Logfile of HijackThis v1.99.1
Scan saved at 8:27:12 PM, on 3/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Please read Ewido Setup Instructions
Install it, and update the definitions to the newest files. Do NOT run a scan yet.
If you have not already installed Ad-Aware SE 1.06, follow these download and setup instructions, otherwise, check for updates: Ad-Aware SE Setup
Don't run it yet!
Next, please reboot your computer in SafeMode by doing the following:
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
Instead of Windows loading as normal, a menu should appear
Select the first option, to run Windows in Safe Mode.
Now scan with HJT and place a checkmark next to each of the following items and click FIX CHECKED:
Nothing open but hijackthis and click "fix checked"
Close HiJackThis.
Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.
The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
Open Ad-aware and do a full scan. Remove all it finds.
Run Ewido:
Click on scanner
Click on Complete System Scan and the scan will begin.
NOTE: During some scans with ewido it is finding cases of false positives.
You will need to step through the process of cleaning files one-by-one.
If ewido detects a file you KNOW to be legitimate, select none as the action.
DO NOT select "Perform action on all infections"
If you are unsure of any entry found select none for now.
When the scan is finished, click the Save report button at the bottom of the screen.
Save the report to your desktop
Close Ewido
Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.
Reboot back into Windows and click the Panda ActiveScan shortcut.
- Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, the contents of smitfiles.txt and the Ewido Log by using Add Reply.
Let us know if any problems persist.
hey thanks so much for the help. it works perfectly now. you are like a giant asprin. i had ran ewido scan and just found some cookies last night. i used bitdefender last night to and found nothing but i did run everything else you told me to.
+ Created on: 4:38:59 PM, 3/17/2006
+ Report-Checksum: 658CE895
+ Scan result:
C:\Documents and Settings\matt\Cookies\matt@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\matt\Cookies\matt@com[2].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\matt\Cookies\matt@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup
spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
Install.dat
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Pea****@beyondlogic.org
Killing PID 844 'explorer.exe'
Killing PID 844 'explorer.exe'
Starting registry repairs
Registry repairs complete
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
SharedTask Export after registry fix
(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com
Registry Pseudo-Format Mode (Not a valid reg file):
Logfile of HijackThis v1.99.1
Scan saved at 4:46:04 PM, on 3/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@888[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@ad.yieldmanager[2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@adultfriendfinder[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@atdmt[1].txt
Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@c.goclick[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@casalemedia[1].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@cassava[1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@ccbill[2].txt
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@cdfreaks[2].txt
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@club.cdfreaks[1].txt
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@counter.hitslink[2].txt
Spyware:Cookie/Sexsuche Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@counter.sexsuche[1].txt
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@cs.sexcounter[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@doubleclick[1].txt
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@findwhat[1].txt
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@hc2.humanclick[1].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@kinghost[2].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@maxserving[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@server.iad.liveperson[2].txt
Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@sexlist[2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@statcounter[2].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@xiti[1].txt
Spyware:Cookie/XXXCounter Not disinfected C:\Documents and Settings\Matt.SERVER-6IQJEP38\Cookies\matt@xxxcounter[1].txt
Virus:Trj/Small.SB Not disinfected C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLER\S-1-5-21-1292428093-1645522239-839522115-1003\Dc1.exe[Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLER\S-1-5-21-1292428093-1645522239-839522115-1003\Dc2\Process.exe
Adware:adware/cws.searchmeup Not disinfected C:\WINDOWS\uniq
Last edited by evilgeniusxp; 18-03-2006 at 10:55 PM.
Good thing you decided to do the Panda scan cause you got a keylogger on your computer.
So if you do credit card transactions, online banking etc., then i strongly advise you to contact those places and advise them you are possibly a victim of identity theft.
ok before i seen your post i had uninstalled bitdefender and tried to install panda titanium version for a trial and panda keeps telling me i have to uninstall bitdefender first. Well i did. lol. i even search the registry for bitdefender and softwin and deleted anything it found. but it still tells me i have to uninstall bitdefender before i can continue installing panda. And i want panda because it found stuff bitdefender didnt. the same reason why i installed bitdefender because norton 2006 didnt find about 5 or 6 viruses bitdefender did. I used the kill box program and it deletes the files. thanks. and here is my new hijack report.
Logfile of HijackThis v1.99.1
Scan saved at 5:59:19 PM, on 3/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)