Hijack via Media Codec 4.0

  Venezia 18:46 08 Oct 06

Inadvertently downloading this programme has resulted in annoying "critical system error" messages appearing, which just direct me to sales sites for anti virus software. I have lots of good free antispyware on the pc, inc adaware, spybot, spyware blaster - all up to date but didn't guard against this.

Hijack this log:

Logfile of HijackThis v1.99.0
Scan saved at 17:36:34, on 08/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Sophos SWEEP for NT\SWNETSUP.EXE
C:\Program Files\Sophos SWEEP for NT\SWEEPSRV.SYS
C:\Program Files\MediaCodec\pmsngr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MediaCodec\pmmon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\SuperCleaner\SuperCleaner.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\MalwareScanner\MalScr.exe
C:\Program Files\Sophos SWEEP for NT\ICMON.EXE
C:\Program Files\Really good spyware etc\SpywareGuard\sgmain.exe
C:\Program Files\Webshots\webshots.scr
C:\Program Files\Really good spyware etc\SpywareGuard\sgbhp.exe
C:\Program Files\Spy-Heal\Spy-Heal.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\HijackThis.exe

O23 - Service: Sony SPTI Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Sophos Anti-Virus Network - Sophos Plc - C:\Program Files\Sophos SWEEP for NT\SWNETSUP.EXE
O23 - Service: Sophos Anti-Virus - Sophos Plc - C:\Program Files\Sophos SWEEP for NT\SWEEPSRV.SYS
O23 - Service: TrueVector Internet Monitor - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Any ideas, please?

  STREETWORK 18:50 08 Oct 06

I have an idea, post the log to click here because its too long to post here and no-one will look at it...

  gudgulf 19:33 08 Oct 06

click here

Is what you have......and there are a number of rogue antimalware programs running too such as Spy-Heal and AntiMalware to name but two.

That is an incomplete log but it's more than enough to suggest you do exactly as STREETWORK suggests and post the full log over at an expert forum.

The MalwareRemoval forums at click here are well recommended by this forum.

  gudgulf 19:37 08 Oct 06

Also known as trojan Zlob-media codec.

More information click here

This thread is now locked and can not be replied to.

