Home > General > Regcmdcons

Regcmdcons

Had to do a 2nd system restore last week and have just gotten through reinstalling programs, etc. however, if you wish to show appreciation and support me personallyfighting against malware, please consider a donation: Back to top #10 jntkwx jntkwx Malware Response Team 4,339 posts OFFLINE Gender:Male If you accept cookies from this site, you will only be shown this dialog once!You can press escape or click on the X to close this box. Put a checkmark beside loaded modules.

Regards,JasonSimple and easy ways to keep your computer safe and secure on the InternetIf I am helping you and have not returned in 48 hours, please feel free to send me If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options. Regards,JasonSimple and easy ways to keep your computer safe and secure on the InternetIf I am helping you and have not returned in 48 hours, please feel free to send me Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:55:05, on 2007-12-14 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Citat: Running processes: C:\WINDOWS\System32\smss.exe

I'll run the aswMBR and send the log. Please right click on the MBR.dat file, and select Send To > Compressed (Zipped) Folder. walkingparadox: Oldman,Thanks! Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy

Jump

Messenger
2008-01-10 18:22 . 2008-01-10 18:22

d--------C:\WINDOWS\system32\svcd
/>2008-01-10 18:22 . 2008-01-10 18:2234,816--a------C:\winvvys.exe
2008-01-10 18:22 . 2008-01-13 12:10114--a------C:\WINDOWS\system32\url3
2008-01-10 18:22 . 2008-01-13 12:10102--a------C:\WINDOWS\system32\url2
2008-01-10 18:22 . 2008-01-13 12:10102--a------C:\WINDOWS\system32\url1
2008-01-10 18:22 . 2008-01-13 12:108--a------C:\WINDOWS\system32\CID

This is because when the programs were first installed, the other user account that you recently added didn't exist, and so some install settings were setup only for the Compaq Owner Using the site is easy and fun. Once you do that, you'll see the file show up as an attachment. Databases Try this.

however, if you wish to show appreciation and support me personallyfighting against malware, please consider a donation: Back to top #7 Barbaraeh Barbaraeh Topic Starter Members 15 posts OFFLINE Local I just had to do a full system recovery last week and am in the process of re-installing programs prior to restoring files from Carbonite. Jump to content Sign In Create Account Search Advanced Search section: This topic Forums Members Help Files Calendar View New Content Forum Rules BleepingComputer.com Forums Members Tutorials Startup List scan completed successfully hidden files: 0 **************************************************************************.Completion time: 2008-01-13 13:37:24 - machine was rebooted [Compaq_Owner]ComboFix-quarantined-files.txt 2008-01-13 18:37:20 oldman: Open Spybot and make sure teatimer is disabled, we will re-enable afterwards.

If you need help, please create your own topic in the appropriate forum.Without looking at any log files, it is difficult to say whether regcmdcons is legitimate or indicating a virus. Copyright (c) windowsvc.com. Sign Up All Content All Content Advanced Search Browse Forums Guidelines Staff Online Users Members More Activity All Activity My Activity Streams Unread Content Content I Started Search More Malwarebytes.com Malwarebytes or read our Welcome Guide to learn how to use this site.

Back to top #9 jntkwx jntkwx Malware Response Team 4,339 posts OFFLINE Gender:Male Location:New England, U.S.A. Tänker att nån kanske RAT'at mig eller smittat mig med någon keylogger, eller liknande. Then, attach the MBR.zip file to your next reply (just like you did with Attach.zip).These programs are rather old (i.e, MS Office 97, for example) so that may not be a Thank you.

Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. I did setup another user but I can't get many of my programs to open when in that user. Aja, körde en hijackthis iaf, här är loggen. Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast!

Do you still need help?If you do, please follow my previous instructions for Zipping and attaching the MBR.zip file to your next reply. or read our Welcome Guide to learn how to use this site. A reboot will be needed to apply the changes.

Flashback.se Flashback Forum drabbades av driftstörningar (9 okt) Undergroundtidningen Oz grundare död (8 sep) Bokmässa för yttrandefrihet inskränker yttrandefriheten (21 aug) Döms för hets mot samer (4 jul) Vinnarna i Flashback

Had to do a 2nd system restore last week and have just gotten through reinstalling programs, etc. exe C:\Program\Internet Explorer\IEXPLORE.EXE C:\Program\HP\Digital Imaging\bin\hpqtra08.exe C:\Program\Last.fm\LastFMHelper.exe C:\Program\OpenOffice.org 2.4\program\soffice.exe C:\Program\OpenOffice.org 2.4\program\soffice.BIN C:\Program\Java\jre1.6.0_04\bin\jucheck.exe C:\Program\Mozilla Firefox\firefox.exe C:\Program\Opera\opera.exe C:\Program\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aftonbladet.se/ R1 - Back to top Page 1 of 3 1 2 3 Next Back to Virus, Trojan, Spyware, and Malware Removal Logs 1 user(s) are reading this topic 0 members, 1 guests, 0 Once again, I went to the Startup Manager in Norton 360 and checked all the files listed by searching on the web.

Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process. To do so do the followingOpen SpybotClick modeclick Advanced modeif you get a warning answer "yes"click toolsclick residentuncheck resident "teatimer" and SDHelper if installedclick allow changerebootOpen HJT, run a system scan Back to top #8 Barbaraeh Barbaraeh Topic Starter Members 15 posts OFFLINE Local time:01:31 AM Posted 04 October 2012 - 04:26 PM Jason, Here's the log from running aswMBR. You can also try the steps located here.

Thank you. ***************************************************************************************************************** .