Shaun
Members-
Content Count
22 -
Joined
-
Last visited
Content Type
Profiles
Forums
Calendar
Everything posted by Shaun
-
Winfixer And About:blank Keeps Popping Up And Freezing Ie
Shaun replied to Shaun's topic in Malware Removal
i did everything above except i didnt see a log for active scan...but it said it found nothing here are the other two logs... Logfile of HijackThis v1.99.1 Scan saved at 7:14:58 PM, on 12/21/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ACS.exe c:\Program Files\Common Files\Symantec Sh -
Winfixer popups and a few other pop ups keep popping up and then it freezes IE. here is my HJT log...can anyone help? I've run Spysweeper and Spybot s&d but things are still messed up... Logfile of HijackThis v1.99.1 Scan saved at 4:26:23 PM, on 12/21/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\W
-
After The Spies Are Removed Some Funny Things Happening With My Ie
Shaun replied to Shaun's topic in Malware Removal
hey Dragon, things seem to be running better...to let you know i also had to do something with deleting the old cache for the disk cleanup and i got it to run then...but thanks again...things seem to be working better...thanks again! ~Shaun -
After The Spies Are Removed Some Funny Things Happening With My Ie
Shaun replied to Shaun's topic in Malware Removal
hey dragon, I tried to do the disk cleanup and i let it run for over a day and a half and it never got past the "calculating space that will be saved" part of the run. On the bottom of the window is said "compress old files" but it had 2 bars in the progress thing and never moved since it started. Not sure why its not working? any help? i tried to come into the chat room you werent there... thanks, Shaun -
After The Spies Are Removed Some Funny Things Happening With My Ie
Shaun replied to Shaun's topic in Malware Removal
hey dragon, I'm about to run disk cleanup but my boot time is really bad...like 5min. not exxagerating...use to take maybe 1.5-2max. after the windows load screen where the little green bar scrolls the screen goes black and pauses for about 2min. then goes to the windows log on. i have added one startup program, being spy s&d teatimer starts up but i dont think that should cause the boot time length. any help? -
After The Spies Are Removed Some Funny Things Happening With My Ie
Shaun replied to Shaun's topic in Malware Removal
Thanks so much...things seem to be working properly now as far as i can tell...boot up time seems a little slow...but i havent tried since running killbox. anything else i should do? besides keep my wife from clicking IM links about checking out pictures... -
After The Spies Are Removed Some Funny Things Happening With My Ie
Shaun replied to Shaun's topic in Malware Removal
WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding. If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly. »»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Product Name: Microsoft Windows XP Current Build: Service Pack 1 Current Build Number: 2600 Internet Explorer Version: 6. -
After The Spies Are Removed Some Funny Things Happening With My Ie
Shaun replied to Shaun's topic in Malware Removal
WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding. If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly. »»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Product Name: Microsoft Windows XP Current Build: Service Pack 1 Current Build Number: 2600 Internet Explorer Version: 6. -
After The Spies Are Removed Some Funny Things Happening With My Ie
Shaun replied to Shaun's topic in Malware Removal
******** 8:59 PM: | Start of Session, Monday, December 12, 2005 | 8:59 PM: Spy Sweeper started 8:59 PM: Sweep initiated using definitions version 582 8:59 PM: Starting Memory Sweep 9:02 PM: Memory Sweep Complete, Elapsed Time: 00:02:50 9:02 PM: Starting Registry Sweep 9:02 PM: Registry Sweep Complete, Elapsed Time:00:00:18 9:02 PM: Starting Cookie Sweep 9:02 PM: Found Spy Cookie: websponsors cookie 9:02 PM: [email protected][2].txt (ID = 3665) 9:02 PM: Found Spy Cookie: adserver cookie 9:02 PM: brandi@adserver[1].txt (ID = 2141) 9:02 PM: Found Spy Cookie: atwola cookie -
After The Spies Are Removed Some Funny Things Happening With My Ie
Shaun replied to Shaun's topic in Malware Removal
So i checked and still the same...banner ads dont load which isnt a bad thing persay but on myspace none of the music players load. I'm only running spysweeper...any help? -
After The Spies Are Removed Some Funny Things Happening With My Ie
Shaun replied to Shaun's topic in Malware Removal
I am currently running AVG, Spy Sweeper, Spyware Guard, and i was running Ewido. i have since uninstalled Ewido. in my spy sweeper shield options the common ad shield was unticked. so i dont think it was spy sweeper. I have to go and check if uninstalling Ewido fixed the problem. I defragged last night and went to bed and never checked my laptop this morning and just went to work. so i dont know if it fixed the problem. I will post in a little bit. thanks -
Logfile of HijackThis v1.99.1 Scan saved at 5:37:05 PM, on 12/9/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS
-
Log of AproposFix v1 ************ Running from directory: C:\Documents and Settings\Brandi\Desktop\aproposfix ************ Registry entries found: ************ No service found! Removing hidden folder: No folder found! Deleting files: Backing up files: Done! Removing registry entries: REGEDIT4 Done! Finished! *************************************************************************** Logfile of HijackThis v1.99.1 Scan saved at 5:30:04 PM, on 12/9/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\Sys
-
Logfile of HijackThis v1.99.1 Scan saved at 5:09:25 PM, on 12/9/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS
-
******** 3:15 PM: | Start of Session, Friday, December 09, 2005 | 3:15 PM: Spy Sweeper started 3:15 PM: Sweep initiated using definitions version 582 3:15 PM: Starting Memory Sweep 3:16 PM: Found Adware: icannnews 3:16 PM: Detected running threat: C:\WINDOWS\system32\omesvr32.dll (ID = 83) 3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 3:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 3:16 PM: The Spy Communication shield has bl
-
I did option 2 gave me the same log as before... L2mfix Beta 120305 Creating Account. The command completed successfully. Adding Administrative privleges. The command completed successfully. Checking for L2MFix account(0=no 1=yes): 1 Granting SeDebugPrivilege to L2MFIX ... successful C:\WINDOWS\System32\D0C2D0F9-13D3-4C9E-8DDC-B617D7B3632B.reg Checking for L2MFix account(0=no 1=yes): 0
-
It fell in the txt file report instead of log...i think L2MFIX find log 120305 These are the registry keys present ******************************************************************************** ** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlx
-
Ok here it is... L2mfix Beta 120305 Creating Account. The command completed successfully. Adding Administrative privleges. The command completed successfully. Checking for L2MFix account(0=no 1=yes): 1 Granting SeDebugPrivilege to L2MFIX ... successful C:\WINDOWS\System32\77BC4A9A-46DF-4E18-A6D5-12209A07A610.reg C:\WINDOWS\System32\C7741FA0-BD2B-4710-BF02-45A4DE1FCBFF.reg C:\WINDOWS\System32\CD882CA8-441B-40CC-BCD7-259682558DBB.reg Checking for L2MFix account(0=no 1=yes): 0 ************************************************************************** Logfile of HijackThis v1.99.1 Scan saved
-
L2MFIX find log 120305 These are the registry keys present ******************************************************************************** ** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Wind
-
Logfile of HijackThis v1.99.1 Scan saved at 1:31:20 PM, on 12/9/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS