Home > I Need > I Need Help With A Virus. PLEASE HJT Log

I Need Help With A Virus. PLEASE HJT Log

We need to know the name of the product (X) it wants you to buy.4. Ask a Question See Latest Posts TechSpot Forums are dedicated to computer enthusiasts and power users. Your HJT log is clean. in the HJTlog is one thing back after reboot. weblink

Jotti returned O findings for the following 2 files: D:\E Drive\AppServ\mysql\bin\mysql.exe D:\E Drive\AppServ\mysql\bin\winmysqladmin.cnt I could not find the file as listed in your previous post. Please don`t post your own virus/spyware problems in this thread. Comodo's Hero Posts: 1124 A minute of your time can help many. Using the site is easy and fun.

Go to C:\Documents and Settings\All Users\Documents delete setup.exe and autorun.inf if present. See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html Run HJT with no other programmes open(except notepad). Download the attached avengerscript.txt and save it desktop Note: the above code was created specifically for this user. If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post).

It will not remove anything, but we don't need it to...1. Facebook Google+ Twitter YouTube Subscribe to TechSpot RSS Get our weekly newsletter Search TechSpot Trending Hardware The Web Culture Mobile Gaming Apple Microsoft Google Reviews Graphics Laptops Smartphones CPUs Storage Cases Similar Topics Need help with setup.exe/autorun.inf virus - HJT log included Sep 10, 2006 Need Help Please! Grtz Jenz Forgotten, i can't find the file: cnshook.dll Sep 19, 2006 #10 howard_hopkinso TS Rookie Posts: 24,177 +19 Download the pocket Killbox programme from HERE.

The last part of the log is missing. Please don't send help request via PM, unless I am already helping you. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you after scanning with MBAM. I have a problem with setup.exe and autorun.inf (probably trojans?), which have infected all my shared folders.

The fourth pc is the pc i have loged(the virus lookes active at this one), just before i made the log i put on my firewall(this was off when i get Please re-enable javascript to access full functionality. Please don't send help request via PM, unless I am already helping you. Sep 18, 2006 #2 jenz TS Rookie Topic Starter First thanx for the quick answer, i've did it.

Preview post Submit post Cancel post You are reporting the following post: HJT log file, need help please This post has been flagged and will be reviewed by our staff. Do not bother contacting us if you are not the topic starter. Regardless if prompted to restart the computer or not, please do so immediately. After running some anti malware and spyware programs I changed to Avg-free Anti virus.

Consistently helpful members with best answers are invited to staff. have a peek at these guys It's free. Have HJT fix the following, by placing a tick in the little box next to(if there). The last part of the log is missing.

After you uncheck these, click on the Save button and close Microsoft AntiSpyware. Follow Us Facebook Twitter Help Community Forum Software by IP.BoardLicensed to: What the Tech Copyright © 2003- Geeks to Go, Inc. Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} - http://h20270.www2.h...cdetection3.cab O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredim...er/imloader.cab O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by10fd.bay10....ex/HMAtchmt.ocx O16 - DPF: check over here Logged The opinions expressed in my posts are my own.

Have HJT fix these inactive enties. TechSpot is a registered trademark. Sep 19, 2006 #9 jenz TS Rookie Topic Starter oke, did dit too, a map called 3721 inprogram files keep turning up after deleting after ewido find it.

Grtz Jenz Sep 18, 2006 #1 howard_hopkinso TS Rookie Posts: 24,177 +19 Hello and welcome to Techspot.

  • Sign In Create Account Body Background skin color theme reset What the Tech Search Advanced Search section: Google This topic Forums Members Help Files Downloads Unreplied Topics View New Content
  • ESET OnlineScanClick the button.For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)Click on to download the ESET Smart Installer.
  • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\cnshook.dll O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
  • Click on Tools, Settings.

Free malware removal help and training has remained a constant. TechSpot Account Sign up for free, it takes 30 seconds. Join the community here, it only takes a minute. Ask a Question See Latest Posts TechSpot Forums are dedicated to computer enthusiasts and power users.

Disruptive posting: Flaming or offending other usersIllegal activities: Promote cracked software, or other illegal contentOffensive: Sexually explicit or offensive languageSpam: Advertisements or commercial links Submit report Cancel report Track this discussion Instead, open a new thread in our security and the web forum. I have two networked PCs. this content So Avira was just chucking a fit...?

Join the community here. Yes, my password is: Forgot your password? sw123 Sep 10, 2006 #2 boytahong TS Rookie Topic Starter Hello -- thanks! Hope you can help me.

Then you can have the file open in safe mode, so you can follow the instructions easier. There were no found threats, therefore I could not "export to text file", as there was nothing to export. Virus cleanup? I have uploaded the ewido log and the HJT log.

c)What directory did it detect it in, and what is the filename?*Optional but Helpful information*1. Please copy/paste the content of c:\avenger.txt into your reply. Extract it but don`t run it yet. What symptoms have you seen?

Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: ElnkScamBHO Class - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dllO2 - BHO: ElnkPubBHO Class Please temporarily disable such programs or permit them to allow the changes.regards myrti If I have been helping you and haven't replied in 2 days, feel free to shoot me a Once you system has rebooted, turn system restore back on and rehide your protected OS files. Join thousands of tech enthusiasts and participate.

Windows 2000, XP) Windows XP SP22. Thanks for your time and effort ;-) I'm gonna go through the old E drive data and see what is rubbish and what is worth keeping. Instead, upload them as text attachments to make your posts easier to read. Use the forums!Follow BleepingComputer on: Facebook | Twitter | Google+ Back to top #5 fitz09 fitz09 Topic Starter Members 5 posts OFFLINE Local time:05:57 PM Posted 17 November 2009 -

Facebook Google+ Twitter YouTube Subscribe to TechSpot RSS Get our weekly newsletter Search TechSpot Trending Hardware The Web Culture Mobile Gaming Apple Microsoft Google Reviews Graphics Laptops Smartphones CPUs Storage Cases Save it to your Desktop and extract it. 2.