Help - Search - Members - Calendar
Full Version: Help I Don't Know What This Is
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
fieryjenthered
:o Hello I have a problem with something called Java/ByteVerify virus and it says its in my c:/programfiles/lavasoft/adaware6/cache/parser.class and another one c:/programfiles/lavasoft/adaware6/cache/counter.class here is a scan.
Logfile of HijackThis v1.97.7
Scan saved at 4:28:33 PM, on 6/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\sistray.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Boomerang Software\eXtendia PC Security Tools\Pfft.exe
C:\Documents and Settings\Jennifer\Local Settings\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dogpile.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eXtendia PC Firewall] C:\Program Files\Boomerang Software\eXtendia PC Security Tools\Pfft.exe
O4 - Startup: Microsoft Outlook.lnk = C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O10 - Broken Internet access because of LSP provider 'pfftsp.dll' missing
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -

Thank you for any help you can provide :unsure:
LoPhatPhuud
Your HiJackThis log is clean.

Also, there is no problem with the messages you are receiving. When AdAware is scanning it decompresses the archive to it's cache folders. As it does this, your AV, AVG in this case, is watching. When AdAware got to your Java runtime software, AVG screamed at what it thought was a "bug". In reality it is safe code. When it is finished, AdAware deletes the cache folder and any contents.

There are two things you can do. Ignore these errors, especially if you have just done a full AV scan. The other choice is to turn off your AV when you are doing a scan with AdAware. If you elect that option, be sure you are not connected to the internet!

Hope this helps and feel free to ask more questions.
fieryjenthered
ahah.gif Thank You Very Much! :thx: applause
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.