PDA

View Full Version : S&D report shows serious 'hijack' attempt?



MadMaxine
2010-09-17, 14:42
Think I'm in real trouble!
My recent Spybot S&D log showed this scary stuff!

14/09/2010 23:16:42 Encountered and terminated Armageddon in C:\Program Files\Java\jre6\bin\java.exe!
14/09/2010 23:17:16 Denied (based on user decision) value "{D9AA6FEA-404B-5DD1-7DF7-0DC26329ED54}" (new data: ""C:\Documents and Settings\...\Application Data\Osqai\waev.exe"") added in System Startup user entry!
14/09/2010 23:17:52 Denied (based on user decision) value "{D9AA6FEA-404B-5DD1-7DF7-0DC26329ED54}" (new data: ""C:\Documents and Settings\...\Application Data\Osqai\waev.exe"") added in System Startup user entry!
14/09/2010 23:17:53 Denied (based on user blacklist) value "{D9AA6FEA-404B-5DD1-7DF7-0DC26329ED54}" (new data: ""C:\Documents and Settings\...\Application Data\Osqai\waev.exe"") added in System Startup user entry!
14/09/2010 23:17:54 Denied (based on user blacklist) value "{D9AA6FEA-404B-5DD1-7DF7-0DC26329ED54}" (new data: ""C:\Documents and Settings\...\Application Data\Osqai\waev.exe"") added in System Startup user entry!
etc, etc,
etc, etc
The bits in red repeat over and over again, must be a thousand times or more, the numbers (time) running in complete sequence!!

15/09/2010 Denied (based on user blacklist) value "{D9AA6FEA-404B-5DD1-7DF7-0DC26329ED54}" (new data: ""C:\Documents and Settings\...\Application Data\Osqai\waev.exe"") added in System Startup user entry!
etc, etc
15/09/2010 Denied (based on user blacklist) value "{D9AA6FEA-404B-5DD1-7DF7-0DC26329ED54}" (new data: ""C:\Documents and Settings\...\Application Data\Osqai\waev.exe"") added in System Startup user entry!

The sequence changes to this..

15/09/2010 23:59:25 (based on ) value "{D9AA6FEA-404B-5DD1-7DF7-0DC26329ED54}" (new data: ""C:\Documents and Settings\...\Application Data\Osqai\waev.exe"") in System Startup user entry!

Before I go into too much detail, I want you to know that I have DDS and ERUNT ready as instructed.
I know you are an amazing team and if anyone can help here, it's you!
Do you think you can help me please?

tashi
2010-09-17, 18:05
Hello MadMaxine,


Before I go into too much detail, I want you to know that I have DDS and ERUNT ready as instructed.


When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
Copy/Paste the contents of 'DDS.txt' into your post.
'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files) (http://windows.microsoft.com/en-us/windows-vista/Compress-and-uncompress-files-zip-files)
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Please start a new topic, provide the logs as so and a volunteer analyst will advise you when available.

Best regards. :)