hijackthis log

Discussion in 'Malware Help (A Specialist Will Reply)' started by taylortoons, May 21, 2006.

  1. taylortoons

    taylortoons Private E-2

    I followed the steps for malware removal, but still have issues with Downloader.ay

    I am running Windows XP. Thanks for any help you can provide.:)

    taylortoons
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    HijackThis is not installed properly. Move HijackThis to C:\Program Files\HJT.

    I need the BitDefender and Panda logs.
     
  3. taylortoons

    taylortoons Private E-2

    I moved the Hijackthis file from the temp folder and ran again. Attached is the log. Neither online scans will run. I have Service Pack 2, but active X will not let me through. I even followed the online directions with no luck. Sorry.

    taylortoons
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Scan with HijackThis and fix teh following lines:
    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  5. taylortoons

    taylortoons Private E-2

    Done. Here is the new log. The R3 log keeps coming back. I ran an additional scan/fix as a double check. Also, Windows Defender still prompts regarding the downloader.ay infection.

    Taylortoons
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  7. taylortoons

    taylortoons Private E-2

    Downloaded and ran. Attached is the log file. I don't believe it is complete. I ran WinPfind twice. The software stopped running at the same folder each time.

    Thanks
    Taylortoons
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    YEs the log is incomplete, we'll work with what we got.

    Follow the directions for running
    Look2Me VX2 Removal
    .

    Using Pocket killbox delete these files:
    Use the procduue for pocket killbox in post #4 of this thread.

    Once back in normal mode run WinPFind again.

    Post the Look2me Destroyer log, and the WinPFind log.
     
  9. taylortoons

    taylortoons Private E-2

    Finished. The L2ME did not have a log option. Just scan, removal, reboot. Attached is the WinPFind log.

    Thanks
    Taylortoons
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    That log is also incomplete.

    Follow the directions for Using GetRunKey.

    Post runkey.txt when finished
     
  11. taylortoons

    taylortoons Private E-2

    Okay. Done. Attached is the log.

    Thanks
    Taylortoons
     

    Attached Files:

  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Boot to Safe Mode.

    Do the following:

    Start -> Run
    type regedit
    click 'OK'

    Registry Editor will open, navigate to and delete the following:
    Close registry editor.

    Open Windows Explorer and delete the following file:
    REBOOT


    Run WInPFind again, let's see if we get a complete log this time.
     
  13. taylortoons

    taylortoons Private E-2

    The first regedit was not there. Neither was the taskdir in System32. I ran Wpfind again. Looks like it stopped in the same place. Here is the error code I got:

    Cannot open file C:\documents and settings\taylortoons\application data\$_hpcst$.hpc

    Thanks again
    Taylortoons

    P.S. Sorry for the delay. Just got back in town from the long weekend.
     

    Attached Files:

  14. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    OK, since WinPFind isn't running all the way through; follow the directions for Running Spy Sweeper.

    Post the SpySweeper log when done.
     
  15. taylortoons

    taylortoons Private E-2

    Here is the spysweeper log.

    Thanks
    Taylortoons
     

    Attached Files:

  16. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  17. taylortoons

    taylortoons Private E-2

    Attached are the two scans. Interestingly, Active Scan and Spy Sweeper associate certain functions of KillBox with Spy Sherriff fake alerts.

    Thanks
    Taylortoons
     
  18. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    The logs didn't attach.. If the files are located in C:\!killbox, then it isn't a false report. This is where killbox stores theh deleted files in case something needs to be restored. You can delete the contents of that folder and them empty the Recycle Bin.
     
  19. taylortoons

    taylortoons Private E-2

    Sorry. Try this...
     

    Attached Files:

  20. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Boot to Safe Mode and Delete teh following Files:
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin

    And Click OK.

    REBOOT

    Post a fresh HijackThis log.
     
  21. taylortoons

    taylortoons Private E-2

    The system32 file was not there. Everything else is complete. Attached is the Hijackthis log.

    Thanks
    Taylortoons
     

    Attached Files:

  22. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe <<===The installed version of Java on this compter is out-date. Install version 1.5.0_07 available from http://www.java.com/en/download/manual.jsp. Make sure you uninstall all older version that are on your computer

    C:\Program Files\Messenger\msmsgs.exe <<=== This is Windows Messenger, and represents a security risk. Disable Windows Messenger by running Shoot The Messenger. If you are using this as your IM client then replace it with MSN Messenger.


    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Otherwise your log is clean.

    Lets flush all your restore points and create a new clean one for your system.

    Disable And Enable System Restore
    How to Protect yourself from malware!

    Safe surfing.
     
  23. taylortoons

    taylortoons Private E-2

    Great. Thanks for all your help! I installed Avast and kept Spy Sweeper. I already have CCleaner (and use it daily) and SpyBot. I have Tea Timer activated. I will try to disable it.

    I had Norton, but uninstalled it because it was a pain/strain on me/my pc. Hopefully, I'm better protected now with easier to use tools.

    Taylortoons
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds