Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
Collaborate in the cloud with Office, Exchange, SharePoint, and Lync
|
|||||||
Collaborate in the cloud with Office, Exchange, SharePoint, and Lync
Unrequested external connections - logs attached
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
Unrequested external connections - logs attached
I've noticed some unusual activity.. Any advice you can offer would be greatly appreciated!
------------------- Proto Local Address Foreign Address State TCP 127.0.0.1:5357 127.0.0.1:50582 TIME_WAIT TCP 127.0.0.1:50630 127.0.0.1:8118 SYN_SENT TCP 127.0.0.1:50631 127.0.0.1:8118 SYN_SENT TCP 127.0.0.1:50632 127.0.0.1:8118 SYN_SENT TCP 127.0.0.1:50633 127.0.0.1:8118 SYN_SENT TCP 192.168.1.1:50603 192.168.1.32:445 SYN_SENT TCP 192.168.1.1:50608 192.168.1.32:445 SYN_SENT TCP 192.168.1.1:50609 192.168.1.32:445 SYN_SENT TCP 192.168.1.1:50610 192.168.1.32:445 SYN_SENT TCP 192.168.1.1:50613 192.168.1.32:139 SYN_SENT TCP 192.168.1.155:5357 192.168.1.156:49751 TIME_WAIT TCP 192.168.1.155:50542 65.31.103.87:49666 TIME_WAIT TCP 192.168.1.155:50544 68.58.113.120:53011 TIME_WAIT TCP 192.168.1.155:50545 68.194.10.5:29253 TIME_WAIT TCP 192.168.1.155:50546 70.243.211.75:53036 TIME_WAIT TCP 192.168.1.155:50548 66.119.43.30:80 TIME_WAIT TCP 192.168.1.155:50562 64.7.222.130:80 TIME_WAIT ----------------------- Cheers, Dave |
|
#2
|
||||
|
||||
|
Welcome aboard
Your MBAM log says "No action taken". Please, re-run it and fix all found issues. Post new log. Then.... Download MBRCheck to your desktop Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator). It will show a black screen with some data on it. Enter N to exit. A report called MBRcheckxxxx.txt will be on your desktop Open this report and post its content in your next reply. ===================================================================== Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
Make sure, you re-enable your security programs, when you're done with Combofix. DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!! |
|
#3
|
|||
|
|||
|
Wow! You're fast!!
Thanks Broni, I'll be back shortly! |
|
#4
|
||||
|
||||
|
OK
.......
|
|
#5
|
|||
|
|||
|
Sorry, Combofix took ages
![]() Latest Logs.. Last edited by 1magoo; 09-04-2010 at 01:20 AM.. |
|
|
|
#6
|
||||
|
||||
|
1. Please open Notepad
2. Now copy/paste the entire content of the codebox below into the Notepad window: Code:
DDS::
uInternet Settings,ProxyServer = 127.0.0.1:8118
uInternet Settings,ProxyOverride = <local>
RegNull::
[HKEY_USERS\S-1-5-21-558963630-3344929182-2255263905-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BFEDF023-89E4-0946-F555-957E028286CC}*]
3. Save the above as CFScript.txt 4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix. 5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again. ![]() 6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
|
|
#7
|
|||
|
|||
|
Hi Broni,
No reboot requested.. Thanks for all your help so far also
|
|
#8
|
||||
|
||||
|
Looks good
![]() Download OTL to your Desktop. * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. * Under the Custom Scan box paste this in: netsvcs drivers32 /all %SYSTEMDRIVE%\*.* %systemroot%\system32\Spool\prtprocs\w32x86\*.dll %systemroot%\system32\*.wt %systemroot%\system32\*.ruy %systemroot%\Fonts\*.com %systemroot%\Fonts\*.dll %systemroot%\system32\spool\prtprocs\w32x86\*.tmp %systemroot%\*. /mp /s CREATERESTOREPOINT %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\user32.dll /md5 %systemroot%\system32\ws2_32.dll /md5 %systemroot%\system32\ws2help.dll /md5 HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
|
|
#9
|
|||
|
|||
|
Thank you - I just tried to PM you, but I have insufficient posts..
Is there another way I can contact you privately please? Doing this now.. |
|
#10
|
||||
|
||||
|
I can PM you and you can reply...
Hold on... |
|
#11
|
|||
|
|||
|
I typed a whole essay and it won't let me reply either! lol
|
|
#12
|
||||
|
||||
|
I Pmed you with my email.
|
|
#13
|
|||
|
|||
|
No extras.txt was created?
The otl.txt file was too big to cut & paste.. |
|
#14
|
||||
|
||||
|
Update your Java version: http://java.com/en/download/index.jsp
Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer. Now, we need to remove old Java installations... Please download JavaRa to your desktop and unzip it to its own folder
======================================================================= Run OTL
=================================================================== Last scans.... Download Security Check from HERE, and save it to your Desktop. * Double-click SecurityCheck.exe * Follow the onscreen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt; please post the contents of that document. ======================================================= Download Temp File Cleaner (TFC) Double click on TFC.exe to run the program. Click on Start button to begin cleaning process. TFC will close all running programs, and it may ask you to restart computer. ======================================================== Disable your antivirus program. Go to Kaspersky website and perform an online antivirus scan.
|
|
#15
|
|||
|
|||
|
Thanks Broni,
TFC crashed at the end (as it tried to reboot I think), so I ran it again, and it was OK.. I'm not able to run Kaspersky... it tells me that "launch of the java application was interupted" ?? |
|
#16
|
||||
|
||||
|
1. Update Firefox.
2. Instead of Kaspersky... Please run a free online scan with the ESET Online Scanner
|
|
#17
|
|||
|
|||
|
Thanks Broni..
I'm still on the first scan. I'll ba back later ![]()
|
|
#18
|
||||
|
||||
|
OK
![]() Most likely, tomorrow morning.... |
|
#19
|
|||
|
|||
|
No threats found
|
|
#20
|
||||
|
||||
|
Your computer is clean
![]() 1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point. Run OTL
Code:
:OTL :Commands [purity] [emptytemp] [EMPTYFLASH] [CLEARALLRESTOREPOINTS] [Reboot]
2. Now, we'll remove all tools, we used during our cleaning process Clean up with OTL:
If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now. 3. Make sure, Windows Updates are current. 4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately! 5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites. 6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer. 7. Run Temporary File Cleaner (TFC) weekly. 8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly. 9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker. The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases. 10. Run defrag at your convenience. 11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html 12. Please, let me know, how is your computer doing. |
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Logs attached, please help
|
13 | Virus and Malware Removal | ||
What do I do next? Attached Logs
|
5 | Virus and Malware Removal | ||
Logs attached
|
23 | Virus and Malware Removal | ||
Help please attached HJT-logs
|
1 | Virus and Malware Removal | ||
Yet another lop.as Logs attached
|
7 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 04:37 AM.


.......




Logs attached, please help