CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Pop-ups and other things please help! (hi-jack and Spyware)
Goto page Previous  1, 2
 
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16536

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Thu Nov 06, 2003 4:07 am    Post subject:
Reply with quote

Holy cr*p! Is there not a better way of relaying such a long scan result?

Back to top
View users profile Send private message
Jamming

Colonel
Colonel
Premium Member

Joined: Jun 22, 2002
Posts: 1874

Premium

PostPosted: Thu Nov 06, 2003 5:01 am    Post subject:
Reply with quote

Remove all of it, Wow and you need instructions on how to set your browser.

Tools Menu on IE> Internet Options> Advance Tab >Make sure both Install on Demand boxes are unchecked. That will help in about 1/3rd of these.

Back to top
View users profile Send private message
CalamityJane

Security Expert
Microsoft MVP

Joined: Oct 05, 2002
Posts: 4004

MVP Premium Security Experts

PostPosted: Thu Nov 06, 2003 11:05 am    Post subject:
Reply with quote

Auestioner,

You have a ton of stuff in there, but also do not have the latest update from Adaware which is really critical

On my Adaware Tutorial, look at the first screen shot on getting the updates and where to look to see what the latest one is. Here is the link again http://forum.gladiator-antivirus.com/index.php?showtopic=8050


This is what you should see
Installed Reference File: 01R229 03.11.2003

For now, go ahead and quarantine all it has found so far (it will say removed, but if you followed my settings for scanning, it will really put them in quarantine). Reboot.

Then get the latest update I've described above and run another scan

This is going to take a number of steps (and possibly some other tools) to get you clean....so we'll take one step at a time Wink

Back to top
View users profile Send private message Visit posters website
!Mariner

Colonel
Colonel
Premium Member

Joined: Aug 25, 2003
Posts: 1914

Premium

PostPosted: Thu Nov 06, 2003 12:19 pm    Post subject:
Reply with quote

Hi CalamityJane,

Have already advised this course of action and
Auestioner has followed up and posted log based on ref-file 01R229 on previous page.

System full of bad stuff. Needs advising on what/what not to keep.

I, like Jamming, would be inclined to ditch the lot.

Can't deal with at moment.

Over to you.

Back to top
View users profile Send private message
CalamityJane

Security Expert
Microsoft MVP

Joined: Oct 05, 2002
Posts: 4004

MVP Premium Security Experts

PostPosted: Thu Nov 06, 2003 12:40 pm    Post subject:
Reply with quote

Hi Mariner,

You're right.....I missed the second scan with the updated version.

I looked at the entire log. He should remove all of them, I don't see anything worth keeping (Be sure you have System Restore disabled). They will all go into quarantine.

Reboot and scan again - see if anything comes back. A number of the items in there I know Adaware cannot completely cure, but it should eliminate a lot.

The next step after that would be a scan with Download *Hijack This!* http://www.tomcoyote.org/hjt/
Unzip, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button. Press that and copy & paste its contents here. Most of what it lists will be harmless or even essential, don't fix anything yet. Someone will be along to tell you what steps to take after you post the content of the scan results.

Sorry for the confusion
Shocked

Back to top
View users profile Send private message Visit posters website
!Mariner

Colonel
Colonel
Premium Member

Joined: Aug 25, 2003
Posts: 1914

Premium

PostPosted: Thu Nov 06, 2003 1:16 pm    Post subject:
Reply with quote

Nothing to apologise for. All to easy to get confused. Well, it is in my case!

Thanks for dealing.

Back to top
View users profile Send private message
Auestioner

Guest
IP: 12.240.*.*






PostPosted: Fri Nov 07, 2003 12:56 am    Post subject:
Reply with quote

Calamity Jane,

You said "Be sure you have System Restore disabled"... how do I check if this is disabled? Thanks for all the help, I'm going to follow those quarantine instructions for ad-aware and then get hijack this.

Back to top
CalamityJane

Security Expert
Microsoft MVP

Joined: Oct 05, 2002
Posts: 4004

MVP Premium Security Experts

PostPosted: Fri Nov 07, 2003 1:59 am    Post subject:
Reply with quote

Auestioner Smile

Depending on your OS

Best Description here:
Disabling Windows XP AutoRestore feature
http://www.europe.f-secure.com/v-descs/sfc_dis1.shtml
In Windows Millenium there was a new feature introduced called System Restore. The new Windows XP has this feature. It creates backup copies of the essential system files so they can be restored if they get corrupted. Sometimes this makes disinfection difficult as backup files can get infected and copied to System Restore folder by Windows. Then after disinfection Windows will copy the infected file back over the clean ones.

System Restore feature can be disabled using the following steps:

1. Select Start/My Computer.
2. Click on "View system information".
3. Select the tab "System Restore".
4. Check the "Turn off System Restore on all drives" checkbox and click "Apply" button.
5. The program asks if you want to turn off System Restore. Click "Yes" button.
6. "Drive settings" has now turned to grey. Click "OK" button.
7. Windows XP System Restore feature is now disabled.

The System Restore feature can be enabled again with the same steps. At step 4. you have to uncheck the Turn Off System Restore on All Drives checkbox.

..............................
Disabling System Restore on Windows ME
http://www.europe.f-secure.com/v-descs/sfc_dis.shtml
In Windows Millenium there was a new feature introduced called System Restore. Windows ME creates backup copies of the essential system files so they can be restored if they get corrupted. Sometimes this makes the disinfection difficult since the backup files can get infected. In those cases Windows will copy the infected file in the place of the clean one.

This feature can be disabled with the following steps

1. Right-click on the My Computer icon and select Properties
2. In the System Properties windows select the Performance tab
3. Click on File System... button
4. In the Filesystem Properties window select the Troubleshooting tab
5. Check the Disable System Restore checkbox
6. Click Apply button
7. Close the windows using the Close button
8. Click Yes when prompted for reboot

The System Restore feature can be enabled again with the same steps. At step 5. you have to uncheck the Disable System Restore checkbox.


P.S. If you do not have Windows XP or Windows ME, don't worry about it as you don't have System Restore Smile

Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer