Can I please Post a Hijackthis file

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Dan Armstrong, Dec 27, 2004.

  1. Dan Armstrong

    Dan Armstrong Private E-2

    I have been working on this PC for 4 days now and running your tutorial . I lost the internet for 2 days and fixed it finally with a winsock fix but now I have lost it again, I am running windows XP Home w/sp2. I am not using the PC in question, I am on braodband and keep mine in check this is my sister-in-laws and man ,, it had 52 viruses on it when I started and I am about at wits end on clearing everything up ,I know it still has swizzor.bo on it and swizzor.bz and have followed the tutorial as best I can considering the PC will not boot in safe mode and would like someone to look at a hijack file to give some advice,, Please help..
    Thanks
    Dan
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. Dan Armstrong

    Dan Armstrong Private E-2

    I am going to try and upload this as an attachment but I don't see anything that says Go Advanced in my posting area just manage attachments.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you were already in Advance mode.

    First let's Fix SpyBot's Ignore Products Bug:
    I want you to run SpyBot and get into the Advanced mode by selecting Mode and then
    Advanced mode. Then select Settings and the in the left column select Ignore Products.
    In the right window pane make sure the All products tab is selected. Then in that
    window, right click your mouse and choose "Deselect all". Now in the left pane click
    at the top on SpyBot S&D and then choose Search for Updates. Download any updates
    required. Now click Check for Problems. Fix any that are found.

    See if that fixes the O10 - Hijacked Internet access by New.Net line seen in your HJT log.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://web.kfhophjyeocpdwdcspcyvdla.biz/uBm75WtJv8RAkVt/DyS5JPEm7FtZfveThPUBQeG12sv7_0WyPuJ_h/iQS0joy5B4.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
     
  5. Dan Armstrong

    Dan Armstrong Private E-2

    Chaslang,
    First I would like to say Thanks for the help,
    Then , the PC in question will not go online right now so is it alright to run lspfix again to see if I can gain internet access to update spybot or is there a way to update it using another PC and transfer the file with a flashdrive.
    Thanks
    Dan
     
  6. Dan Armstrong

    Dan Armstrong Private E-2

    Sorry, I should have tried the updates first , it was able to connect to the updates but still won't let IE work, finishing the instructions and will post another log soon
    Thanks Again
    Dan
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you take care of what I said about the Ignore Products bug. Make sure no items are checked in that list. It has a bug which has 4 products set to be ignored. One of which is new.net
     
  8. Dan Armstrong

    Dan Armstrong Private E-2

    Okay, did everything I was instructed to do and here is a new Hijack file,
    thanks for the help
    Dna
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is basically clean but I have a few comments and a question:

    You must not run multiple antivirus applications. You have both AVG7 and Symantec/Norton running. You need to uninstall one of them.

    If you have Symantec/Norton's Firewall running, have you disabled the one in Win XP SP2?

    Question: What is this SnapDetect stuff?
    C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe
    O4 - Global Startup: Icatch(VI) SnapDetect.lnk = ?

    How is everything working?
     
  10. Dan Armstrong

    Dan Armstrong Private E-2

    The mutiple virus thing,, this is my sister-in-laws PC and she bought norton and installed it with all the viruses running and it may not have worked right is my guess when she installed it,so I installed AVG because I knew I could rely on it, not sure about norton and trojans ,, how reliable is it,I am not sure if Norton has a firewall, haven't made it that far I will look into it, as far as the other crap running I have no idea, she has a digi cam and a video camera could that be it? this is a teenager we are talking about, I just tried Norton and it says I need to uninstall and reinstall says norton 2005 does not support the repair feature? So i will get eh disc from her and reinstall it,, will it and the windows firewall be enough proection for this PC. amybe spybot withit,
    Thanks again for all your help.
    Dan
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Norton is a well known program that some people consider to be very good, however most of us here do not like it or McAfee because they require why too many processes and eat system resources. Most of the free antivirus programs, like Avast, AVG, and AntiVir Personal, do a very good jobs without the bloatware. It's up to you. You may have other things in the Norton package to since some of there software suites add all kinds of stuff like firewall, popup blockers, recycle bin protectors, adware checking, etc. You have to see what you want. But you need to have only on antivirus program installed.

    It's possible that SnapDetect.exe is related to her camera ( or maybe a scanner ?) Right click on it and see who it belongs too by looking at Properties, Version info.

    This is what you need to do: How to Protect yourself from malware!
     
  12. Dan Armstrong

    Dan Armstrong Private E-2

    Chaslang,
    After doing some research onthe Snapdetect.exe file it is a webcam, it is on the install cd also.
    Thanks for all your help the system is running a lot better. When I started on this system it had more than 70 processes runnng it is now down to about 40. I am going to do the protect it from malware you recommend tonight and reinstall norton and update it and run the spyware you guys recommend. Thanks again for all your help. I now read this site on a daily basis.
    Thanks,
    Dan
     
  13. Dan Armstrong

    Dan Armstrong Private E-2

    The system is running a lot better so I decided to run the tutorial again and make sure. Everything seemed to be fine until I ran HS remove and it says it removed 8 items so I ran it again and it said it removed 8 items so I did it again and you guessed it still 8 items ,, whats up with this??
    Thanks for any help
    Dan
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could have a lot of stuff hanging around from an old infection and maybe it is removing 8 at a time. Or maybe it cannot remove the items. First a question, why run it. You should only run HSremove and About:Buster if you have the HSA and or about:blank hijack problem which you should easily be able to tell.

    That said, try running HSremove in safe mode with ALL other process closed and no physical ability (unplug cables) to connect to the internet. Then run About:Buster and allow it to run its secondary scan too. Then reboot to normal mode and do nothing else but run About:Buster and run the secondary scan again. IMMEDIATELY after it completes reboot in normal mode.

    Let me know if About:Buster and HSremove were finding anything.
    Is you HJT log still clean?
     
  15. Dan Armstrong

    Dan Armstrong Private E-2

    Chaslang,
    This PC will not boot in safe mode for some reason, I haven't been able to the whole time, when you hit F8 you hear it pinging but it just boot on up in mormal mode, I ran HS remove in normal mode again and about:Buster Hs remove still says 8 items removed about:buster says no ADS found on system. Here is the latest Hijackthis file tell me what you think, And I would like to say Thanks Again for all your help.
    Thanks
    Dan
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. Dan Armstrong

    Dan Armstrong Private E-2

    Chaslang,
    I was able to boot in safe mode using msconfig and ran what you said, here are the results. Also spyguard keeps telling me an attempt to change IE settings has been detected. it is trying to change my homepage to google.
    HS remove 8 items 1st time
    hs remove 8 items 2nd time
    I checked task manager to see if anything looked fishy and closed everything it would let me
    HSremove 3rd time 8 items
    hs remove 4th time 8 items
    Aboutbuster said no ADS found on system
    attempted clean of temp folder
    pages reset- done
    When I rebooted in normal mode System configuration utility comes up and say I have used the utility to make changes to the way windows starts it says it is in Diagnostic or selective startup mode then tell me how to fix it, all I did was check safe mode and uncheck safe mode.
    Anyway I ran about buster in normal mode with the same 8 items results
    also when I ran aboutbuster it opens 2 My Documents windows is this normal for aboutbuster,
    Thanks for all your help
    Dan
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to re-enable normal boot up using msconfig (the inverse of what you did to get into safe mode).

    You said about:Buster in normal mode found the same 8 items, I think you meant HSremove?
    about:Buster does open MyDocuments when it completes each scan.

    What version of HSremove are you using?
    What version of About:Buster and what version is the Reference file?
     
  19. Dan Armstrong

    Dan Armstrong Private E-2

    About Buster is version 3.0.0.0 and HSremove is version 2.40 I am not sure what you mean by reference file.
    Thanks Again for all the help
    Dan
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must not have downloaded About:Buster from the link in the READ ME as we request that you do. About:Buster is on version 4.0. Download it and then run it. Each time you run it, before doing a scan, you should click the Update button (that is how you find out about the Reference file version). The download file comes with Reference 16 but the current Reference version available is 21. It will show you that. Click the Download Update button to get updated.

    Then run it again as I previously requested.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds