suspected spyfalcon infection

Reply

Join Date: Jul 2005
Posts: 1,542
Reputation: tayspen is on a distinguished road 
Solved Threads: 98
Team Colleague
tayspen's Avatar
tayspen tayspen is offline Offline
<Insert title here>

Re: suspected spyfalcon infection

 
0
  #11
May 19th, 2006
Smitfraudfix, almost always works on that faimly of infections. .

Speaking of which, we need to see that log, before we continue.

Sorry Burton, I didn't even see you posted ewido instuctions in the post above mine
Firefox
Ewido
Tune up windows
Get detailed system information
My Fixes

Member - Alliance of Security Analysis Professionals - Since 2006
Reply With Quote Quick reply to this message  
Join Date: May 2006
Posts: 29
Reputation: haruka108 is an unknown quantity at this point 
Solved Threads: 0
haruka108 haruka108 is offline Offline
Light Poster

Re: suspected spyfalcon infection

 
0
  #12
May 19th, 2006
SmitFraudFix v2.45

Scan done at 14:20:51.88, 05/19/2006 Fri
Run from C:\Documents and Settings\HP_Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600]

������������ C:\


������������ C:\WINDOWS


������������ C:\WINDOWS\system


������������ C:\WINDOWS\Web


������������ C:\WINDOWS\system32


������������ C:\Documents and Settings\HP_Owner\Application Data


������������ Start Menu


������������ C:\DOCUME~1\HP_Owner\FAVORI~1


������������ Desktop


������������ C:\Program Files


������������ Corrupted keys


������������ Desktop Components



������������ Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e04408db-4812-4478-8d4d-e46edcffd3b6}"="AutoDisc Ware"

[HKEY_CLASSES_ROOT\CLSID\{e04408db-4812-4478-8d4d-e46edcffd3b6}\InProcServer32]
@="C:\WINDOWS\system32\fyhhxw.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{e04408db-4812-4478-8d4d-e46edcffd3b6}\InProcServer32]
@="C:\WINDOWS\system32\fyhhxw.dll"


������������ Scanning wininet.dll infection


������������ End
Reply With Quote Quick reply to this message  
Join Date: May 2006
Posts: 29
Reputation: haruka108 is an unknown quantity at this point 
Solved Threads: 0
haruka108 haruka108 is offline Offline
Light Poster

Re: suspected spyfalcon infection

 
0
  #13
May 20th, 2006
for some reason, that one didn't show right...

SmitFraudFix v2.45

Scan done at 17:49:23.49, 05/20/2006 Sat
Run from C:\Documents and Settings\HP_Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600]

������������ C:\


������������ C:\WINDOWS


������������ C:\WINDOWS\system


������������ C:\WINDOWS\Web


������������ C:\WINDOWS\system32


������������ C:\Documents and Settings\HP_Owner\Application Data


������������ Start Menu


������������ C:\DOCUME~1\HP_Owner\FAVORI~1


������������ Desktop


������������ C:\Program Files


������������ Corrupted keys


������������ Desktop Components



������������ Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e04408db-4812-4478-8d4d-e46edcffd3b6}"="AutoDisc Ware"

[HKEY_CLASSES_ROOT\CLSID\{e04408db-4812-4478-8d4d-e46edcffd3b6}\InProcServer32]
@="C:\WINDOWS\system32\fyhhxw.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{e04408db-4812-4478-8d4d-e46edcffd3b6}\InProcServer32]
@="C:\WINDOWS\system32\fyhhxw.dll"


������������ Scanning wininet.dll infection


������������ End
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC