Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » ac8zt2 problem, and HJT log

[Fixed] Hijackthis! Logs - ac8zt2 problem, and HJT log posted in the Security & Safety forums; I am having a problem with the ac8zt2 file and virus. I will be posting my log and praying for help. Thank you all....

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-18-2007
Bronze Member
 
Join Date: Dec 2007
Posts: 3
PC Experience: Some Experience
Aedhan - See this Members User comments on their Profile page
Default ac8zt2 problem, and HJT log

I am having a problem with the ac8zt2 file and virus. I will be posting my log and praying for help. Thank you all.
Attached Files
File Type: log hijackthis.log (9.5 KB, 2 views)



Last edited by Aedhan; 12-18-2007 at 04:45 AM.
  #2  
Old 12-18-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,610
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: ac8zt2 problem, and HJT log

hello aedhan, and welcome to the forums. You've definitely been drilled by something, so let's start with combofix and then take a look at an updated hjt log.

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #3  
Old 12-18-2007
Bronze Member
 
Join Date: Dec 2007
Posts: 3
PC Experience: Some Experience
Aedhan - See this Members User comments on their Profile page
Default Re: ac8zt2 problem, and HJT log

Ok, here are the two logs.

I ran combo fix and it now is letting me access the task manager.
Attached Files
File Type: log hijackthis.log (8.4 KB, 1 views)
File Type: txt log.txt (15.6 KB, 2 views)


  #4  
Old 12-19-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,610
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: ac8zt2 problem, and HJT log

You may want to print these out. please close all other applications, start hjt again, click 'perform system scan only', place a tick next to the following and click 'fix checked'

O2 - BHO: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Pick-a-Proxy Toolbar - {A6790AA5-1213-4567-A46D-0FDAC4EA90EB} - G:\Pick-a-Proxy Toolbar\PLOToolbar.dll (file missing)
O3 - Toolbar: Pick-a-Proxy Toolbar - {A6790AA5-1213-4567-A46D-0FDAC4EA90EB} - G:\Pick-a-Proxy Toolbar\PLOToolbar.dll (file missing)
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O3 - Toolbar: The leosrv - {DCBF721A-11E3-4FB8-93D6-9AE46178D5B6} - C:\WINDOWS\leosrv.dll
O4 - Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe
O4 - Startup: PowerReg Scheduler V3.exe
O8 - Extra context menu item: &Pick-a-Proxy Toolbar - res://G:\Pick-a-Proxy Toolbar\PLOToolbar.dll/MENUSEARCH.HTM
O21 - SSODL: hjoqor - {7B78AEAB-8BDB-4C76-95EF-A5AACB48E8F6} - C:\WINDOWS\hjoqor.dll (file missing)


Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below.

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Open *notepad* and copy/paste the text in the quotebox below into it:
KillAll::
C:\WINDOWS\ttvbontvm.dll
C:\WINDOWS\xcvwer.dll
Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.



Refering to the picture above, drag CFScript.txt into ComboFix.exe
Restart your computer.
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please.

*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall*

reboot, and post a new log.

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #5  
Old 12-28-2007
Bronze Member
 
Join Date: Dec 2007
Posts: 3
PC Experience: Some Experience
Aedhan - See this Members User comments on their Profile page
Default Re: ac8zt2 problem, and HJT log

Ok, did that stuff. Trojan problem is better but now I am receiving the cursed adware/spyware popups.
Attached Files
File Type: log hijackthis.log (7.8 KB, 2 views)
File Type: txt CFlog.txt (55.2 KB, 0 views)


  #6  
Old 12-29-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,610
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: ac8zt2 problem, and HJT log

Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below.

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Open *notepad* and copy/paste the text in the quotebox below into it:

C:\WINDOWS\ttvbontvm.dll
Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.


Refering to the picture above, drag CFScript.txt into ComboFix.exe
Restart your computer.
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please.

*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall*



thanks,




v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 12:46 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
Loans
Loans information and advice from the experts at ThisIsMoney.co.uk

Cingular Ringtones
Cingular ringtones are clear when they are heard on your handset due to higher quality.

Bad Credit Mortgages
Bad credit mortgages information and advice from the experts at Ocean Finance.