Help!!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by thegnat1, Jun 19, 2007.

  1. thegnat1

    thegnat1 Private E-2

    I did the READ and RUN ME FIRST page! I am not sure if it helped or not. Would someone mind please looking over my Hijackthis log for me? Can you tell me how this happened? I run Kaspersky like a fanatic and I don't visit crap sites. I am thinking that the infection came from HP of all places. I downloaded a driver once for my printer and it screwed everything up and I had to end up formating the hard drive!!! What a waste of a dadgum day and night!!! Thank you in advance!
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome


    If you did the READ and RUN ME FIRST then you woudl have more than just one Hijackthis log attached?

    These ones are needed too........



    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!


    Most people are under the very mistaken misconception that HijackThis is a malware removal tool. It is not! HijackThis is simply a tool that is used to identify browser hijackers and in some cases it will show entries for some malware that is for instance running at startup. All it does is list a few of the thousands of registry keys that exist, and it makes no inferences to whether anything being shown is good or bad. That decision is left a person with significant Windows and malware cleaning experience. HijackThis does not come close to showing all malware that could be hiding on a PC. Anyone who has an infected computer and is relying on HijackThis without the benefit of running other scans such as Spybot, Windows Defender, BitDefender & Panda, CCleaner, etc. are more than likely still infected. In most cases, where there is one virus/trojan there are more. The goal of this forum is to remove all malware, and this cannot be done properly by just seeing a HijackThis log.
     
  3. thegnat1

    thegnat1 Private E-2

    Thank you so much for getting back to me. I am not the smartest person when it comes to doing the behind the scenes work on these things. I have the two .bat files but they won't attach. I did a search for runkeys.txt and newfiles.txt and came up empty. I did that WHOLE run and read me first page and there are no files.... Any suggestions???? Should I just take my computer down to the beach and toss it in?? I am not sure what other files you will need to continue helping me. You are correct in saying that I couldn't run the counterspy so I did the AVG, Bit Defender and Panda but not sure what type of files the logs would be. Thanks again for your help!
     
  4. thegnat1

    thegnat1 Private E-2

    I did find a couple of more files......
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And when you attach the logs from GetRunKey and ShowNew, we can then get started. You have to run the programs as instructed on the download pages in order for the logs to be created and you don't need to search for them. They will be exactly where specified. C:\runkeys.txt and c:\newfiles.txt

    It would also be helpful if you explained what malware problems you are having. You said, "Can you tell me how this happened?" But you did not tell us what you are referring to. If you are referring to C:\hp\bin\KillIt.exe it is not problem.
     
  6. thegnat1

    thegnat1 Private E-2

    Okay, I think I have everything now! I must have done something wrong yesterday. In my first inquiry for help I asked how did this happen? I had a check mark somehwhere to automatically download and install updates from HP. I think that is where this crap came from but I am not certain. Here are the first three logs......thanks again!!!!
     

    Attached Files:

  7. thegnat1

    thegnat1 Private E-2

    Here are the remaining few.....
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But I repeat again that C:\hp\bin\KillIt.exe is not a problem. You don't have any malware. Also note that your did not rename HijackThis as required (you renamed the folder not the HijackThis.exe file) but it does not really matter right now since you do not have any malware. You are just running a very old version of Sun Java that you should have uninstalled in step 6 of the READ ME and then you should have clicked the link to download and install the current version. The old versions are security risks.
     
  9. thegnat1

    thegnat1 Private E-2

    Okay, well that's great to know! I am not sure what C:\hp\bin\KillIt.exe is but I never even knew it exsisted so how could I know that it was even a cause for concern? But thank you for letting me know about it! So you didn't find anything suspicious at all on my computer anywhere? I mean one minute it is running at top speed and the next it can't handle me opening two different browser windows at the same time. Maybe you can tell me what this means? When I start up my computer I get two different error messages. The first one says hphmon06.exe unable to locate component-that is on the blue line at the top of the dialog box and inside the box it reads hpzjrd01.dll failed to start because it was not found. Reinstalling the application may fix the problem. The second box says Smart bridge Alerts: MotiveSB.exe Entry Point Not Found-that is on the blue line at the top. Inside reads The procedure entry point GetProcessImageNewFileW could not be located in the dynamic link library PSAPI.DLL. These didn't start popping up until I did the things on the Read and run me first page.....any ideas? Thanks again for letting me pick your smart little brain!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The C:\hp should be a little bit of a give away that it is for your HP software.

    No!

    It's not due to malware based on your logs.

    Again not due to malware and they are also nothing that gets touch while running the READ & RUN ME. You can even see in your logs that nothing related to these was touch or removed. However did you only do what the READ ME instructions requested. I see you installed Prevx2 on June 19th. The READ ME did not ask for it to be run. Also did you run anything else? Did you run the Issues button on CCleaner?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds