Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] pain in the NSAnti

[Fixed] Hijackthis! Logs - [Fixed] pain in the NSAnti posted in the Security & Safety forums; Firstly thanks a lot for the clear instructions I was transferring work on a removable drive from a computer at work, then the alerts started. AVG alerts me that NSAnti ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-30-2008
Bronze Member
 
Join Date: Jan 2008
Posts: 6
PC Experience: Some Experience
pveal - See this Members User comments on their Profile page
Default [Fixed] pain in the NSAnti

Firstly thanks a lot for the clear instructions

I was transferring work on a removable drive from a computer at work, then the alerts started.
AVG alerts me that NSAnti has been found...win/32 NSAnti local/temp/wmy2.dll and also more recently "iesoo.dll trojan horse psw.onlinegames.2QQ"...i choose the option to put in vault. The alert appears again either on boot up or during a session.

Thanks. I attached superanti spyware log and a hijackthis log.
Attached Files
File Type: log hijackthis.log (4.9 KB, 1 views)
File Type: log SUPERAntiSpyware Scan Log - 01-31-2008 - 01-54-35.log (620 Bytes, 0 views)


  #2  
Old 01-30-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,608
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: pain in the NSAnti

hello pveal, and welcome to the forums....you've definitely got something that takes a bigger hammer to look at. Please follow the below steps:

Download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
--------------------------------------------------------------------
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #3  
Old 01-31-2008
Bronze Member
 
Join Date: Jan 2008
Posts: 6
PC Experience: Some Experience
pveal - See this Members User comments on their Profile page
Default Re: pain in the NSAnti

Hello Valis, thanks for the advice. I ran combofix as instructed and also hijackthis. I attached combofix log and new hijackthis log.

Thank you.
Attached Files
File Type: txt hijackthis new log.txt (4.7 KB, 3 views)
File Type: txt combofix log.txt (7.6 KB, 3 views)



Last edited by pveal; 01-31-2008 at 02:44 AM. Reason: didnt attch
  #4  
Old 01-31-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,608
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: pain in the NSAnti

File fix:

Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below.

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Open *notepad* and copy/paste the text in the quotebox below into it:
KillAll::
File::
C:\WINDOWS\system32\ieso0.dll
C:\WINDOWS\system32\fool0.dll
C:\WINDOWS\system32\kxvo.exe
C:\ytmb.bat


Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.

Refering to the picture above, drag CFScript.txt into ComboFix.exe
Restart your computer.
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please.

*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall*


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #5  
Old 01-31-2008
Bronze Member
 
Join Date: Jan 2008
Posts: 6
PC Experience: Some Experience
pveal - See this Members User comments on their Profile page
Default Re: pain in the NSAnti

Hello Valis,

Just did all as instructed above, and thanks again for the clarity. Attached combofix log and HJT fresh log.
Attached Files
File Type: txt hijackthis log new 2.txt (4.8 KB, 2 views)
File Type: txt ComboFix.txt (8.1 KB, 1 views)


  #6  
Old 01-31-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,608
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: pain in the NSAnti

First, please right-click on start, and choose Explore. Click on Tools, Folder Options, and then View. Make sure that there is a tic next to Display contents of System Folders, Show Hidden Files and Folders is selected, and Hide known file extensions is not selected. Now close Explorer.


Then, go to Online malware scan and upload the following files by clicking on the 'browse' button at the top of the page and navigating to the below files. Please post the results in your next post.



C:\800dost.com



Thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Fixed] Problem with: mswinup.exe | winsvcup.exe | winupsvc.exe Irmaxx [Fixed] Hijackthis! Logs 10 09-20-2006 02:55 AM
[Fixed] services.exe NEED HELP ineverwin [Fixed] Hijackthis! Logs 18 05-15-2006 08:23 PM
[Fixed] a "messenger service" window pops up EliasB [Fixed] Hijackthis! Logs 4 08-16-2005 05:04 AM
[Fixed] audio device gone..? InternetUser Windows XP/2000 8 08-13-2005 08:41 PM
[Fixed] - HELP.......Programs Opening & Closing Slowly ?? Snake420 Windows 95, 98 & ME 17 03-27-2005 02:34 PM


All times are GMT +1. The time now is 06:26 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
Hotel Las Vegas
Hotel search in Las Vegas, Nevada.

Hotels Parma
Online hotel reservations in Parma Italy.

Payday Loan
24 hour payday loans fast.