Home > Unknown Virus > Unknown Virus

Unknown Virus

OK I followed step one and none of those programs were on my computer. Now we'll just have to look deeper. API new() Create a new Clamd object. Completion time: 2007-11-16 20:10:26 - machine was rebooted . --- E O F --- 11-16-2007, 06:18 PM #14 marrober9 Registered Member Join Date: Nov 2007 Posts: 22 OS: http://wpquickadminthemes.com/unknown-virus/unknown-virus-killing-all-anti-virus-software.html

i managed t install windows defender, but still no luck. Unable to gain System Privileges ((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 ))))))))))))))))))))))))))))))) . 2007-11-16 19:57 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-11-15 12:26 218,112 --a------ C:\Program Files\Marco Roberts.exe 2007-11-14 14:30

d-------- C:\Program C:\Program Files\TriJinxSetup-dm.exe -> Adware.Trymedia : No action taken. Run Windows Repair Tool to repair pinger.exe related Windows Errors 3. have a peek at these guys

C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt -> TrackingCookie.7search : Cleaned. If using a utility such as winzip you will have to direct it there as it will not unzip to the desktop by default. C:\WINDOWS\onlineshopping.ico FOUND ! Returns a hash of filename => virusname mappings.

C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt -> TrackingCookie.Statcounter : No action taken. ::Report end meronr, Sep 5, 2006 #15 Sponsor This thread has been Locked and is not open to further replies. Advertisement Recent Posts Toshiba Satelitte L755 KEYBOARD... It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot. C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt -> TrackingCookie.Adocean : Cleaned.

Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Thread Status: Not open for further replies. Ewido will now begin the scanning process.

Reboot into Safe Mode. C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt -> TrackingCookie.Hitbox : Cleaned. The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.

the last few days i have had massive problems with my pc involving spyware. http://hijackthis.nl/forum/viewtopic.php?f=34&t=4234&view=next C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt -> TrackingCookie.Com : Cleaned. Post the contents of the ActiveScan report Come back here and post a new HijackThis log along with the logs from the Ewido and Panda scans. It seems i can access some websites only.

The test file t/03quit.t will currently wait 5 seconds before trying a kill -9 to get rid of the process. http://wpquickadminthemes.com/unknown-virus/unknown-virus-please-help.html C:\Program Files\uninstallers.zip/illegal_adv_uninstall.exe -> Not-A-Virus.Hoax.Win32.Renos.dv : No action taken. find_all By default clamd will stop at the first virus it detects. It can take some time, so please be patient and allow it to run it's full course: Using Internet Explorer, visit http://www.kaspersky.com/service?chapter=161739400 Answer Yes, when prompted to install an ActiveX component.

By default tries to connect to a local unix domain socket at /tmp/clamd. When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons. Les lois françaises exigent que nous obtenions votre permission avant d'envoyer des cookies à votre navigateur Web. weblink Yes, my password is: Forgot your password?

Note: Do not mouseclick combofix's window while it's running. Cheeseball81, Sep 1, 2006 #7 meronr Thread Starter Joined: Nov 4, 2003 Messages: 77 Logfile of HijackThis v1.99.1 Scan saved at 1:19:29 PM, on 3/09/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) SlashdotMedia accorde de l’importance à la vie privée de nos utilisateurs.

If we have ever helped you in the past, please consider helping us.

Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. You may have to do something similar on Linux, or just don't use this method to kill Clamd - use kill `cat /path/to/clamd.pid` instead which seems to work fine. hello I have a virus which keeps coming back can anyone help thank you Page 1 of 2 1 2 > Thread Tools Search this Thread 11-12-2007, 08:06 PM C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : No action taken.

Staff Online Now Cookiegal Administrator crjdriver Moderator valis Moderator DaveA Trusted Advisor flavallee Trusted Advisor Noyb Trusted Advisor Advertisement Tech Support Guy Home Forums > Operating Systems > Windows XP > Two registry entries are added every time I reboot: HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\feature control\FEATURE_BROWSER_EMULATION "svchost.exe" and HKEY_USERS\.DEFAULT\Software\Microsoft\windows\cur rent version\internet settings "enable http1_1" = '1' IE8 privacy and security settings are also changed when A case like this could easily cost hundreds of thousands of dollars. check over here If you accept cookies from this site, you will only be shown this dialog once!You can press escape or click on the X to close this box.