Hi,
I had downloaded a file for Network Magic, a program which I use for my wireless network. It installed fine, and later when I went to google and search a topic, it brought up the results, and when I clicked on one, it had several redirects until finally landing at some ad site. So, I tried running Spybot from the active processes (it was already running) yet nothing happened. I double-clicked the shortcut icon from a folder I have it in, and nothing. I then tried running HijackThis and still nothing. My anti-virus program I use is ESET NOD32, along with Windows Defender. I also have ATF Cleaner and used that, and it did clean up the registry a bit but I'm still having same problem. I also tried running Spybot and HijackThis in Safe Mode but they still wouldn't work. So if anyone can help me out that would be great. Thanks
Here are three viruses my NOD32 detected and quarantined:
I had downloaded a file for Network Magic, a program which I use for my wireless network. It installed fine, and later when I went to google and search a topic, it brought up the results, and when I clicked on one, it had several redirects until finally landing at some ad site. So, I tried running Spybot from the active processes (it was already running) yet nothing happened. I double-clicked the shortcut icon from a folder I have it in, and nothing. I then tried running HijackThis and still nothing. My anti-virus program I use is ESET NOD32, along with Windows Defender. I also have ATF Cleaner and used that, and it did clean up the registry a bit but I'm still having same problem. I also tried running Spybot and HijackThis in Safe Mode but they still wouldn't work. So if anyone can help me out that would be great. Thanks
Here are three viruses my NOD32 detected and quarantined:
Quote
7/3/2009 7:11:52 PM Real-time file system protection file C:\DOCUME~1\Zer0ed\LOCALS~1\Temp\tmp3692.tmp Win32/Patched.AW virus deleted (after the next restart) - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\DOCUME~1\Zer0ed\LOCALS~1\Temp\DVDTool.exe.
7/3/2009 7:11:43 PM HTTP filter file http://aralowsiv.com/img/pfqe.php PDF/Exploit.Gen trojan connection terminated - quarantined NT AUTHORITY\SYSTEM Threat was detected upon access to web by the application: C:\WINDOWS\Temp\tempo-1025386953.tmp.
7/3/2009 7:05:08 PM HTTP filter file http://aralowsiv.com/img/pfqe.php PDF/Exploit.Gen trojan connection terminated - quarantined NT AUTHORITY\SYSTEM Threat was detected upon access to web by the application: C:\WINDOWS\Temp\tempo-1025386953.tmp.
7/3/2009 7:11:43 PM HTTP filter file http://aralowsiv.com/img/pfqe.php PDF/Exploit.Gen trojan connection terminated - quarantined NT AUTHORITY\SYSTEM Threat was detected upon access to web by the application: C:\WINDOWS\Temp\tempo-1025386953.tmp.
7/3/2009 7:05:08 PM HTTP filter file http://aralowsiv.com/img/pfqe.php PDF/Exploit.Gen trojan connection terminated - quarantined NT AUTHORITY\SYSTEM Threat was detected upon access to web by the application: C:\WINDOWS\Temp\tempo-1025386953.tmp.
This post has been edited by shredtotears: 03 July 2009 - 10:08 PM

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Back to top









