Hijacked virginity stolen, please help

By Legion_Beef ยท 7 replies
May 22, 2008
  1. Hello,

    I recently downloaded some software from a torrent site and it seemed to work ok but I wasn't impressed with it so I deleted it. Shortly afterwards I was confronted by 'that big blue screen' error that I used to get when using Limewire (the one saying its shutting me down to protect my pc).

    I've had some advice about it as my mate says "you've been hijacked" and suggested to download spybot: S&D, which I somehow managed. I also used the system restore to return to the day before I installed the software and it stated that this would be before the date of the software I had installed which worked for me. Spybot found 18 problems and I've killed them and it seems to consistantly find something wrong after every scan and it keeps asking me to 'allow' or 'deny' changes but I dont know what any of them mean as its all technical jargon. I keep getting odd popups that are clearly not the normal internet, my browser is still google, but no web pages will load, my cookies keep getting reset to 'allow all' and my 'automatic updates' keep being turned off and I cant turn them back on unless I restart my machine and finally, a small back square (ms dos) screen keeps appearing and then I get a box asking to 'close' or 'ignore' and I dont know which to choose. My pc is a Dell E521, 500gig, dualcore processor etc if that changes anything.

    I've read that hijackthis is meant to be good, and I've seen some posts on here from other people being hijacked, but they all seem to be from quite a while ago so I dont know if the help given at that time would still work now considering how fast the net changes/updates.

    Is there any hope for my machine?

    All help much appreciated


    p.s. I also use avg (not the full version) and it has found a few trojans and managed to kill / move them to the vault - previous errors that I've overcome: disabled task manager menu and a fake spyware killer called 'winspyware' that has ceased to plague me now.
  2. kimsland

    kimsland Ex-TechSpotter Posts: 14,523

  3. Legion_Beef

    Legion_Beef TS Rookie Topic Starter

    my log file...

    I have also managed to download hijackthis and this is the log file. It means nothing to me (ah vienna), but maybe someone on here knows what I need to 'fix' out of this list.


  4. kimsland

    kimsland Ex-TechSpotter Posts: 14,523

    Is it possible you have Mcafee and AVG7 Antivirus software running together?

    I'd say uninstall both (yes both) from Add/Remove programs
    Then download and run the new and improved AVG Ver 8 (and it's free !)

    Do a full update, then a full scan
  5. jobeard

    jobeard TS Ambassador Posts: 11,128   +982

    here's two that needs attention
    O4 - HKLM\..\Run: [BMabad0d1e] Rundll32.exe "C:\WINDOWS\system32\ujxthgev.dll",s
    O4 - HKLM\..\Run: [a89e3e82] rundll32.exe "C:\WINDOWS\system32\esjgcviv.dll",b
    Spybot has attempted to clean these -- verify that they are removed

    O4 - HKLM\..\RunOnce: [SpybotDeletingA1792] command /c del "C:\WINDOWS\system32\ddcDuUMc.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6504] cmd /c del "C:\WINDOWS\system32\ddcDuUMc.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2776] command /c del "C:\WINDOWS\system32\byXNddbB.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1650] cmd /c del "C:\WINDOWS\system32\byXNddbB.dll_old"​
  6. Blind Dragon

    Blind Dragon TS Evangelist Posts: 3,908

    You need to follow the link that kimsland provided above as some of those entries should be dealt with.
  7. Legion_Beef

    Legion_Beef TS Rookie Topic Starter

    some success

    Hi and thankyou for any responses

    I uninstalled both of them and installed avg 8, which has cleared up alot of problems as I can get my task manager up now, and my cookies have stopped changing to allow all, but my internet isn't working fully. Msn works fine, and I can get onto google, but I keep getting error after logging onto my pc but I dont know what they mean. I'll make a note of them when they next come up and see if they ring any bells.... meanwhile I'll print off everything on this page as I cant access this site from home as other than google every other page times out.


  8. kimsland

    kimsland Ex-TechSpotter Posts: 14,523

    Run Startup Control Panel and remove those invalid startup links (Usually all except AVG8)

    Make sure that you check all tabs in that program.
Topic Status:
Not open for further replies.

Similar Topics

Add your comment to this article

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...