TechSpot

Need help with virus

By WTFMan
Mar 31, 2008
Topic Status:
Not open for further replies.
  1. I am receiving several popups which leads me to believe that my machine is infected. The messages are exactly the ones in tariqalimohamed's thread (unable to link since I'm a newbie), but I figured in case there were unique issues on my own machine that my own HIJackThis log should be posted and gone through.

    Can someone assist?

    Thanks for your help.
  2. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Stop this startup and uninstall:
    C:\Program Files\Trillian\trillian.exe
    Filename: trillian.exe
    Description: Added by a variant of the AGOBOT/GAOBOT WORM!

    Remove this: O8 - Extra context menu item: &NeoTrace It!
    It's one source of the pop-ups.

    Winsock LSP- ALL of these are Winsock hijackers (010)

    you're showing 21 Registry startups (04)- WAY too many! Stop hat you don't need to start at boot and run in the background

    You have a very high number (16) of non-Microsoft services running (023). This can be a security risk so check all and determine if they are legitimate and need to be running.

    You are running AdAware 2007, SpyCatcher, Spybot S&B and it's Tea Timer in Real Time, AVG anti-spyware, More than 1 in Real Time can cause a conflict.

    You have a large number of server and network processes running. Do you use them all? Are they secure?

    This is just a head start to give you an idea of what's going on. Jobeard will be along to "officially" go through your log and direct you are removal options.
  3. Blind Dragon

    Blind Dragon TS Evangelist Posts: 4,048

  4. WTFMan

    WTFMan TS Rookie Topic Starter

    Here are the current logs. I went though those instructions and still have pop-ups referring me to buy that fake anti-spyware stuff.
  5. Blind Dragon

    Blind Dragon TS Evangelist Posts: 4,048

    CFScript

    Open notepad and copy/paste the text in the code box below into it:
    NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
    Also ..

    Pay particular attention to this :-

    Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
    Save this as CFScript.txt

    Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.

    [​IMG]

    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log.


    Download and Run ATF Cleaner
    Download ATF Cleaner by Atribune to your desktop.

    Double-click ATF Cleaner.exe to open it.

    Under Main choose:
    Windows Temp
    Current User Temp
    All Users Temp
    Cookies
    Temporary Internet Files
    Prefetch
    Java Cache

    *The other boxes are optional*
    Then click the Empty Selected button.

    Firefox or Opera:
    Click Firefox or Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    Click Exit on the Main menu to close the program.
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.