Could someone please check my HJT log for a bug please

Discussion in 'Malware Help (A Specialist Will Reply)' started by richo, Mar 27, 2005.

  1. richo

    richo Private E-2

    3 days ago was infected withthe jimbutt spyware. Found this forum, between this and other info managed to delete the offender. While I struggled for some hours, finally it worked. Found Bitdefender online scan of operating programs great for analysing, Symantec and MicroTrend could not be accessed.
    Uninstalled outdated 2003 nortons antivirus and Systemsworks ( as a disabled pensioner can't afford the luxury ! ).
    Installed the following, AVG anti virus, AdAware, Spybot with the recommended patch, Spyguard, Zonealarm, Killbox, Aboutbuster and CC cleaner.
    All updated and have updated Windows XP home.
    However, two problems have arisen, 1 of which I'm unsure as to its origin and purpose - spyware ?
    My dialup is connected and there is full receiving activity, even though this is the only site I'm connected to, no other windows open.. As far as I can tell I'm downloading/receiving something which I know nothing about and can't see any suspicious activity which indicates a virus or spyware.
    Have run Adaware and Spybot to come up with no result. All the other applications are active and supposedly protecting.
    Have made a log of HJT and would like someone to analyse for me and advise on a course of action.
    This is my first post, no expert on these matters, but would like to get my system operating properly.
    My other problem is related to accessing the net from my sons computer, which now has been blocked, I think by Zone alarm. Will ask in the appropriate forum for advice.
    TIA.
    cheers
    richo
     
  2. richo

    richo Private E-2

    Forgot to add.......
    installed MozillaFirefox as my internet browser as recommended here in the " sticky "
    Before Zonealarm was installed, I sent the appropriate spyware etc programs to my sons computer. He has Vet Antivirus installed as his antivirus.
    Thanks.
    richo
     
  3. richo

    richo Private E-2

    Ahhh ha. Looks as though Microsoft update is trying to dowload SP2 into my computer, a 75mb download through a dialup receiving 4kbs ! Brilliant.
    Computer shop will install this for me, free ( if I ask nicely ).
    So how do I stop this download, which has been running now for some 4 hours to get 18 mb downloaded ?
    Probably not the right forum to ask, but seeing as I posted here initially......
    thanks
    richo
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just cancel the download if you do not want to continue it!

    As far as malware problems goes....if you still have issues with them we have procedures that we like to have followed completely before getting to a HijackThis log. Here they are:


    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. richo

    richo Private E-2

    Thanks chaslang,
    I have followed the procedures outlined below, before making the HJT log, I'm pretty sure the malware is gone.......
    BUT, I can't seem to stop the download from microsoft, which is where I think it's coming from. Left machine on last night, have had a few hours sleep. must've disconnected at some stage and is now 2.5 hours into downloading again.
    If it is microsoft service pack2 downloading - how do I cancel it ? Can't understand the instructions/notice on the MS site with regard to the download re cancelling.
    Between this and my sons computer being unable to acess the net since installing Zonealarm I've spent hours with my phone tied up ( I only have access to dialup and 1 phone line where I live ) the monitor seems to be the only thing I gwet to look at !
    Any assistance would be greatly appreciated.
    How do I cancel the download ........please.
    Thanks
    richo.
     
  6. richo

    richo Private E-2

    Okay, went to Control Panel and changed the Automatic Updates to Turn Off Automatic Updates. That seems to have fixed the autodownload.
    Would still like to have someone view the HJT log, performed as per the " sticky ", which was how I found out about all these free programs and procedures for preventing further malware.
    thanks
    richo
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I already stated in my first message that after performing all steps of the READ ME, to post your HJT log per my instructions.
     
  8. richo

    richo Private E-2

    Here is the log chaslang. Thanks, will await your reply.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only items in your HJT log that should be fix are:

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    So run HJT and select those two lines and fix them.

    Are you having any specific problems on this PC?
     
  10. richo

    richo Private E-2

    Thanks chaslang,
    Problems seem to be resolved. The two items you suggested deleting ( and I have ) were relating to the Bitdefender online scan, which I used as I was unable to use/access the Microtrend or Symantec online virus checker. Bitdefender worked well for me and provided the solution for a place to work from.
    I performed all the processes on the READ ME for this forum, apart from the startup in safe mode, as I had managed to kill the problem by the time I got to that stage.
    Thanks for your assistance, all looks well for now. No doubt the future will see some malady crop up - it always does ! Hopefully I've learnt something along the way. sure didn't want to be a bother to anyone or waste your valuable time when there are others probably more worthy of the assistance.
    cheers
    richo
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds