Heres my thingy please help this is the third time i ask for help my comp gone crazy on me!!!
Logfile of HijackThis v1.99.1
Scan saved at 6:25:23 PM, on 10/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
My name is dobhar and I will be looking over your log. Looks like you have some "Nasties" so please give me some time to go look it over and I will post back as soon as possible. If you have any questions please post back as a reply to this Thread\Topic and I will be advised by email so I can return and help you. Do not start another Thread\Topic.
dude i dont know what OS is im just 13 so please when u tell me something please tell me all the steps. thank you so much for attending me :smileyvery-happy:
You posted => "
dude i dont know what OS is im just 13 so please when u tell me something please tell me all the steps". OS means Operating System...like Windows XP.
You have a couple Nasties...like a LOP Infection...
I first have a question...as per the entry below, what is
2locks.exe. I cannot find any info on this file
O4 - HKCU\..\Run: [mags fork] C:\DOCUME~1\Elin_2\APPLIC~1\BOOKMA~1\2locks.exe
Let's get to it...
__________________________________________________________________
Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) availble to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes. ________________________________________________________________________
Step 1. ========== We need to uninstall some programs
(if found in list) using "
Add or Remove Programs" in the Control Panel:
- Get into
Control Panel.
- Double-click "
Add or Remove Programs".
- Look in the
Currently installed programs box for each program listed below and if it is there:
- Click on it to select it.
- Click "
Change/Remove" (or "
Change") button.
- If you are prompted to confirm the removal of the program, click "
Yes"
Lop.com LOP SEARCH Window Searching Window Active Search Plugin Browser Enhance r Brows er Enhancer Ultimate Browse r Enhancer Ultimate Browser En hancer L.O P. Un insta11 L O.P. Un instal1 Live 0n line Portal Live.0nli ne Porta1
Step 2. ========== - Open Microsoft AntiSpyware.
- Click on
Tools, Settings. - In the left pane, click on
Real-time Protection. - Under
Startup Options uncheck
Enable the Microsoft AntiSpyware Security Agents on startup (recommended). - Under
Real-time spyware threat protection uncheck
Enable real-time spyware threat protection (recommended). - After you unchecked these, click on the
Save button and close Microsoft AntiSpyware.
- Right click on the Microsoft AntiSpyware Icon on the taskbar and select
Shutdown Microsoft AntiSpyware.
Step 3. ========== - Start Notepad
- Copy/paste the following
BOLD text below into a new Notepad text file.
Quote: @ECHO OFF dir %Windir%\tasks /a h > files.txt notepad files.txt del /q files.txt
- Save it to your Desktop as
findjobs.bat.
- File Name:
findjobs.bat; Save it as: File Type:
All Files (*.*)
(Note: not as a text document or it wont work)
- Locate the
findjobs.bat on your Desktop and double-click it
- When notepad opens,
copy/paste the content in your next reply
- When you close Notepad the CMD window will close automatically and the text file will be deleted.
Step 4. ========== - Reboot computer into "
Safe Mode" Using the
F8 method:
- As soon as the
BIOS is loaded begin
tapping the F8 key until the
Boot Menu appears
- Use the arrow keys to select the
Safe Mode menu item
(Note: For additional help in booting into Safe Mode, see the following site - http://www.pchell.com/support/safemode.shtml)
Step 5. ========== We need to make sure all Hidden Files are showing so please:
* Open "
My Computer" then click on "
Tools" and from the drop down menu select "
Folder Options".
* Select the "
View" tab.
* Under the "
Hidden files and folders" heading SELECT "
Show hidden files and folders".
* UNCHECK the "
Hide file extensions for known types option".
* UNCHECK the "
Hide protected operating system files (recommended) option".
* Click "
Yes" to confirm.
* Click "
OK"
Step 6. ========== - Make sure Microsoft Antispyware is disabled
- Close all Windows and programs
- Run
HijackThis...
-
Select\check the following entries,
Double-check to make sure that only these entries are checked...
- Click the "
Fix checked" button...
- Close HijackThis
Step 7. ========== We now need to cleanup all the
Temp, Temorary Internet Files, Recycle Bin, etc... - Start the
CCleaner program
- Get into "
Options" => Select "
Advanced" => Deselect\uncheck "
Only delete files in Windows Temp folders older than 48 hours"
- We are only going to work with the "Cleaner" section.
(Note: Do not use the "Issues" section)
- click on the
Run Cleaner button in the lower right-hand corner
- After complete close program
- Make sure the recycle Bin is empty
Step 8. ========== Run Panda's online virus scan from
http://www.pandasoftware.com/products/activescan.htm and perform a full system scan.
- Once you are on the Panda site click the "
Scan your PC" button
- A new window will open...click the big "
Check Now" button
- Enter your
Country - Enter your
State/Province - Enter your
e-mail address and click
send - Select either
Home User or Company - Click the big
Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
- Click on "
Local Disks" to start the scan
- Post Panda scan results in your next reply
Step 9. ========== - Reboot your computer back into "
Normal Mode"
- Post back a fresh new HijackThis log
- Post back the Panda ActiveScan results
- Post "Findjobs" results
- Make sure you have re-enabled MSAS (Microsoft Antispyware)
It has been 7 days since I last heard from you. I will be monitoring this thread for another 7 days. If unanswered at the end of those 7 days I will be considering this topic closed and will not be monitoring it for replies.
sorry well this is what i got man....i couldnt do the panda thing because it kept on freezing and it often closed on its own so i got angry and didnt try it again. tried it about 6 times....
This is the Findjobs.bat thing:
Volume in drive C has no label.
Volume Serial Number is AC26-01C5
Directory of C:\Documents and Settings\Elin_2\Desktop
My Hijackthis file:
Logfile of HijackThis v1.99.1
Scan saved at 7:38:30 PM, on 10/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
First of all please do not wait 7 days before replying back...The fixes I tell you to do on day 1 may not work on day 7. If you want you PC cleaned up I would really appreciate that you reply back as soon as possible or if you cannot run the fixes for a few days can you please let me know.
Before we go any further I need to know a few things...
1) Have you installed some software since your last log? I am seeing items in it that I did not see before.
- Your version of
BearShare...is it the paid or free version. The free version has spyware or other unwanted parasites bundled into it. I'm guessing you installed the "FREE" version as you now have the
WhenUSave "Nasty" installed on your PC.
Please have a look at this SpywareInfo page =>
http://www.spywareinfo.com/articles/p2p/
- "barb internet enc creative"...Can you tell me what this is...
Vga Download.exe
- "C:\DOCUME~1\Elin_2\APPLIC~1\CORNLO~1\ooze gpl.exe"...Can you tell me what this is. I'm pretty sure this is a "Nasty" but I need to be positive. What is the full name for the folder "CORNLO~1". You will find it in "C:\Documents and Settings\Elin_2\Application Data\CORNLOxxxxxxx <<<= Please fill in the x's
- I asked you in my last post if you knew what this was -
2locks.exe. I'm also pretty sure this is also a "Nasty" but once again I need to make sure. What is the full name of the folder "BOOKMA~1". You will find it in C:\Documents and Settings\Elin_2\Application Data\BOOKMAxxxxx <<<= Please fill in the x's
2) After going through your HijackThis log I am not seeing any evidence of an Antivirus program installed on your PC. That is not good. :( You need an AV installed immediately otherwise your just going to get infected again and we would be doing this all over again. I can recommend a good "FREE" (also spyware free) AV program called AVG 7.0. It is quite easy to install. Please download and install AVG 7.0 from...
- Download AVG 7.0 location =>
http://free.grisoft.com/softw/70free/setup/avg70free_344a618.exe - A Reference Guide can be found (note: It is in PDF format...Adobe Reader is needed =>
http://free.grisoft.com/softw/70free/doc/avg_fre_ref_en_70_12.pdf _______________________________________
Please reply back as soon as possible with answers to my questions. Also after installing AVG 7.0 please post back a fresh new HijackThis log.
This Thread\Topic is closed due to lack of responce from poster. I have stopped monitoring it for replies. If you still require assistance please start a new thread and post a fresh new HijackThis log. One of our volunteers will be glad to help you. :)
chadwinn
2 Posts
1097
0
Posted October 4th, 2005 00:00