Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

[Fixed] Hijackthis! Logs - [Pending] siiiigh. posted in the Security & Safety forums; I have been away for two days and come back home to find this, Spylocked on my system. The information I have dug out is people were downloading porn yesterday. ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 04-16-2007
gilesmcpherson's Avatar
Silver Member
 
Join Date: Mar 2007
Location: Valencia, Spain
Posts: 108
gilesmcpherson - See this Members User comments on their Profile page
Default [Pending] siiiigh.

I have been away for two days and come back home to find this,

Spylocked on my system.

The information I have dug out is people were downloading porn yesterday. Feel pretty mad at this and have to do all this work again on my clean system. Open house becomes abused here temperatures running preeeeeetty high.


ive attatched a log. I understand they installed a spyware revoval tool to try to do something before i got back this morning. They dont know which and its not showing on system but i cant be sure of anything just at the moment.


Giles. thanking you all again in advance.


ps have the wee window from spylocked popping up all the time ... they also said that they uninstalled this program with its uninstaller but i see no such uninstaller and cant verify if this is the truth or not.
Attached Files
File Type: log hijackthis.log (4.7 KB, 2 views)


  #2  
Old 04-16-2007
upgrader's Avatar
Site Manager
My PC
 
Join Date: Jul 2006
Location: /home/upgrader/
Posts: 6,329
PC Experience: Some Experience
upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page
Send a message via MSN to upgrader Send a message via Skype™ to upgrader
Default

Hi giles,

Can you follow prework in my signature and come back with all three logs if running windows xp, thanks Chris.


__________________
PCHF Rules--PCHF Prework--PCHF Downloads
  #3  
Old 04-16-2007
gilesmcpherson's Avatar
Silver Member
 
Join Date: Mar 2007
Location: Valencia, Spain
Posts: 108
gilesmcpherson - See this Members User comments on their Profile page
Default

ok .. prework done .. sorry i should have know to follow that i wa just a litle distracted by what had happened in my absence.

ill detail what i did for your sake ..

ran hjthis in normal mode ... the one you have.

prework 1 done

safe mode run ccleaner

safe mode run spyware + log + clean + log

reboot

safe mode run spyware + log and no infection

run kapersky its clean

reboot

normal mode run kapersky online scan

. finish .

still see icon for spylocked on bar bottom right with flashing red circle with diag red bar and pops up window coming on intermittently.

send all to you.


Thanks Chris.

Giles

ps .. i still have not turned system restore back and wont till you say so ... wont reboot either till have go ahead.

files attached .. no anitvirus logs as they say clean.
Attached Files
File Type: rar Log files.rar (6.5 KB, 0 views)


  #4  
Old 04-16-2007
upgrader's Avatar
Site Manager
My PC
 
Join Date: Jul 2006
Location: /home/upgrader/
Posts: 6,329
PC Experience: Some Experience
upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page
Send a message via MSN to upgrader Send a message via Skype™ to upgrader
Default

HI Giles,

LOL im not a security analyst *looks up - wish i was* lol. One of our analysts will be with you soon, in the meantime can you answer to say whether the voyager problem is sorted in that thread.

Thanks,

Chris


__________________
PCHF Rules--PCHF Prework--PCHF Downloads
  #5  
Old 04-17-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,610
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

wow. Dunno what you did, or how you did it, but you did it right, that's for sure. Let's start with AVG alone and go from there.

First download AVG Anti-Spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program. After the trial period, the scanner will continue to work, and you will still be able to receive updates; however, certain advanced setting will no longer be available unless purchsased
  1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
  2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
  3. On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  4. Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  6. Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  1. Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  2. Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  4. AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  5. If you have any infections you will prompted, then select "Apply all actions"
  6. Next select the "Reports" icon at the top.
  7. Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  8. Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the results of the AVG Anti-Spyware report scan.
Be sure to post the hjt log AFTER the avg has run, as I have seen avg clean up some of what is on your machine. Not all of it, but at least some it. So you should be posting back 2 logs, the avg FIRST, the hjt SECOND.

Thanks, giles.

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #6  
Old 04-17-2007
gilesmcpherson's Avatar
Silver Member
 
Join Date: Mar 2007
Location: Valencia, Spain
Posts: 108
gilesmcpherson - See this Members User comments on their Profile page
Default

havent used pc yet .. with me .. be on it shortly .. evrything always happens at once lol.

when i say i havent slept in 62 hours I really mean exactly that. lol

I thought it polite to keep you informed so i post but its brief.

Really have no energy to find that post chris moving the mouse take all i have lol but yes its done. I will put an answer up as to how it was resolved as i feel its important in its simplicity.

Another 9 hours up then sleep. i will be onto it tomorrow evening when i get to relax again.

see you soon.

Giles


thanks to the both of you.



Last edited by gilesmcpherson; 04-17-2007 at 11:19 PM.
  #7  
Old 04-18-2007
upgrader's Avatar
Site Manager
My PC
 
Join Date: Jul 2006
Location: /home/upgrader/
Posts: 6,329
PC Experience: Some Experience
upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page
Send a message via MSN to upgrader Send a message via Skype™ to upgrader
Default

I will put an answer up as to how it was resolved as i feel its important in its simplicity.
Thanks


__________________
PCHF Rules--PCHF Prework--PCHF Downloads

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 01:13 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
Reggaeton Video Codes
Play our reggaeton videos on your MySpace page.

Loan
We are the experts. Our name says it all. Get advice from Moneyexpert.

Internet Advertising
Join the free co-op advertising network and increase your traffic.