Results 1 to 4 of 4

Thread: Browser Hijacked; VirusBursters; Critical System Errors; Windows Security Alerts

  1. #1
    Junior Member
    Join Date
    Nov 2006
    Posts
    2

    Default Browser Hijacked; VirusBursters; Critical System Errors; Windows Security Alerts

    Hi,
    I'm new here, but spent all last night trying to fix my computer! I have done everything that you guys required before posting. However, after completing the PandaScan for All My Computer and saving the results, I cannot find them on my computer ANYWHERE. The results found one virus that it disinfected, 2 "Hacking tools and potentially unwanted tools" and about 80+ spyware/adware results that it could not fix. At the moment I am re-running the scan, but since it will probably take a few more hourse, I wanted to go ahead and post in case something happens to my saved version of Hijackthis. Below please find the results for that scan.

    Basically, IE has turned my Google homepage into a System Security Alert that won't go away even with changing the internet options and rebooting. I am getting aggressive advertising from all kinds of "suspect" spyware products, and my internet is randomly freezing. I am also getting random pornography sites that pop-up when I am not even on the internet - each site is an ad for locating people "in my city" which they have correctly defined (these are not sites that I have visited before.) There is a button on each page that says "if abuse, click here" and when I click it, it tells me to uninstall a codec program. When I do, it is back after I reboot. Thanks so much for your help! I will re-post when the Panda Virus Scan finishes again.

    Logfile of HijackThis v1.99.1
    Scan saved at 7:59:45 AM, on 11/2/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\ibmpmsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\TrueCodec\isamonitor.exe
    C:\PROGRA~1\ThinkPad\CONNEC~1\Qctray.exe
    C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\WINDOWS\system32\tp4serv.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
    C:\WINDOWS\system32\RunDll32.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\PROGRA~1\SYMANT~3\VPTray.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\Program Files\TrueCodec\isamini.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\WINDOWS\System32\QCONSVC.EXE
    C:\Program Files\Symantec AntiVirus\SavRoam.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\AIM\aim.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    C:\Documents and Settings\eoconnor\Local Settings\Temporary Internet Files\Content.IE5\O5UFS5Q3\HijackThis[1].exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.netscape.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.unc.edu/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://surfix.w-lan.whu.edu/proxy.pac
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    N3 - Netscape 7: user_pref("browser.startup.homepage", "www.unc.edu"); (C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\prefs.js)
    N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\prefs.js)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O2 - BHO: (no name) - {8bf5b8fc-11cb-409f-8c91-4d4ca04a1b6d} - C:\Program Files\TrueCodec\isaddon.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O3 - Toolbar: Protection Bar - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - C:\Program Files\TrueCodec\iesplugin.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [QCTRAY] C:\PROGRA~1\ThinkPad\CONNEC~1\Qctray.exe
    O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe /server"
    O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
    O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
    O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~3\VPTray.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {10E0E75E-6701-4134-9D95-C0942ED1F1C8} (Snapfish Outlook Import ActiveX Control) - http://www.snapfish.com/SnapfishOutlookImport.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: clamoring - {0d9eb558-0666-479e-868a-21b1d1a53bd1} - C:\WINDOWS\system32\veklo.dll
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
    O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

  2. #2
    Junior Member
    Join Date
    Nov 2006
    Posts
    2

    Default My Virus scan report from Panda ActiveScan

    Incident Status Location

    Adware:Adware/VideoKeyCodec Not disinfected C:\Program Files\TrueCodec\iesplugin.dll
    Adware:Adware/VideoKeyCodec Not disinfected C:\Program Files\TrueCodec\pmmon.exe
    Adware:Adware/SecurityError Not disinfected C:\WINDOWS\system32\veklo.dll
    Adware:adware/tvmedia Not disinfected C:\Documents and Settings\eoconnor\Application Data\tvmcwrd.dll
    Adware:adware/transponder Not disinfected c:\windows\dlmax.dll
    Adware:adware/ieplugin Not disinfected c:\windows\kwv2.dat
    Adware:adware/exact.bargainbuddy Not disinfected c:\windows\launcher.exe
    Adware:adware/ncase Not disinfected c:\windows\msbbi.exe
    Adware:adware/windowenhancer Not disinfected c:\windows\system32\SBUtils
    Adware:adware/sidesearch Not disinfected c:\program files\Lycos
    Adware:adware/btgrab Not disinfected Windows Registry
    Adware:adware/mbkwbar Not disinfected Windows Registry
    Adware:adware/topmoxie Not disinfected Windows Registry
    Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@atwola[1].txt
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@go[2].txt
    Spyware:Cookie/Paypopup Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@paypopup[1].txt
    Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@www.myaffiliateprogram[1].txt
    Spyware:Cookie/MyWay Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@www.xzoomy[1].txt
    Virus:Trj/Downloader.FK Disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\GLOXWXAB\stc[1].html
    Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.2o7.net/]
    Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.adtech.de/]
    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.com.com/]
    Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.fortunecity.com/]
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.go.com/]
    Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.maxserving.com/]
    Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.perf.overture.com/]
    Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.qksrv.net/]
    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.realmedia.com/]
    Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.revenue.net/]
    Spyware:Cookie/Santa Monica networks inc Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.smni.com/]
    Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.tribalfusion.com/]
    Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[www.myaffiliateprogram.com/]
    Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@2o7[1].txt
    Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@adultfriendfinder[2].txt
    Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@atwola[1].txt
    Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@drivecleaner[1].txt
    Spyware:Cookie/Malwarewipe Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@malwarewipe[2].txt
    Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@stats.drivecleaner[2].txt
    Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@stats1.reliablestats[2].txt
    Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@statse.webtrendslive[2].txt
    Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@www.drivecleaner[1].txt
    Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@www.systemdoctor[1].txt
    Spyware:Cookie/VirusBurst Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@www.virusburst[2].txt
    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@247realmedia[1].txt
    Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@ad.yieldmanager[1].txt
    Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@ads.pointroll[1].txt
    Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@advertising[1].txt
    Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@atdmt[2].txt
    Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@bluestreak[1].txt
    Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@burstnet[1].txt
    Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@casalemedia[2].txt
    Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@cs.sexcounter[2].txt
    Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@ehg-dig.hitbox[2].txt
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@go[1].txt
    Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@hitbox[2].txt
    Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@mediaplex[1].txt
    Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@questionmarket[2].txt
    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@realmedia[1].txt
    Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@server.iad.liveperson[2].txt
    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@statcounter[1].txt
    Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@statse.webtrendslive[1].txt
    Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@trafficmp[1].txt
    Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@webpower[2].txt
    Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@www.burstbeacon[1].txt
    Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@www.myaffiliateprogram[2].txt
    Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@z1.adserver[1].txt
    Adware:Adware/SecurityError Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\laf2D8.tmp
    Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Loader.EX_[C:\Documents and Settings\eoconnor\Local Settings\Temp\Loader.EXe]
    Adware:Adware/MBKWBar Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\mbkwnst.cab[mbkwnst.exe][MBKWBar.exe]
    Adware:Adware/MBKWBar Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\mbkwnst.cab[mbkwnst.exe][MBKWBar.exe][IEToolBar.dll]
    Adware:Adware/MBKWBar Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\mbkwnst.exe[MBKWBar.exe]
    Adware:Adware/MBKWBar Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\mbkwnst.exe[MBKWBar.exe][IEToolBar.dll]
    Spyware:Spyware/BetterInet Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\mm_reco.exe
    Spyware:Spyware/BetterInet Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\randreco.exe
    Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\temp.fr4CA5\Tvm.exe
    Adware:Adware/TVMedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\temp.fr4CA5\TvmBho.dll
    Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\temp.fr4CA5\TvmCore.dll
    Adware:Adware/TVMedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Tvm.upd
    Adware:Adware/TVMedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\tvmupdater.exe
    Potentially unwanted tool:Application/VirusBurst Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\vb2D9.exe[VirusBursters.exe]
    Potentially unwanted tool:Application/DriveCleaner Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temporary Internet Files\Content.IE5\ZYOF7LCX\installdrivecleanerstart[1].cab[UDC6_0001_D19M1908NetInstaller.exe]
    Spyware:Spyware/Support Not disinfected C:\Program Files\Support.com\bin\tgcmd.exe
    Adware:Adware/VideoKeyCodec Not disinfected C:\Program Files\TrueCodec\iesuninst.exe
    Potentially unwanted tool:Application/VirusBurst Not disinfected C:\Program Files\VirusBursters\VirusBursters.exe
    Adware:Adware/MBKWBar Not disinfected C:\WINDOWS\mbkwnst.exe[MBKWBar.exe]
    Adware:Adware/MBKWBar Not disinfected C:\WINDOWS\mbkwnst.exe[MBKWBar.exe][IEToolBar.dll]
    Last edited by tashi; 2006-11-02 at 17:01. Reason: Two topics merged

  3. #3
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hi tuckerville and welcome to Safer Networking Forums

    You got some infections there...

    Please download HijackThis to your desktop from here -> HijackThis 1.99.1
    Create a new folder named HijackThis to your desktop. Move Hijackthis.exe into that folder.

    Please download SmitfraudFix (by S!Ri)
    Extract the content (a folder named SmitfraudFix) to your Desktop.

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
    Please copy/paste the content of that report into your next reply along with a fresh Hijackhis log.

    Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
    http://www.beyondlogic.org/consulting/proc...processutil.htm

    NOTE: Do not run any other options from SmitfraudFix until I tell you to do so!
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  4. #4
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    This topic is closed due to lack of a response.

    If you need it re-opened please send a private message (pm) to a forum staff member and provide a link to the thread.

    Applies only to the original topic starter.
    Last edited by Mr_JAk3; 2006-11-11 at 09:43. Reason: This topic is closed due to lack of a response.
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •