Help - Search - Members - Calendar
Full Version: Think but not for sure infected
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
mick
I cleaned a machine up last evening for a friend. Installed CC Cleaner, Spysweeper, Counterspy, Adaware and Spybot. Ran all of them until every one of them came up with zero found. After that, went and ran a registry fixer I had put on to back and deep scan the registry.

I noticed when the machine would shut down a box would pop up that would say something to the effect that the .DLL could not shut down because it failed to initialize. When I traced this down in the registry it was in the RunOnce key with the folling statement:

C:\WINDOWS\FONTS\ACCIIS.EXE RERUN

No matter how many times I run any of these softwares or manually delete, it will not go away. This is something new to me and was not able to find anything by doing a Google search either. Anyone? help! Thanks

Mike
LoPhatPhuud
First:
Create a directory on your hardrive to save HijackThis.exe. A directory like c:\hijackthis. If you do not do this, you will not be able to use the backup/restore features.

Download HijackThis from:

HijackThis Download Site

Save this file into the directory you made previously and then run the program named hijackthis.exe. When the program opens click on the Config button, then click on the Misc Tools button, and click on the Check for update online button. When it completes checking/applying updates press the back button.

Now click on the Scan button and when it is finished click on the Save Log button. A Notepad window will open with the contents of this log. Click on Edit then click on Select all. Then click on Edit and then Click on Copy.

Create a reply to this post here and right click in message area and select paste to paste the log into the post.

Someone will reply to you after reading this post. DO NOT fix any entries unless you understand what you are doing.

To see a tutorial with screenshots on using HijackThis you can click on the link below:

How to use HijackThis to remove Browser Hijackers, Malware, & Spyware


Second:
Download 'Autoruns' from here:
http://www.sysinternals.com/Utilities/Autoruns.html

Unzip to a folder and the double click on autoruns.exe

Wait until the program has finished running (the status line will show 'Ready')
Under the 'Options' menu, make sure that 'Include Empty Sections' is checked.
Wait again until ready.

Be sure the 'Everything' tab is selected.
Select 'File -> Save' and save the output file.

Copy the contents of the Autoruns text file and post its contents in this thread.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.