Adouma
2006-07-17, 02:50
Righto, here's the problem:
I keep getting random pop ups in Firefox, even when I'm not browsing. AdAware says that there are two modules it doesn't like, both called "Adware.Look2Me".
Name:Adware.Look2Me
Category:Adware
Object Type:Process
Size:-
Location:C:\WINDOWS\system32\jt2s07f7e.dll
Last Activity:16/07/2006 10:47:23 p.m.
Relevance:High
TAC index:7
Comment:iieshare.dll.dmp
Name:Adware.Look2Me
Category:Adware
Object Type:Process
Size:-
Location:C:\WINDOWS\system32\kmdlt.dll
Last Activity:16/07/2006 11:28:44 p.m.
Relevance:High
TAC index:7
Comment:iieshare.dll.dmp
When I try to fix them, Ad Aware says it can't do anything because they're running. It offers to fix them at startup, but we'll get to that in a minute...
Spybot finds a few things, too. Here's the report:
--- Search result list ---
Command Service: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService
Command Service: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService
Command Service: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cmdService
Look2Me.Topconverting: Temporary file (File, nothing done)
C:\WINDOWS\system32\guard.tmp
When I try to remove them, it says that only one can be removed. The rest have to be removed at startup. But here's the problem for both this and AdAware: Something is making my computer show an error, something about RUNDLL, at startup. This prevents those two programs from starting, making it impossible to remove the infections. I can't remember the exact error, but will screenshot it if you need it.
Panda Activescan, the all powerful tool for telling you why you need to buy their products, tells me that I have no fewer than forty-one instances of spyware on my computer:
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.2o7.net/]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.888.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.anm.co.uk/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.com.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.go.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.gostats.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.microsofteup.112.2o7.net/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.qksrv.net/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.rn11.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.weborama.fr/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[ad.sensismediasmart.com.au/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[adserver.filefront.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[server.iad.liveperson.net/hc/18766632]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[server.iad.liveperson.net/hc/91338698]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[www.advnt01.com/]
Spyware:Cookie/YieldManager
And, finally, the godlike Hijackthis. I attatched the report to save space.
Any help would be appreciated. Thank you in advance.
I keep getting random pop ups in Firefox, even when I'm not browsing. AdAware says that there are two modules it doesn't like, both called "Adware.Look2Me".
Name:Adware.Look2Me
Category:Adware
Object Type:Process
Size:-
Location:C:\WINDOWS\system32\jt2s07f7e.dll
Last Activity:16/07/2006 10:47:23 p.m.
Relevance:High
TAC index:7
Comment:iieshare.dll.dmp
Name:Adware.Look2Me
Category:Adware
Object Type:Process
Size:-
Location:C:\WINDOWS\system32\kmdlt.dll
Last Activity:16/07/2006 11:28:44 p.m.
Relevance:High
TAC index:7
Comment:iieshare.dll.dmp
When I try to fix them, Ad Aware says it can't do anything because they're running. It offers to fix them at startup, but we'll get to that in a minute...
Spybot finds a few things, too. Here's the report:
--- Search result list ---
Command Service: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService
Command Service: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService
Command Service: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cmdService
Look2Me.Topconverting: Temporary file (File, nothing done)
C:\WINDOWS\system32\guard.tmp
When I try to remove them, it says that only one can be removed. The rest have to be removed at startup. But here's the problem for both this and AdAware: Something is making my computer show an error, something about RUNDLL, at startup. This prevents those two programs from starting, making it impossible to remove the infections. I can't remember the exact error, but will screenshot it if you need it.
Panda Activescan, the all powerful tool for telling you why you need to buy their products, tells me that I have no fewer than forty-one instances of spyware on my computer:
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.2o7.net/]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.888.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.anm.co.uk/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.com.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.go.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.gostats.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.microsofteup.112.2o7.net/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.qksrv.net/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.rn11.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.weborama.fr/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[ad.sensismediasmart.com.au/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[adserver.filefront.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[server.iad.liveperson.net/hc/18766632]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[server.iad.liveperson.net/hc/91338698]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\Mac\Application Data\Mozilla\Firefox\Profiles\u09x3rnt.default\cookies.txt[www.advnt01.com/]
Spyware:Cookie/YieldManager
And, finally, the godlike Hijackthis. I attatched the report to save space.
Any help would be appreciated. Thank you in advance.