending: Something is wrong here ... | TeresaBloom | Spyware / AdWare | 12 | 05-08-2008 12:23 AM |
| Thread Tools | |
| Display Modes | |
|
|





























Linear Mode

