HijackThis log, already ran READ&RUNMEFIRST

Discussion in 'Malware Help (A Specialist Will Reply)' started by TerribleToucan, Feb 7, 2006.

  1. TerribleToucan

    TerribleToucan Private E-2

    Ok, so I've done everything in READ AND RUN ME FIRST, but still my problem persists. Read the HijackThis (read before posting) sticky, and got rid of a few problems. The ones that I'm worried about, however, weren't confirmed in any of the lists on that thread and I really don't want to delete anything crucial. So, here's the log.

    Edit by bjgarrick: Inline log attached

    So the problem I seem to be having appears to be related to the O4 eee2.exe files; there appears to be a program running in the background, that, when I use CtrlAltDelete to open TaskManager, comes up as 'upps'. So I Go to Process and it comes up as eee2.exe . I really am pretty new to all this stuff, so I can't say I completely understand the risk of deleting these files, but I decided I would get confirmation first. Also, there appears to be a browser hijacker (or something) that opens a browser window with the Page Can Not Be Displayed screen on it every once in a while, whether I'm online or not. This pagehas, in the bar along the top, 'duf'. I have no idea what to do about this. Oh, and if it helps, I don't believe that browser has any of the usual browser stuff in it; no BHO Toolbars, no HTML bar, or anything of the kind. Help if you can, and sorry if I failed to follow any sort of procedure in doing this.

    Thanks in advance,
    -jack
     

    Attached Files:

    Last edited by a moderator: Feb 7, 2006
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I also need the logs from the two online scans listed in the READ ME.
     
  3. TerribleToucan

    TerribleToucan Private E-2

    Okay, I knew I forgot something :\ Just re-ran both scans to keep them up-to-date, and here's an updated HijackThis log. It'll be an attachment this time, unlike in my last post :\
     

    Attached Files:

  4. TerribleToucan

    TerribleToucan Private E-2

    Any assistance at all? Please?
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  6. TerribleToucan

    TerribleToucan Private E-2

    It seems that Ewido has fixed all my problems. I'll post the log just to be certain, but I'm fairly sure my spyware problems have been eradicated. Thank you. A lot.

    -jack
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Now please attach a fresh HJT log.
     
  8. TerribleToucan

    TerribleToucan Private E-2

    OK, here's the log (sorry if I should have known to do this - I really have trouble remembering things like this :\ )
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add/Remove Programs for the following and uninstall them if found:

    Ewido

    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    O4 - HKLM\..\Run: [{30-04-44-4E-ZN}] C:\windows\system32\dwdsregt.exe FI002

    Again, make sure ALL browser windows are closed when you click FIX.

    Now, Please boot into Safe Mode, be sure you have the Viewing of Hidden Files & Folders Enabled per the tutorial. Now, navigate to and DELETE the following if they should remain:

    C:\windows\system32\dwdsregt.exe

    Next, run CCleaner to clean up cookies and temp files.

    Finally, I would like you to flush your System Restore points. Please follow the instructions in the below:


    • Disable and Re-enable System Restore

    • Turn OFF System Restore to flush any bad Restore Points.

    • Then, follow the instructions at the bottom of the linked page to Re-enable the Restore Utility which will create a fresh restore point.
    After you complete the above reboot once more and then scan with HijackThis and attach the new log.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds