Have logs that need to be checked

By TimeParadoX ยท 8 replies
Nov 2, 2007
  1. I recently clicked a link that took me to a website that downloaded a virus thing on my computer, I posted the logs that needed to be checked

    I noticed 1 entry from my HJT logs that was not there before I clicked link:

    O4 - HKUS\S-1-5-21-240903536-377311529-3107768155-1011\..\Run: [RecordNow!] (User 'Justin')

    I looked up RecordNow and it seems to be a program that is used to rip music and stuff, I never downloaded it before

    Should I fix it?
    Here's a picture of a search I did for the program, it has strange properties

    I did AVG / Avast! scans and found nothing
    Also panda rootkit found nothing

    SpyBot: S&D found a entry called LSA


    HJT log:
  2. kitty500cat

    kitty500cat TS Evangelist Posts: 2,154   +6

    Looks like something went wrong with the HJT attachment (doesn't open).

    RecordNow is a program by Sonic that (I think) is bundled with some computers. You can remove it if you don't use it.

    I see nothing bad in your ComboFix log, except for the following newly created service:


    Go to the start menu, click on run, type cmd and press enter.

    Once the command window appears, type in the following:


    Please post the output of that command, along with a fresh HJT log.

    Regards :)

    This thread is for the use of TimeParadoX only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our Security and the Web forum.
  3. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Have HJT fix this entry.

    O4 - HKUS\S-1-5-21-240903536-377311529-3107768155-1011\..\Run: [RecordNow!] (User 'Justin')

    Have SS&D fix all those entries.

    Regards Howard :)
  4. TimeParadoX

    TimeParadoX TS Rookie Topic Starter Posts: 2,273

    Thanks howard and kitty.

    Kitty when I tried to do what you said it gave a failed message saying:

    "Specific service does not exist as a installed service"

    Also howard, when I went to recheck my HJT logs to delete that entry it was gone, maybe combofix picked it up or something?
  5. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    If Combofix picked it up, it should be in the Combofix report.

    Your system looks pretty clean, other than what SS&D found, which I trust you have fixed?

    Regards Howard :)
  6. TimeParadoX

    TimeParadoX TS Rookie Topic Starter Posts: 2,273

    I did fix the SS&D found

    I guess when I go into my non-admin account ( Justin ) it loads that recordnow thing, could I just delete it manually by deleting the programs?
  7. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    If it doesn`t show up in add remove programmes, then yes, you can delete it manually.

    However, there are several versions of Recordnow!. Look HERE and see if you can identify which version you have.

    Regards Howard :)
  8. TimeParadoX

    TimeParadoX TS Rookie Topic Starter Posts: 2,273

    Well I didn't install recordnow ever... It just randomly appeared on my computer after I clicked that link someone sent me on Steam Friends
  9. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Then, uninstall it if it`s in add remove programs. If it isn`t, just manually delete it.

    Regards Howard :)
Topic Status:
Not open for further replies.

Similar Topics

Add your comment to this article

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...