Announcement

Collapse
No announcement yet.

How do u get rid of malware

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #31
    yep, and it comes up with a black screen. It says safe mode but that's it.

    ACK!
    Don't try to confuse the issue with half-truths and gorilla dust!

    Comment


    • #32
      uhh ok.. well... how about the recovery disk?
      In da butt.
      "Do not worry if others do not understand you. Instead worry if you do not understand others." - Confucius
      THE UNDEFEATED SUPERCITIZEN w:4 t:2 l:1 (DON'T ASK!)
      "God is dead" - Nietzsche. "Nietzsche is dead" - God.

      Comment


      • #33
        thanks lol
        will a system restore to 3 months ago work?
        When you find yourself arguing with an idiot, you might want to rethink who the idiot really is.
        "It can't rain all the time"-Eric Draven
        Being dyslexic is hard work. I don't even try anymore.

        Comment


        • #34
          It might.

          There's also a decent chance that a quick glance with RegEdit will fix it ... usually malware stuff sticks itself into the /hkey_current_user/software/microsoft/windows/currentversion/run or /runonce, or /hkey_local_machine/(same) paths ... you just look there and see what is not supposed to be there. (Adaware does more or less that.) If you know the program you're trying to kylle, you can usually find that online first.
          <Reverend> IRC is just multiplayer notepad.
          I like your SNOOPY POSTER! - While you Wait quote.

          Comment


          • #35
            Can you post a Hijack This log? I can probably read it and find the specific issue, if vundofix isn't working for ya ...
            <Reverend> IRC is just multiplayer notepad.
            I like your SNOOPY POSTER! - While you Wait quote.

            Comment


            • #36
              Why not just do what most women do and get your man to do it for you?
              Try http://wordforge.net/index.php for discussion and debate.

              Comment


              • #37
                Originally posted by Oerdin
                Why not just do what most women do and get your man to do it for you?
                well post #14 was Tubes (her manservant)
                To us, it is the BEAST.

                Comment


                • #38
                  Originally posted by snoopy369
                  Can you post a Hijack This log? I can probably read it and find the specific issue, if vundofix isn't working for ya ...
                  I am still working on this my pc wont even restore what the hell is going on
                  When you find yourself arguing with an idiot, you might want to rethink who the idiot really is.
                  "It can't rain all the time"-Eric Draven
                  Being dyslexic is hard work. I don't even try anymore.

                  Comment


                  • #39
                    I did ad ware found 96 problems but wants me to pa 50 bucks to clean it up
                    hell i can recover the dam thing for free
                    just need to get all my hawaii pics on a new disc
                    When you find yourself arguing with an idiot, you might want to rethink who the idiot really is.
                    "It can't rain all the time"-Eric Draven
                    Being dyslexic is hard work. I don't even try anymore.

                    Comment


                    • #40
                      Originally posted by Pekka
                      Drose, oh yeah, why don't you start being smart too. I guess you want to ride on his wave, somehow lifting you to new levels as well. Well I got news for you buster, not gonna happen.
                      Jesus tap-dancing Christ, when did you turn into such a prima donna? Your post and his were 3 SECONDS APART. Pull your head out of your ass for a change. You need to get some fresh air, man.
                      The cake is NOT a lie. It's so delicious and moist.

                      The Weighted Companion Cube is cheating on you, that slut.

                      Comment


                      • #41
                        Pssst, DRose, he is making fun of you
                        "I have been reading up on the universe and have come to the conclusion that the universe is a good thing." -- Dissident
                        "I never had the need to have a boner." -- Dissident
                        "I have never cut off my penis when I was upset over a girl." -- Dis

                        Comment


                        • #42
                          Pssst, Spiffor, I know.
                          The cake is NOT a lie. It's so delicious and moist.

                          The Weighted Companion Cube is cheating on you, that slut.

                          Comment


                          • #43
                            Originally posted by Mrs. Tuberski
                            I am still working on this my pc wont even restore what the hell is going on
                            I'm not sure what you mean here ... but this is what I mean.


                            Download HijackThis from TomCoyote.org and view quick start tutorial.


                            Download "Hijack This" from this site, run it, and paste the save log to here It is a log of all of the random things your computer runs ... which probably includes your problem.

                            From that list, I (or any experienced spyware blasting person) can probably deduce which program to delete and how to delete it
                            <Reverend> IRC is just multiplayer notepad.
                            I like your SNOOPY POSTER! - While you Wait quote.

                            Comment


                            • #44
                              here it is:

                              Logfile of HijackThis v1.99.1
                              Scan saved at 9:19:00 PM, on 10/9/2005
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                              C:\WINDOWS\system32\LEXBCES.EXE
                              C:\WINDOWS\system32\LEXPPS.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                              C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                              C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
                              C:\WINDOWS\system32\svchost.exe
                              c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
                              C:\WINDOWS\system32\igfxtray.exe
                              C:\WINDOWS\system32\hkcmd.exe
                              C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                              C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
                              C:\WINDOWS\system32\hphmon05.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\Program Files\QuickTime\qttask.exe
                              C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
                              C:\WINDOWS\system32\LXSUPMON.EXE
                              C:\PROGRA~1\mcafee.com\agent\mcagent.exe
                              C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
                              C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
                              C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                              C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
                              C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
                              C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
                              C:\Program Files\Microsoft Office\Office\OSA.EXE
                              C:\Program Files\MSN Messenger\msnmsgr.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Messenger\msmsgs.exe
                              C:\DOCUME~1\Laptop\LOCALS~1\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe

                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ts/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
                              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...ario&pf=laptop
                              O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_ 7_0.dll
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                              O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
                              O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system32\pmkjj.dll
                              O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                              O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
                              O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                              O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
                              O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                              O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_ 7_0.dll
                              O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
                              O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                              O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                              O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
                              O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
                              O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
                              O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                              O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                              O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
                              O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
                              O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                              O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
                              O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
                              O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
                              O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                              O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
                              O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\adwarealert.Exe -boot
                              O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
                              O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
                              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
                              O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
                              O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                              O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                              O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                              O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                              O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                              O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
                              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
                              O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
                              O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
                              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=laptop
                              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                              O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...4/mcinsctl.cab
                              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1098900681199
                              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
                              O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                              O20 - Winlogon Notify: pmkjj - C:\WINDOWS\system32\pmkjj.dll
                              O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                              O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                              O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                              O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                              O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\Laptop\Local Settings\Temporary Internet Files\Content.IE5\89S3KF03\cwshredder[1].exe (file missing)
                              O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                              O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
                              O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
                              O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                              O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
                              O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
                              O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
                              When you find yourself arguing with an idiot, you might want to rethink who the idiot really is.
                              "It can't rain all the time"-Eric Draven
                              Being dyslexic is hard work. I don't even try anymore.

                              Comment


                              • #45
                                Run msconfig to turn off everything you don't need so far.

                                BTW why are you running Norton, McAfee andAVG? Wouldn't your computer be a little slow?

                                These look fishy:

                                O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                                O20 - Winlogon Notify: pmkjj - C:\WINDOWS\system32\pmkjj.dll

                                You also got this, though it looks like the file got nuked already.

                                O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\Laptop\Local Settings\Temporary Internet Files\Content.IE5\89S3KF03\cwshredder[1].exe (file missing)
                                (\__/) 07/07/1937 - Never forget
                                (='.'=) "Claims demand evidence; extraordinary claims demand extraordinary evidence." -- Carl Sagan
                                (")_(") "Starting the fire from within."

                                Comment

                                Working...
                                X