Jump to content

Red_Rock

Members
  • Posts

    3
  • Joined

  • Last visited

Reputation

0 Neutral

Recent Profile Visitors

335 profile views
  1. Everything appears to be fine for the time being! Thank you for the help TwinHeadedEagle. I was just being paranoid when I saw the incoming attacks as I bought this laptop used.
  2. Thanks for the reply, Twin Headed Eagle. Here are the results: Zoek.exe v5.0.0.1 Updated 12-November-2015Tool run by Owner on Sat 11/14/2015 at 3:05:16.75.Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64Running in: Normal Mode Internet Access DetectedLaunched: C:\Users\Owner\Desktop\zoek.exe [scan all users] [script inserted] ==== System Restore Info ====================== 11/14/2015 3:06:28 AM Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfullyC:\Users\Owner\AppData\Local\VirtualStore deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Batch Command(s) Run By Tool====================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ==== Deleting Files \ Folders ====================== C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) not foundC:\Users\Owner\AppData\Roaming\Sublime Text 2 deletedC:\PROGRA~3\Kingsoft deletedC:\PROGRA~3\Package Cache deletedC:\Windows\SysNative\config\systemprofile\Searches deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]"web2pdfextension@web2pdf.adobedotcom"="C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn" [11/06/2015 12:24 AM][HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]"{F74D5734-46F5-4B16-96F0-1E7FBF41B750}"="C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension\2.0b12" [11/05/2015 09:55 PM] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\g3n974b3.default- ThinkVantage Password Manager - C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension\2.0b12- Undetermined - %ProfilePath%\extensions\uBlock0@raymondhill.net.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== ==== Chromium Look ====================== Google Chrome Version: 46.0.2490.86 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensionsefaidnbmnnnibpcajpcglclefindmkaj - No path found[]lpdfbkehegfmedglgemnhbnpmfmioggj - No path found[] uBlock₀ - Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagmThinkVantage Password Manager - Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpdfbkehegfmedglgemnhbnpmfmioggj ==== Set IE to Default ====================== Old Values:[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main][HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]"Start Page"="http://www.duba.com/?f=1"[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]"Start Page"="http://www.duba.com/?f=1" New Values:[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCHKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCHKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02HKCU\SearchScopes\{44177982-996D-4b79-B29F-5B60E13A5169} - http://www.baidu.com/s?wd={searchTerms}&tn=98012088_dg&ch=5&ie=utf-8 ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfullyC:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfullyC:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfullyC:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfullyC:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfullyC:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfullyC:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfullyC:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PX03G1RR will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Owner\AppData\Local\Mozilla\Firefox\Profiles\g3n974b3.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1605 folders=112 111691315 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfullyC:\Users\Default User\AppData\Local\Temp emptied successfullyC:\Users\Owner\AppData\Local\Temp will be emptied at rebootC:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at rebootC:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfullyC:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptiedC:\Users\Owner\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\ib978D.tmp" deleted"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\ib978E.tmp" deleted"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\ib979F.tmp" deleted"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\ib99A2.tmp" deleted"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\ib9F10.tmp" deleted"C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PX03G1RR" not found ==== EOF on Sat 11/14/2015 at 3:27:24.58 ======================
  3. Hi, I am worried that I may have a malware infection on my laptop. There were attempts by an unknown ip address to access svchost.exe and one attempt outbound from chrome.. I tried to follow instructions from other threads to see if anything came up but I would like to be completely sure that my laptop is not infected. I have attached the protection log from that day alongside the scan results from FarBar. Thank you. protectionlog.txt FRST.txt Addition.txt
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.