MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Closed Thread
 
Thread Tools Display Modes
  #1  
Old 12-26-04, 13:15
Wallyzworld Wallyzworld is offline
Private E-2
 
Join Date: Dec 2004
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default May I send a HJT log please?

hey there ... I have tried every suggestion in your list - I cannot see the problem. May I send a hijack this log for you to give advice to?
Please let me know.
Thanks
Sponsored links
  #2  
Old 12-26-04, 15:12
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,766
Thanks: 62
Thanked 7,831 Times in 4,252 Posts
Default Re: May I send a HJT log please?

If you have followed ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal and you still have a problem, follow the guidelines below and post your HJT log as an attachment.

Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
  #3  
Old 12-29-04, 16:21
Wallyzworld Wallyzworld is offline
Private E-2
 
Join Date: Dec 2004
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: May I send a HJT log please?

here is my hjt log. Thanks
Attached Files
File Type: txt hijackthis.txt (5.0 KB, 14 views)
  #4  
Old 12-29-04, 16:53
bjgarrick's Avatar
bjgarrick bjgarrick is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Oct 2004
Location: Southern Alabama
Posts: 16,069
Thanks: 0
Thanked 224 Times in 221 Posts
Default Re: May I send a HJT log please?

First of all, whats problems are you experiencing?
  #5  
Old 12-29-04, 23:34
Wallyzworld Wallyzworld is offline
Private E-2
 
Join Date: Dec 2004
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: May I send a HJT log please?

When running IE, I can get to certain websites but when I access a particular site, even majorgeeks, IE freezes and the computer reboots.
Sponsored links
  #6  
Old 12-30-04, 00:06
bjgarrick's Avatar
bjgarrick bjgarrick is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Oct 2004
Location: Southern Alabama
Posts: 16,069
Thanks: 0
Thanked 224 Times in 221 Posts
Default Re: May I send a HJT log please?

After running the online scans and tools. Have you found any particular infections? Other than IE freezing and rebooting are you experiencing any other problems?
  #7  
Old 12-30-04, 00:13
bjgarrick's Avatar
bjgarrick bjgarrick is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Oct 2004
Location: Southern Alabama
Posts: 16,069
Thanks: 0
Thanked 224 Times in 221 Posts
Default Re: May I send a HJT log please?

FIRST, make sure "System Restore" is disabled temporarily.

Run Hijack This and have it fix these entries. Before removing anything with HJT please close all browsers.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.msn.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k


After fixing these entries, reboot and see if problem remains. Let me know. Thanks!
  #8  
Old 12-30-04, 00:14
Wallyzworld Wallyzworld is offline
Private E-2
 
Join Date: Dec 2004
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: May I send a HJT log please?

had a fun time huning down and eliminating the mad.dll one - also found istsvc.exe and that was eliminated as well. Had a dozen from ad-aware. Spybot and the others have all been run and is clean.
  #9  
Old 12-30-04, 00:38
Wallyzworld Wallyzworld is offline
Private E-2
 
Join Date: Dec 2004
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: May I send a HJT log please?

removed R1 as requested and he R0 as well. I removed the O4 line with the kernal fault check and it was gone. I rebooted out of safe mode and ran IE - I got to majorgeeks.com first page, but when I clicked on the forums link it crashed again. Went back to safe mode and looked at the O4 line (kernal fault check) had returned. I repeated the removal of this. Went in and out of normal and safe mode and ran HJT and it was gone every time. It comes back only after IE crashes. I think this is some type of Windows reporting error file. Any more suggestions before I "format c:"....?
  #10  
Old 12-30-04, 00:44
bjgarrick's Avatar
bjgarrick bjgarrick is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Oct 2004
Location: Southern Alabama
Posts: 16,069
Thanks: 0
Thanked 224 Times in 221 Posts
Default Re: May I send a HJT log please?

First lets make sure your system is clean from malware.

1) Download SpySweeper

2)Install SpySweeper, after you have SpySweeper installed go to "Options" and update definitions.

3)After update is complete click on "Sweep Now" and do a system scan. This will detect most malware on a system. After scan is complete remove all found traces and post me a log of that. Thanks!
Sponsored links
  #11  
Old 12-30-04, 01:22
Wallyzworld Wallyzworld is offline
Private E-2
 
Join Date: Dec 2004
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: May I send a HJT log please?

it found a lot of crap - didnt work though. Log is attached; had to break down into "a" and "b" as the file is too large. "A" is attached - let me know if you need "b" too. IE crashes at majorgeeks.com front page now again.
Arrgh
Attached Files
File Type: txt Spy Sweeper Session Log122904a.txt (82.7 KB, 5 views)
  #12  
Old 12-30-04, 01:31
bjgarrick's Avatar
bjgarrick bjgarrick is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Oct 2004
Location: Southern Alabama
Posts: 16,069
Thanks: 0
Thanked 224 Times in 221 Posts
Default Re: May I send a HJT log please?

Make sure you have updated definitions, reboot and do this same SpySweeper scan in "Safe Mode". You have some nasty malware.
  #13  
Old 12-30-04, 02:10
Wallyzworld Wallyzworld is offline
Private E-2
 
Join Date: Dec 2004
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: May I send a HJT log please?

All updated, ran in normal and safe mode - still nothing. here is the new spysweeper log. Any further leads?
BTW ... Thanks for your help so far!
Attached Files
File Type: txt Spy Sweeper Session Log123004.txt (1.4 KB, 4 views)
  #14  
Old 12-30-04, 02:24
bjgarrick's Avatar
bjgarrick bjgarrick is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Oct 2004
Location: Southern Alabama
Posts: 16,069
Thanks: 0
Thanked 224 Times in 221 Posts
Default Re: May I send a HJT log please?

Just a quick question, do you have "Content Advisor" enabled?
  #15  
Old 12-30-04, 02:36
Wallyzworld Wallyzworld is offline
Private E-2
 
Join Date: Dec 2004
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: May I send a HJT log please?

No its not .. that would be too easy right?
Sponsored links
  #16  
Old 12-30-04, 02:38
bjgarrick's Avatar
bjgarrick bjgarrick is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Oct 2004
Location: Southern Alabama
Posts: 16,069
Thanks: 0
Thanked 224 Times in 221 Posts
Default Re: May I send a HJT log please?

I have ran into some situations to where the content advisor was causing IE to crash like that on certain sites. Ok if its not that then we need to go more in deph to find out whats causing this.

When did this start?

Do you recieve any specific error messages and/or numbers? If so please provide me with that information.
  #17  
Old 12-30-04, 02:45
Wallyzworld Wallyzworld is offline
Private E-2
 
Join Date: Dec 2004
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: May I send a HJT log please?

I've been fighting this for about three weeks I guess. I joined the geeks the week before xmas and started sing your information on everything. No error messages or anything pop up. Just a freeze and it restarts. My homepage is google, and I can get to there, and any other simple html site, but once the site gets "complex" (for lack of better terminology this late) it freezes and crashes.
  #18  
Old 12-30-04, 03:10
bjgarrick's Avatar
bjgarrick bjgarrick is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Oct 2004
Location: Southern Alabama
Posts: 16,069
Thanks: 0
Thanked 224 Times in 221 Posts
Default Re: May I send a HJT log please?

Try this,

1) Click Start, Run.

2) In the Open box, type:iexplore.exe /rereg

3) Click OK

4) Reboot, and see if problem is fixed
  #19  
Old 12-30-04, 03:33
Wallyzworld Wallyzworld is offline
Private E-2
 
Join Date: Dec 2004
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: May I send a HJT log please?

No - i wish it solved it but it did not. Tried in regular and in safe mode.
  #20  
Old 12-30-04, 03:57
bjgarrick's Avatar
bjgarrick bjgarrick is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Oct 2004
Location: Southern Alabama
Posts: 16,069
Thanks: 0
Thanked 224 Times in 221 Posts
Default Re: May I send a HJT log please?

Do this before we continue, Download CCleaner

Install and run this program, it will clean your temporary internet files, cookies, etc;

Close all browsers before running this program.
Sponsored links
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 03:39.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


All content Copyright MajorGeeks.com source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger