Can someone take a look at my HT log? =)

Status
Not open for further replies.
I think my notebook is infected with someone, help me please! =]

oh btw I scnnaed my pc with ad aware, spyboat search and destroy and avg antivirus
 
Boot to safe mode before fixing.

These should be fixed:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://zwotgbtjglumgv.us/CTd8g6wBGZiYmDmPuJCdPksggtuBPc/kEx/oCkrmW0hApUcnENpUYpThA4jOoSg5.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xfqbqqrkjhlvpgvgvpbjvq.com/CTd8g6wBGZjJmVUf/frR1B82lALuULfmlzHRzbhsou8.jpg

O2 - BHO: (no name) - {11FC4626-850C-6A86-8751-6C550DD7281B} - C:\WINDOWS\System32\lbda.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll


What's this supposed to be? If you don't know, fix:

O4 - HKCU\..\Run: [Move Wma] C:\DOCUME~1\ANDREA~1\APPLIC~1\SKIPBL~1\grey each.exe


I don't know if you use Land Desktop, if not, fix these:

O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\Land Desktop 3\AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\Land Desktop 3\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\Land Desktop 3\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\Land Desktop 3\AcPreview.ocx
 
Hello and welcome to Techspot.

The grey each.exe file looks like a possible trojan to me.

Go HERE and follow the instructions exactly.

Post a fresh HJT log into this thread, only after doing the above.

Regards Howard :wave: :wave:
 
Status
Not open for further replies.
Back