Member Panel


Sponsors and Ads

Live Tag Cloud

[Fixed] Hijackthis! Logs - [Answered] Spam Virus posted in the Security & Safety forums; Here is an updated HJT . I'm pretty sure I will just re-install windows tomorrow because i have given up. My ISO disabled me today for spamming. I had to ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #7  
Old 03-19-2008
vindicta's Avatar
Bronze Member
 
Join Date: Mar 2008
Posts: 13
PC Experience: Very Experienced
vindicta - See this Members User comments on their Profile page
Default Re: Spam Virus

Here is an updated HJT. I'm pretty sure I will just re-install windows tomorrow because i have given up. My ISO disabled me today for spamming. I had to call and clear things up. So unless you're able to look at this quickly..it might be too late. Congrats virus, you're won.
Attached Files
File Type: log hijackthis.log (10.8 KB, 1 views)


  #8  
Old 03-19-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,585
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: Spam Virus

you can clean this one, it's abandoned:

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -

Go here: http://www.bleepingcomputer.com/comb...o-use-combofix
Follow the instructions for ComboFix, then paste the results along with a new HJT log.

Thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #9  
Old 03-20-2008
vindicta's Avatar
Bronze Member
 
Join Date: Mar 2008
Posts: 13
PC Experience: Very Experienced
vindicta - See this Members User comments on their Profile page
Default Re: Spam Virus

I already used Combo fix. I was given the advice from another website. Here is the log for that.
Attached Files
File Type: txt log.txt (13.0 KB, 1 views)


  #10  
Old 03-20-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,585
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: Spam Virus

Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below.

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Open *notepad* and copy/paste the text in the quotebox below into it:
KillAll::
File::
C:\sqmdata00.sqm
C:\sqmnoopt00.sqm
C:\axmfr.exe
C:\WINDOWS\system32\B66678A0E9.sys


Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.






Refering to the picture above, drag CFScript.txt into ComboFix.exe
Restart your computer.
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please.

*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall*

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #11  
Old 03-21-2008
vindicta's Avatar
Bronze Member
 
Join Date: Mar 2008
Posts: 13
PC Experience: Very Experienced
vindicta - See this Members User comments on their Profile page
Default Re: Spam Virus

I've done this. Still the virus continues to spam emails.


  #12  
Old 03-23-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,585
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: Spam Virus

please post another combo log. And what do you mean by 'spam emails', exactly? Is your machine sending stuff out?

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Fixed] services.exe error, comp keeps restarting Frish [Fixed] Hijackthis! Logs 13 01-25-2007 12:33 PM
[Resolved] Computer Slow upgrader [Fixed] Hijackthis! Logs 20 09-21-2006 07:54 AM
[Fixed] winlogon hook ; ; syztem [Fixed] Hijackthis! Logs 14 09-07-2006 12:42 AM
[Fixed] Major Problem, Need Help!!! naqeeb23 [Fixed] Hijackthis! Logs 16 08-12-2006 02:30 PM
Active Virus Shield (Free AV based on Kaspersky) joe5 Anti-Virus (AV) 0 08-09-2006 10:50 PM


All times are GMT +1. The time now is 12:35 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top