Your Computer Is Infected!

Discussion in 'Gaming' started by pimpy101, Dec 31, 2005.

  1. pimpy101

    pimpy101 Well-Known Member

    Posts:
    482
    Likes Received:
    0
    Joined:
    May 22, 2005
    Okay, i recently went to a porn site and downloaded a codec which basically f*ck comp, atleast i admitted that i learned my lesson and will never ever download porn again. Anyways im on windows media center and the only spyware remover i have is Ad-aware.....anyways i keep getting this annoying message which is really really making me angry

    [​IMG]

    Please is there someway to get rid of that annoying message i know im infected it that keeps coming up so annoying and any other tips on how i can remove this infection... i swear if anyone helps i will truely be greatfull
     
  2. Carbon.

    Carbon. Well-Known Member

    Posts:
    2,099
    Likes Received:
    0
    Joined:
    Oct 24, 2005
    hmmm never seen that sorry cant help you.
     
  3. beatsta

    beatsta Well-Known Member

    Age:
    36
    Posts:
    2,123
    Likes Received:
    0
    Joined:
    May 22, 2005
    Location:
    Birmingham, england
    Run a hijackthis scan and post the logfile.
     
  4. dj_VeNoM

    dj_VeNoM Member

    Posts:
    9
    Likes Received:
    0
    Joined:
    Sep 28, 2005
    Have you tried actually running anti-ware products?

    Not just an anti-virus program, but anti-spyware, such as SpyBot Search and Destroy.
     
  5. pimpy101

    pimpy101 Well-Known Member

    Posts:
    482
    Likes Received:
    0
    Joined:
    May 22, 2005
    i ran ad-aware and microsoft spyware thing :blink:
     
  6. .Faith

    .Faith Well-Known Member

    Posts:
    443
    Likes Received:
    0
    Joined:
    Jun 18, 2005
    if your isp is ntl.

    you can download there free anti virus from there site
     
  7. King Chaos

    King Chaos Well-Known Member

    Posts:
    124
    Likes Received:
    0
    Joined:
    Aug 25, 2005
  8. Deathwing

    Deathwing Well-Known Member

    Posts:
    684
    Likes Received:
    0
    Joined:
    Nov 4, 2005
    NEVER DOWNLOAD PORN. You will get infected with all sorts of crap. Once got redirected to a website by mistake, didn't download anything and ended up receiving 364 viruses 184 trojans and thousands upon thosands of spyware and adware.
     
  9. Equivalent Exchange

    Equivalent Exchange Well-Known Member

    Posts:
    1,466
    Likes Received:
    0
    Joined:
    Nov 9, 2005
    http://www.download.com/HijackThis/3000-80...tml?tag=lst-0-1

    Download, and run. DO NOT ATTEMPT TO FIX ANYTHING. Just post the big log it generates.

    Again, DO NOT ATTEMPT TO FIX ANYTHING WITH HIJACKTHIS.

    :)
     
  10. J.B

    J.B Member

    Posts:
    12
    Likes Received:
    0
    Joined:
    Dec 30, 2005
    Meh personely...I would run my spyware stuff...um there are a few websites that will look at ur pc but wont really delete anything...thta is fine...if ya are not an idoit with PCs then ya can open the Directory...after ya save it of course...then go to Google and type in the program tjhat a website gave ya and say remove after it...ya will get about a million hate sites and one or two sites that will tell ya how to manualy remove it.,..that is what I use to do...but now I got Mcfee and it wont even let that file in...and if ya wanna download porn...use firefox...it saves all download info to a special file that is coded with stuff so noffin can come out...if that made no sense wat so ever...well I am srry and I can slow down next time...
     
  11. beatsta

    beatsta Well-Known Member

    Age:
    36
    Posts:
    2,123
    Likes Received:
    0
    Joined:
    May 22, 2005
    Location:
    Birmingham, england
    Check to see if you can open up taskmanager.
     
  12. pimpy101

    pimpy101 Well-Known Member

    Posts:
    482
    Likes Received:
    0
    Joined:
    May 22, 2005
    no, i cant...

    this is the hijack file
    Logfile of HijackThis v1.99.1
    Scan saved at 9:26:09 PM, on 12/31/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\mssearchnet.exe
    C:\WINDOWS\system32\nvctrl.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Digital Media Reader\shwiconem.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
    C:\WINDOWS\zHotkey.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\ALCWZRD.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Winamp\winampa.exe
    C:\PROGRA~1\McAfee.com\Agent\McRegWiz.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\SpyAxe\spyaxe.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\SpyAxe\spyaxe.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\Stomp\RecordNow MAX\MyCDPro.exe
    C:\Program Files\Stomp\RecordNow MAX\Wizard\MyCD.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\PROGRA~1\MSNGAM~1\zproxy.exe
    C:\PROGRA~1\MSNGAM~1\zone.exe
    C:\PROGRA~1\MSNGAM~1\zclient.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.875\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gatewaybiz.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
    O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hp8E45.tmp
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
    O4 - HKLM\..\Run: [Mixersel] C:\Program Files\Realtek\InstallShield\mixersel.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\McRegWiz.exe /autorun
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [SpyAxe] C:\Program Files\SpyAxe\spyaxe.exe /h
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha...v45/yacscom.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
    O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures04.aim.com/ygp/aol/plugin/u...AIM.9.5.1.8.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab34246.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
     
  13. Land Shark

    Land Shark Well-Known Member

    Posts:
    250
    Likes Received:
    0
    Joined:
    Jun 2, 2005
    just reformat, its the only way to know that a virus has been completely deleted from your comp.
     
  14. pimpy101

    pimpy101 Well-Known Member

    Posts:
    482
    Likes Received:
    0
    Joined:
    May 22, 2005
    i think i am.... now to sound like a newb again but how exactly do you refomat i saved all my files to disc so im ready...the way ive been doing it is with my system restore disc is that the proper way?
     
  15. Ohms Law JR.

    Ohms Law JR. Well-Known Member

    Age:
    35
    Posts:
    1,621
    Likes Received:
    0
    Joined:
    Sep 30, 2005
    Location:
    Lakeland, FL
    i had this same thing it turned out to be a joke

    i did a system restore to the other day and i was back yp and running like i was
     

Share This Page