1. jamiesosebee

    jamiesosebee Private E-2

    Ok Guys/Gals thank you in advance for your reply's and advice i'll try to make this a painless as possible and as clear as i can please bear with me lol

    1: The First Problem I noticed was Yazak for some reason it just wouldnt login any more and still will not. it keeps giving this as a reason why it will not

    " Server forcefully rejected your request "

    My Solutions:
    Tried New Servers lol
    Diff Usernames/Passwords
    Uninstalled/Reinstalled Multiple Times
    Changed My Ip Address the uninstalled / reinstalled but still getting the above mentioned error!

    2: The Second Problem i encountered just a minute or two ago! I downloaded and installed CCleaner Succesfully or so i thought until i tried to launch the program its self the program would appear for maybe a second then vanish and is still doing it!

    My Soulutions:
    uninstalled/reinstalled multiple times
    thats all i've done.

    im really stuck here guys i usually try to figure things out on my on but ive read countless articles and nothing usefull helps with my problem

    ps a couple other programs related to yahoo will not login either.

    i've ran HiJack this And MalwareBytes but im not sure how to read them and what to do, Ill attach a copy of the log in code form

    any and all help is greatly appreciated thanks for your time.



    Hijack This Scan Log:
    Code:
    Logfile of HijackThis v1.99.1
    Scan saved at 1:30:09 AM, on 9/11/2011
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    c:\windows\TEMP\fesm.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\windjyeft.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\nusac.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\winifgt.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\winprivmh.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\winvswu.exe
    C:\Documents and Settings\Home Window\Desktop\HijackThis\HijackThis.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\odjj.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\winlstihe.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\xafmk.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\winrnvaiy.exe
    
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/ext/hp/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com/p/hp/?http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daum.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/ext/hp/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
    O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI9130~1\Datamngr\ToolBar\searchqudtx.dll
    O2 - BHO: Loader Class - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~1\WI9130~1\Datamngr\BROWSE~1.DLL
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1305254721807
    O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
    O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    
    
    Malwarebytesantimalware scan log
    Code:
    Malwarebytes' Anti-Malware 1.51.1.1800
    www.malwarebytes.org
    
    Database version: 7689
    
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702
    
    9/11/2011 2:06:44 AM
    mbam-log-2011-09-11 (02-06-42).txt
    
    Scan type: Full scan (C:\|)
    Objects scanned: 218337
    Time elapsed: 1 hour(s), 47 minute(s), 31 second(s)
    
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 2
    
    Memory Processes Infected:
    (No malicious items detected)
    
    Memory Modules Infected:
    (No malicious items detected)
    
    Registry Keys Infected:
    (No malicious items detected)
    
    Registry Values Infected:
    (No malicious items detected)
    
    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogoff (PUM.Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    
    Folders Infected:
    (No malicious items detected)
    
    Files Infected:
    c:\documents and settings\home window\my documents\Y!mini.exe(Trojan.Dropper) -> Quarantined and deleted successfully.
    c:\documents and settings\home window\my documents\tcpz_20090108\tcpz_20090108\virtualdevice\Driver\tcpz-x86d.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
    
     
  2. plodr

    plodr Major Geek Super Extraordinaire

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please follow these instructions:

    READ & RUN ME FIRST. Malware Removal Guide

    Also use windows explorer to find and delete:
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\windjyeft.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\nusac.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\winifgt.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\winprivmh.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\winvswu.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\odjj.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\winlstihe.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\xafmk.exe
    C:\DOCUME~1\HOMEWI~1\LOCALS~1\Temp\winrnvaiy.exe

    ATTACH the requested logs once you are finished running the scans.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds