1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Virus/Malware issue

Discussion in 'Malware and Virus Removal Archive' started by nobbie_ferguson, 2008/03/27.

  1. 2008/03/27
    nobbie_ferguson

    nobbie_ferguson Inactive Thread Starter

    Joined:
    2005/04/11
    Messages:
    48
    Likes Received:
    0
    I clicked on a link from a mates msn message and it kindly put some sort of virus/malware onto my PC. So could someone in the know please look over these logs and give me some help with ridding my PC of this. Avira AntiVir seems to be unable to find quite a lot of it.
    I am running Vista x64 Ultimate.

    HJT Log:


    Kapersky Log:

    Thanks very much.
     
  2. 2008/03/27
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi nobbie :)

    The two infected items reported in the KAV scan are really of no consequence.

    C:\Users\Rob\AppData\Local\Temp\NERO14399\Toolbar.exe --> AdTool.Win32.MyWebSearch.bm
    E:\WINDOWS\system32\pbsvc.exe --> Win32.AdMedia.al

    First is in a Temp folder and the second belongs to PunkBuster. Embedded adware common to many freeware apps.

    We need to have a better look at things with a Deckards log, and you need to update your version of HijackThis. Please read this topic, install the latest version of Hijackthis, run a scan and save the log (you can close it for now). Then, download and run Deckard's System Scanner and post BOTH the main.txt and extra.txt logs. You may be required to put them in sepearate posts due to character count limitations.
     

  3. to hide this advert.

  4. 2008/03/28
    nobbie_ferguson

    nobbie_ferguson Inactive Thread Starter

    Joined:
    2005/04/11
    Messages:
    48
    Likes Received:
    0
    Hi noahdfear,


    Thanks. Thats good to know that not much came up, when i scanned with Kapersky it found so many things then asked me to pay to have them removed i was mildly worried.


    Downloaded the newest HJT, here is the log:

     
  5. 2008/03/28
    nobbie_ferguson

    nobbie_ferguson Inactive Thread Starter

    Joined:
    2005/04/11
    Messages:
    48
    Likes Received:
    0
    Here are the two Deckards logs,

    Main.txt:

    The rest is continued in the next post as it exceeds the character limit
     
  6. 2008/03/28
    nobbie_ferguson

    nobbie_ferguson Inactive Thread Starter

    Joined:
    2005/04/11
    Messages:
    48
    Likes Received:
    0
    and Extra.txt:

    Cheers
     
  7. 2008/03/28
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    I see nothing unusual in those logs. You do have a BHO that should be removed using HijackThis.

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    Are you getting alerts to an infection or experiencing other issues?
     
  8. 2008/03/28
    nobbie_ferguson

    nobbie_ferguson Inactive Thread Starter

    Joined:
    2005/04/11
    Messages:
    48
    Likes Received:
    0
    No, i'm not getting any alerts or anything. I downloaded this file that was clearly sent through a mates MSN by some kind of malware. I ran all my antivirus/anti spyware programmes, they found nothing, then i did the kapersky online sacn which told me i was infected but you have to pay to get them to remove the infections. My antivirus then about an hour after me doing a full system scan found a virus just with its real time scanner, i deleted that but was worried that there may have been more copies of it/further infection. So if it looks clean then it may well be.
    In which case, thank you very much for your time and help. :)
     
  9. 2008/03/28
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Keep an eye on things, especially when using MSN. If you notice anything peculiar, don't hesitate to post back and we'll dig deeper. ;)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.