- Oct 5, 2012
- 2,697
Hi Fiery,
FYI
FYI
Igorica said:Hi!
I notice today while surfing the net that my laptop freezes a little, I don't know if that has something to do with the virus.
I tried to post the logs which I got after Hitmanpro scan but I couldn't post them.
Code:HitmanPro 3.7.1.186 www.hitmanpro.com Computer name . . . . : KORISNIK-325758 Windows . . . . . . . : 5.1.3.2600.X86/2 User name . . . . . . : KORISNIK-325758\korisnik License . . . . . . . : Free Scan date . . . . . . : 2013-02-01 21:56:23 Scan mode . . . . . . : Normal Scan duration . . . . : 6m 31s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 1 Traces . . . . . . . : 42 Objects scanned . . . : 687.608 Files scanned . . . . : 33.564 Remnants scanned . . : 248.379 files / 405.665 keys Suspicious files ____________________________________________________________ E:\Documents and Settings\korisnik\My Documents\util\TEMSSetup-x32.exe Size . . . . . . . : 1.531.971 bytes Age . . . . . . . : 1585.1 days (2008-09-30 18:43:19) Entropy . . . . . : 8.0 SHA-256 . . . . . : 0BFA43932BFBBA47E6B9D2EA18DA92EFA2A3F6B88242F49F9155B8067567DE14 Publisher . . . . : Threat Expert Ltd. Description . . . : ThreatExpert Memory Scanner Setup Version . . . . . : ThreatExpert Copyright . . . . : Threat Expert Ltd. RSA Key Size . . . : 1024 Authenticode . . . : Invalid Fuzzy . . . . . . : 31.0 Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Malware remnants ____________________________________________________________ HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE ERROR PAGE BYPASS ZONE CHECK FOR HTTPS KB954312\ (Trojan.FakeAV) Potential Unwanted Programs _________________________________________________ HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1\ (Babylon) HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr\ (Babylon) Repairs _____________________________________________________________________ hosts E:\WINDOWS\system32\drivers\etc\ Cookies _____________________________________________________________________ E:\Documents and Settings\korisnik\Application Data\Mozilla\Firefox\Profiles\bcs0odkv.default\cookies.sqlite:ad.yieldmanager.com E:\Documents and Settings\korisnik\Cookies\59L0I4Z6.txt E:\Documents and Settings\korisnik\Cookies\BEZF3GAD.txt E:\Documents and Settings\korisnik\Cookies\C7H0ER9P.txt E:\Documents and Settings\korisnik\Cookies\JV5NTNEN.txt E:\Documents and Settings\korisnik\Cookies\KULATPQO.txt E:\Documents and Settings\korisnik\Cookies\ND1O2XKY.txt E:\Documents and Settings\korisnik\Cookies\NSGQCMPK.txt E:\Documents and Settings\korisnik\Cookies\OY47NYJW.txt E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ad.360yield.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ad.net.hr E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:adbrite.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.24sata.hr E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.emg-network.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:adtech.de E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:at.atwola.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:atdmt.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:casalemedia.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:choicemediainc.112.2o7.net E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:collective-media.net E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:dmtracker.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:doubleclick.net E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:h.atdmt.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:invitemedia.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:kontera.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:linksynergy.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:media6degrees.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:mm.chitika.net E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:revsci.net E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ru4.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:statcounter.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:stats.snacktools.net E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:track.adform.net E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:tribalfusion.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:xiti.com E:\Documents and Settings\korisnik\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:zedo.com