could anyone help with my log ?

Discussion in 'Malware Help (A Specialist Will Reply)' started by lee2lee, Dec 30, 2004.

  1. lee2lee

    lee2lee Private E-2

    hi, find-it-easy.org seems to be taking over my comp.

    here is my log.
     

    Attached Files:

  2. tagged

    tagged Private E-2

    Hi Lee!

    You should go through the 'Read me first before before asking for support.' sticky posted by Major Attitude.
    http://forums.majorgeeks.com/showthread.php?t=35407. It's located above the posts on this Spyware Specific forum page. It'll help out a lot.

    Make sure to try to complete all the steps, and write down any problems you encounter with them, and what symptoms remain when you're finished. Then post back with the results.



    Good Luck!
     
  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed,including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  4. lee2lee

    lee2lee Private E-2

    hi, i have ran through what you said and didnt really get any where. dont really know what to do now?
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Ok, First thing I notice is that your not up-to-date on your OS updates. For your safety you need at LEAST WinXP Service Pack 1a, I would highly suggest installing WinXP Service Pack 2 ASAP to get all the latest security fixes because as of right now your vulnerable to a lot. Also from viewing your log you have no signs of running the online virus scans. In order to repair your infections you need to completely read what we post. Please run the online virus scans and follow the threads to make it easier on both of us.

    TrendMicro Online Virus Scan

    Symantec Online Virus Scan
     
  6. lee2lee

    lee2lee Private E-2

    right, did both the virus scans,

    one came up with 4 and i deleted them and the other came up with these

    C:\Documents and Settings\lee\Local Settings\Temporary Internet Files\Content.IE5\CPEBOHQJ\file[1].exe is infected with Downloader.Trojan
    C:\Documents and Settings\lee\Local Settings\Temporary Internet Files\Content.IE5\GX27CLIN\1632[2] is infected with Bloodhound.Exploit.6
    C:\Documents and Settings\lee\Local Settings\Temporary Internet Files\Content.IE5\OVERSPQV\index[1].htm is infected with MHTMLRedir.Exploit


    i just done another log as well.
    hope this will help
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Ok, lets do this:

    1)Download and run CCleaner

    2)This will clean your temp files, cookies, etc; After you run this tool go into the folder "C:\Documents and Settings\lee\Local Settings\Temporary Internet Files" and delete "Content.IE5" if it still exist.

    Complete this and I will be back shortly to tell you about the log. If I dont make it back im sure chaslang will take a look at it.
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Ok, Im back for a little while, Ok lets run HJT again and fix this item. Before removing anything with HJT please close all browsers.

    O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:\foo.mht!http://82.179.166.145/x15.chm::/trs15.exe

    After removing this reboot, other than this your log looks fine.

    Are you still having the problem?
     
  9. lee2lee

    lee2lee Private E-2

    seem to of fixed it.

    Thanks mate.

    any more probs ill give u a shout.
     
  10. lee2lee

    lee2lee Private E-2

    invaded by homepage hijacker! Help!

    hi, i had it the other day and it went and now its back.

    Please could you check me log and see if there is any problems.

    Thanks lee
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. lee2lee

    lee2lee Private E-2

    Right, the same problem has come back.
    Ive put a new log up.
    Lee
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I have merged you back into one thread.

    You never updated your OS and IE versions as was requested back on 12/30/2004 by BJ. Unless you want to keep on having problems you will need to do this.

    Please explain what your problems are. Does it have anything to do with this line:
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://192.168.0.1/

    Isn't 192.168.0.1 part of your network? Possibly your DNS server?
     
    Last edited: Jan 9, 2005
  14. lee2lee

    lee2lee Private E-2

    Hi, right ive updated windows, im not to sure what any of the lines on the log mean so you might have to help me, this is my new log.

    Thanks lee
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now you have updated! But what are the problems that you are having?
     
  16. lee2lee

    lee2lee Private E-2

    right when i open explorer it get an ad come up find-it-easy.org, cant get rid of that, also, if i go got google and search for something, when i click on my search the page starts to load and then an ad takes over the page, click back and the page starts to load then a different add takes over the page.

    Very anoying.
    Any ideas.

    Lee
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  18. lee2lee

    lee2lee Private E-2

    Yea i do you ebay stuf, i have ebay toolbar as well.

    here is my ad-aware info.
    Definitions File Loaded:
    Reference Number : SE1R23 16.12.2004
    Internal build : 28
    File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
    File size : 418765 Bytes
    Total size : 1325342 Bytes
    Signature data size : 1295582 Bytes
    Reference data size : 29248 Bytes
    Signatures total : 36831
    Fingerprints total : 624
    Fingerprints size : 23478 Bytes
    Target categories : 15
    Target families : 634

    13-01-2005 19:12:04 Performing WebUpdate...

    Installing Update...
    Definitions File Loaded:
    Reference Number : SE1R25 11.01.2005
    Internal build : 30
    File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
    File size : 412196 Bytes
    Total size : 1300547 Bytes
    Signature data size : 1270864 Bytes
    Reference data size : 29171 Bytes
    Signatures total : 36186
    Fingerprints total : 604
    Fingerprints size : 22767 Bytes
    Target categories : 15
    Target families : 632


    13-01-2005 19:12:20 Success
    Update successfully downloaded and installed.



    I think that site applies to me but there is so much info on there.

    Lee
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so it looks like you did not have the latest Ad-Aware reference file. So now that is updated to the SE1R25 11.01.2005 version. But double check your Ad-Aware SE program version (that was the other item I asked for). Is it version 1.05? If not, get it updated.

    Run Ad-Aware SE and click Scan Now then select Perform full system scan. Then click Next and let it scan. This may take awhile. When it finishes have it fix everything and let me know if and what it found.
     
  20. lee2lee

    lee2lee Private E-2

    hi, yea it is 1.05, ive removed the ebay and google tool bar and i think that got rid of it, i also did the system scan after, it found 18 objects, ive deleted them now.
    Any thing else i can do now to flush out anything that is still on my comp.

    Lee
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  22. lee2lee

    lee2lee Private E-2

    yes, thanks for all your help mate.

    Lee
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Happy I could help!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds