Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Members New Posts Donate Unanswered Posts Site Spy Search


Reply
 
Thread Tools
  #1  
Old 01-12-2007, 02:06 AM
No Avatar
CJ New Member
 
Thumbtack is offline
 
Join Date: Nov 2007
Last Online: 28-12-2007 02:34 AM
Posts: 5
iTrader: (0)
Thumbtack is on a distinguished road
Default Killing Off My Spyware/Malware (take 2)

I apologize for not reading all of the steps before my previous post. I have now followed those steps, but I'm having a problem...

I can upload only one of the three, required log files as an attachment (which is included here). The other two get an "invalid file" problem. All three files are of the same type and one of the disallowed files is smaller than the one that made it into this thread, so it can't be a size issue. Any idea what I'm doing wrong? Thanks.
Attached Files
File Type: txt log.txt (589 Bytes, 1 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #2  
Old 01-12-2007, 02:09 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 08:43 PM
Posts: 4,605
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Killing Off My Spyware/Malware (take 2)

Are they saved as .txt files?

If you have to copy and paste them in the thread then do that.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #3  
Old 01-12-2007, 02:17 AM
No Avatar
CJ New Member
 
Thumbtack is offline
 
Join Date: Nov 2007
Last Online: 28-12-2007 02:34 AM
Posts: 5
iTrader: (0)
Thumbtack is on a distinguished road
Default Killing Off My Spyware/Malware (take 2)

Okay, figured it out. Here are the other two files. As for my symptoms...

My computer will sometimes be working fine but at other times it will going into "loud, busy, thinking mode" at which time I can hear the tower thinking away as if it's downloading the entire internet. Everything I'm doing will slow to a crawl and well... I'm sure you know this old tale. I have no idea if this is simply typical computer behavour or if it's spyware doing nasty stuff. Thanks in advance for any help.
Attached Files
File Type: txt SUPERAntiSpyware Scan Log.txt (464 Bytes, 1 views)
File Type: txt hijackthis.txt (10.5 KB, 1 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #4  
Old 01-12-2007, 02:32 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 08:43 PM
Posts: 4,605
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Killing Off My Spyware/Malware (take 2)

Go to add/remove programs and uninsatll ActiveScan Antivirus (if there)


Open HijackThis and select "Do a system scan only"

Place a check mark next to:

O2 - BHO: (no name) - {11A1463D-DFDF-48F9-9DC6-C3A7613293F5} - C:\WINDOWS\System32\llog.dll (file missing)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O20 - Winlogon Notify: yvbb01 - yvbb01.dll (file missing)
O24 - Desktop Component 0: Warning homepage - C:\WINDOWS\warnhp.html

Close all windows and click "Fix checked"


Please download Combofix by sUBs from either here or here

Save Combofix.exe to your your Desktop.

1. Double click combofix.exe & follow the prompts. (from the keyboard select 1 and press enter)
2. When finished, it will produce a log for you.
3. Attach that log in your next reply.

Note:
Do not mouseclick combofix's window while it's running. That may cause your computer to stall


Next post please attach:
combofix.txt log
New HijackThis log
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #5  
Old 01-12-2007, 04:30 AM
No Avatar
CJ New Member
 
Thumbtack is offline
 
Join Date: Nov 2007
Last Online: 28-12-2007 02:34 AM
Posts: 5
iTrader: (0)
Thumbtack is on a distinguished road
Default Killing Off My Spyware/Malware (take 2)

Okay, I did everything you mentioned. I didn't see ActiveScan Antivirus in the add/remove list, but I saw it in the HijackThis scan. I checked it along with the other things you told me to check, but I noticed that it was there again after I rebooted.

After the Combofix scan, I couldn't connect to the internet for some reason so I rebooted (this is the roboot I mentioned in the above paragraph) and everything seemed fine. One odd thing though, after I checked the appropriate boxes in the HijackThis scan and clicked "fix checked", my desktop wallpaper vanished. It's no big deal, but it is a bit odd.

Thanks again for all of this help.
Attached Files
File Type: txt Combofixlog.txt (10.4 KB, 2 views)
File Type: txt hijackthis2ndscan.txt (10.2 KB, 1 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #6  
Old 01-12-2007, 04:46 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 08:43 PM
Posts: 4,605
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Killing Off My Spyware/Malware (take 2)

Download Panda Anti-Rootkit.zip

Unzip it and run the PAVARK.exe file.

Tick the box that says In depth scan and follow the on screen instructions.

Let me know the results in your reply.

PLease Note: Panda Antirootkit is not comaptible with Windows Vista.

If you are running Vista, please download the AVG Antirootkit

Run the scan and be sure to check mark the In depth scan.


Let me know if anything was found and removed.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #7  
Old 01-12-2007, 05:09 AM
No Avatar
CJ New Member
 
Thumbtack is offline
 
Join Date: Nov 2007
Last Online: 28-12-2007 02:34 AM
Posts: 5
iTrader: (0)
Thumbtack is on a distinguished road
Default Killing Off My Spyware/Malware (take 2)

I downloaded Panda (I'm not using Vista) and ran the in depth scan. It found nothing at all. Am I all clean or do I have more homework to do?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #8  
Old 01-12-2007, 04:34 PM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 08:43 PM
Posts: 4,605
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Killing Off My Spyware/Malware (take 2)

Press ctrl+alt+delete (all at once)

Click the processes tab and look for (if there) ActiveScan.exe

Right click it and choose End process


Open HijackThis and select Do a system scan only and place a check mark next to:

O4 - HKLM\..\Run: [ActiveScan Antivirus] ActiveScan.exe
O4 - HKLM\..\RunServices: [ActiveScan Antivirus] ActiveScan.exe
O4 - HKUS\S-1-5-18\..\RunServices: [ActiveScan Antivirus] ActiveScan.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunServices: [ActiveScan Antivirus] ActiveScan.exe (User 'Default user')

Close all windows and click Fix checked.


Go to Start > Run and copy and paste next command in the field:

ComboFix /u



Make sure there's a space between Combofix and /
Then hit Enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again

Read this thread Keeping yourself safe on the web

If you have any more problems let us know.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Malware Removal - Help VNani Virus, Spyware & Security 23 10-04-2008 12:29 AM
malware log antbann Virus, Spyware & Security 4 01-03-2008 08:31 PM
Slow Computer? It May Not Be Malware evilfantasy Virus, Spyware & Security 0 26-10-2007 06:51 PM
How can I remove vicious malware? waynestep Virus, Spyware & Security 28 28-08-2007 10:26 PM
Fantastico Killing the Trade? quinda Web Design, Hosting & SEO 3 17-03-2007 12:01 AM


Copyright ©2006 - 2008 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.

Page copy protected against web site content infringement by Copyscape