here's my hijack log, and im an infant in this game so please I'd appreciate any help. Ive already run ewido, ad aware se, spy bot, cc cleaner and AVG 7.1 and all of em updated. The issue is message window keeps popping on my screen every now and then giving some wierd messages.
Logfile of HijackThis v1.99.1
Scan saved at 4:55:50 AM, on 10/18/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
It varies from time to time :( when i right click on the application on windows task manager and select go to process it points to a file named csrss.exe
In the text box it says
*****
Message from SECURITY to ALERT on 10/18/2006 8:59:04 AM
STOP!
Registry Cleaner Recomended
to fix the errors please do the following
1.Download registry repair from www.regrinsepro.com
2.Install Registry repair
3.Run registry repair
4.Reboot your computer
FAILURE TO ACT NOW MAY LEAD TO DATA LOSS AND CORRUPTION
*******
and at the end there is an OK button. And its different varient of the same message all the time.
Im at a loss as to what this is :( im thinking Id better start backing up my files now.
No need to start backing up your data, it's just a scam. That's adware for us. :) Unfortunately, I can't get a name from just the website given.
Let's see if Kaspersky will pick it up.
Go here and run Kaspersky Online Scanner.
Accept the terms.
After downloading, click "My Computer".
After scanning, click "Save report as".
Save as a text file and post it.
Scan Statistics:
Total number of scanned objects: 70076
Number of viruses found: 2
Number of infected objects: 7 / 0
Number of suspicious objects: 0
Duration of the scan process: 02:35:43
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pyza7zlz.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pyza7zlz.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pyza7zlz.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pyza7zlz.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pyza7zlz.default\cert8.db Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pyza7zlz.default\history.dat Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pyza7zlz.default\key3.db Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pyza7zlz.default\parent.lock Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\_restore{FEEBD813-7060-4F65-AAE2-D58B4C0526A8}\RP104\change.log Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd9437.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\System Volume Information\_restore{33A53034-3654-4BC9-8E3E-16B04AE2C7A9}\RP19\A0039931.exe/data0001 Infected: Trojan-Downloader.Win32.Agent.oz skipped
H:\System Volume Information\_restore{33A53034-3654-4BC9-8E3E-16B04AE2C7A9}\RP19\A0039931.exe NSIS: infected - 1 skipped
H:\System Volume Information\_restore{33A53034-3654-4BC9-8E3E-16B04AE2C7A9}\RP202\A0305461.exe/VirtuallyJenna-2.017.002-cracked-installer.msi/_6A5BC9DCF6308413044425600E433DB7/_A072FB71F98447849289D58C552E0E01 Infected: Trojan-PSW.Win32.QQPass.ly skipped
H:\System Volume Information\_restore{33A53034-3654-4BC9-8E3E-16B04AE2C7A9}\RP202\A0305461.exe/VirtuallyJenna-2.017.002-cracked-installer.msi/_6A5BC9DCF6308413044425600E433DB7 Infected: Trojan-PSW.Win32.QQPass.ly skipped
H:\System Volume Information\_restore{33A53034-3654-4BC9-8E3E-16B04AE2C7A9}\RP202\A0305461.exe/VirtuallyJenna-2.017.002-cracked-installer.msi Infected: Trojan-PSW.Win32.QQPass.ly skipped
H:\System Volume Information\_restore{33A53034-3654-4BC9-8E3E-16B04AE2C7A9}\RP202\A0305461.exe RAR: infected - 3 skipped
H:\System Volume Information\_restore{33A53034-3654-4BC9-8E3E-16B04AE2C7A9}\RP202\A0305461.exe PE_Patch: infected - 3 skipped
J:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
J:\System Volume Information\_restore{FEEBD813-7060-4F65-AAE2-D58B4C0526A8}\RP104\change.log Object is locked skipped
tried the system restore option,still dint work. I tried disabling it and running it too and still it popped up. This is driving me nuts now. When i wake up in the morning i have to close the damn annoying window at least 30 time (no joke).
Click Start > Control Panel.
Double-click Administrative Tools.
Select Services > Double-click on Messenger.
In the Messenger Properties window, select Stop.
Choose Disable as the Startup Type.
Click OK.
im back after a format, cleaned out everything ! can you please recommend which softwares to use as protection ? i dont have a firewall or anything of the sort.
and which anti nasties software should i run and how often ?
a big thank you for all the advice and help you have gave me so far ! ive learnt quite a bit now.
The best tip I can give anyone is not use Internet Explorer unless needed.
Browsers Firefox <--My personal favorite.
Opera If you choose to keep IE or choose to switch to Firefox, I strongly recommend you get the McAfee Site Advisor plugin.