Hijackthis log review

Discussion in 'Malware Help (A Specialist Will Reply)' started by declaredinsane, Feb 20, 2009.

  1. declaredinsane

    declaredinsane Private E-2

    I was wondering if anyone can take a look at this log and tell me if anything looks like a virus and so on. Thank you for yor time. :-D

    Logfile of Trend Micro HijackThis v2.0.2
     
    Last edited by a moderator: Feb 21, 2009
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid addtional delay in getting a response, it is strongly advise that after completing the READ & RUN ME you also read this sticky Don't Bump! It Only Hurts You!!!. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. declaredinsane

    declaredinsane Private E-2

    Logfile of Trend Micro HijackThis v2.0.2






    EDIT: User did not follow instructions to attach the requested logs.
     
    Last edited by a moderator: Feb 22, 2009
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have now posted a HJT log twice. You may either follow the instructions I gave you or decide to deal with your issues in a different manner.
     
  5. declaredinsane

    declaredinsane Private E-2

    I checked and there is no TDSSserv.sys on my system. I also did everything else. And still every now and then it doesnt go staight to my homepage.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And this will continue to happen until you finish the Read and Run First instructions and attach the requested logs:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip
     
  7. declaredinsane

    declaredinsane Private E-2

    Here are the files
     

    Attached Files:

  8. declaredinsane

    declaredinsane Private E-2

    last file
     

    Attached Files:

    • sas.log
      File size:
      895 bytes
      Views:
      1
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Find and delete this:
    C:\Users\Jake\AppData\Local\d3d9caps.dat

    What are you being directed to and does this happen with all browsers?

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.
     
  10. declaredinsane

    declaredinsane Private E-2

    Thank you so much!!! I did everything and now go straight to my home page. Every now and then it would take me to other search engines but thats a thing of the past now. What was C:\Users\Jake\AppData\Local\d3d9caps.dat? Once again ty so much.:-D
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome......the file could be a legit MS file, but it is usually associated with Windows Presentation....so it can also be a malware item.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds