Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Hijack Log and w32.Gaobot!inf virus
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
removing iSearch Toolbar »
« Sasser traffic pattern?  
AuthorAll Replies

paddy_cass

join:2004-05-03
reply to paddy_cass
Re: Hijack Log and w32.Gaobot!inf virus

Can i also add that the file svchost.exe is continuously running in the background. Not sure if this is a prob or not but when i attempt to close it it restarts the comnputer. An RPC violation.


John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England

said by paddy_cass See Profile:
Can i also add that the file svchost.exe is continuously running in the background. Not sure if this is a prob or not but when i attempt to close it it restarts the comnputer. An RPC violation.

You should have about 4 svchost.exes running.
--
Better to remain silent and be thought a fool, than to speak and remove all doubt.


darkstar2778
Premium
join:2004-01-20
Florida
clubs:


1 edit
reply to paddy_cass
Wait for an expert to come along and help you out (please don't do anything with Hijack This until an expert comments). This looks off to me:

O4 - HKLM\..\Run: [Msrv32] Msrv32.exe
O4 - HKLM\..\Run: [avserve2.exe] C:\WINDOWS\avserve2.exe
O4 - HKLM\..\RunServices: [Msrv32] Msrv32.exe

I see some things you can fix but will let someone with more experience post. Do you know what this is:

O4 - HKLM\..\RunServices: [soundtasks] soundtasks.exe

EDIT: Please move Hijack This to it own permanent folder (i.e. C:\Hijack This\hijackthis.exe). This will allow it to make back-ups of any changes you make. This is important in the event you need to restore items you chose to fix with Hijack This.

paddy_cass

join:2004-05-03
reply to John2g
yeah, i have 4, does anyone know how to get rid of the virus

paddy_cass

join:2004-05-03
reply to darkstar2778
Have no idea, MSRV.exe is a w32.Gaobot virus. When i get rid of the current virus by simply deleting the file its associated with it reappears again.

This is actually the very first hijack log i have ever run.


darkstar2778
Premium
join:2004-01-20
Florida
clubs:

reply to paddy_cass
You're in good hands now paddy_cass See Profile....hang tight as I would imagine John2g See Profile is looking around to help you now.
Forums » Up and Running » Security » Securityremoving iSearch Toolbar »
« Sasser traffic pattern?  


Saturday, 28-Nov 06:55:20 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [121] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [71] TiVo Sees Record Customer Losses
· [69] In-Flight Internet Headed For Bumpy Landing?
· [66] Verizon CEO: Hulu Will Be Dead Soon
· [62] Thanksgiving Open Thread
· [51] Weekend Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· [Newsgroups] Newzleech down? [Filesharing Software]
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Backstab vs screws (not which to use) [Home Repair & Improvement]
· [Config] cisco asa 5505 with multiple outside IP addresses [Cisco]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]
· [FS] Laptops + Memory + E8400 + More! [For Sale/Wanted]