Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 05-07-2007, 09:58 AM   #21 (permalink)
Registered User
 
Join Date: May 2007
Posts: 19
OS: Windows XP


Re: Multiple infections

Activescan.txt


Incident Status Location

Spyware:Cookie/Xiti Not disinfected C:\Deckard\System Scanner\20070507042631\backup\DOCUME~1\dale\LOCALS~1\Temp\Cookies\dale@xiti[1].txt
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\dale\Cookies\dale@anm.co[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\dale\Cookies\dale@atwola[2].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\dale\Cookies\dale@azjmp[2].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\dale\Cookies\dale@cgi-bin[11].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\dale\Cookies\dale@cgi-bin[4].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\dale\Cookies\dale@cgi-bin[7].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\dale\Cookies\dale@cgi-bin[9].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\dale\Cookies\dale@com[1].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\dale\Cookies\dale@gostats[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\dale\Cookies\dale@go[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\dale\Cookies\dale@xiti[1].txt
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe
Potentially unwanted tool:Application/NirCmd.A Not disinfected D:\dump\ComboFix.exe[ComboFixT\nircmd.exe]
Spyware:Cookie/NewMedia Not disinfected F:\safehold\setup\Cookies\dale@anm.co[1].txt
Spyware:Cookie/Atwola Not disinfected F:\safehold\setup\Cookies\dale@atwola[1].txt
Spyware:Cookie/Azjmp Not disinfected F:\safehold\setup\Cookies\dale@azjmp[2].txt
Spyware:Cookie/Cgi-bin Not disinfected F:\safehold\setup\Cookies\dale@cgi-bin[11].txt
Spyware:Cookie/Cgi-bin Not disinfected F:\safehold\setup\Cookies\dale@cgi-bin[4].txt
Spyware:Cookie/Cgi-bin Not disinfected F:\safehold\setup\Cookies\dale@cgi-bin[7].txt
Spyware:Cookie/Cgi-bin Not disinfected F:\safehold\setup\Cookies\dale@cgi-bin[9].txt
Spyware:Cookie/GoStats Not disinfected F:\safehold\setup\Cookies\dale@gostats[2].txt
Spyware:Cookie/Go Not disinfected F:\safehold\setup\Cookies\dale@go[1].txt
Spyware:Cookie/Xiti Not disinfected F:\safehold\setup\Cookies\dale@xiti[1].txt
Spyware:Cookie/Xiti Not disinfected F:\safehold\setup\Local Settings\Temp\Cookies\dale@xiti[1].txt
Spyware:Cookie/Atwola Not disinfected F:\storage\setup.old\Cookies\dale@atwola[1].txt
Spyware:Cookie/Cgi-bin Not disinfected F:\storage\setup.old\Cookies\dale@cgi-bin[6].txt
Spyware:Cookie/360i Not disinfected F:\storage\setup.old\Cookies\dale@ct.360i[2].txt
Spyware:Cookie/Go Not disinfected F:\storage\setup.old\Cookies\dale@go[2].txt
Spyware:Cookie/MediaTickets Not disinfected F:\storage\setup.old\Cookies\dale@kinghost[1].txt
Spyware:Cookie/Rn11 Not disinfected F:\storage\setup.old\Cookies\dale@rn11[2].txt
Spyware:Cookie/Target Not disinfected F:\storage\setup.old\Cookies\dale@target[2].txt
Spyware:Cookie/Xiti Not disinfected F:\storage\setup.old\Cookies\dale@xiti[1].txt
Spyware:Cookie/Atwola Not disinfected F:\storage\setup.old\Local Settings\Temp\Cookies\dale@atwola[1].txt
Spyware:Cookie/Belnk Not disinfected F:\storage\setup.old\Local Settings\Temp\Cookies\dale@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected F:\storage\setup.old\Local Settings\Temp\Cookies\dale@dist.belnk[2].txt
ohno is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 05-08-2007, 10:23 AM   #22 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,552
OS: WinXP and Vista


Re: Multiple infections

Hi,

Other than cookies, your logs are clean.

Empty these folders:

F:\safehold\setup\Cookies
F:\storage\setup.old\Cookies

Your logs are clean. If there aren't any more problems, please continue with these final instructions and helpful links:

Reset hidden/system files and folders
Windows XP
===============
Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View tab.
* Deselect the Show hidden files and folders option.
* Select the Hide file extensions for known types option.
* Select the Hide protected operating system files option.
Click Yes to confirm.
Click OK.

Ensure Windows Auto Update is Enabled
*Go to Start>Run - type wuaucpl.cpl
*Tick on the checkbox - "Automatically download the updates, and install them on the schedule that I specify".
Click on "OK".

Create a new System Restore point
Click Start >> Run - type SYSDM.CPL & press Enter
* Select the System Restore Tab
* Tick on the checkbox - "Turn off System Restore on all drives"
Click Apply
* Then untick the same checkbox & click OK
This will prevent any reinfection from previous restore points.


To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:

McAfee Site Advisor--free version. The folks there check out websites and based on their findings, rate it as Safe, Unknown, Caution, or Bad.

SpywareBlaster 3.5.1 to help prevent spyware from installing in the first place. Install & update SpywareBlaster with the latest definitions. After you have updated, click the button - enable protection for all unprotected items.

Spyware Guard to catch and block spyware before it can execute.

IE-SPYAD.EXE to block access to malicious websites so you cannot be redirected to them from an infected site or email. IE/Spyad places more than 4000 dubious websites and domains in the IE Restricted list. This severely impairs attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites. This is a self-extracting .ZIP file, save it to your desktop. Once downloaded, double-click on it to extract the files inside (default dir is C:\IE-SPYAD)
  • Now navigate to C:\ie-spyad. Double click to open it.
  • From within the folder, double-click install.bat
  • Select Option #2 - Install the new IE-SPYAD list, by typing 2
  • Then return to the main menu.
  • Select option #4 - Add the old porn sites domain, by typing 4

Update all these programs regularly. Without regular updates you will not be protected when new malicious programs are released.

In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:

PC Safety and Security--What Do I Need?

HOW DID I GET INFECTED IN THE FIRST PLACE? by Tony Klein
THE ANTI-SPYWARE TUTORIAL
MAKING INTERNET EXPLORER SAFER
Understanding and Using Firewalls

**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

-----------------------------------------------------

Follow the list above and the potential for infection will reduce dramatically.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-08-2007, 12:31 PM   #23 (permalink)
Registered User
 
Join Date: May 2007
Posts: 19
OS: Windows XP


Re: Multiple infections

Ried... Thank you so much! I am going through the list right now!!!
ohno is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-08-2007, 09:30 PM   #24 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,552
OS: WinXP and Vista


Re: Multiple infections

You're quite welcome--stay safe out there.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 11:26 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85