two computers looking for connections from others

Discussion in 'Malware Help (A Specialist Will Reply)' started by GlennJr, Mar 10, 2006.

  1. GlennJr

    GlennJr Private E-2

    I have a small business with several computers. Two have spyware problems.

    Norton detects this but can not remove it. I get numerous warnings about the computers looking for connections. I have read your instructions and followed them to the best of my ability.

    I may have messed up on bitdefender. It tried to do an active x installation, I feared this was spyware, but then could not get the report from that program.

    I am trying to attach the necessary files. Each time I click on upload it looks like it is not working. Hopefully it is and I'm just too stupid to find where it indicates that there are attachments.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Maybe this will help you: HOW TO: Attach Items To Your Post

    Make sure you run ALL steps in the READ ME and attach the three requested logs:
    Bitdefender
    PandaActiveScan
    HijackThis (make sure you follow instructions in step 7 properly).
     
  3. GlennJr

    GlennJr Private E-2

    Thanks.

    Running the scans really helped. But I'm still getting the message:

    Windows Kernel Core component is attempting to listen to connections from other computers.

    I did get the attachments uploaded this time. Any help would be greatly appreciated. Thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have any idea what the below is for?
    O4 - Startup: map.pif = C:\MAP.BAT

    This runs each time you start your PC.

    Your HJT logs is pretty clean. There are just a few things to cleanup from your Panda and CounterSpy logs.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Then locate the below file using Windows Explorer and delete them:
    c:\windows\inf\conscorr.inf
    c:\windows\conscorr.ini
    C:\WINDOWS\INF\POLALL1R.INF
    C:\TEMP\FLEOK <--- the whole folder
    c:\temp\msbb.log
     
  5. GlennJr

    GlennJr Private E-2

    Thanks for taking the time to help, I really appreciate it.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but you did not give any feedback on my last message.

    Also are you still having any malware problems?
     
  7. GlennJr

    GlennJr Private E-2


    It looks like it is fixed. Thanks. If other problems pop up I'll be sure to come back, but it looks like it is fixed.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. It is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. GlennJr

    GlennJr Private E-2

    Got it. THANKS again.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds