top
Auction Ticker
Help please.
Goto page 1, 2, 3, 4  Next
 
Post new topic   Reply to topic    Rakion League Forum Index -> Tech Help
Author Message
Ivonnely
League Advocate



Joined: 25 Sep 2006
Posts: 177
Pictures: 0
Location: Sinep

PostPosted: Wed May 21, 2008 4:04 am    Post subject: Help please. Reply with quote

My hotmail account info keeps getting stolen. Last week Tuesday I tried to log in only to discover that my password was changed. But I did the password recovery and got in just fine. Changed my pass to a more secure one, one with capitals and numbers. Also changed my security question to something not so obvious. Wednesday morning this week rolls around and I can't log in - again. Go to password recovery and wow lol, that's changed too. So I am screwed major unless there is any way around this. And there doesn't seem to be.. If anyone could help me with this part I'd love you forever.

Second problem, it's apparant that some thing is getting this info on my comp and sending it back to someone. I know this because this is the only computer I use to log in to my email since I can't do it at work, nor have I been to anyone's house and logged in there. I deleted all my previous system restores past the first date my password got stolen, during a cleanup run, and well, now I'm kinda screwed so if I installed something, I've no clue what it is.. Can someone recommend a software they've tried, used, and it's worked for them to remove this sort of thing? Thank you.

When I get home, I'll try to go through everything I've downloaded. Is there no hope for the first part?
_________________
Back to top
View user's profile Send private message Send e-mail
Ivonnely
League Advocate



Joined: 25 Sep 2006
Posts: 177
Pictures: 0
Location: Sinep

PostPosted: Wed May 21, 2008 4:27 am    Post subject: Reply with quote

Went through ALL my processes. Found something called wininit.exe Searched online. Looks like I've found my trojan/virus. It's listed as a system process and the description says Windows Start-Up Application.

Can't believe this lol. I was just bragging to my coworkers about how I don't use anti virus and never catch anything! And here we go lol.. So now that I've found it.. What do you suggest I use?

eDiT: Sorry for double posting!! Freaking out over here ><
_________________
Back to top
View user's profile Send private message Send e-mail
lengend



Joined: 02 Nov 2006
Posts: 3107
Pictures: 0
Location: public_html/home

PostPosted: Wed May 21, 2008 4:29 am    Post subject: Reply with quote

you got keylogged lmfao

only way to fix it is a format, unless you can find the process and registry keys...

getting your hotmail account good luck thats a tough one
_________________

Back to top
View user's profile Send private message
Ivonnely
League Advocate



Joined: 25 Sep 2006
Posts: 177
Pictures: 0
Location: Sinep

PostPosted: Wed May 21, 2008 4:30 am    Post subject: Reply with quote

ZoneHacks wrote:
you got keylogged lmfao

only way to fix it is a format, unless you can find the process and registry keys...

getting your hotmail account good luck thats a tough one


Alright thank you.. Was planning on downgrading to xp anyway and here we go LOL.. Thanks.
_________________
Back to top
View user's profile Send private message Send e-mail
lengend



Joined: 02 Nov 2006
Posts: 3107
Pictures: 0
Location: public_html/home

PostPosted: Wed May 21, 2008 4:31 am    Post subject: Reply with quote

hmmm, go to start > run > and type services.msc see if you can find it there when it starts up and try to disable it, if it doesn't work try in safe mode

may i know which OS are you using?
_________________

Back to top
View user's profile Send private message
Ivonnely
League Advocate



Joined: 25 Sep 2006
Posts: 177
Pictures: 0
Location: Sinep

PostPosted: Wed May 21, 2008 4:40 am    Post subject: Reply with quote

ZoneHacks wrote:
hmmm, go to start > run > and type services.msc see if you can find it there when it starts up and try to disable it, if it doesn't work try in safe mode

may i know which OS are you using?


Windows Vista.

eDiT: I also don't know if wininit.exe is the actual virus.. Searching more I saw it's part of Windows? So not certain for sure.
_________________
Back to top
View user's profile Send private message Send e-mail
lengend



Joined: 02 Nov 2006
Posts: 3107
Pictures: 0
Location: public_html/home

PostPosted: Wed May 21, 2008 4:43 am    Post subject: Reply with quote

now i have no clue since...its windows vista and i don't have that much knowledge in vista

i'm gonna eat since its lunch here in europe, i'll be back in 20 mins
_________________

Back to top
View user's profile Send private message
Ivonnely
League Advocate



Joined: 25 Sep 2006
Posts: 177
Pictures: 0
Location: Sinep

PostPosted: Wed May 21, 2008 4:48 am    Post subject: Reply with quote

ZoneHacks wrote:
now i have no clue since...its windows vista and i don't have that much knowledge in vista

i'm gonna eat since its lunch here in europe, i'll be back in 20 mins


Ok thanks. Really appreciate the help.

Looked that file up in services, didn't find it there.. But when I searched more online, it's looking like it's a part of Vista lol. So now I'm really clueless. Think I'll just wipe my hard drive to take care of that issue.. Though it would've been nicer to find it now, so I can get to getting a new email and changing as much info as I can.

Do you recommend any spyware/virus/trojan removal programs?
_________________
Back to top
View user's profile Send private message Send e-mail
lengend



Joined: 02 Nov 2006
Posts: 3107
Pictures: 0
Location: public_html/home

PostPosted: Wed May 21, 2008 5:09 am    Post subject: Reply with quote

Ivonnely wrote:
ZoneHacks wrote:
now i have no clue since...its windows vista and i don't have that much knowledge in vista

i'm gonna eat since its lunch here in europe, i'll be back in 20 mins


Ok thanks. Really appreciate the help.

Looked that file up in services, didn't find it there.. But when I searched more online, it's looking like it's a part of Vista lol. So now I'm really clueless. Think I'll just wipe my hard drive to take care of that issue.. Though it would've been nicer to find it now, so I can get to getting a new email and changing as much info as I can.

Do you recommend any spyware/virus/trojan removal programs?


try nod32 which i use for anti virus, spyware programs...i don't use them, i find no need for them, spyware free for a year Very Happy

do me a favour download hijackthis

http://www.majorgeeks.com/download3155.html

do me a search and paste the log here, i'll look at your processes
_________________

Back to top
View user's profile Send private message
Ivonnely
League Advocate



Joined: 25 Sep 2006
Posts: 177
Pictures: 0
Location: Sinep

PostPosted: Wed May 21, 2008 5:15 am    Post subject: Reply with quote

Ok dowloading hijackthis. Will paste the log in a few.

And I'll try nod32. Thanks.

Lol you know, I was pretty cocky about not catching anything.. Thought I was so careful about what I downloaded and where I downloaded it from.. *sigh*
_________________
Back to top
View user's profile Send private message Send e-mail
Ivonnely
League Advocate



Joined: 25 Sep 2006
Posts: 177
Pictures: 0
Location: Sinep

PostPosted: Wed May 21, 2008 5:18 am    Post subject: Reply with quote

Logfile of HijackThis v1.99.1
Scan saved at 7:18:17 AM, on 5/21/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\sttray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
C:\Program Files\TiVo\Desktop\TiVoNotify.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
O9 - Extra 'Tools' menuitem: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D025CEC7-4821-4591-907E-5DF05B7AD1A3}: NameServer = 151.196.0.38,151.196.0.39
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe" /service (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
_________________
Back to top
View user's profile Send private message Send e-mail
lengend



Joined: 02 Nov 2006
Posts: 3107
Pictures: 0
Location: public_html/home

PostPosted: Wed May 21, 2008 5:25 am    Post subject: Reply with quote

i don't see a problem at all...did you end the process that you mentioned earlier or something?
_________________

Back to top
View user's profile Send private message
Ivonnely
League Advocate



Joined: 25 Sep 2006
Posts: 177
Pictures: 0
Location: Sinep

PostPosted: Wed May 21, 2008 5:30 am    Post subject: Reply with quote

ZoneHacks wrote:
i don't see a problem at all...did you end the process that you mentioned earlier or something?


Nope, it's still running. There is a difference though.. When I press ctrl alt delete and go to processes, there's a button on the bottom left that say "show processes from all users". With that unchecked, the wininit.exe process doesn't show up. When I check the box, it does show up. And so do a few more processes o.o
_________________
Back to top
View user's profile Send private message Send e-mail
lengend



Joined: 02 Nov 2006
Posts: 3107
Pictures: 0
Location: public_html/home

PostPosted: Wed May 21, 2008 5:41 am    Post subject: Reply with quote

vista is hiding something :OOO
_________________

Back to top
View user's profile Send private message
Ivonnely
League Advocate



Joined: 25 Sep 2006
Posts: 177
Pictures: 0
Location: Sinep

PostPosted: Wed May 21, 2008 5:46 am    Post subject: Reply with quote

ZoneHacks wrote:
vista is hiding something :OOO


another reason why it's lovable? lol. well thank you very much. you're like a godsend at a time when i'm freaking out lol. running the anti virus now, and i'll just do a clean install later to windows xp xD
_________________
Back to top
View user's profile Send private message Send e-mail
Display posts from previous:    View previous topic : View next topic  
Post new topic   Reply to topic    Rakion League Forum Index -> Tech Help All times are GMT - 6 Hours
Goto page 1, 2, 3, 4  Next
Page 1 of 4

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum