Tea,
Thanks again for all the help.
Here's a list of what I run or on my computer:
Ad-Aware SE
A-Squared
SpyBot S&D
SpywareBlaster
Type: Posts; User: neenersnitzel; Keyword(s):
Tea,
Thanks again for all the help.
Here's a list of what I run or on my computer:
Ad-Aware SE
A-Squared
SpyBot S&D
SpywareBlaster
Nothing specific, I guess its just normal. When I come to this page, It appears that I have to go through 4 or five pages to get here. Maybe since I have had a problem with it I'm just noticing all...
Tea,
I went surfing last night and even went to sites that I don't normally view, and I ran into a few re-directs, but nothing on the scale that I was having. I think you have beaten this one for...
tea,
After I ran /flushdns, it said it had successfully flushed.
After I ran /displaydns, it said the following:
Windows I P Configuration
1.0.0.127.in-addr.arpa
...
Tea,
Did as requested up to the log posting. As you can see, the O17 entry has changed the numbers. I guess a little surfing will be the true test. after I finish this post I will do the...
Tea,
Ran the Killbox - didn't get a "Pending Operations prompt", Scaned with HJT and checked the O17 entry, ran a new FixWareout, and here's the reports:
Last edited 8/11/2006
Post this...
Tea,
I work in a casino as a surveillance officer, and one of the things that guides me is "If it dosen't look right, it's not" after I posted the last results, I found a second log on my...
Tea,
that was painless enough, here's the log:
09/05/06 18:02:36 [Info]: BlackLight Engine 1.0.46 initialized
09/05/06 18:02:36 [Info]: OS: 5.1 build 2600 (Service Pack 2)
09/05/06 18:02:36...
Tea,
I found and deleted the first three, but could not locate a encodex.exe to delete. Rebooted and the ones I deleted were still gone. Did the dial-up thing and ran a HJT scan, the O17 is...
Tea,
This looks like you might be on to something. It's way over my head. thanks for being there!
Neenersnitzel
Jotti's malware...
Tea,
In the two connections listed, neither one has the Internet Protocol (TCP/IP) item in it.
One conection is labeled UMACS which is my Internet connection and uses a 56K modem and ...
Tea,
when I reboot, HJT runs a scan automaticly. The O17 entry isn't in the resulting scan. After I connect to my dial-up connection, I re-run the scan
and the O17 entry i in there again! Don't...
Tea,
Yes I do use Cookiewall. Currently there are nine saved cookies, everything else gets the boot.
Here's the report from Combofix:
Neener - 06-08-30 15:42:09.67
ComboFix 06.08.30BT...
Tea,
Went into MSCONFIG and disabled WINPatrol. By the way, when I scan with HJT before I get online, there is no O17 entry. After I do the dial-up thing then I get it. Here's the reports....
Tea,
Hope this means something to you, to me it dosn't seem to have made much headway.
Neenersnitzel
...
Teacup61, that an interesting handle.
Sorry that I've not answered sooner, but a tree about 25 ft. from my house took a direct lightning strike on Friday night and Ive been without a modem.
...
This entry has only been on my computer for about three weeks, I've been with the same ISP for nearly six years, so I don't think it has anything to do with them. i will call and ask them anyway.
I ran a scan with HJT and an online scan with eTrust, both ar posted.
eTrust Antivirus Web Scan
Scan Results: 32811 files scanned. 3 viruses were detected.
File Infection Status Path
cstlz.exe Win32/Alureon!generic infected C:\WINDOWS\system32\
...
I have run my anti-virus, A-Surared, Spybot S&D,and Spyware blaster: all in safe mode. Also have downloaded and ran Fixwareout. this is where my machine stands at the moment. every time I delete...
In my HJT scan, the only thing I can find that is out of the ordinary is the entry
O17 - HKLM\System\CCS\Services\Tcpip\..\{EAC62E71-ED80-48AE-B816-A0480BD2CDED}: NameServer = 85.255.114.6...