Hijackthis log

Discussion in 'Malware Help (A Specialist Will Reply)' started by wilk, May 30, 2005.

  1. wilk

    wilk Private E-2

    I never really had a problem with spyware until now. A few cousins were over (they are younger) I wasn't home and apparently they were on my computer messing around. Now I got lots of spyware. I just reinstalled XP Pro with SP2 about 3 weeks ago. I downloaded all the programs you suggested and ran them. I always used AVG, Ad-Aware, Spybot and Microsoft Anti-Spyware. I never had to run hijackthis but here is my log file.

    Thanks for the help.
     

    Attached Files:

  2. wilk

    wilk Private E-2

    Also after all scans I am getting a pop up in IE named "Aurora". I only use IE for a few sites, the rest I use Firefox.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. HJT logs should only be posted when requested and then they must be attachments to your message.

    Fisrt, download Nail/Bolder/Aurora Remover 0.3.1 Beta and save it to its own folder like c:\ABIremover

    - Now extract the abiremover.exe file from the ZIP file into the folder you created but do not run the EXE yet.

    - Reboot into Safe Mode with no network suppost and do not run anything else but what I tell you to run!

    - Run the ABIRemover.exe, press install, wait (explorer window will disapear)

    - When it finishes just reboot and continue with the below steps.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    Also to get you started and to reduce the size of your HJT log. Do the following:




    After doing ALL of the above you still have a problem, boot into normal mode and (make sure you follow these directions, you were running HJT from the ZIP file):


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. wilk

    wilk Private E-2

    Thanks, i'll give that a try.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you still have problems and wind up posting a HijackThis log at the end, do not reboot or power down you PC after posting the log. Simply disconnect you cable to the internet for security. A power down or reboot could cause the problem to mutate.
     
  6. JudyPatudy

    JudyPatudy Private E-2

    i would like to post my log, but i dont know how to do it as an attachment.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not your thread! You should not be posting here. Read the Announcement and the sticky threads. No HJT logs are to be posted without them being requested and they will not be requested until the following sticky thread steps have been run:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
     
  8. wilk

    wilk Private E-2

    Ok I did everything you asked. I no longer get those IE popups.

    Hsremove found 8 items and removed them.
    Adaware found 30 items (most were cookies).
    Spybot found "ABetterInternet" and removed it.

    All other programs didn't find anything. Ran AVG Antivirus with all updates and found nothing.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not need to run HSremove (or About:Buster) because you do not have about:blank or HSA hijack issues.

    You should complete the steps in my previous message to you and post the follow up HJT log.
     
  10. wilk

    wilk Private E-2

    Ok, here's my log.

    Thanks.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean but note you did not install HJT where requested. You had it here:
    C:\Documents and Settings\Jeff\My Documents\hijackthis\HijackThis.exe

    Does Ewido Security Suite include a firewall?
     
  12. wilk

    wilk Private E-2

    Sorry forgot to uninsall that. No it doesn't but i'm using a router. Should that be enough or should I also use a software firewall? I heard Sygate was good.

    Thanks.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have a software firewall and after installing it, disable the one in WinXP SP2 which is not good enough. Yes Sygate is good. See the reference to it in the below:

    How to Protect yourself from malware!
     
  14. wilk

    wilk Private E-2

    Thanks for the link, installed sygate. Does this program update?
     
  15. tblue

    tblue Corporal

    You can set it to update automatically.
    Go to Tools>Options>Updates
    Check update automatically :)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As a personal preference, I do not always like to have updates performed automatically. It can sometimes get you into a state where you swear "I have not installed anything new....I don't understand what's wrong" because updates are done without your knowledge. I prefer to control what is updated and when. On the otherside if you are very bad about keeping up to date, it may be a good thing for you.

    If you were to select autoupdates on any software, the only ones I would allow are:
    - antivirus
    - spyware blocking tools
    - firewall

    Others I would get manually so you control your destiny. ;)
     
  17. tblue

    tblue Corporal

    Thats good advice. I don't want to HJ this thread but do you have Windows update automatically??
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Absolutely not. I always check for them myself. On a few WinXP systems, I have it notify me when updates are available only. And I choose what and when to install what I want. On a few PCs I did not want WinXP SP2. I need SP1 for testing malware problem so I do not want to upgrade. So I always select Custom Install and bypass SP2.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds