Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs
Register for a Free Account

[Fixed] Hijackthis! Logs - [Fixed] Adware please help! posted in the Security & Safety forums; Have you just downloaded and installed this? YazzleBundle-1264.exe...


Reply
Free PC Performance Scan
Old 09-21-2006   #8
Elite Member
 
joe5's Avatar
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,025
Default

Have you just downloaded and installed this?

YazzleBundle-1264.exe
__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

joe5 is offline   Reply With Quote
Advertisement - Register to Remove

Old 09-22-2006   #9
Bronze Member
 
Join Date: Sep 2006
Location: East New Market, Maryland
Posts: 11
Default

Nope, I don't even recognise the name from anywhere.
xmetalxheartsx_ is offline   Reply With Quote
Old 09-22-2006   #10
Elite Member
 
joe5's Avatar
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,025
Default

Just checking since the infection has reinstalled itself again it seems.

First delete this file:

C:\WINDOWS\YazzleBundle-1264.exe

Then again look in your add/remove programs for any of these:

Oin
OuterInfo
Yazzle by OIN
Yazzle Picster by OIN
Yazzle Sudoku by OIN
Cowabanga by OIN
PuritySCAN By OIN
Snowballwars by OIN
ipwins
Zolero
Tizzletalk
MediaTickets
Forethought
Quicklinks
PSLister
or anything similar with Oin or Outerinfo in it.


If any of those names are found, click on it, and click remove.
Reboot and delete this folder if found:
C:\Program Files\PurityScan


If not listed, download and run this uninstaller:
http://www.outerinfo.com/OiUninstaller.exe
Tutorial for the uninstaller if needed:
Uninstaller
Reboot when done and delete this folder if found:
C:\Program Files\PurityScan


Then run Combofix again, and when done, please post the log from that plus a new HJT log.
__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

joe5 is offline   Reply With Quote
Old 09-26-2006   #11
Bronze Member
 
Join Date: Sep 2006
Location: East New Market, Maryland
Posts: 11
Default

Sorry a little slow..i have been busy with school.

I have deleted the file. and here are the logs. I haven't gotten a popup however in about 4 days.
Attached Files
File Type: txt ComboFix.txt (21.1 KB, 2 views)
File Type: log hijackthis.log (23.0 KB, 1 views)
xmetalxheartsx_ is offline   Reply With Quote
Old 09-26-2006   #12
Elite Member
 
joe5's Avatar
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,025
Default

Run HijackThis , select to do a "system scan only" and then place a check beside each of the following:

R3 - Default URLSearchHook is missing
O4 - HKCU\..\Run: [Tbsa] "C:\DOCUME~1\Amanda\MYDOCU~1\SEMBLY~1\alg.exe" -vt yazb
Now first close all windows and browsers other then HijackThis , then click Fix checked and close HijackThis.

After that reboot your pc.


And you have just used msconfig, did you disable anything? If yes, then please re-enable them again or I can't see them, and fix them if needed.

To enable all startup items please follow these instructions:
  • Start | Run | type msconfig | OK
  • If not already selected go to the General tab.
  • Under Startup Selection select "Normal Startup - load all device drivers and services".
  • Click Apply and then Close.
  • When given the option to restart or not , please choose to not restart the computer.
  • Post a new HJT log when you are done.

Restarting isn't necessary because they will show in an HJT log anyway , and this way the malware doesn't become active.
__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

joe5 is offline   Reply With Quote
Old 09-26-2006   #13
Bronze Member
 
Join Date: Sep 2006
Location: East New Market, Maryland
Posts: 11
Default

Done everything succesfully..and yes i disabled a couple programs I wasn't using anymore. But I've re enabled it again and here's the log.
Attached Files
File Type: log hijackthis.log (23.1 KB, 1 views)
xmetalxheartsx_ is offline   Reply With Quote
Old 09-26-2006   #14
Elite Member
 
joe5's Avatar
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,025
Default

The Purityscan infection is finally gone. It was being very stobborn this time.. but its gone now.

Looks like these where the ones you disabled?


O4 - HKLM\..\Run: [ymetray] "C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" -preload
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ICQ Lite] "C:\Program Files\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1153790911\ee\AOLSoftware.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [KCeasy] C:\Program Files\KCeasy\KCeasy.exe /hide
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp

They are all legit so they don't have to fixed. You can disable them again if you want or remove them with HJT. That wont effect the programs and they can still be normally manually started when needed.


How is it going with your pc now? Any problems left?
__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

joe5 is offline   Reply With Quote

Reply

Bookmarks

Tags
adware, fixed

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 12:46 PM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2