TechSpot

Can someone take a look at my HT log? =)

By makito
Aug 2, 2006
  1. I think my notebook is infected with someone, help me please! =]

    oh btw I scnnaed my pc with ad aware, spyboat search and destroy and avg antivirus
     
  2. Mictlantecuhtli

    Mictlantecuhtli TS Evangelist Posts: 4,345   +11

    Boot to safe mode before fixing.

    These should be fixed:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://zwotgbtjglumgv.us/CTd8g6wBGZiYmDmPuJCdPksggtuBPc/kEx/oCkrmW0hApUcnENpUYpThA4jOoSg5.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xfqbqqrkjhlvpgvgvpbjvq.com/CTd8g6wBGZjJmVUf/frR1B82lALuULfmlzHRzbhsou8.jpg

    O2 - BHO: (no name) - {11FC4626-850C-6A86-8751-6C550DD7281B} - C:\WINDOWS\System32\lbda.dll (file missing)
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll


    What's this supposed to be? If you don't know, fix:

    O4 - HKCU\..\Run: [Move Wma] C:\DOCUME~1\ANDREA~1\APPLIC~1\SKIPBL~1\grey each.exe


    I don't know if you use Land Desktop, if not, fix these:

    O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\Land Desktop 3\AcDcToday.ocx
    O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\Land Desktop 3\InstBanr.ocx
    O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\Land Desktop 3\InstFred.ocx
    O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\Land Desktop 3\AcPreview.ocx
     
  3. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    The grey each.exe file looks like a possible trojan to me.

    Go HERE and follow the instructions exactly.

    Post a fresh HJT log into this thread, only after doing the above.

    Regards Howard :wave: :wave:
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...