also @ TechSpot: Exploit allows command prompt to launch at Windows 7 login screen

TechSpot

"HJT" ComboFix log part 1

Discussion in 'Virus and Malware Removal' started by IHateHackers, May 1, 2007.

Thread Status:
Not open for further replies.
  1. IHateHackers Newcomer, in training

    Log Files Must Be Posted As Attachments And Not Copy And Pasted.
  2. howard_hopkinso Newcomer, in training

    Please post all the requested logfiles as attachments. See HERE for instructions.

    Regards Howard :)

    This thread is for the use of IHateHackers only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  3. IHateHackers Newcomer, in training

    im going to re-run avg spyware again though to be on the safe side...

    standby for repost of HJT logs, i saw no action taken in my log file for AVG im going to try and redo that step and will get you all the logs for AVG Combo Fix and HJT together

    I did do the AVG right, i just saved the wrong report...the Trojan i had in there was cleaned out but i dont have it in the log ill show you the No action taken one which shows the trojan(but it was cleaned out)
  4. howard_hopkinso Newcomer, in training

    Everything looks pretty clean mate.

    Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    O16 - DPF: {389956FE-3A45-469C-B944-70308E06BAAC} (CVServerObject Object) - http://192.168.1.10:81/videocom.cab

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = DIGITAL
    O17 - HKLM\Software\..\Telephony: DomainName = DIGITAL
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = DIGITAL
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = DIGITAL

    Only fix the above 017 entries, only if you don`t recognise the domain.

    Click on the fix checked button.

    Close HJT and reboot your system.

    Let me know if you`re still having problems.

    Regards Howard :)

    This thread is for the use of IHateHackers only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
Thread Status:
Not open for further replies.