BleepingComputer.com: Infected

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Infected Infection from a 'DHL' email

#1 User is offline   robertdavis 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 1
  • Joined: 17-November 10

Posted 17 November 2010 - 08:16 AM

Good afternoon, I new to this so I'll launch straight in and thank anyone in advance for sparing 2 minutes to read this. A good friend received an email which she thought was from DHL couriers advising her of a short delivery with an attached zip file allegedly containing further info. She tried to upzip and nothing appeared to happen. I advised her to run super antispyware and malwarebytes. Mbam was OK but SAS found this:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/17/2010 at 01:54 PM

Application Version : 4.45.1000

Core Rules Database Version : 5873
Trace Rules Database Version: 3685

Scan type : Complete Scan
Total Scan Time : 00:04:40

Memory items scanned : 548
Memory threats detected : 0
Registry items scanned : 10799
Registry threats detected : 2
File items scanned : 0
File threats detected : 0

Security.HiJack[ImageFileExecutionOptions]
(x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EHSHELL.EXE
(x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EHSHELL.EXE#Debugger

I've tried to clean twice but with no success
help!
regards

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users