Jump to content
IObit Forum
Top Free Driver Updater Tools Best 25 PC Optimization Software Best 22 Antimalware Best 22 Uninstaller Software IObit Coupons & Discount Offers PC Optimizer Mac Boost Advice IObit Coupons A Good Utility Program From IObit IObit Promo Codes IObit Coupon Codes IObit Coupons and Deals FAQs Driver Booster Pro Review

suspected hijack


scrd01

Recommended Posts

ESET Online Scan

 

Scan your computer with the ESET FREE Online Virus Scan

 

* Click the ESET Online Scanner button.

 

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop

* Double click on the esetsmartinstaller_enu.exe icon on your desktop.

* Place a check mark next to YES, I accept the Terms of Use.

 

* Click the Start button.

* Accept any security warnings from your browser.

* Leave the check mark next to Remove found threats and place a check next to Scan archives.

* Click the Start button.

* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.

* When the scan completes, click List of found threats.

* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.

* Click the Back button then click Finish.

 

In your next reply please include the ESET Online Scan Log

Link to comment
Share on other sites

I take it your happy with things

I'm happy if you're happy. Let's do a few more scans.

 

SUPERAntiSpyware

 

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

 

Download SuperAntispyware Free Edition (SAS)

* Double-click the icon on your desktop to run the installer.

* When asked to Update the program definitions, click Yes

* If you encounter any problems while downloading the updates, manually download and unzip them from here

* Next click the Preferences button.

 

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts

* Click the Scanning Control tab.

* Under Scanner Options make sure only the following are checked:

 

•Close browsers before scanning

•Scan for tracking cookies

•Terminate memory threats before quarantining

Please leave the others unchecked

 

•Click the Close button to leave the control center screen.

 

* On the main screen click Scan your computer

* On the left check the box for the drive you are scanning.

* On the right choose Perform Complete Scan

* Click Next to start the scan. Please be patient while it scans your computer.

* After the scan is complete a summary box will appear. Click OK

* Make sure everything in the white box has a check next to it, then click Next

* It will quarantine what it found and if it asks if you want to reboot, click Yes

 

•To retrieve the removal information please do the following:

•After reboot, double-click the SUPERAntiSpyware icon on your desktop.

•Click Preferences. Click the Statistics/Logs tab.

 

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

 

•It will open in your default text editor (preferably Notepad).

•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

 

* Save the log somewhere you can easily find it. (normally the desktop)

* Click close and close again to exit the program.

*Copy and Paste the log in your post.

**************************************

http://img233.imageshack.us/img233/7729/mbamicontw5.gif Please download Malwarebytes Anti-Malware from here.

 

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.

Extra Note:

 

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

Link to comment
Share on other sites

sas log

 

Hi dave,

SAS log,will forward MBAM after completion

 

 

SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 10/09/2010 at 08:59 PM

 

Application Version : 4.44.1000

 

Core Rules Database Version : 5661

Trace Rules Database Version: 3473

 

Scan type : Complete Scan

Total Scan Time : 01:32:51

 

Memory items scanned : 688

Memory threats detected : 0

Registry items scanned : 9863

Registry threats detected : 0

File items scanned : 125062

File threats detected : 8

 

Adware.Tracking Cookie

C:\Users\Melaine\AppData\Roaming\Microsoft\Windows\Cookies\Low\melaine@ad.yieldmanager[2].txt

C:\Users\Melaine\AppData\Roaming\Microsoft\Windows\Cookies\Low\melaine@ads.bleepingcomputer[1].txt

C:\Users\Melaine\AppData\Roaming\Microsoft\Windows\Cookies\Low\melaine@collective-media[2].txt

C:\Users\Melaine\AppData\Roaming\Microsoft\Windows\Cookies\Low\melaine@media6degrees[2].txt

C:\Users\Melaine\AppData\Roaming\Microsoft\Windows\Cookies\Low\melaine@microsoftinternetexplorer.112.2o7[1].txt

C:\Users\Melaine\AppData\Roaming\Microsoft\Windows\Cookies\melaine@atdmt[2].txt

C:\Users\Melaine\AppData\Roaming\Microsoft\Windows\Cookies\melaine@atdmt[3].txt

C:\Users\Melaine\AppData\Roaming\Microsoft\Windows\Cookies\melaine@atdmt[4].txt

 

 

 

 

roy

Link to comment
Share on other sites

add to prev

 

Here's the OTS log, I thought I'd post it instead of attaching it as its so small:

 

[Files/Folders - Modified Within 30 Days]

C:\Users\Grizzle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.

 

this file is in the docs file also found a second suspect file associated with it any thoughts

 

Roy

Link to comment
Share on other sites

* Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.

* Now type commy /uninstall in the runbox

* Make sure there's a space between commy and /Uninstall

* Then hit Enter

 

* The above procedure will:

* Delete the following:

* ComboFix and its associated files and folders.

* Reset the clock settings.

* Hide file extensions, if required.

* Hide System/Hidden files, if required.

* Set a new, clean Restore Point.

 

*********************************

1.Double click OTM to launch it.

Vista users right click and choose Run As Administrator

2. Click on the CleanUp! button.

3. OTM will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.

4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)

5. When finished exit out of OTM.

 

*************************************

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

 

Double-click TFC.exe to run it.

 

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

 

TFC will close all programs when run, so make sure you have saved all your work before you begin.

 

* Click the Start button to begin the cleaning process.

* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.

* Please let TFC run uninterrupted until it is finished.

 

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

 

**************************************

Remember only install ONE firewall

 

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)

2) Online Armor

3) Agnitum Outpost

4) PC Tools Firewall Plus

 

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

**********************************************

Please run this scan for administrations purposes.

 

* Open IObit Security 360.

* Click the Update button and download any available updates.

* Choose Quarantine threats when removing them in Scan Parameters of Scan Setting in Options.

* Click Apply and OK buttons.

* Next (on the left) click the Scan button.

* Choose the Full Scan (Scan all hard drives in your computer) option to begin the scan.

* Once the scan has completed click Remove

* Next click Save a Report

* Post the IObit Security 360.log in your next reply.

****************************************************

Use the Secunia Software Inspector to check for out of date software.

 

•Click Start Now

 

•Check the box next to Enable thorough system inspection.

 

•Click Start

 

•Allow the scan to finish and scroll down to see if any updates are needed.

•Update anything listed.

.

----------

 

Go to Microsoft Windows Update and get all critical updates.

 

----------

 

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

 

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.

* Using SpywareBlaster to protect your computer from Spyware and Malware

* If you don't know what ActiveX controls are, see here

 

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

 

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

 

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.

Safe Surfing!

Link to comment
Share on other sites

admin post 360

 

Hello, Dave

 

clean up done

I360 report enclosed

 

IObit Security 360

 

OS:Windows Vista

Version:1.5.0.13

Define Version:1841

Time Elapsed:01:08:46

Objects Scanned:170576

Threats Found:1

 

|Name|Type|Description|ID|

Tracking Cookies - Removed, Cookies, Cookie:melaine@atdmt.com/, 7-1541

 

 

Thanks again for all your help

 

 

Roy

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...