Hijack this log + explanation - Need Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by LongshotJoe, Jul 16, 2005.

  1. LongshotJoe

    LongshotJoe Private E-2

    A little over a week ago I was infected pretty severly with trojan horses and who knows what else, having about:blank issues and programs constantly trying to add themselves to my start menu.

    I researched previous posts here and tried to fix everything on my own, via programs cwshredder, ewido secuirty suite, ccleaner, ad-aware SE w/ plugin, aboutbuster5, spywareblaster, kill2me, stinger, sbybot search and destroy, hsremove, plvxcleaner (along with registering Norton Anti Virus, and using Adware Filter and Microsoft Antispyware) AND, of course, Hijackthis. Quite a grocery list, I know.

    Anyways, through all of it, I managed to get rid of about:blank along with any visible problems I was having. However, when I run CCleaner every couple of days, I find new files in my Windows and Windows/system32 folders listed as "issues" that seem similar to the ones trying to install themselves into my start menu when I was having problems (apihi.exe, jeyz.exe, javauv.exe, ipaj32.exe - I could go on and list the other 422 but you get the idea)...

    So, after trying to do this myself, I'd like to ask for some help from the pros, which I definitely am not. Sorry if I provided too much information, just wanted to give you a background and let you know I spent hours and hours last weekend trying to fix it myself before asking for anyone's time. I just want to finish this up to insure I don't run into any future meltdowns like I had last weekend. Thanks so much for your time and help in advance, it's great to have people so knowledgeable offerring help, here is my most recent Hijackthis logfile.

    [EDIT] Inline log converted to attachment per forum rules stated in the sticky thread at top of forum. [/EDIT]
     

    Attached Files:

    • hjt.txt
      File size:
      8.5 KB
      Views:
      4
    Last edited by a moderator: Jul 16, 2005
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is clean, the only entry thats needs fixing is the one below.

    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)

    Are you having any problems?
     
  3. LongshotJoe

    LongshotJoe Private E-2

    No problems that are affecting my computer use right now, but, when I run CCleaner every 3 or so days, I have 300-500 files in my C:/Windows and C:/Windows/system32 folders that are listed as "issues." I clean them, and then 3 days later there are a new 300-500 of them.

    They seem like the sort of startup files that Microsoft Antispyware was alerting me about (apihi.exe, jeyz.exe, javauv.exe, ipaj32.exe, etc) which were trying to be added to my system startup registry back when my computer was totally ****ed.

    Would these files, if I didn't clean them with CCleaner every few days, eventually become part of a larger problem I'd have to deal with? I have no idea what these files are or why there are 3-500 new ones every couple days I check. Thanks again.

    -Joe
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I dont recommend using the Issues part of CCleaner because its known to cause more problems than good so I would stay away from that scan.

    If you want a registry cleaner then I would recommend Reg Supreme Pro.
     
  5. LongshotJoe

    LongshotJoe Private E-2

    Okay, thank you, will do from now on... and the 300-500 Windows & Windows/System32 files? Anything I should know or be concerned about regarding those? Appreciate the help, once again.

    -Joe
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Click Start > Run > Type in msconfig

    Click the startup tab, check EVERYTHING in there and click ok. DO NOT REBOOT!

    Attach a new HJT log after you complete the above and lets see if there is any change.
     
  7. LongshotJoe

    LongshotJoe Private E-2

    Did what you said, here you go. (still haven't fixed the 09 - MUSICMATCH entry, just wanted to wait until you said there weren't any other issues)

    Hope this all looks good. Is there an explanation for all those files if my log is now clean? (though I guess if you say I have nothing to worry about, i shouldn't worry about anything :)

    Thanks once again for your help, really appreciate your time in answering my questions.

    Inline log attached!
     

    Attached Files:

    Last edited by a moderator: Jul 16, 2005
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is still clean except for this one entry below which you will need to fix with HJT. There is a few unnecessary entries but nothing bad.

    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)

    After you remove the above entry reboot and run CCleaner to cleanup any junk files. Then let me know if your having any problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds