We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

is my pc infected with something?

2

Comments

  • donnajunkie
    donnajunkie Posts: 32,412 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    Browntoa wrote: »
    it's not a HP Pc is it ??

    it is sort of, its a compaq.
  • donnajunkie
    donnajunkie Posts: 32,412 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    GunJack wrote: »
    Some stuff I've never heard of in there, but googled and got answers...

    Do you use swarmcast at all ??
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,AutoConfigURL = http://local.swarmcast.net:8001/proxy.pac

    If MBAM and SAS are scanning okay, may be other issues affecting defender and ad-aware (neither of which are much kop, IMHO). Looking at info on the worm, it would seem that it's more server-based, and is "unlikely" to infect a home pc, other than the home pc being on the receiving end.

    i have never heard of swarmcast and dont know what it does.
  • donnajunkie
    donnajunkie Posts: 32,412 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    Browntoa wrote: »
    fix these

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe

    on my pc there is something called exif launcher which is related to software for a digital camera. will this be the same thing that is called launcher here? i dont want to remove something if it is going to affect the smooth running of that software or quicktime and itunes regarding the other two.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    FIX these (If you havnt done so already)
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,AutoConfigURL = http://local.swarmcast.net:8001/proxy.pac
    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe


    Parts of norton are still running, use the removal tool
    http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039

    Reboot and run another hijack log
    :idea:
  • GunJack
    GunJack Posts: 11,894 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    i have never heard of swarmcast and dont know what it does.

    in that case I'd fix it....it appears to be a video streaming enabling prog....

    http://swarmcast.com/

    is their homepage (god I love google ;))
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • GunJack
    GunJack Posts: 11,894 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    by the way everytime i do a scan with kaspersky it always says that this is a vulnerability. should i ignore it? or do i need to do something? i believe it is connected to adobe flash player.

    flashplayer has had some issues recently...usually fixed by uninstalling and re-installing...
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • GunJack
    GunJack Posts: 11,894 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    google SMINST and you get a mixed bag...some recon it's part of HP/compaq recovery suite, others recon it's a trojan :confused: Anyone got any pukka gen to shed some light on this one??
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • You could send the file to Virustotal - http://www.virustotal.com/
  • donnajunkie
    donnajunkie Posts: 32,412 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    aliEnRIK wrote: »
    FIX these (If you havnt done so already)
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,AutoConfigURL = http://local.swarmcast.net:8001/proxy.pac
    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe


    Parts of norton are still running, use the removal tool
    http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039

    Reboot and run another hijack log

    i ran norton removal when i changed over. i have just ran it again and it still leaves the odd thing. i suspect it could be down to norton having came with the pc and therefore it may always be around because it might be kept in the d drive incase of a system restore. obviously when a system restore is done you get everything that was there when you first turned on the pc.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    ok doki
    Just hope its not effecting anything
    :idea:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.2K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 600.9K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.