Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Rootkit.Zeroaccess
Message
<blockquote data-quote="schoj05" data-source="post: 120565" data-attributes="member: 8135"><p>Hi Kuttus </p><p></p><p>I tried a recommended programme to me called Windows Repair, which I ran and it has fixed my internet connection issues, and I can now connect through safe mode networking to the internet</p><p></p><p>As soon as I did that , I ran for the 1st time Hitman pro and it caught 7 threats that were still active on my Laptop </p><p></p><p>report has been posted?</p><p></p><p>[code]</p><p>HitmanPro 3.7.3.194</p><p>www.hitmanpro.com</p><p></p><p> Computer name . . . . : JONATHANS</p><p> Windows . . . . . . . : 6.1.1.7601.X86/2</p><p> Safe Mode Boot . . . : NETWORK</p><p> User name . . . . . . : Jonathans\Jona</p><p> UAC . . . . . . . . . : Disabled</p><p> License . . . . . . . : Trial (30 days left)</p><p></p><p> Scan date . . . . . . : 2013-05-13 22:51:02</p><p> Scan mode . . . . . . : Normal</p><p> Scan duration . . . . : 5m 3s</p><p> Disk access mode . . : Direct disk access (SRB)</p><p> Cloud . . . . . . . . : Internet</p><p> Reboot . . . . . . . : Yes</p><p></p><p> Threats . . . . . . . : 2</p><p> Traces . . . . . . . : 5</p><p></p><p> Objects scanned . . . : 1,213,214</p><p> Files scanned . . . . : 23,512</p><p> Remnants scanned . . : 352,254 files / 837,448 keys</p><p></p><p>Malware _____________________________________________________________________</p><p></p><p> C:\ProgramData\Microsoft\Media Tools\MediaIconsOverlays.dll -> Quarantined</p><p> Size . . . . . . . : 225,280 bytes</p><p> Age . . . . . . . : 5.0 days (2013-05-08 22:18:09)</p><p> Entropy . . . . . : 6.4</p><p> SHA-256 . . . . . : E6A37A94CF4998E0DA0EFAAABB179899B445F1453CF355EA729D1DCD2B8B63FE</p><p> Needs elevation . : Yes</p><p> Product . . . . . : Online files icon's overlay</p><p> Publisher . . . . : Microsoft</p><p> Description . . . : Online files icon's overlay</p><p> Version . . . . . : 1.0.2.5</p><p> Copyright . . . . : Microsoft</p><p> Gossip . . . . . . : crosoft</p><p> > Emsisoft . . . . . : Trojan.Win32.Agent.amn!A2</p><p> Fuzzy . . . . . . : 117.0</p><p> One or more antivirus vendors have indicated that the file is malicious.</p><p> This file was most recently added as automatic startup.</p><p> Program starts automatically without user intervention.</p><p> Time indicates that the file appeared recently on this computer.</p><p> The file is in use by one or more active processes.</p><p> The file appears to be part of an installation package or setup program. This is typical for most programs.</p><p> Startup</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\ShellIconOverlayIdentifiers\1MediaIconsOverlay\</p><p> References</p><p> HKLM\SOFTWARE\Classes\CLSID\{1EC23CFF-4C58-458f-924C-8519AEF61B32}\</p><p> Forensic Cluster</p><p> -0.0s C:\ProgramData\Microsoft\Media Tools\</p><p> 0.0s C:\ProgramData\Microsoft\Media Tools\MediaIconsOverlays.dll</p><p> 3.0s C:\ProgramData\Microsoft\Media Tools\temp\</p><p> 7.0s C:\ProgramData\Microsoft\Media Tools\plugins\</p><p></p><p></p><p>Malware remnants ____________________________________________________________</p><p></p><p> HKU\S-1-5-21-3659869320-2491200586-312378291-1000\Software\Microsoft\Internet Explorer\LowRegistry\Extensions\CmdMapping\{B58926D6-CFB0-45d2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> Deleted</p><p></p><p></p><p>[/code]</p></blockquote><p></p>
[QUOTE="schoj05, post: 120565, member: 8135"] Hi Kuttus I tried a recommended programme to me called Windows Repair, which I ran and it has fixed my internet connection issues, and I can now connect through safe mode networking to the internet As soon as I did that , I ran for the 1st time Hitman pro and it caught 7 threats that were still active on my Laptop report has been posted? [code] HitmanPro 3.7.3.194 www.hitmanpro.com Computer name . . . . : JONATHANS Windows . . . . . . . : 6.1.1.7601.X86/2 Safe Mode Boot . . . : NETWORK User name . . . . . . : Jonathans\Jona UAC . . . . . . . . . : Disabled License . . . . . . . : Trial (30 days left) Scan date . . . . . . : 2013-05-13 22:51:02 Scan mode . . . . . . : Normal Scan duration . . . . : 5m 3s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : Yes Threats . . . . . . . : 2 Traces . . . . . . . : 5 Objects scanned . . . : 1,213,214 Files scanned . . . . : 23,512 Remnants scanned . . : 352,254 files / 837,448 keys Malware _____________________________________________________________________ C:\ProgramData\Microsoft\Media Tools\MediaIconsOverlays.dll -> Quarantined Size . . . . . . . : 225,280 bytes Age . . . . . . . : 5.0 days (2013-05-08 22:18:09) Entropy . . . . . : 6.4 SHA-256 . . . . . : E6A37A94CF4998E0DA0EFAAABB179899B445F1453CF355EA729D1DCD2B8B63FE Needs elevation . : Yes Product . . . . . : Online files icon's overlay Publisher . . . . : Microsoft Description . . . : Online files icon's overlay Version . . . . . : 1.0.2.5 Copyright . . . . : Microsoft Gossip . . . . . . : crosoft > Emsisoft . . . . . : Trojan.Win32.Agent.amn!A2 Fuzzy . . . . . . : 117.0 One or more antivirus vendors have indicated that the file is malicious. This file was most recently added as automatic startup. Program starts automatically without user intervention. Time indicates that the file appeared recently on this computer. The file is in use by one or more active processes. The file appears to be part of an installation package or setup program. This is typical for most programs. Startup HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\ShellIconOverlayIdentifiers\1MediaIconsOverlay\ References HKLM\SOFTWARE\Classes\CLSID\{1EC23CFF-4C58-458f-924C-8519AEF61B32}\ Forensic Cluster -0.0s C:\ProgramData\Microsoft\Media Tools\ 0.0s C:\ProgramData\Microsoft\Media Tools\MediaIconsOverlays.dll 3.0s C:\ProgramData\Microsoft\Media Tools\temp\ 7.0s C:\ProgramData\Microsoft\Media Tools\plugins\ Malware remnants ____________________________________________________________ HKU\S-1-5-21-3659869320-2491200586-312378291-1000\Software\Microsoft\Internet Explorer\LowRegistry\Extensions\CmdMapping\{B58926D6-CFB0-45d2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> Deleted [/code] [/QUOTE]
Insert quotes…
Verification
Post reply
Top