BleepingComputer.com: Question- Antivirus Action - Hijackthis

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Question- Antivirus Action - Hijackthis Removing Antivirus Action with Hijackthis

#16 User is offline   Orange Blossom 

  • OBleepin Investigator
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 29,825
  • Joined: 14-July 06
  • Gender:Not Telling
  • Location:Bloomington, IN

Posted 12 November 2010 - 10:19 PM

Looking at your initial post, I suspect a deeper look at the system will be necessary.

Please follow the instructions in ==>This Guide<==. If you cannot complete a step, skip it and continue.

Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include a description of your computer issues and what you have done to resolve them.

If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.

Orange Blossom :cherry:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom
An ounce of prevention is worth a pound of cure
SuperAntiSpyware, SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#17 User is offline   rtc<3 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 12
  • Joined: 12-November 10

Posted 12 November 2010 - 10:33 PM

OH MY FRICKIN FLIPPIN GOSH THANK YOU! :D

I showered while it ran and i came back and it found 5 and it's goneeeeeeee!!!! :D

#18 User is offline   rtc<3 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 12
  • Joined: 12-November 10

Posted 12 November 2010 - 10:50 PM

View PostOrange Blossom, on 12 November 2010 - 10:19 PM, said:

Looking at your initial post, I suspect a deeper look at the system will be necessary.

Please follow the instructions in ==>This Guide<==. If you cannot complete a step, skip it and continue.

Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include a description of your computer issues and what you have done to resolve them.

If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.

Orange Blossom :cherry:

Thank you but I got it with the help of the previous poster :)

#19 User is offline   AustrAlien 

  • Inquisitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,706
  • Joined: 15-July 09
  • Gender:Male
  • Location:Cowra NSW Australia

Posted 12 November 2010 - 10:51 PM

Post the MBAM log please.
AustrAlien
Google is my friend. Make Google your friend too.

Posted Image

#20 User is offline   rtc<3 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 12
  • Joined: 12-November 10

Posted 12 November 2010 - 10:53 PM

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5104

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

11/12/2010 10:27:43 PM
mbam-log-2010-11-12 (22-27-43).txt

Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 262068
Time elapsed: 29 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\wnxmal (Rogue.SecuritySuite) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\qcscyfeb (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ibfutsvd (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Kate McGuire\Local Settings\Application Data\syssvc.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kate McGuire\Local Settings\Temp\gxnphpqxg\gefwwmdtsbl.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.

#21 User is offline   AustrAlien 

  • Inquisitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,706
  • Joined: 15-July 09
  • Gender:Male
  • Location:Cowra NSW Australia

Posted 12 November 2010 - 10:59 PM

That looks good to me. No further issues showing there.

Don't forget steps #18, #19, & #20 <<< Important!

You should then be right to go ....

I don't know why OB suggested that you post in the MR forum with logs, unless she saw something that I didn't see ... I will go have a look at your initial post again to check.
AustrAlien
Google is my friend. Make Google your friend too.

Posted Image

#22 User is offline   rtc<3 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 12
  • Joined: 12-November 10

Posted 12 November 2010 - 11:05 PM

Thank you again! :D

and so sorry I was kinda snappy with you, you were just trying to help but it was honestly just cause I'm not feeling well. Have a nice night,and thank you so much. :)

#23 User is offline   AustrAlien 

  • Inquisitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,706
  • Joined: 15-July 09
  • Gender:Male
  • Location:Cowra NSW Australia

Posted 12 November 2010 - 11:07 PM

View Postrtc<3, on 12 November 2010 - 10:33 PM, said:

OH MY FRICKIN FLIPPIN GOSH THANK YOU! :D

I showered while it ran and i came back and it found 5 and it's goneeeeeeee!!!! :D

Great! Glad we could help.

Yes, you are right to go. I had a look at your first post and there is nothing there to indicate that you might have a more serious issue.

Let us know if you have any further questions.

Take care and good luck. My sympathies: Hope you feel better soon.

PS ... no worries about the snappy bit ... we understand (but sometimes forget) how stressful it can be on the other end of this forum.
AustrAlien
Google is my friend. Make Google your friend too.

Posted Image

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users