Jump to content

Malware that can be found by Ad-Aware but not removed.


Recommended Posts

I previously posted my log but found out later on that it were incomplete so thus I am re-posting a complete log here. Hope you guys can help.

To describe my problem in bigger detail:

My Ad-Aware 2008 picks up a nasty piece of malware (TIA: 7 on their threat assessment level), but fails to delete it. Malwarebytes Anti-Malware is however unable to find it for reasons unknown. One thing I have noticed that its doing is re-directing my Internet Explorer Browser. It does not fully re-direct it though, it tries over and over and reloads the current page Im using.

Here is my log, hope you can help me get rid of this problem.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:43:20, on 2008-07-31

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program\Vanliga filer\Symantec Shared\ccProxy.exe

C:\Program\Vanliga filer\Symantec Shared\ccSetMgr.exe

C:\Program\Norton Internet Security\ISSVC.exe

C:\Program\Vanliga filer\Symantec Shared\SNDSrvc.exe

C:\Program\Vanliga filer\Symantec Shared\SPBBC\SPBBCSvc.exe

C:\Program\Vanliga filer\Symantec Shared\ccEvtMgr.exe

C:\Program\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program\Vanliga filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\WINDOWS\System32\svchost.exe

C:\Program\Vanliga filer\Microsoft Shared\VS7Debug\mdm.exe

C:\Program\Norton Internet Security\Norton AntiVirus\navapsvc.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\pctspk.exe

C:\WINDOWS\System32\svchost.exe

C:\Program\Vanliga filer\Symantec Shared\CCPD-LC\symlcsvc.exe

D:\Program\Webroot\Spy Sweeper\SpySweeper.exe

C:\WINDOWS\Explorer.EXE

C:\Program\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

C:\WINDOWS\system32\devldr32.exe

C:\Program\Vanliga filer\Symantec Shared\ccApp.exe

C:\Program\ANI\ANIWZCS2 Service\WZCSLDR2.exe

C:\Program\Telia\Supportassistent\bin\sprtcmd.exe

D:\program\Quick time\QTTask.exe

C:\Program\iTunes\iTunesHelper.exe

D:\Program\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program\Windows Media Player\WMPNSCFG.exe

C:\WINDOWS\system32\ntvdm.exe

C:\Program\iPod\bin\iPodService.exe

C:\Program\MSN Messenger\msnmsgr.exe

C:\Program\Mozilla Firefox\firefox.exe

C:\Program\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://66.40.21.70/search.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = L

Link to post
Share on other sites

MBAB LOG, in Swedish. It says is that I made a full scan and that no threats were picked up.

Malwarebytes' Anti-Malware 1.22

Databasversion: 972

Windows 5.1.2600 Service Pack 2

02:57:46 2008-07-22

mbam-log-7-22-2008 (02-57-46).txt

Skanningstyp: Fullst

Link to post
Share on other sites

Here is the log in english, it is also up to date.

Malwarebytes' Anti-Malware 1.23

Database version: 987

Windows 5.1.2600 Service Pack 2

12:37:18 2008-08-04

mbam-log-8-4-2008 (12-37-18).txt

Scan type: Quick Scan

Objects scanned: 43309

Time elapsed: 15 minute(s), 24 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.