Bree26

Members
  • Content Count

    38
  • Joined

  • Last visited

Everything posted by Bree26

  1. Logfile of HijackThis v1.99.1 Scan saved at 7:17:36 PM, on 6/30/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:
  2. Thank you! I'll just start all over again with a new topic.
  3. OK...what do I have to do to get an answer to my post below: "Sweepstakes.com driving me crazy" and get this resolved? It has been over a week since the last response, I did what I was told to do and posted it and I've been waiting for an answer since then. In the meantime, my computer is giving me multiple Windows Explorer error messages, running incredibly slow, and just seems messed up in general. If you can't answer my questions here, please direct me to another website, etc. that can. Thank you!
  4. OK...I posted what I was asked for last Thursday and have been waiting patiently for a reply; I understand weekends, summer, whatever,etc., but I still have no idea whether my comp is reinfected or not and AVG keeps finding 23 objects every morning when it runs a scan. I'd appreciate any kind of reply before an entire week goes by, please... And my Windows Task Manager shows CPU Usage running between 50%-to an amazing 100% and a page file usage of 1.67-1.75 GB. Firefox is running at 37,772 K it was a high of 69,000-something), SpywareDoctor at 24,616 K and AIM at 23,832 K. I have no idea w
  5. Rootkit Revealer: HKLM\SOFTWARE\Classes\webcal\URL Protocol 3/3/2005 2:26 AM 13 bytes Data mismatch between Windows API and raw hive data. Hijack This Log: Logfile of HijackThis v1.99.1 Scan saved at 11:44:49 AM, on 6/22/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOW
  6. I set up a new account and it started even stranger behavior. When I tried to switch from the new user (named, quite originally, "Test") to my account, which is password protected, I couldn't enter the last two characters of my password. As soon as I would type the second-to-last character, it would highlight the Test icon as if I were attempting to log on to that account. So I chose to log on to my daughter's account and it went through without a hitch. Then I tried to log on to my son's account from daughter's acctount - no go; had to use the ctrl/alt/del method. I removed the password
  7. I downloaded ZoneAlarm yesterday. Still trying to figure out what to allow and what not to allow, but we'll get it eventually. Would ZoneAlarm cause iTunes to randomly drop some songs from my kids' libraries? That was something a little weird that happened last night. Anyway, the startup list follows, and again, thank you for your help: StartupList report, 6/18/2006, 2:33:46 PM StartupList version: 1.52.2 Started from : C:\Documents and Settings\Susan\My Documents\HJT\HijackThis.EXE Detected: Windows XP SP2 (WinNT 5.01.2600) Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180) * Using def
  8. Logfile of HijackThis v1.99.1 Scan saved at 1:45:40 PM, on 6/15/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.e
  9. I posted a few weeks ago about a problem I was having with Sweepstakes.com but now I think I have even more problems, way beyond that. I ran Ewido, HiJackThis and Panda ActiveScan. The following are the results: Ewido: Scan result: C:\dfrgntfsdr.exe -> Downloader.Adload.bo : Cleaned with backup :mozilla.89:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\txe72xm3.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.90:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\txe72xm3.default\cookies.txt -> TrackingCoo
  10. Panda results as follows: Incident Status Location Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\txe72xm3.default\cookies
  11. These logs are huge...sorry! I'll break it down. Full ewido report below: ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 10:45:58 AM, 5/12/2006 + Report-Checksum: 96FE2F6D + Scan result: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ScreensaversInstaller -> Adware.Screensavers : Cleaned with backup :mozilla.10:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\txe72xm3.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.11:C:\Documents and Settings\Adam\Applica
  12. OK. Here is the HijackThis log: Logfile of HijackThis v1.99.1 Scan saved at 12:23:29 PM, on 5/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\P
  13. I have tried several things to get rid of Sweepstakes.com and nothing has worked. Here is a copy of my HJT log. I would really appreciate any help at all. Logfile of HijackThis v1.99.1 Scan saved at 1:04:37 PM, on 5/10/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOW