Member Panel


Sponsors and Ads

Live Tag Cloud

[Fixed] Hijackthis! Logs - oimfuskated posted in the Security & Safety forums; this computer is not mine... but who ever used it before me did something naughty with out any antivirus program installed. now there are MANY different viruses on this thing. ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-22-2007
jbid6984's Avatar
Bronze Member
 
Join Date: Dec 2007
Posts: 8
PC Experience: Experienced
jbid6984 - See this Members User comments on their Profile page
Default oimfuskated

this computer is not mine... but who ever used it before me did something naughty with out any antivirus program installed. now there are MANY different viruses on this thing. i've tried everything i can think of get rid of them. i usually use avg but it was too late for avg to help when i got the pc. can some one assist me here. i have hijackthis logs and avg logs, please help me.
Thanks
JB
Attached Files
File Type: log HijackThis.log (8.5 KB, 0 views)



Last edited by Pgh; 12-22-2007 at 01:30 PM.
  #2  
Old 12-22-2007
The_Napster's Avatar
Bronze Member
My PC
 
Join Date: Dec 2007
Location: Blackburn, Lancashire, England, UK
Posts: 94
PC Experience: Always Learning
The_Napster - See this Members User comments on their Profile page The_Napster - See this Members User comments on their Profile page The_Napster - See this Members User comments on their Profile page The_Napster - See this Members User comments on their Profile page The_Napster - See this Members User comments on their Profile page The_Napster - See this Members User comments on their Profile page The_Napster - See this Members User comments on their Profile page The_Napster - See this Members User comments on their Profile page The_Napster - See this Members User comments on their Profile page The_Napster - See this Members User comments on their Profile page
Send a message via ICQ to The_Napster Send a message via MSN to The_Napster Send a message via Yahoo to The_Napster
Default Re: oimfuskated

if u can attach both hijackthislog and avg logs
a member from the security team will analyse it for u
thnx, Ash


  #3  
Old 12-22-2007
Pgh's Avatar
Pgh Pgh is offline
Moderator
My PC
 
Join Date: Jul 2006
Location: Hertfordshire, UK
Posts: 522
PC Experience: Experienced
Pgh - See this Members User comments on their Profile page Pgh - See this Members User comments on their Profile page
Send a message via AIM to Pgh Send a message via MSN to Pgh
Default Re: oimfuskated

Hi jbid6984, welcome to PCHF. It might be best if you upload those logs for one of our security experts to take a look at, then they can assist you better.

Thanks

Pgh


__________________

  #4  
Old 12-22-2007
jbid6984's Avatar
Bronze Member
 
Join Date: Dec 2007
Posts: 8
PC Experience: Experienced
jbid6984 - See this Members User comments on their Profile page
Default Re: oimfuskated

well... i have dne scans for avg anti spyware and super antisyware but i neither program will save the logs... so here are the logs for hijackthis. i dont know if this will help but i hope it does.
Attached Files
File Type: log hijackthis.log (9.0 KB, 2 views)


  #5  
Old 12-23-2007
dahli's Avatar
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 548
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: oimfuskated

Hello and welcome to PCHF,

Look in your control panel's add/remove programs for PuritySCAN By OIN, OuterInfo, OIN, Cowabanga, SnowballWars or similar. Click on it and then click remove.

Reboot and if found, delete this folder:

C:\Program Files\PurityScan

If not listed, download and run this uninstaller:
http://www.outerinfo.com/OiUninstaller.exe
Outerinfo Network : Consumers : Uninstall Outerinfo
Tutorial for the uninstaller if needed

Reboot when done and if found, delete this folder:

C:\Program Files\PurityScan

You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is intended by its creator to be used under the guidance and supervision of an expert, not for private use. Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.


If you have used Combofix before, please delete the version you have and redownload it again, because Combofix is being updated everyday.

Disconnect from the Internet while running ComboFix.

Temporarily disable any anti-virus and anti-malware real-time protection before performing a scan.
They can interfere with ComboFix or remove some of its embedded files which may cause unpredictable results.
Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.



1. Download this file - combofix.exe to your Desktop.
Note:
It is important that it is saved directly to your desktop

2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you, C:\ComboFix.txt. Post the ComboFix log and a fresh Hijackthis log in your next reply.
Do NOT post the ComboFix-quarantined-files.txt - unless I ask you to.
Do NOT run ComboFix more than once.
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
Do not run Combofix more than once.
In case you see a sed.cfexe error with the option to send a report or not, choose "don't send".
The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

If you have Norton Antivirus installed then disable script blocking so it will not interfere with the fix.

To disable Norton Script blocking Service:

* Disable the Script Blocking Service:
To open Services, click Start, point to Settings, and then click Control Panel.
Double-click Administrative Tools, and then double-click Services.
Find ScriptBlocking services, Right-click the service, and then click and then click Properties.
On the General tab, under Startup, click Disabled.
Under Service Status, click Stop button. Click Apply button.

* Disable the Script Blocking In Norton Settings:
Start Norton Antivirus.
Click Options. If a menu appears when you click Options, then click Norton Antivirus. The Norton Antivirus Options dialog box appears.
Click Script Blocking.
Uncheck Enable Script Blocking (recommended).
Click OK
You can reenable it afterwards when everything is clean again.


Trojan Hunter has been reported to detect combofix as Worm.Qiv.100.



Thanks.


__________________
Steve
  #6  
Old 12-24-2007
jbid6984's Avatar
Bronze Member
 
Join Date: Dec 2007
Posts: 8
PC Experience: Experienced
jbid6984 - See this Members User comments on their Profile page
Default Re: oimfuskated

ok. i cannot find purityscan or any oin files... i used the link to remove outerinfo and my pc is working much better. when i did an avg scan in safemode, it still recognized the downloader.purityscan.ee and several tracking cookies. can you help me???
here is my hijackthis log.
Attached Files
File Type: log hijackthis.log (7.6 KB, 0 views)



Last edited by jbid6984; 12-24-2007 at 06:42 PM.

Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 12:30 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top