Results 1 to 10 of 11

Thread: SpywareStormer

Hybrid View

  1. #1
    rolu Guest

    Re: SpywareStormer

    User name: rolyp1
    The password you are not having!
    An email arrived from 'aumha' confirming my user name and password which
    were as was submited!
    That's after their server failed to recognise me!
    My details *were and are correct*.
    I have posted the hijackthis log file to a forum at 'aumha'.
    Maybe we can find SpywareStormer in my 98SE registry
    Thanks mutchly (if that's a word)
    ---
    rolu


    "siljaline" <siljaline@invalid.com> wrote in message
    news:YO17e.3474$MZ2.619966@news20.bellglobal.com.. .
    > "rolu" wrote:
    > <snip>
    > > I seems the registration at aumha doesn't work!
    > > All my details are correct.
    > > I've allowed cookies.
    > > They seem to think I've registered before but I can't get the password!

    even
    > > if 'I've forgotten it'
    > > Is there somewhere else I can get some kind person to look at my

    HijackThis
    > > log?

    >
    > What user-name did you or are you currently registered under at AumHa

    Forums?
    >
    > Silj
    >
    > --
    > siljaline




  2. #2
    rolu Guest

    Re: SpywareStormer


    "rolu" <rolu@rolu.org> wrote in message
    news:qs27e.9583$5F3.983@news-server.bigpond.net.au...
    > User name: rolyp1
    > The password you are not having!
    > An email arrived from 'aumha' confirming my user name and password which
    > were as was submited!
    > That's after their server failed to recognise me!
    > My details *were and are correct*.
    > I have posted the hijackthis log file to a forum at 'aumha'.
    > Maybe we can find SpywareStormer in my 98SE registry
    > Thanks mutchly (if that's a word)
    > ---
    > rolu
    >

    Duh, mea culpa the word is "muchly' me thinks.
    But Spyware Stormer is still storming me.
    A link to someone who knows how to remove it would be appreciated.
    I do know format c:/s will work!
    As for aumha !!?
    ---
    rolu.



  3. #3
    siljaline Guest

    Re: SpywareStormer

    "rolu" wrote:
    <snip>
    > I have posted the hijackthis log file to a forum at 'aumha'.


    Please post back the URL from AumHa Forums, here_

    Silj

    --
    siljaline

  4. #4
    rolu Guest

    Re: SpywareStormer


    "siljaline" <siljaline@invalid.com> wrote in message
    news:wFm7e.4129$MZ2.747025@news20.bellglobal.com.. .
    > "rolu" wrote:
    > <snip>
    > > I have posted the hijackthis log file to a forum at 'aumha'.

    >
    > Please post back the URL from AumHa Forums, here_


    You posted:
    http://aumha.net/viewforum.php?f=30>
    You posted:
    http://aumha.net/profile.php?mode=register

    The post back from Aumha has been not only deleted, but removed.
    Sorry, but do like to keep, not only myself, but my computer clean!
    It seems I now have registration rights, *but how can AumHa's software
    decide I'm who I'am and then reject me.?!
    And email *then* me with confirmation with the details I entered?!

    Now for SpywareStormer!

    Here's the log:
    Logfile of HijackThis v1.99.1
    Scan saved at 5:12:21 PM, on 14/04/05
    Platform: Windows 98 SE (Win9x 4.10.2222B)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
    C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
    C:\PROGRAM FILES\SCANSOFT\OMNIPAGESE2.0\OPWARESE2.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\STARTUPMONITOR.EXE
    C:\PROGRAM FILES\KEMAILKB\KEMAILKB.EXE
    C:\PROGRAM FILES\ERASER\ERASER.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
    C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    http://www.abc.net.au/newsradio
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    http://pcworld.idg.com.au
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
    http://www.javacoolsoftware.com/spyw...terdonate.html
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
    C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
    C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
    c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
    C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
    files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
    powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
    O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
    O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [OpwareSE2] "C:\Program
    Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
    O4 - HKLM\..\Run: [OPSE2 Reminder] "C:\PROGRAM
    FILES\SCANSOFT\OMNIPAGESE2.0\EREGENG\EREG.EXE" -r "C:\PROGRAM
    FILES\SCANSOFT\OMNIPAGESE2.0\EREGENG\ereg.ini"
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
    O4 - HKLM\..\Run: [KEMailKb] C:\PROGRA~1\KEMAILKB\KEMailKb.EXE
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
    powrprof.dll,LoadCurrentPwrScheme
    O4 - HKCU\..\Run: [Eraser] C:\PROGRAM FILES\ERASER\ERASER.EXE -hide
    O4 - HKCU\..\RunServices: [Eraser] C:\PROGRAM FILES\ERASER\ERASER.EXE -hide
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM
    FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM
    FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM
    FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward Links - res://C:\PROGRAM
    FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate into English - res://C:\PROGRAM
    FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html

    ---
    rolu



  5. #5
    siljaline Guest

    Re: SpywareStormer

    "rolu" wrote:
    <snip>
    > Now for SpywareStormer!
    >
    > Here's the log:
    > Logfile of HijackThis v1.99.1

    <Log Snipped as it is _incomplete_ >

    Re: AumHa Forums, Rolu!
    Go to http://aumha.net/ - click on Login - and provide
    the user name and password.

    If that (doesn't) work, please have email me at <elist@aumha.org> - *from*
    the same email address he used to register! - state his user name and ask
    to reset his password.

    Silj

    --
    siljaline




Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •