afterdawn.com  > forums  > software, operating systems and more  > windows - virus and spyware problems  > virus/ spyware maybe????  
											
												
	
	
						 				 	
	
	
	
		
			
			
			
				
			
		 
	
												 
															
															
	
			
			
				
					Virus/ Spyware Maybe????
				 
				
				
					
				 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						
							
								
							
							
								Junior Member
								
									
								
							
							 
						29. April 2006 @ 08:08 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Here is the log file for HijackThis and i have no idea how to read it and tell good files from bad ones.  I also need some info on the "svchost".  I dont know if it's good to have.
http://www.afterdawn.com/ http://install.anark.com/client/version3/windows-ie/en/AMClient.cab http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab http://www.pcpitstop.com/mhLbl.cab  
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Advertisement
							 
						 
					
						
							
							
						 
					 
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						29. April 2006 @ 08:42 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Hi
pushow15.dll 
http://www.virustotal.com/   
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Junior Member
								
									
								
							
							 
						29. April 2006 @ 08:57 Link to this message 
								  
								 
					
					
					
						
						
						
							
							That file was not found!!! 
							
						
						
						
						
							This message has been edited since posting. Last time this message was edited on 29. April 2006 @ 10:41 
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						29. April 2006 @ 11:23 Link to this message 
								  
								 
					
					
					
						
						
						
							
							So you didn't find it or does virustotal's scanner say that? 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Junior Member
								
									
								
							
							 
						29. April 2006 @ 11:46 Link to this message 
								  
								 
					
					
					
						
						
						
							
							I didn't find one on my computer.  It was scanning hidden fils and folders also, i made sure of that. 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						29. April 2006 @ 12:25 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Download Ewido
http://www.ewido.net/en/download/ HijackThis  for example C:\Hjt and put it there. After that disable or shutdown Winpatrol and Spybot  TeaTimer.
HijackThis , do a system scan only and check these:
R3 - Default URLSearchHook is missing
 
http://www.pchell.com/support/safemode.shtml HijackThis  log and the report from ewido. 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Junior Member
								
									
								
							
							 
						29. April 2006 @ 15:28 Link to this message 
								  
								 
					
					
					
						
						
						
							
							ok,   below are the hjt and ewido reports. Thank you very much
http://www.afterdawn.com/ http://install.anark.com/client/version3/windows-ie/en/AMClient.cab http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab http://www.pcpitstop.com/mhLbl.cab  
							
						 
						
						
						
							This message has been edited since posting. Last time this message was edited on 29. April 2006 @ 15:29 
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						29. April 2006 @ 22:53 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Fix these:
O2 - BHO: (no name) - {BE2ED590-CA49-46B5-8CCE-244FB2E0D1AA} - (no file)
 
 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Junior Member
								
									
								
							
							 
						30. April 2006 @ 03:19 Link to this message 
								  
								 
					
					
					
						
						
						
							
							ok, i got an error message when I tryed to fix one of them. Should I e-mail him????
HijackThis  scan log, if possible
 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						30. April 2006 @ 06:15 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Sorry for the delay
Spybot -S&D
 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Advertisement
							 
						 
					
						
							
							  
					 
				
				
				
					
						
							
								
							
							
								Junior Member
								
									
								
							
							 
						30. April 2006 @ 08:06 Link to this message 
								  
								 
					
					
					
						
						
						
							
							They both fixed correctly and i think the problems are gone. Thanks 
							
						
						
						
						
						 
					 
				
				
			
			
			
			
			
		
		
	
			
			
		
	 
 
					
						
							afterdawn.com  > forums  > software, operating systems and more  > windows - virus and spyware problems  > virus/ spyware maybe????