i've seen somewhere here got fake adobe is it? correct me if im wrong.
say adobe got virus lah then what. went to youtube then FF prompted me to download adobe flash in or der to watch videos. i just reformatted comp btw.
then it says KEY32 cannot donno what. the pop-up saying about KEY32 doesnt look like XP but Windows 2000 or 95/98.
so is key32 a virus?
vertmonyet
less than half an hour got VIRUT virus. WTF IS THIS.
no porn shits no downloads except adobe flash.
cos of MSN?
ndmmxiaomayi
Yes, there's a fake Adobe.
Well... I didn't posted, because it wasn't too important. Looks like you got it.
vertmonyet
KNN.
means FF prompts me to download adobe.
what a bummer.
i used avg. so does that mean im clear? do i need to post a HJT?
vertmonyet
now i tio backdoor. i MERELY downloaded adobe linked from FF.
what next? cannot shutdown?
vertmonyet
is "scantoweb" a virus?
ndmmxiaomayi
Yup, please post a log.
vertmonyet
screw the world wide web
Logfile of HijackThis v1.99.1 Scan saved at 10:19:28 AM, on 7/21/2007 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Logfile of HijackThis v1.99.1 Scan saved at 3:44:52 PM, on 7/22/2007 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1185081298202 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
ndmmxiaomayi
Windows still not updated.
vertmonyet
updated already?
Logfile of HijackThis v1.99.1 Scan saved at 5:14:54 PM, on 7/22/2007 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)