Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
I need help to remove system care antivirus from my server
Message
<blockquote data-quote="Ladylike" data-source="post: 131264" data-attributes="member: 10596"><p>[code]</p><p>HitmanPro 3.7.6.201</p><p>www.hitmanpro.com</p><p></p><p> Computer name . . . . : HP-PC</p><p> Windows . . . . . . . : 6.1.1.7601.X86/2</p><p> User name . . . . . . : HP-PC\HP</p><p> UAC . . . . . . . . . : Enabled</p><p> License . . . . . . . : Free</p><p></p><p> Scan date . . . . . . : 2013-08-01 10:42:38</p><p> Scan mode . . . . . . : Normal</p><p> Scan duration . . . . : 1h 16m 6s</p><p> Disk access mode . . : Direct disk access (SRB)</p><p> Cloud . . . . . . . . : Internet</p><p> Reboot . . . . . . . : No</p><p></p><p> Threats . . . . . . . : 0</p><p> Traces . . . . . . . : 1168</p><p></p><p> Objects scanned . . . : 946,251</p><p> Files scanned . . . . : 46,827</p><p> Remnants scanned . . : 269,825 files / 629,599 keys</p><p></p><p>Suspicious files ____________________________________________________________</p><p></p><p> C:\Users\HP\AppData\Local\Temp\F354.tmp</p><p> Size . . . . . . . : 265,121 bytes</p><p> Age . . . . . . . : 1.0 days (2013-07-31 11:16:53)</p><p> Entropy . . . . . : 7.8</p><p> SHA-256 . . . . . : D3FF690FC6E0C0C25E49E5E032ED552837B825133A63E300B94952F515149EF3</p><p> Fuzzy . . . . . . : 22.0</p><p> Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.</p><p> The file name extension of this program is not common.</p><p> Authors name is missing in version info. This is not common to most programs.</p><p> Version control is missing. This file is probably created by an individual. This is not typical for most programs.</p><p> Time indicates that the file appeared recently on this computer.</p><p> Program contains PE structure anomalies. This is not typical for most programs.</p><p> Forensic Cluster</p><p> -6.1s C:\Users\HP\AppData\Roaming\Microsoft\Windows\Recent\APCON2 12_13 sever-071613.ptb.lnk</p><p> -4.3s C:\Windows\Prefetch\FILESCOUT.EXE-C27540D1.pf</p><p> 0.0s C:\Users\HP\AppData\Local\Temp\F354.tmp</p><p> 3.6s C:\Users\HP\AppData\Roaming\Microsoft\Windows\Recent\OTL.Txt for server.lnk</p><p> 13.5s C:\Windows\Prefetch\NOTEPAD.EXE-86E0E9B9.pf</p><p> 40.8s C:\Windows\Prefetch\RESTORER1.0.0.1.EXE-446DDE63.pf</p><p> 40.9s C:\Windows\Prefetch\F354.TMP-F6A5589E.pf</p><p> 41.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{05F70771-FC13-4779-A7A3-92EBD52C4AA7}</p><p></p><p></p><p>Cookies _____________________________________________________________________</p><p></p><p> C:\Users\HP\AppData\Roaming\Microsoft\Windows\Cookies\2AB7K5OK.txt</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ad.360yield.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ad.mlnadvertising.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ad.yieldmanager.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ads.creative-serving.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ads.p161.net</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ads.pubmatic.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:adtech.de</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:adtechus.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:advertising.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:apmebf.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:atdmt.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:burstnet.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:c1.atdmt.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:casalemedia.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:collective-media.net</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:dmtracker.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:doubleclick.net</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:fastclick.net</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:in.getclicky.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:invitemedia.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:kontera.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:media6degrees.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:overture.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:pool-eu-ie.creative-serving.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:questionmarket.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:revsci.net</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ru4.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:serving-sys.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:smartadserver.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:statcounter.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:stats.adotube.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:stats.snacktools.net</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:survey.g.doubleclick.net</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:track.adform.net</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:tribalfusion.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:www.googleadservices.com</p><p> C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:zedo.com</p><p></p><p></p><p>[/code]</p></blockquote><p></p>
[QUOTE="Ladylike, post: 131264, member: 10596"] [code] HitmanPro 3.7.6.201 www.hitmanpro.com Computer name . . . . : HP-PC Windows . . . . . . . : 6.1.1.7601.X86/2 User name . . . . . . : HP-PC\HP UAC . . . . . . . . . : Enabled License . . . . . . . : Free Scan date . . . . . . : 2013-08-01 10:42:38 Scan mode . . . . . . : Normal Scan duration . . . . : 1h 16m 6s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 0 Traces . . . . . . . : 1168 Objects scanned . . . : 946,251 Files scanned . . . . : 46,827 Remnants scanned . . : 269,825 files / 629,599 keys Suspicious files ____________________________________________________________ C:\Users\HP\AppData\Local\Temp\F354.tmp Size . . . . . . . : 265,121 bytes Age . . . . . . . : 1.0 days (2013-07-31 11:16:53) Entropy . . . . . : 7.8 SHA-256 . . . . . : D3FF690FC6E0C0C25E49E5E032ED552837B825133A63E300B94952F515149EF3 Fuzzy . . . . . . : 22.0 Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. The file name extension of this program is not common. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Program contains PE structure anomalies. This is not typical for most programs. Forensic Cluster -6.1s C:\Users\HP\AppData\Roaming\Microsoft\Windows\Recent\APCON2 12_13 sever-071613.ptb.lnk -4.3s C:\Windows\Prefetch\FILESCOUT.EXE-C27540D1.pf 0.0s C:\Users\HP\AppData\Local\Temp\F354.tmp 3.6s C:\Users\HP\AppData\Roaming\Microsoft\Windows\Recent\OTL.Txt for server.lnk 13.5s C:\Windows\Prefetch\NOTEPAD.EXE-86E0E9B9.pf 40.8s C:\Windows\Prefetch\RESTORER1.0.0.1.EXE-446DDE63.pf 40.9s C:\Windows\Prefetch\F354.TMP-F6A5589E.pf 41.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{05F70771-FC13-4779-A7A3-92EBD52C4AA7} Cookies _____________________________________________________________________ C:\Users\HP\AppData\Roaming\Microsoft\Windows\Cookies\2AB7K5OK.txt C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ad.360yield.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ad.mlnadvertising.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ad.yieldmanager.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ads.creative-serving.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ads.p161.net C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ads.pubmatic.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:adtech.de C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:adtechus.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:advertising.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:apmebf.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:atdmt.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:burstnet.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:c1.atdmt.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:casalemedia.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:collective-media.net C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:dmtracker.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:doubleclick.net C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:fastclick.net C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:in.getclicky.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:invitemedia.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:kontera.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:media6degrees.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:overture.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:pool-eu-ie.creative-serving.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:questionmarket.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:revsci.net C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:ru4.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:serving-sys.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:smartadserver.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:statcounter.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:stats.adotube.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:stats.snacktools.net C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:survey.g.doubleclick.net C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:track.adform.net C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:tribalfusion.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:www.googleadservices.com C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8ix8f98r.default\cookies.sqlite:zedo.com [/code] [/QUOTE]
Insert quotes…
Verification
Post reply
Top