KingHomeLogger

Language: JP EN DE FR
2010-09-08
New Items
users online
Forum » Everything Else » Tech Support » KingHomeLogger
KingHomeLogger
 Cerberus.Liandaru
Offline
Server: Cerberus
Game: FFXI
user: Liandrian
Posts: 2730
By Cerberus.Liandaru 2010-05-01 20:52:40
Link | Quote | Reply
 
SpyBot Search & Destroy just found this program on my computer. I killed it, but I need to know how infested I might be. I'm running all possible scans on my system, but are there folders and hidden files I need to search for?
 Quetzalcoatl.Sectumsempra
Offline
Server: Quetzalcoatl
Game: FFXI
user: Sect
Posts: 3987
By Quetzalcoatl.Sectumsempra 2010-05-01 20:54:28
Link | Quote | Reply
 
http://forums.spybot.info/showthread.php?t=39951

First thing to show up on google. I'll do some deeper research if you need.
 Alexander.Nepharite
Offline
Server: Alexander
Game: FFXI
user: nepharite
Posts: 605
By Alexander.Nepharite 2010-05-01 20:56:09
Link | Quote | Reply
 
Cerberus.Liandaru said:
SpyBot Search & Destroy just found this program on my computer. I killed it, but I need to know how infested I might be. I'm running all possible scans on my system, but are there folders and hidden files I need to search for?


http://forums.spybot.info/showthread.php?p=260749
 Alexander.Nepharite
Offline
Server: Alexander
Game: FFXI
user: nepharite
Posts: 605
By Alexander.Nepharite 2010-05-01 20:56:35
Link | Quote | Reply
 
looks like i was beat to the punch
 Cerberus.Liandaru
Offline
Server: Cerberus
Game: FFXI
user: Liandrian
Posts: 2730
By Cerberus.Liandaru 2010-05-01 21:10:48
Link | Quote | Reply
 
I also found a Norton Security Scan icon. It doesn't look like the normal Norton Antivirus icon. I think I'm under attack lol.
 Quetzalcoatl.Sectumsempra
Offline
Server: Quetzalcoatl
Game: FFXI
user: Sect
Posts: 3987
By Quetzalcoatl.Sectumsempra 2010-05-01 21:12:08
Link | Quote | Reply
 
Cerberus.Liandaru said:
I also found a Norton Security Scan icon. It doesn't look like the normal Norton Antivirus icon. I think I'm under attack lol.
Right click it, hit properties, and paste the file path it leads to here.
 Cerberus.Liandaru
Offline
Server: Cerberus
Game: FFXI
user: Liandrian
Posts: 2730
By Cerberus.Liandaru 2010-05-01 21:18:59
Link | Quote | Reply
 
I already killed it. It looked funny, we don't use Norton anyway, so I deleted it.
 Quetzalcoatl.Sectumsempra
Offline
Server: Quetzalcoatl
Game: FFXI
user: Sect
Posts: 3987
By Quetzalcoatl.Sectumsempra 2010-05-01 21:21:31
Link | Quote | Reply
 
Cerberus.Liandaru said:
I already killed it. It looked funny, we don't use Norton anyway, so I deleted it.
If you can, undelete it and get the file path. That sounds like a case of SmitFraud
 Cerberus.Liandaru
Offline
Server: Cerberus
Game: FFXI
user: Liandrian
Posts: 2730
By Cerberus.Liandaru 2010-05-01 21:33:35
Link | Quote | Reply
 
You're exactly right. I've found a whole bunch entries. This happened to my mom's computer a few years ago. It was a pain in the *** to deal with. I didn't get any popups directing me to any antivirus spyware, BUT upon looking at http://www.pchell.com/support/smitfraud.shtml i'm finding quite a few of the files it lists on there. Spybot is finding a bunch of stuff too. win32.Seneka.rtk. This is the same program I found at my mom's I think. She ended up having to buy a new computer by the time it was all said and done.
 Asura.Daleterrence
Offline
Server: Asura
Game: FFXI
user: Dalight
Posts: 5163
By Asura.Daleterrence 2010-05-01 21:52:10
Link | Quote | Reply
 
I'd like to thank this thread for reminding me to scan after I got back from my gfs place. Shouldn't find anything though, better to be safe than sorry however.
 Cerberus.Liandaru
Offline
Server: Cerberus
Game: FFXI
user: Liandrian
Posts: 2730
By Cerberus.Liandaru 2010-05-01 21:52:46
Link | Quote | Reply
 
Here's the logfile from Malwarebytes

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4058

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

5/1/2010 10:49:29 PM
mbam-log-2010-05-01 (22-49-29).txt

Scan type: Quick scan
Objects scanned: 120407
Time elapsed: 8 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.Zango) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\seneka.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\senekadf.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\010112010146101105.rx (Malware.Trace) -> Quarantined and deleted successfully.
 Cerberus.Liandaru
Offline
Server: Cerberus
Game: FFXI
user: Liandrian
Posts: 2730
By Cerberus.Liandaru 2010-05-01 23:49:34
Link | Quote | Reply
 
I ran scans and lots of them. Ran AVG, Malwarbytes, Spybot. My computer found a lot of stuff from a "double-click.net" which ended up coming from ffxiclopedia. These could just be cookies used to track stuff. But I also came up with a bunch of seneka stuff too. I don't know where I could have picked this stuff up at. I don't do any weird surfing, don't download anything unless I know for a fact it's safe (pretty much so nothing tbh). The only thing I can figure that happened is that I let my daughter's friend use the computer and she went to some "superpoke pets" site, wtf ever that is. Beats me. But I think I caught it time. Got rid of the fake Norton and McAfee stuff that had recently popped up.
 Kujata.Akeda
Offline
Server: Kujata
Game: FFXI
user: Akeda
Posts: 1698
By Kujata.Akeda 2010-05-01 23:51:39
Link | Quote | Reply
 
You didn't run HijackThis. It can show a lot of useful info if you can read the output.
 Asura.Daleterrence
Offline
Server: Asura
Game: FFXI
user: Dalight
Posts: 5163
By Asura.Daleterrence 2010-05-01 23:51:40
Link | Quote | Reply
 
Cerberus.Liandaru said:
Got rid of the fake Norton and McAfee stuff that had recently popped up.

People are asking to get infected if they do use the "real" Norton or McAfee. =P

Edit: Glad you caught it in time though.
 Cerberus.Liandaru
Offline
Server: Cerberus
Game: FFXI
user: Liandrian
Posts: 2730
By Cerberus.Liandaru 2010-05-02 00:01:05
Link | Quote | Reply
 
What's a safe site to get HijackThis from? I'll give that a try too.
 Asura.Daleterrence
Offline
Server: Asura
Game: FFXI
user: Dalight
Posts: 5163
By Asura.Daleterrence 2010-05-02 00:03:06
Link | Quote | Reply
 
http://free.antivirus.com/hijackthis/ is safe.
 Cerberus.Liandaru
Offline
Server: Cerberus
Game: FFXI
user: Liandrian
Posts: 2730
By Cerberus.Liandaru 2010-05-02 00:05:10
Link | Quote | Reply
 
Thank you very much! Much appreciated :)
 Asura.Daleterrence
Offline
Server: Asura
Game: FFXI
user: Dalight
Posts: 5163
By Asura.Daleterrence 2010-05-02 00:12:24
Link | Quote | Reply
 
No problem, just be careful with HijackThis, you can mess up your system if you aren't.

TrendMicro said:
Trend Micro HijackThis is a free utility that generates an in depth report of registry and file settings from your computer. HijackThis makes no separation between safe and unsafe settings in its scan results giving you the ability to selectively remove items from your machine. In addition to this scan and remove capability HijackThis comes with several tools useful in manually removing malware from a computer.

IMPORTANT: HijackThis does not determine what is good or bad. Do not make any changes to your computer settings unless you are an expert computer user.

Advanced users can use HijackThis to remove unwanted settings or files.

The part in bold in particular. ^^
 Cerberus.Liandaru
Offline
Server: Cerberus
Game: FFXI
user: Liandrian
Posts: 2730
By Cerberus.Liandaru 2010-05-02 00:13:58
Link | Quote | Reply
 
EEEEEEEP. Well I'm running it now. I've got a list of bad files to look for. I've dealt with this seneka thing before, so if it's there still, hopefully this finds it.
 Asura.Daleterrence
Offline
Server: Asura
Game: FFXI
user: Dalight
Posts: 5163
By Asura.Daleterrence 2010-05-02 00:18:45
Link | Quote | Reply
 
Cerberus.Liandaru said:
EEEEEEEP. Well I'm running it now. I've got a list of bad files to look for. I've dealt with this seneka thing before, so if it's there still, hopefully this finds it.

Okay, good luck! ^^
 Cerberus.Liandaru
Offline
Server: Cerberus
Game: FFXI
user: Liandrian
Posts: 2730
By Cerberus.Liandaru 2010-05-02 00:19:27
Link | Quote | Reply
 
Here's the logfile. Lots of Explorer stuff going on...and I don't have Exploder open, nor do I use it. Beats me.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:17:24 AM, on 5/2/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Zinio\ZinioReader.exe
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cndt
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Trillian Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\RunOnce: [isDeleteMe] "C:\Windows\system32\cmd.exe" /c "C:\Users\Josh\AppData\Local\Temp\isDel.bat"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Zinio DLM] C:\Program Files\Zinio\ZinioReader.exe /autostart
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PC Cleaner] C:\Program Files\PC Cleaner\PCCleanerTray.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Snapfish Media Detector.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {C3A57B60-C117-11D2-BD9B-00105A0A7E89} (SAXFile ActiveX Control) - http://www.diskfaktory.com/create/01/SAXFile.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 10240 bytes
 Asura.Daleterrence
Offline
Server: Asura
Game: FFXI
user: Dalight
Posts: 5163
By Asura.Daleterrence 2010-05-02 00:25:04
Link | Quote | Reply
 
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

... Hmm.. Thought you said you don't use Norton?

And the IE stuff doesn't look deadly, however it still might be trying to run in the background.

Ignore that bit, I just actually read the entries, yeah that is pretty much normal.
 Cerberus.Liandaru
Offline
Server: Cerberus
Game: FFXI
user: Liandrian
Posts: 2730
By Cerberus.Liandaru 2010-05-02 00:28:06
Link | Quote | Reply
 
I uninstalled Norton a little while ago. Still have the Norton Protection Center thing running down there though. Not sure. That's been here since we got the computer, so i'm not too worried about that. Looks like from all the different scans I've done tonight, i've gotten the machine fairly cleaned up. Lesson learned is this: do not allow strange children to use your computer.
 Asura.Daleterrence
Offline
Server: Asura
Game: FFXI
user: Dalight
Posts: 5163
By Asura.Daleterrence 2010-05-02 00:31:33
Link | Quote | Reply
 
Cerberus.Liandaru said:
I uninstalled Norton a little while ago. Still have the Norton Protection Center thing running down there though. Not sure. That's been here since we got the computer, so i'm not too worried about that. Looks like from all the different scans I've done tonight, i've gotten the machine fairly cleaned up. Lesson learned is this: do not allow strange children to use your computer.

If you go to Run > Services.msc and find "Symantec Core LC" on that list you can stop it running completely.
Log in to post.