also @ TechSpot: Exploit allows command prompt to launch at Windows 7 login screen

TechSpot

HiJack This log

Discussion in 'Virus and Malware Removal' started by jarvis, Nov 9, 2004.

Thread Status:
Not open for further replies.
  1. jarvis Newcomer, in training

    Hi all, I am just wondering if there is anything that I should remove from my system according to this log from HJT..

    Thanks

    log is attached...

    Attached Files:

  2. acidosmosis TechSpot Chancellor

    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s

    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net

    O16 - DPF: {D9EA64B2-B966-E177-332C-78B69886526D} - http://download.newaol.com/bkpromo/download/PerformerSetup.cab



    I skimmed through real fast and may have missed a few, but I would remove these. You also have a lot of useless programs running in startup that you could remove.

    You also need to scan with AdAware and SpyBot. I can see that you have obvious spyware/adware.
  3. jarvis Newcomer, in training

    Thank you very much =p
  4. RealBlackStuff Newcomer, in training

    Next time, please submit files like this in a file.txt format, like from Notepad.
    I would not DREAM of opening someone's M$-doc file!
  5. Gunny Newcomer, in training

    I fully agree with realblackstuff. Attachments can contain viruses and infect the computers of those trying to help you. Not very nice!!!
Thread Status:
Not open for further replies.