View Single Post
Old 11-04-2007, 08:59 PM   #9 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,353
OS: N/A


Re: Pop-ups, Hijackthis log file

Quote:
Number of viruses found: 36
Number of infected objects: 109
That's a lot of crap you have there.



Open notepad and copy/paste the text in the quotebox below into it:

Code:
http://www.techsupportforum.com/security-center/hijackthis-log-help/187771-pop-ups-hijackthis-log-file.html#post1153888
Collect::
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\0394ccd6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\0b2331d6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\0d42b0d6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\1bc6f4d6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\23a82af6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\24833106.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\25f48af6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\29be5ab6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\30d261f6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\3f4db1d6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\435c95b6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\4bf9a8f6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\4fb79af6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\52690ee6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\64a88ce6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\68baaaf6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\698175c6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\84c10ff6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\859c3af6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\8d7c66d6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\9721abf6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\99ca1af6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\a7a70536.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\ae9f9ea6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\b26acbd6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\b4a073d6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\bd879af6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\c8c1faf6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\c8d726e6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\d74acaf6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\e2d89356.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\ebf93af6.exe
C:\Documents and Settings\Owner.BOBBY\Local Settings\Application Data\ef6bd166.exe
File::
C:\Documents and Settings\Owner.BOBBY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-44f46a27-40822d38.zip
C:\Documents and Settings\Owner.BOBBY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-68a78113-30f4dccb.zip
C:\Documents and Settings\Owner.BOBBY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-540c1c76-4067b059.zip
C:\Documents and Settings\Owner.BOBBY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-5d29f7ed-52026c20.zip
C:\Documents and Settings\Owner.BOBBY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv430.jar-61fcb0a5-41babed0.zip
C:\Documents and Settings\Owner.BOBBY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv557.jar-23cd1d22-30b6c555.zip
C:\Documents and Settings\Owner.BOBBY\Desktop\[4]-Submit_2007-11-05@11.28.zip
C:\Documents and Settings\Owner.BOBBY\My Documents\My Music\Bobby Favorites\BSINSTALL.exe
C:\Documents and Settings\Owner.BOBBY\My Documents\My Music\My Downloads\Native.Instruments.Traktor.DJ.Studio.v3.1.3.incl.Keygen-AiR.zip
C:\Downloads\RollerCoasterTycoon2-dm[1].exe
C:\Program Files\Morpheus\morpheustoolbar.exe
C:\Program Files\ProcManager.exe
C:\WINDOWS\system32\ehlzeb.dll
C:\WINDOWS\system32\hrcopul.dll
C:\WINDOWS\system32\kdrix.exe
C:\WINDOWS\system32\qfyqakn.dll
C:\WINDOWS\system32\ztysid.exe
C:\WINDOWS\woinstall.exe
Folder::
C:\Deckard
C:\Documents and Settings\Owner.BOBBY\Desktop\backups
C:\Program Files\e52wpldb
C:\Program Files\MalwareWiped 6.9
C:\WINDOWS\bundles
C:\WINDOWS\Downloaded Program Files\CONFLICT.1
C:\WINDOWS\Downloaded Program Files\CONFLICT.2
C:\WINDOWS\Downloaded Program Files\CONFLICT.3
C:\WINDOWS\Downloaded Program Files\CONFLICT.4
C:\WINDOWS\Downloaded Program Files\CONFLICT.5
C:\WINDOWS\Downloaded Program Files\CONFLICT.6
C:\WINDOWS\inst
C:\WINDOWS\system32\Cache
Save this as "CFScript"




Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply.

Additonally, ComboFix will generate another zipped file on your Desktop, called [4]Submit@Date_Time.zip
Before proceeding to the next step, please submit this file to http://www.bleepingcomputer.com/subm....php?channel=4


---------------


ESET Online Scanner - Beta
  • Please go to the following link ESET Online Scanner Link
  • Tick the box YES, I accept the Terms Of Use
  • Click the Start button
  • Now click the Install button
  • Click Start

    The scanner engine will initialise and update
  • Do Not tick the box Remove found threats
  • Click the Scan button

    The scan will now run, please be patient
  • When the scan finishes click the Details tab
  • Copy and paste the contents of the scan back here.
__________________

Question - what have you done for the community today?
sUBs is offline