CiD popups
 
  Tweaks.com
 Home    Members    Calendar    Who's On        Main Site
 



««12

CiD popupsExpand / Collapse
Author
Message
Posted 5/3/2008 9:53 AM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 5/4/2008 6:52 AM
Posts: 8, Visits: 53
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/03/2008 at 11:18 PM

Application Version : 4.0.1154

Core Rules Database Version : 3452
Trace Rules Database Version: 1444

Scan type       : Complete Scan
Total Scan Time : 00:09:21

Memory items scanned      : 371
Memory threats detected   : 0
Registry items scanned    : 4756
Registry threats detected : 0
File items scanned        : 11225
File threats detected     : 50

Adware.Tracking Cookie
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@server.cpmstar[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@ad[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@www.adserver5[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@1056212609[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@atdmt[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@questionmarket[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@apmebf[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@eas.apm.emediate[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@2o7[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@microsoftgamestudio.112.2o7[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@burstnet[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@adinterax[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@counter.hitslink[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@advertising[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@cassava[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@hitbox[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@youporn[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@adserver.filefront[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@media.adrevolver[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@bs.serving-sys[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@tribalfusion[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@realmedia[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@ad.yieldmanager[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@serving-sys[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@specificclick[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@partypoker[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@ads-dev.youporn[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@msnportal.112.2o7[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@ehg-segaofamerica.hitbox[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@fastclick[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@rotator.adjuggler[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@adrevolver[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@partygaming.122.2o7[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@247realmedia[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@ads.vlaze[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@mediaplex[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@profiles.hitslink[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@server.iad.liveperson[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@www.burstnet[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@doubleclick[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@ehg-gamespyinc.hitbox[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@adv.ertisement[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@richmedia.yahoo[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@888[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@tacoda[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@statcounter[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@adultfriendfinder[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@zedo[1].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@ads.sun[2].txt
 C:\Documents and Settings\Jose Mari\Cookies\jose mari@azjmp[2].txt


^_^

Post #238838
Posted 5/3/2008 9:54 AM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 5/4/2008 6:52 AM
Posts: 8, Visits: 53
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:25:02 PM, on 5/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\VMSnap3.EXE
C:\WINDOWS\Domino.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [VMSnap3] C:\WINDOWS\VMSnap3.EXE
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.EXE
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 5796 bytes


^_^

Post #238839
Posted 5/3/2008 9:58 AM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 29,010, Visits: 54,734
Your log is clean,please do the following:

Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update to the latest version.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u6'.
3. Click the "Download" button to the right.
4. Select the Platform and Language for your download,then check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language - jre-6u6-windows-i586-p.exe' [15.21 MB] and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java version.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u6-windows-i586-p.exe to install the newest version.


You should take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:

Simple and easy ways to keep your computer safe and secure on the Internet:
http://www.bleepingcomputer.com/tutorials/tutorial82.html

How to prevent Malware:
http://users.telenet.be/bluepatchy/miekiemoes/prevention.html

So how did I get infected in the first place:
http://forums.spybot.info/showthread.php?t=279

Malware Cleanup Programs and Preventative Procedures:
http://russelltexas.com/malware/allclear.htm

Hardening Windows Security - Part 1:
http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html

Hardening Windows Security - Part 2:
http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html


________________________________________


ASAP & UNITE member since 2006





Spreadfirefox Affiliate Button Get Thunderbird!
Post #238840
« Prev Topic | Next Topic »

««12

Reading This TopicExpand / Collapse

All times are GMT -6:00, Time now is 7:27pm

Powered By InstantForum.NET v4.1.4 © 2008
Execution: 0.078. 9 queries. Compression Enabled.