Jump to content

Agent_J

Members
  • Posts

    2
  • Joined

  • Last visited

Everything posted by Agent_J

  1. Thank you for the welcome RPMcMurphy. As per instructions, DDS.txt below and I have attached Attach.txt and GMER.txt logs DDS (Ver_10-11-10.01) - NTFSx86 Run by Jason at 13:52:54.42 on Tue 11/23/2010 Internet Explorer: 8.0.6001.18975 BrowserJavaVersion: 1.6.0_13 Microsoft Attach.txt Gmer.txt
  2. Hello, First of all I want to say thank you for the amazing service you guys provide in this forum. I have a problem, concerning Shell.exe, DWM.exe and svchost.exe which are identified as trojans. I am running the latest Malwarebytes and it detects those three executables and lets me quarantine and delete them, but they reappear instantly with new creation dates. Here are the files I could not permanently delete as they recreate themselves: C:\Users\Jason\AppData\Roaming\Microsoft\svchost.exe C:\Users\Jason\AppData\Roaming\Microsoft\stor.cfg C:\Users\Jason\AppData\Roaming\Microsoft\Windows\shell.exe C:\Users\Jason\AppData\Local\Temp\dwm.exe There is also a really strange entry in my HJT log stating something about a proxy : R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:50370 I dont use proxies. And for last, there is also a malicious entry that keeps coming back even after delete : F3 - REG:win.ini: load=C:\Users\Jason\AppData\Local\Temp\dwm.exe If you need any logs, let me know and I'll post immediately. Any help will be greatly appreciated. Thank you so much!
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.