WiredWX Hobby Weather ToolsLog in

 


Re : Need help to remove Zlob.P0rn.ad trojan.

3 posters

descriptionSolvedRe: Re : Need help to remove Zlob.P0rn.ad trojan.

more_horiz
------- Supplementary Scan -------
.
uStart Page = google.com/
IE: Download all links with IDM - d:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - d:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - d:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
TCP: {D6F8E87F-492C-45F4-B83E-0C1AA6076ACD} = 202.188.0.133,202.188.1.5
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-20 09:08:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\docume~1\KONGFE~1.KON\LOCALS~1\Temp\lucene-8f1fcbf021dcd382c7e990dd6e7ba569-commit.lock 0 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(728)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(792)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\progra~1\Grisoft\AVG7\avgamsvr.exe
c:\progra~1\Grisoft\AVG7\avgupsvc.exe
e:\storm code\Storm Codec\stormliv.exe
e:\nero 7\InCD\InCDsrv.exe
e:\storm code\Storm Codec\stMgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
d:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2008-12-20 9:25:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-20 01:25:26
ComboFix2.txt 2008-12-19 18:11:07

Pre-Run: 2,605,367,296 bytes free
Post-Run: 2,596,540,416 bytes free

259 --- E O F --- 2008-07-23 14:31:47

descriptionSolvedRe: Re : Need help to remove Zlob.P0rn.ad trojan.

more_horiz
Looks okay now, what problems remain?

descriptionSolvedRe: Re : Need help to remove Zlob.P0rn.ad trojan.

more_horiz
Great. Just now I cant sign in to my MSN and the internet is like slow. But now i guess its back to normal. So, one thing ... my pc now is still not secure rite? As you mention earlier, the best way is still to reformat it. This means for now, its better that I do not access website like banking, or other important sites to prevent my password to be leaked out?

What else can i do if i do not want to reformat my pc. Change my IP address? Sorry as I'm not a very computer literate person. Btw, thank you very much for your hard work Smile.... Its great to have you guys out there to help people around. Smile...

descriptionSolvedRe: Re : Need help to remove Zlob.P0rn.ad trojan.

more_horiz
Hello.
Yes, I advice don't do any online banking from this machine.
You can't really change your IP without changing your ISP. There are ways to change it, but they can cause problems and are just generally annoying to remember.

descriptionSolvedRe: Re : Need help to remove Zlob.P0rn.ad trojan.

more_horiz
Since this issue is resolved, this topic is closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a new topic for your questions.

descriptionSolvedRe: Re : Need help to remove Zlob.P0rn.ad trojan.

more_horiz
Since this issue is resolved, this topic is closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a new topic for your questions.

descriptionSolvedRe: Re : Need help to remove Zlob.P0rn.ad trojan.

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum