also @ TechSpot: Leaked next generation iPhone casing photos validate multiple rumors

TechSpot

Any help would be appreciated. Logs attached

Discussion in 'Virus and Malware Removal' started by wasewell, Jan 25, 2010.

Thread Status:
Not open for further replies.
  1. wasewell Newcomer, in training

    We have two problems that may or may not be related. The browsers re-direct to random websites. The other problem is repeated "AXWIN Frame Window: svchost.exe-Application Error"s that shut down the computer and require reboots.

    We have completed the 8-step Viruses/Spyware/Malware Preliminary Removal Instructions and are attaching the logs.

    Thank you for your help.

    Wasewell

    Attached Files:

  2. Tmagic650 TechSpot Ambassador

    Remove/Fix these Hijackthis entries:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)


    We will try the ESET On-Line Scanner next:
    Scanner
  3. wasewell Newcomer, in training

    Thank you for your response Tmagic650.

    How do I remove/fix the Highjack this entries?

    Wasewell
  4. Archean TechSpot Paladin

    1. You have to be logged in as Administrator
    2. Click on start, then Run
    3. type regedit and press Enter.
    4. You can press Ctrl+F and type in the registry key you are looking for; then delete it by pressing Del or Right click on it and select delete.

    once done exit regedit and you should be alright.

    Goodluck
  5. wasewell Newcomer, in training

    Thank you, Archean. It appears that I have removed the two entries that Tmagic650 listed. Now should I run the ESET on-line scanner?

    Wasewell
  6. Archean TechSpot Paladin

    Sure you can do that anytime; and goodluck for future :)
  7. wasewell Newcomer, in training

    Hello
    We removed the Hijackthis enties that were listed by Tmagic650 and we ran the ESET on-line scanner with nothing found. We still have our problems.

    Any more suggestions?

    Wasewell
  8. Tmagic650 TechSpot Ambassador

  9. Archean TechSpot Paladin

    Combofix is a good option also you can try these, this first one is pretty decent, also this one.
  10. wasewell Newcomer, in training

    Is it better to run Combofix first or the other programs you've suggested? Svchost.com and RepairSvchost.org.

    Thanks,
    Wasewell
  11. Archean TechSpot Paladin

    Try combofix first, and please keep us posted. thanks
  12. wasewell Newcomer, in training

    When I try to download Combofix, first McAfee jumps in, finds and deletes an "Artimis" trojan. Then I get an "Error copying file or folder" Cannot copy ComboFix[1]: Access is denied.

    Wasewell
  13. Archean TechSpot Paladin

    That is very strange; anyhow have you tried the other utils I've suggested?
  14. wasewell Newcomer, in training

    No. I want to deal with the redirect. The other can wait.

    I tried to download Combofix with another computer and had the same results.

    "Error copying file or folder" Cannot copy ComboFix[1]: Access is denied.


    Any suggestions?

    Wasewell
  15. Archean TechSpot Paladin

    I am downloading it from the download link right now; no such issues, when you click on download link are you selecting to save the file on your desktop?
  16. wasewell Newcomer, in training

    I had to disable McAfee to download and use ComboFix. I am attaching the ComboFix log.

    Wasewell

    Attached Files:

  17. wasewell Newcomer, in training

    Hi

    I just wanted to bump my thread hoping someone will see my ComboFix log from my previous message and comment.

    Thank you,

    Wasewell
  18. wasewell Newcomer, in training

    How does my ComboFix log look?

    The computer seems to be behaving presently but the ComboFix instructions said the log should be looked over for further problems.

    Thank you,

    Wasewell
  19. Tmagic650 TechSpot Ambassador

    Everything's cool. Practice safe computing by deleting cookies and temp files regularly... Use a good free antivirus program
  20. wasewell Newcomer, in training

    Thank you all, very much, for your help and your advice.

    Wasewell
Thread Status:
Not open for further replies.