4 Attachment(s)
Email hijacked - possibly from this computer
This computer has had issues anyway, running slowly, etc. but yesterday my husband's email account was hijacked and everyone he had ever emailed got a sob story about how he was stranded in the UK and needed money, and please send, and he would pay them back in a few days....he promised.
When I tried to log into my yahoo account, I didn't see my signin page with appropriate 'seal' so I figured the hijack came from this computer.
I'll post all the logs, but one extra detail. I have an external hard-drive. Didn't want to scan that, so did malwarebytes Quick scan, then rebooted, then disconnected hard-drive (which rebooted Windows for some reason -- I know I should have disconnected before the malwarebytes scan, but didn't, and didn't rescan -- just thought you should know), then continued with the gmer and dds.
Anyway, here it all is...I thought you wanted these logs posted in-line, but they're too big, so I'll attach. Thanks so much for your help...I think it's quite a mess.
OK, I'll add as separate replies -- still had to delete some stuf
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4396
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11
8/5/2010 7:01:27 PM
mbam-log-2010-08-05 (19-01-27).txt
Scan type: Quick scan
Objects scanned: 204872
Time elapsed: 44 minute(s), 8 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 16
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 37
Files Infected: 488
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\asd3.testmyie2 (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\asd3.testmyie2.1 (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3f143c3a-1457-6cca-03a7-7aa23b61e40f} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\WUSN.1 (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Cydoor Services (AdWare.Cydoor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Cydoor (AdWare.Cydoor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\DownloadWare (Adware.DownloadWare) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DownloadWare (Adware.DownloadWare) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave (Adware.WhenU) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{3f143c3a-1457-6cca-03a7-7aa23b61e40f} (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
Folders Infected:
C:\Documents and Settings\Eric\Application Data\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\IESkins (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\HostOI (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\HostOI\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\HostOI\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\HostOL (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\HostOL\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\HostOL\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\dynamic\hstat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\dynamic\Tooltip (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\dynamic\ustat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\1 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\2 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\IESkins (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\HostOI (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\HostOI\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\HostOI\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\HostOL (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\HostOL\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\HostOL\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\dynamic\hstat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\dynamic\Tooltip (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\dynamic\ustat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\static\1 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\static\2 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AdCache (AdWare.Cydoor) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-2527948133-1975315110-1187317151-1007\Dc9.tmp (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\dynamic\1.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\dynamic\1005433.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055563.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055639.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055780.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
... Still too long...all Adware.Hotbar stuff deleted the rest. Let me know if you want it.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\2\layout.cdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\2\linkpathlegal.txt (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\2\progress.res (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\2\samplegroups2.txt (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\2\s_icons_buttons.res (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\2\t2_bg.res (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\2\theweb.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\2\top7.cdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\2\Top7_theweb.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Application Data\Hotbar\v3.0\Hotbar\static\2\tsd_bg.res (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\reports.txt (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\IESkins\EZbar.bmp (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\dynamic\1.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055547.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055556.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055563.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055780.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\dynamic\1070500.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeremy\Application Data\Hotbar\v3.0\Hotbar\dynamic\1141546.sdf (Adware.Hotbar) -> Quarantined and deleted successfully.
... Same for this user