I have Nod32 as anti virus solution and I think I undergo foolishly installed "getmirar " somehow. However the install did not complete as I do not find any of the files for that process in the system where on many sites I am told. I will find the infection the following alert is shown to me about once every 15 mins or less. Alert detailsArchive:htt:/download getmirar com/f3/EXE-876927-58-SB cabThreat:a variant of Win32/Adware. Mirar applicationthe log starts here........******************************************Logfile of Trend Micro HijackThis v2.0.2Scan saved at 8:07:05 PM on 11/15/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16544)kick mode: NormalRunning processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\Explorer. EXEC:\WINDOWS\system32\spoolsv exeC:\schedule Files\Eset\nod32kui exeC:\WINDOWS\system32\rundll32 exeC:\WINDOWS\system32\RunDLL32 exeC:\Program Files\Java\jre1.6.0_03\bin\jusched exeC:\WINDOWS\system32\oodtray exeC:\Program Files\VMware\VMware Workstation\vmware-tray exeC:\schedule Files\VMware\VMware Workstation\hqtray exeC:\DOCUME~1\Rain\LOCALS~1\Temp\tem172C tmp exeC:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch exeC:\Program Files\Common Files\Ahead\Lib\NMBgMonitor exeC:\WINDOWS\system32\ctfmon exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1. EXEC:\Program Files\Logitech\MouseWare\system\em_exec exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc exeC:\WINDOWS\system32\E_S00RP1. EXEC:\Program Files\Common Files\Microsoft Shared\VS7correct\MDM. EXEC:\Program Files\Eset\nod32krn exeC:\Program Files\Norton go\Agent\VProSvc exeC:\WINDOWS\system32\nvsvc32 exeC:\WINDOWS\system32\oodag exeC:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService exeC:\WINDOWS\system32\svchost exeC:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2 exeC:\WINDOWS\system32\vmnat exeC:\WINDOWS\system32\vmnetdhcp exeC:\schedule Files\VMware\VMware Workstation\vmware-authd exeC:\WINDOWS\System32\svchost exeC:\Program Files\Mozilla Firefox\firefox exeC:\Downloads\HiJackThis exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www google caR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start summon = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,fail_Page_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www google caR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start summon = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(fail) = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local summon = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no register)O2 - BHO: Adobe PDF Reader cerebrate Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper dllO2 - BHO: Media Holding Enterprises. LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\schedule Files\ContextTool\ContextTool-2 dllO2 - BHO: SACert categorise - {740FE5FB-65F1-46C5-9E54-A19C8A8D7AC2} - C:\WINDOWS\system32\SoftAheadCert dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv dllO2 - BHO: (no label) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Windows be Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin dllO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32. EXE C:\WINDOWS\system32\NvCpl dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz exe /installO4 - HKLM\..\Run: [nod32kui] "C:\schedule Files\Eset\nod32kui exe" /WAITSERVICEO4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg cpl,CMICtrlWndO4 - HKLM\..\Run: [NvMediaCenter] RunDLL32 exe NvMCTray dll,NvTaskbarInitO4 - HKLM\..\Run: [QuickTime Task] "C:\schedule Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched exe"O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\lay~1\modify~1\isuspm exe -startupO4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray exeO4 - HKLM\..\Run: [Logitech Utility] Logi_MwX. ExeO4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\transfer\DRIVERS\W32X86\3\E_S4I2G1. EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"O4 - HKLM\..\Run: [Auto EPSON Stylus CX5400 on SANDRA] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1. EXE /P34 "Auto EPSON Stylus CX5400 on SANDRA" /O22 "\\SANDRA\Sandi Printer" /M "Stylus CX5400"O4 - HKLM\..\Run: [vmware-tray] C:\Program Files\VMware\VMware Workstation\vmware-tray exeO4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Workstation\hqtray exe"O4 - HKLM\..\Run: [MbarInstall] C:\DOCUME~1\Rain\LOCALS~1\Temp\tem172C tmp exeO4 - HKLM\..\Run: [AWMON] "C:\schedule Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch exe"O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor exe"O4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [Auto EPSON Stylus CX5400 on SANDRA] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1. EXE /P34 "Auto EPSON Stylus CX5400 on SANDRA" /M "Stylus CX5400" /EF "HKCU"O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator exe (User 'SYSTEM')O4 - HKUS\. fail\..\RunOnce: [RunNarrator] Narrator exe (User 'Default user')O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL. EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}.
Forex Groups - Tips on Trading
Related article:
http://www.geekstogo.com/forum/index.php?showtopic=176821
comments | Add comment | Report as Spam
|