Hicjackthis.log HELP!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by raygt13, Oct 30, 2004.

  1. raygt13

    raygt13 Private E-2

    [log removed]
    ______________________________

    That is my hijackthis.log is there anything i can remove to speed up my computer???????? :rolleyes:
     
    Last edited by a moderator: Oct 30, 2004
  2. PhilliePhan

    PhilliePhan Guest

    Hi raygt13,

    There are a number of issues in your log that need to be addressed. But first, you should note that you are running HijackThis improperly.

    Please take a run through the steps HERE: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Then, if a HijackThis log is required, please read this before attaching a log: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Work through the Basic Spyware, Trojan And Virus Removal Tutorial and post back with the results.

    Best luck,
    PP
     
  3. raygt13

    raygt13 Private E-2

    Help spware problem!!!

    Ok can u please help me i just had bad spyware and virus i think i got rid of most of em can u please check my Hijackthis.log :rolleyes:
     

    Attached Files:

  4. PhilliePhan

    PhilliePhan Guest

    Re: Help spware problem!!!

    Hi Raygt13,

    There are a number of issues in your log that need to be addressed. But, as I mentioned in your other thread, you are running HJT improperly. You need to put HJT in its own safe folder C:\Program Files\ HijackThis.

    It does look like you have exhausted many options in your fight, so once you put HJT in the proper place, attach a fresh log and we'll go from there ;)

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    PP
     
  5. raygt13

    raygt13 Private E-2

    Help (hijackthis)

    ok well this time i think i posted my log correctly
    can you please make an anylisis on it tx
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Help (hijackthis)

    Why do you keep starting new threads for the same problems? Please remain in one thread.

    I merged you back to your old thread.

    EDIT: Okay make that, merged back into a couple of old threads.

    WHEN ARE YOU GOING TO DO THE READ ME FIRST STEPS?

    You were requested to do this several times. Even in another (fourth thread on same problem): http://forums.majorgeeks.com/showthread.php?t=46038
     
    Last edited: Oct 30, 2004
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Help (hijackthis)

    Okay! It looks like you may have run the READ ME FIRST. I see the online scanner traces in your HJT log. You should have stated that you had run them and what they found.

    You still have a load of trojans running.
     
  8. PhilliePhan

    PhilliePhan Guest

    raygt13,

    Please run through the tutorial first, next time!

    Your IE is a bit old and you should decide between AVG and Avast if you haven't already.

    Please turn System Restore OFF and Enable the Viewing of Hidden Files as per the Tutorial.

    Use Task Manager to end the following running processes if found:
    l?ass.exe
    unotzf.exe
    CSV7P070.exe
    Meruoq.exe
    haltpapi.exe
    sabr.exe
    hhscm32.exe


    Run HijackThis and Check the Boxes for the Following:
    R3 - Default URLSearchHook is missing

    O3 - Toolbar: (no name) - {58A83E4F-477A-4A3F-BF9B-B65BC2BD5598} - (no file)

    O4 - HKLM\..\Run: [weyfxz] C:\WINDOWS\System32\unotzf.exe

    O4 - HKLM\..\Run: [CSV7P70] C:\Program Files\CSBB\CSV7P070.exe

    O4 - HKLM\..\Run: [Rxagik] C:\WINDOWS\Meruoq.exe

    O4 - HKLM\..\Run: [238g38j] haltpapi.exe

    O4 - HKCU\..\Run: [Buem] C:\Documents and Settings\Administrator\Application Data\sabr.exe

    O4 - HKCU\..\Run: [Jnm] C:\WINDOWS\System32\l?ass.exe

    O4 - HKCU\..\Run: [J0rmRUHFO] hhscm32.exe


    Make sure ALL Browser Windows are Closed when you click FIX.

    Reboot into Safe Mode and DELETE the following:

    C:\WINDOWS\System32\unotzf.exe
    C:\Program Files\CSBB --> The Folder
    C:\WINDOWS\Meruoq.exe
    C:\Documents and Settings\Administrator\Application Data\sabr.exe
    C:\WINDOWS\System32\l?ass.exe

    Reboot to Normal Windows, attach a fresh log & tell us how things are working. I'll check back when I get a chance.

    PP
     
  9. raygt13

    raygt13 Private E-2

    ok i followed the tutorial this time rly sry bout b4 guyz heres my new log
    i could not find the files unotzf.exe, CSBB, Meruq.exe

    Heres my log
     

    Attached Files:

  10. PhilliePhan

    PhilliePhan Guest

    Hi Raygt13,

    Please turn System Restore OFF and Enable the Viewing of Hidden Files as per the Tutorial.

    Run HijackThis and Check the Boxes for the Following:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.5:80 - if you do not recognize this as your Proxy Server

    O3 - Toolbar: (no name) - {58A83E4F-477A-4A3F-BF9B-B65BC2BD5598} - (no file)

    O4 - HKLM\..\RunServices: [SystemSAS] system32.exe


    Make sure All browser windows are Closed when you click FIX.

    Now, boot to Safe Mode and DELETE this if found:
    C:\Windows\System\system32.exe - Note that it may be hidden and delete it ONLY if found as listed.

    Reboot to Normal Windows, attach a fresh log & tell us how things are working.

    Best,
    PP
     
  11. raygt13

    raygt13 Private E-2

    O4 - HKLM\..\RunServices: [SystemSAS] system32.exe

    DOnt u need that file?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. goldfish

    goldfish Lt. Sushi.DC

    That could be legit : do you have a network on the machine your running this on? i.e. is it at an office.

    Unless its a loopback reference I can't see that doing any harm.
     
  14. PhilliePhan

    PhilliePhan Guest

    Thanks Chas, Goldfish

    Regarding the R1 - I figured it was OK. Just being thorough.

    RayGT- I mistyped this one: C:\Windows\System\system32.exe should be C:\Windows\System32\system32.exe

    I imagine you noticed this as well and took the proper action.

    PP
     
  15. raygt13

    raygt13 Private E-2

    Am i good im not sure please check my log and anylayze it one last time tx
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It looks okay now. But why do you have msconfig running at startup?
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    Are you using selective startup? Why? What are you trying to avoid loading?
     
  17. raygt13

    raygt13 Private E-2

    i dunno wut happend but i went to put it in safe mode to looke for/delete a file i was told (i went to run and typed msconfig to boot in safe mode n now i contiusly get this message how can i rid of it?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run msconfig and select normal startup. We are going to need a new HJT log after this because this could allow other dormant items to start running. That's okay. It's the only way we can find them and fix them.
     
  19. raygt13

    raygt13 Private E-2

    i put it back to normal n ran another scan check this one please
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks okay! Any other problems?
     
  21. raygt13

    raygt13 Private E-2

    my aim is glitching out when i try to sign on please anyalyze my log
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What does glitching out mean?

    Your HJT log is clean. Have you tried using todays Aim Fix: AIM Fix 1.0 (Updated)
     
  23. raygt13

    raygt13 Private E-2

    Ok letz start off the explanation
    in my computer running under 1 internet is 2 computers main one with router to this one attached by an ethernet cord (i pretty much aint paying for this connection another words) The main computer however crashed and i had to relace the cpu. No i cannot figure out how to configure the main computer to pickup the signal . in this process even thou my router is not running off of that computer my internet at home on this computer does not work or works VERY LITTLE. for instance somethimes after waiting 5 mniutes my AIM goes on
    but usually it stays at step 1 or step 2 and doesnt freeze just wont go online. I also experience a similar probelem with my browser i have OPTIMUM ONLINE (cable) any advice
     
  24. Kodo

    Kodo SNATCHSQUATCH

    so you have PC 2 attached to PC1 which is then attached to the router? (just trying to clarify). Or are they both seperately connected to the router?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And did you configure PC1 for DHCP? What OS?

    And if you had all these problems we already fixed on PC2, you should be checking PC1 for similar issues.
     
  26. raygt13

    raygt13 Private E-2

    OS windowz XP on both
    Linux router

    the main is a 2year old computer that i had totally wiped out on has installed windows xp and microsoft office

    How can i configure main computer to connect to the router and pick up internet service
     
  27. raygt13

    raygt13 Private E-2

    how do i configure PC1 for DHCP
     
  28. raygt13

    raygt13 Private E-2

    Both seprertaly connected each has itz own port in my router ... im on PC2 mright now in skool (wireless internet) at home i cannot get service Or i get realY SLOW SERVICE
     
  29. raygt13

    raygt13 Private E-2

    OK new news ma pc2 is working all i need now is to get internet on my totally cleaned out Pc1 (main pc) that was a 3com usb interface plugged into then USB for service i need to configure it so i can acces the web on that one
    how can i do that?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is a getting a little confusing! I thought we cleaned PC2 not PC1.

    PC1 does not have a normal Ethernet Card in it? Are you saying that you are using a USB port on PC1 to connect to a router that provides a USB interface?

    You need to bring up that Network connection and right click it to see how it is configures (static addressing or DHCP). You router has to be configure appropriately too. Since PC2 works see how it gets an IP address (static or DHCP) and set up PC1 similarly.
     
  31. raygt13

    raygt13 Private E-2

    Ok look i got optimum online itz cable

    i got a router which has in port 3 and 4 to different computers
    port 4 is my laptop which works but i replaced PC 3 with a new totally cleaned out PC the ethernet cord will now fit into tha back of this pc so i have this 3com netwrok interface thingy soo i can plug the connection into the usb however PC 3 is not windowz 98 anymore it is XP therefore the disk to configure the 3com network interface is not valid wut can i do to configure PC 3?? :rolleyes:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds