ericagm

Members
  • Content Count

    14
  • Joined

  • Last visited

About ericagm

  • Rank
    Member
  1. I couldn't figure out how to view the log. Here is what I got: 8/11/2008 3:21:30 AM:437 Immunizer Results ActiveX section has been immunized. No items were processed. 8/11/2008 9:24:05 AM:0 Immunizer Results ActiveX section has been immunized, Processed 2 items. 8/11/2008 1:41:41 PM:750 Service Stopped Spyware Doctor Service Application Stopped 8/11/2008 1:43:26 PM:140 Service Started Spyware Doctor Service Application started 8/11/2008 1:43:26 PM:156 OnGuards status All OnGuards were Enabled 8/11/2008 1:43:26 PM:906 Immunizer Results ActiveX section has been immunized. No items we
  2. I haven't heard the random sound clips yet!!! phew! I re-ran Spy Doctor and it said I had A LOT of infected files with Application.TrackingCookies, Adware.Advertising, and Spyware.Known_Bad_Sites. Is this the same issue? or something completely different? I click to Clean the files, but every time I re-scan, files continue to be infected. I'm not sure if this is related to my previous problem??
  3. When I reran Hijack This, these did not show up: O23 - Service: afinding Service (afinding) - Unknown owner - C:\WINDOWS\system32\AFinding.exe (file missing) O23 - Service: macidwe Service (macidwe) - Unknown owner - C:\WINDOWS\system32\macidwe.exe (file missing) O23 - Service: NOBICYT Service (NOBICYT) - Unknown owner - C:\WINDOWS\system32\Nobicyt.exe (file missing) O23 - Service: perfs Service (perfs) - Unknown owner - C:\WINDOWS\system32\perfs.exe (file missing) O23 - Service: routing Service (routing) - Unknown owner - C:\WINDOWS\system32\routing.exe (file missing) O23 - Service: sobicyt
  4. OTMoveIT2 Log: Explorer killed successfully Service not present: afinding. Service not present: macidwe. Service not present: NOBICYT. Service not present: perfs. Service not present: routing. Service not present: sobicyt. Service not present: tdxdowkc. Service not present: wserving. C:\WINDOWS\system32\AFinding.exe moved successfully. C:\WINDOWS\system32\macidwe.exe moved successfully. C:\WINDOWS\system32\Nobicyt.exe moved successfully. C:\WINDOWS\system32\perfs.exe moved successfully. C:\WINDOWS\system32\routing.exe moved successfully. C:\WINDOWS\system32\sobicyt.exe moved successfully. C:\
  5. OOOOPs i didn't do the second part. I just saw that! let me do it now and post the new log. Sorry about that.
  6. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:50:07 AM, on 8/10/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\AFinding.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\
  7. Thanks for the steps. Here is my recent log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:28:34 AM, on 8/10/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\AFinding.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\C
  8. I found it: Deckard's System Scanner v20071014.68 Run by EricaGM on 2008-08-07 18:40:09 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 87: 2008-08-07 22:40:27 UTC - RP468 - Deckard's System Scanner Restore Point 86: 2008-08-06 21:21:38 UTC - RP467 - Spyware Doctor: Cleaning Threats 85: 2008-08-06 21:20:53 UTC - RP466 - Spyware Doctor: Cleaning Threats 84: 2008-
  9. I posted the only log that came up on a notepad. Where can I find this missing log on my computer? Thanks
  10. OTMoveIt2 C:\Documents and Settings\EricaGM\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-3ad601a5-526d3b9d.zip moved successfully. C:\Documents and Settings\EricaGM\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-6a9bb2f0.zip moved successfully. File/Folder C:\WINDOWS\system32\afinding.exe not found. C:\WINDOWS\system32\atsxyzd.sys moved successfully. C:\WINDOWS\system32\ceswxfst.sys moved successfully. C:\WINDOWS\system32\cexwxfst.sys moved successfully. C:\WINDOWS\system32\cfexfst.sys moved successfully. C:\WINDOWS\system32\nftscpd.
  11. Thank you for the detailed steps. Easy to follow. Here are both logs, Kaspersky first: Thursday, August 7, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Thursday, August 07, 2008 18:37:50 Records in database: 1067337 Scan settings Scan using the following database extended Scan archives yes Scan mail databases yes Scan area My Computer C:\ D:\ E:\ Scan statistics Files scanned 90765 Threat name 52 Infected objects 91 Suspicious objects 0 Duration of the scan 02:48:5
  12. Thank you for replying to me!! Please let me know what the next steps are. I really appreciate your help in this. Here is my HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:24:59 PM, on 8/6/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\W
  13. Hi, I've recently been hearing sound clips that pop up at random times. I hear anything from music bits, to movie previews, etc. Spyware Doctor detects Trojan.Dowloader but cannot remove it. I don't know how to clean my computer of this malware. Someone, please help!