Check my logs

Status
Not open for further replies.
hi guys. the other day i my friend send me a file, and even though through my whole life i have told everyone i know to never open .exe files, i ignored my own advice and now pay for it. :(

i catched a few trojans. in particular trojan downloader. Conhook. now it appears that these are only affecting my internet explorer, but i only use opera and chrome anyway. Either way i would still like not to be infested :p . i have done many scans and so on, but everytime i delete these files with my spyware doctor or mcafee , and run a scan the next day to make sure that they actualy are gone, it appears they are still there. my computer still picks up the same trojans. now i would like to add, that all these scans have been done with my non-admin account on my xp mashine. if infact the problem here is that i have to use my admin account to delete these, please let me know, and i am sorry. but if thats not the problem, i folowed the 8 steps and i have the log files, would apreciate if anyone could take a look at them. thank you !
 
Download combofix.exe to your desktop.

Open notepad and copy/paste the text in the quote box below into it:
NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
Also ..

Pay particular attention to this:

Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
Code:


File::
C:\DOCUME~1\Kousha\LOCALS~1\Temp\wjhcasdl.dll,b
C:\DOCUME~1\Kousha\LOCALS~1\Temp\pmnkKAqP.dll,c
C:\DOCUME~1\Kousha\LOCALS~1\Temp\fccyyVPh.dll,#1
C:\DOCUME~1\Kousha\LOCALS~1\Temp\wjhcasdl.dll
C:\DOCUME~1\Kousha\LOCALS~1\Temp\pmnkKAqP.dll
C:\DOCUME~1\Kousha\LOCALS~1\Temp\fccyyVPh.dll

Save this as CFScript.txt

Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.

CFScript.gif


This will start ComboFix. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log.
 
Status
Not open for further replies.
Back