can someone help...(RESOLVED)

  1. #1
    oohmfgitstonyy is offline Valued Member

    Unhappy can someone help...(RESOLVED)

    okay im new to this and i dont know how to use any hi jack logs or whatever so please dont like ban me or get mad at me. all i know is i used yahoo thing to scan and it says im infected with Win32/SCKeylog.P...can you guys help me delete it? i would really appreciate it..

  2. #2
    Neal is offline Dedicated Member
    HI,



    Hi and welcome,


    go to the link below and do everything there and post a hijackthis log from the link provided there. Thanks, then we can take a look and see what has your computer by the throat.

    http://www.d-a-l.com/help/showthread.php?t=32403

  3. #3
    oohmfgitstonyy is offline Valued Member
    uhm sorry Neal but i don't know where to reply so im guessing reply here? kay heres my log...i did everything on that page..and i appreciate you helping me. thanks a lot.

    Logfile of HijackThis v1.99.1
    Scan saved at 10:15:59 AM, on 7/12/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
    C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\PROGRA~1\Yahoo!\YOP\yop.exe
    C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
    C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Common Files\AOL\1139021766\ee\AOLSoftware.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    C:\Program Files\Yahoo!\Antivirus\ISafe.exe
    C:\Program Files\AIM\aim.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SS SS Plugin - {1D1B2879-99FF-11E3-8D96-D7ACAC95952A} - C:\WINDOWS\system32\bpkwb.dll (file missing)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [OSCD_Creator] c:\Dell\PreODM.EXE
    O4 - HKLM\..\Run: [Acronis?True?Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
    O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
    O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
    O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
    O4 - HKLM\..\Run: [stratas]
    O4 - HKLM\..\Run: [System service70] C:\WINDOWS\\\etb\\pokapoka70.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139021766\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\RunServices: [stratas]
    O4 - HKLM\..\RunOnce: [OSCD_Creator] C:\Dell\PreODM.EXE /2
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [stratas]
    O4 - HKCU\..\Run: [RK Launcher] C:\Program Files\RK Launcher\RKLauncher.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
    O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://nprotect.roseonlinegame.com/n...etizen/npx.cab
    O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://nprotect.roseonlinegame.com/n...rypt/npkcx.cab
    O20 - Winlogon Notify: automainer - automainer.dll (file missing)
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

  4. #4
    oohmfgitstonyy is offline Valued Member
    ooh and p.s. how do you make your internet faster? because mines slow, or not slow, but i get disconnected off of Aol Instant Messenger a lot automatically...is it because i use netgear?

  5. #5
    Neal is offline Dedicated Member
    Are you on dial up?


    Remove from add/remove program: if present

    Ares
    Viewpoint/viewpoint Manager/Viewpoint Media



    Reboot



    To clean your temp folder, recycle bin, etc..please download this free tool:

    CCleaner

    Don't install any Toolbars, or other programs, should it ask you!Just uncheck the option of installing the Yahoo toolbar.
    It will put a shortcut on your Desktop.
    Click on CCleaner to start it. Then click "Run Cleaner", just use the windows tab up front by default.

    Then Reboot (Exit)





    Download LQfix.exe and place it on your desktop.
    Doubleclick LQfix.exe and click install.
    Leave the default settings. If you change them, the fix will fail.
    Make sure 'Launch LQfix' is checked. After clicking finish in the install, the fix will start.
    Follow the prompts on the screen.
    Your system will reboot afterwards.
    Please be patient after reboot, because there is a script running in the background.

    After the tool is finished reboot






    Download and install
    Ewido anti-spyware
    4.0
    (uninstall any previous version first).
    • Click the Download BUTTON. On the next page click the
      Download now BUTTON.
    • Save and then install (Run) from the save location.
    • Open/Run ewido anti-spyware
    • Wait a few moments and Ewido should Auto update itself (note date of last
      update). If it doesn't update, click the update ICON at top of
      screen:

    • Click on the Update now LINK at the top of the window
      • Click on the Start update button
      • Wait for the update to download and install
  6. This is very important to get the LATEST
    updates

  7. Click on the Status ICON
    • Under "Your computers Security"
      Click change status on Resident shield to inactive
      (ONLY consider activation of that feature once you are
      clean)
  8. Click on the Scanner ICON at the top of the window
  9. Click on the Settings tab then select Recommended Actions
    and choose Quarantine




  10. Close ALL open Windows / Programs / Folders. Please start
    Ewido, and run a full scan:
    • Click on the default Status ICON and select
      the Scan now LINK.

      OR

    • Click on the Scanner ICON . Select the Scan
      TAB.

      • Select Complete System Scan. Ewido will now begin to scan your
        system.

    • If Ewido finds anything it will list them in the Preview WINDOW:
      • Make sure that Set all elements to: shows
        Quarantine, if not click on the link and choose
        Quarantine from the popup menu.
      • Select Apply all actions at the bottom of the window (and the
        items found will be quarantined - and recoverable, if any items are needed
        back).

    • When the scan has completed, click on the Save Scan Report button
      and save the scan to your Desktop where it can be easily found.
    • Copy and paste the EWIDO scan results into your next
      post.
    • Close Ewido.


    I also need a new hijackthis log plese. Thanks.

  • #6
    oohmfgitstonyy is offline Valued Member
    uhm..im not using dial up its dsl but it disconnects sometimes..when i play gunbound or whatever, it goes my internet connection have been waiting too long? i don't know. but um, should i remove yahoo's virus things?






    EDIT :: um the virus thingy or spyware thingy is only a trial....:[

  • #7
    oohmfgitstonyy is offline Valued Member
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 9:00:21 PM 7/12/2006

    + Scan result:



    C:\WINDOWS\Downloaded Program Files\mm81.ocx -> Downloader.VB.ov : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{1D1B2879-99FF-11E3-8D96-D7ACAC95952A} -> Logger.PerfectKeylogger : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{1D1B2879-99FF-11E3-8D96-D7ACAC95952A} -> Logger.PerfectKeylogger : Cleaned with backup (quarantined).
    HKU\S-1-5-21-2967879142-2590334051-584863204-1006\Software\Microsoft\Windows\CurrentVersion\Ext \Stats\{1D1B2879-99FF-11E3-8D96-D7ACAC95952A} -> Logger.PerfectKeylogger : Cleaned with backup (quarantined).
    :mozilla.10:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.11:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.205:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.28:C:\Documents and Settings\ToOoOonY\Application Data\Mozilla\Firefox\Profiles\7lb43xmz.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.29:C:\Documents and Settings\ToOoOonY\Application Data\Mozilla\Firefox\Profiles\7lb43xmz.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.6:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.7:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.8:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.9:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    C:\Documents and Settings\backup\Cookies\backup@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.213:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.215:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.243:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.244:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.248:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.69:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
    :mozilla.75:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
    :mozilla.17:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.18:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.19:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.20:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.21:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.33:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1B.tmp -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    :mozilla.23:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.24:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.25:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.197:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Centrport : Cleaned with backup (quarantined).
    :mozilla.54:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
    :mozilla.20:C:\Documents and Settings\ToOoOonY\Application Data\Mozilla\Firefox\Profiles\7lb43xmz.default\coo kies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    :mozilla.26:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    :mozilla.242:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.16:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.160:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.183:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.175:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    :mozilla.176:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    :mozilla.93:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
    :mozilla.94:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
    :mozilla.214:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.219:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.230:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.236:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.240:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.24:C:\Documents and Settings\ToOoOonY\Application Data\Mozilla\Firefox\Profiles\7lb43xmz.default\coo kies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.25:C:\Documents and Settings\ToOoOonY\Application Data\Mozilla\Firefox\Profiles\7lb43xmz.default\coo kies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.26:C:\Documents and Settings\ToOoOonY\Application Data\Mozilla\Firefox\Profiles\7lb43xmz.default\coo kies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.90:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.191:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.192:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.193:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.194:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.55:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.56:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.57:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.58:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    C:\Documents and Settings\backup\Cookies\backup@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined).
    :mozilla.50:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.51:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.22:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.42:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.43:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.44:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    C:\Documents and Settings\Guest\Cookies\guest@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.72:C:\Documents and Settings\backup\Application Data\Mozilla\Firefox\Profiles\fx9fd1nb.default\coo kies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


    ::Report end


    and


    Logfile of HijackThis v1.99.1
    Scan saved at 9:01:09 PM, on 7/12/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    C:\Program Files\Yahoo!\Antivirus\ISafe.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
    C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
    C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\PROGRA~1\Yahoo!\YOP\yop.exe
    C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
    C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program Files\Common Files\AOL\1139021766\ee\AOLSoftware.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\AIM\aim.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [OSCD_Creator] c:\Dell\PreODM.EXE
    O4 - HKLM\..\Run: [Acronis?True?Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
    O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
    O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
    O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
    O4 - HKLM\..\Run: [stratas]
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139021766\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKLM\..\RunServices: [stratas]
    O4 - HKLM\..\RunOnce: [OSCD_Creator] C:\Dell\PreODM.EXE /2
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [stratas]
    O4 - HKCU\..\Run: [RK Launcher] C:\Program Files\RK Launcher\RKLauncher.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
    O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload.ijjimax.com/game...Plugin7USA.cab
    O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://nprotect.roseonlinegame.com/n...etizen/npx.cab
    O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://nprotect.roseonlinegame.com/n...rypt/npkcx.cab
    O20 - Winlogon Notify: automainer - automainer.dll (file missing)
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

    .. kay thanks? i cant remove ares cus i need it..

  • #8
    Neal is offline Dedicated Member
    OK,


    Yahoo thingys appear to be the only anit-virus you have and should keep it if you want it.
    But there are free versions out there like Avast and AVG.


    http://www.avast.com/eng/programs.html

    http://free.grisoft.com/doc/1


    You also need a free firewall:

    http://www.sunbelt-software.com/Kerio.cfm


    Run hijackthis and click on scan button and put a check next to this:


    O20 - Winlogon Notify: automainer - automainer.dll (file missing)


    Nothing open but hijackthis and click on fix checked.


    keylogger is gone


    Everything ok?

  • #9
    oohmfgitstonyy is offline Valued Member
    um why are all of them only for like, 30 days trial. but anyways thank-you a lot, i will surely be back when i need help. :] thanks Neal u kick @$$ :] ty ty ty. how old are you may i ask? im sorry for typing weird im not used to it because i usually use slang :] but anyways how else can i talk to u if im bored or got a question besides on this? do u have Aol Instant Messenger (AIM) or MSN or something? thanks once again. peace out homie

  • #10
    Neal is offline Dedicated Member
    Save 20% on AVG Internet Security 2012 Suite!
    It is OK if the trial runs out the program will still work good just not like the paid version will. I use Avast free version and Kerio sunbelt firewall paid version.


    No messenger programs.


    I am 48 and live in USA, New Mexico.


    If you have anymore problems just post a hijackthis log starting a new thread here in this forum.



    If you are no longer having any more trouble here is some preventative measures for you.

    Here are some preventive measures you can take to keep your computer from getting infected again. also keep all these and Ad-awareSE and SpybotS&D updated.

    http://www.d-a-l.com/help/showthread.php?t=32403

    Flush your restore points in ME and XP, by turning System Restore off and then back on.
    This will create a fresh restore point.


    Explained Here:
    Windows XP: http://vil.nai.com/vil/SystemHelpDoc...ysRestore.aspx

    Explained Here
    Microsoft ME:
    http://service1.symantec.com/SUPPORT...rc=sec_doc_nam


    RegProtect

    This small registry protection tool will save you hours of heartache by notifying you when some program good or bad is trying to access your registry.

    You have the option of allowing(good) items or blocking(bad)items.


    http://www.diamondcs.com.au/index.php?page=regprot


    To reduce the re-infection potential for malware and protect yourself against spyware, here are a few helpful suggestions:

    1. Keep Windows and Internet Explorer current with the latest critical security updates from Microsoft. This will patch many of the security holes through which attackers can gain access to your computer. You CANNOT complete this update using an alternate browser.
    http://v5.windowsupdate.microsoft.co....aspx?ln=en-us

    http://www.microsoft.com/windows/ie/default.asp


    2. Run your antivirus software regularly, and to keep its definitions up-to-date. If you are thinking about switching, there are a some good free Antivirus programs that are decent, including AVG and Avast!.
    AVG: http://free.grisoft.com/doc/1

    Avast: http://www.avast.com/eng/avast_4_home.html


    3. In addtion to using Ad-aware consider using another free malware scanning/removal program:
    Windows Defender

    http://www.microsoft.com/athome/secu...e/default.mspx


    4. Consider using a free firewall if you are not already using one. Some good free ones are:
    Kerio
    http://www.sunbelt-software.com/Kerio.cfm

    OutPost Personal Firewall:
    Outpost



    5. Consider using an alternate free browser for general web surfing but you must use IE for windows update.
    Mozilla Firefox: www.mozilla.org/products/firefox/


    6. Consider increasing your browser security by using these programs:
    SpywareGuard will protect your homepage from being hijacked: http://www.javacoolsoftware.com/spywareguard.html
    SpywareBlaster will increase browser protection by blocking Thousands of known malware sites by adding them to IE's restricted sites zone. Download it here:

    http://www.javacoolsoftware.com/spywareblaster.html


    If you use SpywareBlaster, you can also use a customblocklist to add even more entries into IE restricted sites zone. Go to this site for the current list and how to use instructions: http://customblockinglist.cjb.net/


    IE-SPYAD is similar in that it adds thousands more known malware sites to IE's restricted zone. Download it here:
    https://netfiles.uiuc.edu/ehowes/www/resource.htm


    Block access to Untrustworthy Sites

    You can prevent your computer from visiting a myriad of untrustworthy sites and ad-servers by installing a customised hosts file. One of the best available is the: MVPS Hosts File. Simply follow the instructions to install the file in the correct location. This will not only make surfing safer but will improve website load times and block popups from many of the large ad-servers.



    *Remember just like your primary anti-virus software, it is important to keep all of these programs up-to-date and use them on a regular basis. It's Free

  • + Reply to Thread
    Page 1 of 2 1 2 LastLast