Jump to content

saintlydoo

Members
  • Content Count

    47
  • Joined

  • Last visited

Everything posted by saintlydoo

  1. Hi On several occasions I've run malwarebytes and the following errors have popped up and i have removed them but they have then returned. Please could you let me know what they are. I'm am running windows 7 64bit professional Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Database version: 7026 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 05/07/2011 13:41:22 mbam-log-2011-07-05 (13-41-17).txt Scan type: Quick scan Objects scanned: 190951 Time elapsed: 45 minute(s), 31 second(s) Memory Processes Infected: 0 Memory Modules In
  2. Thats done what now? Seems to be running ok!
  3. DDS and ESETScan UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-11-10.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 20/08/2006 14:25:17 System Uptime: 25/11/2010 18:21:00 (3 hours ago) Motherboard: Dell Inc. | | 0RJ272 Processor: Intel® Pentium® M processor 1.70GHz | Microprocessor | 1695/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 53 GiB total, 31.011 GiB free. D: is FIXED (NTFS) - 19 GiB total, 18.516 GiB fr
  4. Hi I've tried posting this several times already I wonder if I could have some advice please. I've been getting lots of viruses on my wife's laptop recently. Not sure if I've cleared them all when running virus checker (SOPHOS) and malwarebytes software. Posted DDS and HJT log posted below. I also keep getting a mshta.exe and wscript message appearing on zone alarm firewall, what is this? Thanks DDS (Ver_10-11-10.01) - NTFSx86 Run by Chas at 14:49:44.06 on 24/11/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.
  5. Been getting lots of viruses recently. Not sure if I've cleared them all when running virus checker (SOPHOS) and malwarebytes software. Posted HJT log below. I also keep getting a mshta.exe and wscript message appearing on zone alarn firewall, what is this? Below are DDS and HJT log files DDS (Ver_10-11-10.01) - NTFSx86 Run by Chas at 14:49:44.06 on 24/11/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.268 [GMT 0:00] AV: Sophos Anti-Virus *On-access scanning enabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183
  6. Been getting lots of viruses recently. Not sure if I've cleared them all when running virus checker (SOPHOS) and malwarebytes software. Posted HJT log below. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 12:02:12, on 24/11/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe
  7. Its seems to be much better. What now?
  8. Kaspersky Log -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Wednesday, June 3, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Wednesday, June 03, 2009 18:57:12 Records in database: 2302549 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - M
  9. combofix log ComboFix 09-05-31.06 - Doo 02/06/2009 21:45.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.430 [GMT 1:00] Running from: c:\documents and settings\Doo\Desktop\Combo-Fix.exe AV: Sophos Anti-Virus *On-access scanning disabled* (Outdated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD} FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\wind
  10. New Hijackthis log Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:27:02, on 02/06/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\s
  11. its a massive load of meaningless code (to me anyway) not sure if thats what you mean.................not sure i should be sending that!!?? there is far to much of it. computer not the quickest but thats probably due to age and amount of stuff on it. keep getting the windows security alert symbol saying anti-virus unable to update which is a bit concerning. when i double click on it it says virus protection out of date..............can't seem to get it to update!!!
  12. DDS doesn't open as 2 logs it opens in notepad, what do i need to do? I no longer have comodo installed by the way!!!
  13. Been getting lots of viruses recently. Not sure if I've cleared them all when running virus checker and malwarebytes software. Posted HJT log below. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 06:37:05, on 23/05/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16827) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender
  14. log files as requested -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Thursday, December 4, 2008 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Thursday, December 04, 2008 05:23:48 Records in database: 1436003 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes
  15. Below are the log files. I've run malwarebytes again as well cheers info.txt logfile of random's system information tool 1.04 2008-12-02 08:41:27 ======Uninstall list====== -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL -->C:\WINDOWS\UNRecode.exe /UNINSTALL -->M
  16. i ran sophos virus checker and malwarebytes.
  17. Hi I recieved an email (probably spam) from 'fanboxnotes' which said i had been tagged by somebody i knew. stupidly i clicked on the link but closed it down as I wasn't sure what it was (looked a bit like a chat/social network site). I've since read that it may well be a dodgy site so I've run a virus and malware check and my machine and it seems to be clean. I wonder if someone could check the below hijackthis file. Logfile of HijackThis v1.99.1 Scan saved at 16:31, on 2008-12-01 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Runnin
  18. Well Juliet I cannot thank you enough for your help. You are an absolute superstar. Many many thanks. I have run the critical updates and added the spyware plus I already use Firefox (I find it a much better browser than IE). I will definitely read through the prevention tips you posted as well. well all i can say is thanks again. have a great weekend saintlydoo
  19. hijackthis, malwarebytes reports Logfile of HijackThis v1.99.1 Scan saved at 12:37, on 2008-11-14 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\brsvc01a.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\brss01a.exe C:\Program Files\Common Files\Apple\Mobile Device
  20. yeah i ran the Combofix /u as you said but it just left those files. i've manually deleted them now and fixed those commands in hijackthis. everything seems ok at the mo. what would you like me to send you now. hijackthis/malwarebytes report?
  21. an adware/PUA file named NirCmd was detected, as it was yesterday. i've done a search on it and found it in the C:\combofix directory plus there are some other files of a similar name in c:\windows\prefetch NIRCMD.CFEXE-0E3F4BC2.pf NIRCMD.CFEXE-19FF4781.pf NIRCMD.COM-10563DC3.pf NIRCMD.COM-323C21EC.pf NIRCMD.EXE-2C39EF53.pf NIRCMDC.CFEXE-049E77E5.pf what should i do with them?
  22. done those two things and here are the reports from malwarebytes and hijackthis not sure what issue are remaining. but i am running a virus check as we speak Malwarebytes' Anti-Malware 1.30 Database version: 1392 Windows 5.1.2600 Service Pack 3 2008-11-14 08:05:27 mbam-log-2008-11-14 (08-05-27).txt Scan type: Quick Scan Objects scanned: 71835 Time elapsed: 3 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0
  23. hopefully we are getting somewhere i'm away from that computer now, i will do the next step in the morning thanks
×
×
  • Create New...