Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] I have tons of malware and trojans! help!!

[Fixed] Hijackthis! Logs - [Fixed] I have tons of malware and trojans! help!! posted in the Security & Safety forums; Hello all, this is my first post in the forum; I hope the gurus and experts can save my computer! My work is now like a hell. :computer_ failures:  ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-13-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 12
Oender - See this Members User comments on their Profile page
Unhappy [Fixed] I have tons of malware and trojans! help!!

Hello all, this is my first post in the forum; I hope the gurus and experts can save my computer! My work is now like a hell. :computer_

failures:

 Very slow connection speed
 Tons of browser pop up windows opens also when browser is closed
 Browser affected: IE, Opera and firefox.
 &nbspefault browser: Oepra 8.51
 Transparent shape banners appear on my screen (flash banners)
 Meesenger goes offline constantly.
 Banner, banner and more banners.

Please help me to delete the necessary entries on my HJT log!
Attached Files
File Type: txt hjt.txt (13.5 KB, 1 views)



Last edited by merlin; 12-13-2005 at 10:32 PM.
  #2  
Old 12-13-2005
merlin's Avatar
Trusted Security Analyst
My PC
 
Join Date: Jul 2005
Location: Wisconsin
Posts: 2,622
PC Experience: Computers Fear Me
merlin - See this Members User comments on their Profile page merlin - See this Members User comments on their Profile page
Send a message via Yahoo to merlin
Default

Hello Oender and Welcome To PCHF

Could you please go to prework in my signature and follow the directions there and we will get ya cleaned up as fast as we can!!


__________________
QuickTime Alternative..Hijackthis..SpeedFan..ATI Tool..Whats Running..Everest..Absolute Control..All Drivers
If you feel we saved you some money please help support this site by DONATING as this site is funded by great people like you

OUT FOR LUNCH


  #3  
Old 12-14-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Can you also download and run Stinger and Vcleaner , see below for links.
Also try an online AV scan.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #4  
Old 12-14-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 12
Oender - See this Members User comments on their Profile page
Unhappy All prework done, malware still present

Originally Posted by merlin
Hello Oender and Welcome To PCHF

Could you please go to prework in my signature and follow the directions there and we will get ya cleaned up as fast as we can!!


Dear Merlin.-

I did all the steeps that you tell me, but de adware still remain!

some samples

[IMG][/IMG]



I also uplodad myHJT log again!

Hope can help me again!

Oender
Attached Files
File Type: txt oender_hijackthis.txt (13.6 KB, 1 views)
File Type: txt ewido Scan report_20051214.txt.txt (5.6 KB, 1 views)


  #5  
Old 12-14-2005
ladygreenwitch's Avatar
Administrator
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,694
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Silly Oender,

That's because we haven't started the fix yet.

OK, let me take a look at your logs, and I will be right back.

TTFN

LGW


  #6  
Old 12-14-2005
ladygreenwitch's Avatar
Administrator
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,694
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

:smiley: Hi Oender,

OK, here is some information about one of the worms you are infected with, I include it because it may prove useful in your protecting yourself in the future, as it appears that you do a pretty good job of protecting your PC.

http://www.sophos.com/pressoffice/ne...a_priston.html

OK, Please do the following. Download Counter Spy and RegSupremePro, and Housecall, from my signature.

Please use the CCleaner again, double check that you have System Restore disabled, and all files and folders are showing.

Install and run Housecall, let it fix all that it finds.

Next install and run Counter Spy, also, let it fix all that it finds.

Please do a system search and delete any reference to "Look2me"

Please run HijackThis again, and fix the following, if they are still present. Afterward delet the files/folders in bold.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
R3 - Default URLSearchHook is missing
O3 - Toolbar: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O4 - HKCU\..\Run: [Nllo] C:\WINDOWS\System32\??oolsv.exe
O20 - Winlogon Notify: RunServices - C:\WINDOWS\system32\n66q0gj5e6o.dll (file missing)
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\strialui.dll
Now run CCleaner again. Next, install RegSupremePro, it will want to make a backup to your cache, let it. Once it has finished, click on the Registry Cleaner tab, select Aggressive, let it run. When it is done, click on Select, choose All. Click on Fix and let it fix all that it finds.

Reboot your PC, now run a new ewido scan, and a new HJT scan and post their logs back here.

Look forward to your reply,

TTFN

LGW


  #7  
Old 12-14-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 12
Oender - See this Members User comments on their Profile page
Exclamation New info i hope can help the HJT log analysis...

Originally Posted by ladygreenwitch
Silly Oender,

That's because we haven't started the fix yet.

OK, let me take a look at your logs, and I will be right back.

TTFN

LGW
Hello again

:huh: I get some extra interesting info! I ended the ADSL connection in the moment when the browser was trying to retrieve a new banner. A error screen appears with the base domain www.ad-a-w-a-r-e.com <-- this domain then redirects to the banner server. Another tip: all the URL?s of banner have a little F1 flag icon, all the same.

eoc.

Oender
Mexico City



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 10:23 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
Debt Consolidation
Money Expert's secured loan comparison service can help solve your debt consolidation problems.

News
Workwide news from the UK paper - the mirror.

Debt Consolidation
Money Expert's secured loan comparison service can help solve your debt consolidation problems.