Hijack This Log help required please.. :o)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Fizzbitt, Jun 8, 2007.

  1. Fizzbitt

    Fizzbitt Private E-2

    Hi all,

    Firstly just want to say i love the site as its got shed loads of info and downloads available to help you out for whatever you require.

    Secondly i have read through the pre posting a HJ log thing as well and can confirm i have followed it all the way through.

    I have got a virus off a MSN windows messenger from a friend and when i clicked on the link it buggereg my computer up.

    Issus are that my Windows firewall is continually being switched off and i have to manually start the services.

    Also as soon as i type in the word hi jack in a IE browser it just closes down automatically.

    I have installed and run all the usual malware.

    Please can somone take a look at this log and advise what the best place of action is next.

    Cheers in Advance..
    Fizz
     
  2. Fizzbitt

    Fizzbitt Private E-2

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Actually not you have not followed ANY of the instructions. If you had, you would not have posted a HijackThis log inline and that was installed improperly and that was not renamed. In addition. You would have attach the 5 other required logs from the READ & RUN ME first.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. Fizzbitt

    Fizzbitt Private E-2

    you know what,...there are so many links... lol.. I can promise you i followed one of them down tot he last insturction..

    Its also 2am here so im a tad tired so my apologies..

    Ok.. this part of the instructions..

    When i type in msconfig and his the enter button... the egtime appears for a bit but then nothing happens.. tried this a couple of time now.. confused
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue on with the instructions and we will worry about this later.
     
  6. Fizzbitt

    Fizzbitt Private E-2

    ok... AVG Antispyware ran and found no issues this time. Only problem was that i was unable to save the results as i think i didnt press the save button ontime.

    The other logs i have as follows

    newfiles.txt
    runkeys.txt
    Spybot S&D
    Hijack

    The bitdefender link is down so didnt get that...

    Please help.. this is driving me mad....:cry
     

    Attached Files:

  7. Fizzbitt

    Fizzbitt Private E-2

    last of the logs

    p.s) Also a point to note... when i try and access the services via the control center the window closes down.

    I can get to it using the right mouse click on my computer and clicking on Manage though. It seems that something keeps turniong off the windows firewall.. i ahve to manually start it each time i come onto the computer...
     

    Attached Files:

    Last edited: Jun 9, 2007
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the other requested logs! BitDefender is not down.
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    Also as requested in the READ ME, HJT logs must be obtain in normal boot mode. However before attach a new one, do the below.

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe, click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program

    Now attach a HJT log from normal boot mode.
     
  9. Fizzbitt

    Fizzbitt Private E-2

    Hey Lang...

    Botht he Panda site and the Bitfender would not come up when i treid them before but now i have tired them again and this time they both work so i will run them later.

    With regards to the HJT log i forgot to mention that i cant run it in normal mode because it shuts down as soon as i open it! confused

    Please can you suggest a way to run it without this happening?

    Just ran the HostsXpert as requested as well.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach then as soon as completed.

    Now download the attached file named chodefix.zip (see the bottom of this message). Save it to your Desktop . Then extract ALL of the files from it. Then double click on the chodefix.bat file. This will try to fix some of the damage caused by the Chode infection that you have. You should see a message like the below when it finishes (in about 3 seconds).
    Tell me if you see this message or not or if you get an error message instead. No matter what happens just continue on to the next steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT - see if you can run in normal boot mode now
     

    Attached Files:

  11. Fizzbitt

    Fizzbitt Private E-2

    Chodefix has been ran as requested and i got the end message exactly the same as you had quoted.

    Tried to open hijackthis and it still shut on me straight away.

    Bitfender scan has completed and here is the log as requested.

    Pandabeat is the next thing which im about to run..

    regards...
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Next time just attach the renamed html file from Bitdefender as requested in the READ ME.

    You need to also attach the new GetRunKey and ShowNew logs too. And how did you previously get a HijackThis log? Can you do it the same way? Is HijackThis.exe rename to analyse.exe?
     
  13. Fizzbitt

    Fizzbitt Private E-2

    It would not allow me to add the html file when i tried to upload the attachment. I then had to copy it into a Word document to enable me to upload it.

    I have renamed it to analyse.exe as requested as it also shows in the log i posted previously.

    The only way i can run HijackThis is within safemode but you said that i need to run it in normal mode which it wont allow me to do.

    Just to confirm that i have ran the pandascan and got a log which i need to upload but im currently at work and will get it uploaded when i get home.

    It found 2 virus's which it disinfected and 22 spyware and 2 hacking things but it did not remove those. I presume it just highlights the issue for you?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The directions in the READ ME tell you to rename the file to have a .txt extension so that it can be uploaded.

    Yes but I have no idea what file you were trying to run. Many times people keep the HijackThis.exe files laying around in many spots on the hard disk and sometimes they run the wrong copy.

    Okay. If this is the only way you can run it then it could be better than nothing.

    Yes Panda is primarily just a scanning tool used to help us find problems. It will disinfect a few things but most items are ignored. It does report lots of cookies which are not issues to worry about. Just attach the log when you get how.

    Also try installing and running the below which has the ability to produce a HijackThis log equivalent.

    a-squared HiJackFree

    When you run it, look at the lower left side and you will see a Save logfile hotkey. Click it and select HJT compatible. Save the log and attach it here.

    Also don't forget to attach the new logs I requested from GetRunKey and ShowNew after ChodeFix was run.
     
  15. Fizzbitt

    Fizzbitt Private E-2

    rightfinally some good news...

    It seems that after a couple of reboots i can now run the hijackthis in normal mode! :D The chodefix obviously must have solved that particular issue for me! Cheers!

    Right.. the logs as requested.

    Active Scan and Hijackthis
     

    Attached Files:

  16. Fizzbitt

    Fizzbitt Private E-2

    Now newfiles and runkeys and the bitfender renamed with a .txt extension.

    Right.. one more thing.. since running the chodefix, it solved a couple of issues but now when i boot the machine up i get the following messages in order.

    http://i147.photobucket.com/albums/r307/fizzbitt/FizzPC.jpg

    Now please can you tell me how to get to the registry file to remove this line?

    Thanks again in advance..
    Fizz
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F3 - REG:win.ini: load=C:\WINDOWS\system32\krjignjdst\smss.exe
    F3 - REG:win.ini: run=C:\WINDOWS\system32\krjignjdst\smss.exe
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - Startup: smss.lnk = ?

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  18. Fizzbitt

    Fizzbitt Private E-2

    Right.. I have run the system scan on hijack accordingly and selected the files you have told me to... now as soon as i click on fix i get the following 2 messages...

    http://i147.photobucket.com/albums/r307/fizzbitt/hijackerror.jpg

    Now when i run the system scan again.. the first 3 files i selected have now gone but the 04 - startup; smss.ink is still there.

    =====



    Now with regards to the fixME.reg.

    I have saved the file accordingly with the bold text in place. Saved it to the desktop at which point the icon changed to a registry type. As soon as i double clicked on it i got the following message.

    C:\Documents and settings\Faisal\Desktop\fixME.reg is not a valid Win32 application
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The infection you had (and that we are still working on ) disables registry editing so that if blocks you from removing the infection. Some of the steps I have given thus far have improved things but registry editing has still been disabled.

    If you click Start, Run and enter regedit and click OK, does the registry editor open or do you get a message saying that the administrator has disabled registry editing?
     
  20. Fizzbitt

    Fizzbitt Private E-2

    Nope.. i can access that just fine... Although i aint used it before and am not familiar with it.

    There is a tree list to the left as im sure your aware... would you like me to screenshot it for you so you can see waht it contains or is it a generic setup?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Bring up the registry editor again and click File and select Import. Then navigate to the C:\Documents and settings\Faisal\Desktop\fixME.reg file and double click on it from the import window. Say yes to the prompt to add it to your registry. Tell me if you receive a success message. Also if you get a success message, finish the other remaining steps from message number 17.
     
  22. Fizzbitt

    Fizzbitt Private E-2

    That import process worked a treat. I no longer get the reg error messages upon a reboot.

    I have also now followed the remaining steps in post #17.

    Here are the longs as requested.

    Just to confirm now that my computer seems to be running normally once more. I have manged to get sygate installed and running fine now! :)

    Really Really appreciate your help on this one matey. Top class.. :)
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  24. Fizzbitt

    Fizzbitt Private E-2

    All the steps have been followed and once again im in your debt.

    Muchas Gracias!:D
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds