Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs
Register for a Free Account

[Fixed] Hijackthis! Logs - [Fixed] Please help it going from bad to worse. posted in the Security & Safety forums; ok i am running windows xp with mcafee anti and pc tools spyware doctor. a few weeks ago (bout 2) i seemed to pick up some adware that i just ...


Reply
Free PC Performance Scan
Old 10-05-2007   #1
Bronze Member
 
Join Date: Oct 2007
Posts: 11
Exclamation [Fixed] Please help it going from bad to worse.

ok i am running windows xp with mcafee anti and pc tools spyware doctor.
a few weeks ago (bout 2) i seemed to pick up some adware that i just cant remove.
my adware program gets rid of it the it just keeps coming back.
it has caused my comp to run very slow can take ages to open IE now and just as long to do nearly any easy task. i have 1gig of ram but might as well be using 256 at this speed , it has started taking ages to shutdown and start up crashing freezing and pop-ups of an unfit nature (have 3 young children who use my comp) to constantly sundenly pop-up. also my items on my desktop move around lol !!! my itunes went from over 300 songs to NONE they all just dissapeared!!!
i have down loaded hjt to see if you guys can be of any help (on knees praying)
the adware comes up as ..adware.advertising and application tracking cookies that look harmless but i have a badsites 1 as well that keeps getting found but not always and that shows a high risk 1.
panda keeps saying that there are 2 hacking tools and rootkits on my comp but can never finish the scan.

not sure what other info you need !! hjt log and other scan results is attached also i finally
got 2 run a full scan with panda and thier results r below.(hope it ok to post these !!)

hjt results.txt

scan results.txt

Report-Scan-20071005-231307.txt


Incident Status Location
Spyware:Cookie/YieldManager Disinfected C:\Documents and Settings\Cat\Cookies\cat@ad.yieldmanager[2].txt
Spyware:Cookie/Advertising Disinfected C:\Documents and Settings\Cat\Cookies\cat@advertising[1].txt
Spyware:Cookie/Atlas DMT Disinfected C:\Documents and Settings\Cat\Cookies\cat@atdmt[1].txt
Spyware:Cookie/Doubleclick Disinfected C:\Documents and Settings\Cat\Cookies\cat@doubleclick[1].txt
Spyware:Cookie/Mediaplex Disinfected C:\Documents and Settings\Cat\Cookies\cat@mediaplex[1].txt
Adware:Adware/Lop Disinfected C:\Program Files\Adverts\uninst.exe
Potentially unwanted tool:Application/InternetGameBox No disinfected C:\WINDOWS\Temp\NSIS_Install_igb.exe <---------- found this file and delated it as it seemed to be 1 that just would stop showing up

any help would be much appriciated.
wizardaire is offline   Reply With Quote
Advertisement - Register to Remove
Old 10-06-2007   #2
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default Re: Please help it going from bad to worse.

Hello.

Please download F-Secure BlackLight
  • Save BlackLight to your desktop.
  • Double-click blbeta.exe then accept the agreement.
  • Click > Scan then > Next
  • After the scan you'll see a list of all items found. Please click Next and exit. Don't choose to rename anything yet! I want to see the log first, because legitimate items can also be present there.
  • There will be a log on your desktop with the name fsbl.xxxxxxx.log (where the xxxxxxx are numbers) Please post the contents of this log in your next reply.
chiaz is offline   Reply With Quote
Old 10-06-2007   #3
Bronze Member
 
Join Date: Oct 2007
Posts: 11
Default Re: Please help it going from bad to worse.

Download Blacklight Beta graphical user interface version
Download Blacklight Beta command line version

thxs for helping
which version do i need to download please?
wizardaire is offline   Reply With Quote
Old 10-06-2007   #4
Bronze Member
 
Join Date: Oct 2007
Posts: 11
Default Re: Please help it going from bad to worse.

ok srry but i have tried to download both now but the line version is not detected on my comp(put thru search cuz it wasnt on my desktop) and the other is not an exe file just a blue couloured like triangle called fsblc and when clicked it just very quickly flashes a black screen then gone.

srry not very good at this what have i done wrong?

Last edited by wizardaire; 10-06-2007 at 09:10 AM.
wizardaire is offline   Reply With Quote
Old 10-06-2007   #5
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default Re: Please help it going from bad to worse.

You CAN specify the file to be saved on your desktop.

Click on this link again:
https://europe.f-secure.com/exclude/blacklight/fsbl.exe

You will be prompted to save it. Now specify the file to be saved on your desktop (or whereever you think it is convenient).

Try running it now...


If you get an error message, or cannot get it to run for some reason, please capture a screenshot of it.

If you have any queries regarding the above steps, please do not send me a pm as you have done. Simply post it here and I'll get to it as soon as possible.
chiaz is offline   Reply With Quote
Old 10-06-2007   #6
Bronze Member
 
Join Date: Oct 2007
Posts: 11
Default Re: Please help it going from bad to worse.

ok i did save to desktop but it doesnt show for some reason or when i scan for it, any way i went to your above link and downloaded again but it says" the evaluation period for this version of f-secure of blacklight has expired" and the 1 that 1st downloaded flashes a black screen then gone way to fast to get a pic of it lol srry.

Last edited by wizardaire; 10-06-2007 at 06:45 PM.
wizardaire is offline   Reply With Quote
Old 10-07-2007   #7
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default Re: Please help it going from bad to worse.

No worries, we'll try another tool.

Download GMER from here:
GMER - Files

Unzip it to the desktop.

Open the program and click on the Rootkit tab.
Make sure all the boxes on the right of the screen are checked, EXCEPT for ‘Show All’.
Click on Scan.
When the scan has run click Copy and paste the results (if any) into a Notepad file. Then attach it to this thread.
chiaz is offline   Reply With Quote

Reply


Bookmarks

Tags
bad, fixed, worse
Similar discussions...
Thread Thread Starter Forum Replies Last Post
[Fixed] CMOS/GPNV Checksum Bad z11 Motherboards 4 02-19-2008 08:20 PM
[Fixed] msmo again.. msmo [Fixed] Hijackthis! Logs 41 11-09-2006 04:59 PM
[Fixed] This one has a bad popup problem sumodeluxe [Fixed] Hijackthis! Logs 14 08-27-2006 10:41 PM
[Fixed] Hijackthis log- think bad ajspurs [Fixed] Hijackthis! Logs 7 08-11-2006 01:07 PM

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 12:29 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2