Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [FIXED] Another lost soul who needs help.

[Fixed] Hijackthis! Logs - [FIXED] Another lost soul who needs help. posted in the Security & Safety forums; Ok, I've been attempting to get rid of this one on my own, the symptoms are as follows: Initial install caused spysheriff to pretend to be removing spyware, and changed ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-21-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 5
loudambiance - See this Members User comments on their Profile page
Default [FIXED] Another lost soul who needs help.

Ok, I've been attempting to get rid of this one on my own, the symptoms are as follows:

Initial install caused spysheriff to pretend to be removing spyware, and changed wallpaper to a blue bg with a black box that said something to the affect that 'you are infected with spyware', and locked the background in display properties where it could not be changed. After which the pop ups started.

Through the process of running Spybot S&D, Ms Antispyware, Adaware, and Spyware Doctor, I ridded my self of SpySheriff and deleted the html file it had made my wallpaper, eventually through a registry patch I found on through google, I fixed the desktop. Now I can't stop the popups. I follow the prehelp suggestions of CCleaner and Ewido, Ewido removed some more things, but the pop ups are still there. Through the use of SysInternals tools, Process Explorer, RootKit Finder, PsList, and Autoruns, as well as the use of Xp's Administrator Services window, I have not been able to find anything out of the ordinary running. Included as attachments are the Ewido and Hijack this logs. Anything you find will be greatly appreciated.

Thanks,
Danl
Attached Files
File Type: txt Scan report_20051120.txt.txt (15.3 KB, 1 views)
File Type: txt hijackthis.txt (9.7 KB, 1 views)


  #2  
Old 11-21-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 5
loudambiance - See this Members User comments on their Profile page
Default

[update] Am running Trend Micro's Housecall now, cause my Symantec Corporate Antivirus 9.0 found nothing.


  #3  
Old 11-21-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Load Ambiance , welcome to PCHF.

You can cancel the online scan for now , it's not gona fix the Look2me infection you have im afraid....



But i will. :tongue:




Before using HijackThis Please Do the Following:



Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.


Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.


Please download CCleaner


Since you have a Look2me infection on there , atm Spysweeper is the only way to get rid of that infection:


Download and scan with Spysweeper from:
http://www.webroot.com/downloads/ (click on free trial on the right for direct download)

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
Click on "Options" > "Sweep Options" and check "Sweep all Folders on Selected drives".
Check "Local Disc C" and under "What to Sweep", check every box.
Click on "Sweep" and allow it to fully scan your system.
When the sweep has finished, click "Remove" to remove any items found.
Exit SpySweeper and reboot your computer.

NOTE: After Spysweeper has finishined and removed any items found, it is important that you exit and reboot your computer right away to ensure the infection is fully removed.

Then boot in safemode (hit f8 when booting up) and fix these with hjt:
(if still present)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R3 - Default URLSearchHook is missing
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTS...=http://www.vi ewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?1&6&04.00.07.02&unknown&un known&http://aolexpressions.aol.com/testdr...peId=1&catId=4 3&langCode=&subcatId=995&tm=343&expId=7819
O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\system32\msctl32.dll (file missing)
O20 - Winlogon Notify: StillImage - C:\WINDOWS\system32\k2620cjoefoc0.dll
Now please run Ccleaner and then reboot to normal mode.


And to make sure you got everything from Spysherrif you could walktrhough the instructions here to see if you missed anything:
http://forums.majorgeeks.com/showthread.php?t=65945

Also i see you don't have a firewall , to prevent problems like this you should really have one. If you want you can have a look in our download section for some free ones.

Then please post a new hjt log to check.


Comments on this post
loudambiance comments: Was very helpful
__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #4  
Old 11-21-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 5
loudambiance - See this Members User comments on their Profile page
Default

because i can't afford to purchase spy sweeper... would it work to simply press reset... go into safe mode and delete all the files that spy sweeper listed?


  #5  
Old 11-21-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

You get a 30 day trial with spysweeper and it should remove everything it finds for that period, did you click on the "free trial" link?

Or did you use the online spyware scan? If yes then use the "free trial" download link above that.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 11-21-2005 at 06:04 AM.
  #6  
Old 11-21-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 5
loudambiance - See this Members User comments on their Profile page
Default

I am 95% sure i clicked free trial, and it scanned then said that i have to pay ( get subscription) to remove the objects it found.



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
damaged / lost disk header janimal Windows XP/2000 7 10-20-2005 10:32 AM
Help Me Overclock My System,Im Lost nickle211 Overclocking 4 10-11-2005 06:50 AM
[FIXED] can't run .exe programs - lost :-( smartbbrain Windows XP/2000 8 09-01-2005 11:09 PM
[Pending] LOST VOLUME CONTROL-HELP! JW Sound etc 1 06-04-2005 09:44 AM
[Answered] I lost my 10/100 driver and modem driver photographer All other Hardware 2 05-22-2005 09:06 AM


All times are GMT +1. The time now is 05:28 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
Free phpBB forum
Free phpBB forum

Gourmet Chocolate Assortments
Why resist? Gourmet chocolate is the perfect indulgence.

Mobile Phone
Mobile phone information from Three.