HijackThis Logfile

Discussion in 'Malware Help (A Specialist Will Reply)' started by mvirella, Mar 25, 2006.

  1. mvirella

    mvirella Private E-2

    Hey guys,
    I read and am in the process of following the instructions to remove the SurfSideKick crap from my computer. I'm attaching a copy of the log file from hijack this. I'm in the first stages, I havent gotten into the actual removal yet, this is the first thing I've done.
     

    Attached Files:

  2. mvirella

    mvirella Private E-2

    ok, here's the logfile after all the steps have been completed. There was no repair.dll files anywhere, so I just continued steps. I still have popups coming up like crazy, and I have some svchost.exe on my desktop, but its not in add or remove programs, and its not coming up in my spyware scans. Any ideas?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You have a load of problems (maybe 20 or 30 different issues)! And some of them a big trouble to remove.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  4. mvirella

    mvirella Private E-2

    OK, I'm back...I finished all the steps, and I have attached all the log files. I cleaned out alot that was wrong with the PC, but it says there are still problems, and I dont know what to do next.
    It's running alot faster, and I'm not getting as many pop ups as I was before, but there were alot of things that couldnt be fixed.
    Here goes:

    CCLeaner - Ran fine
    Windows Malicious Spyware Removal Tool - found Worm: Win32/Alcan.B
    Ad-Aware SE - found MRU List (26), Windows (1, TAC rating 3), Possible Browser Hijack (2), WebEnhancer (TAC 9) - all were removed successfully.
    SpyBot - found CoolWWWSearch, DeskWizz, CAS-Client, Smitfraud-C, Web-Nexus, NewDotNet, Zeno, Network Moniter, Windows Security Center Anti Virus Disable Notify - All were removed successfully.
    Windows Defender - found NewDotNet, SurfSideKick ( I have followed all the steps to remove this per the Special Removal Instructions, but it was still found after), Adware, Yazzle Sudoku, Desktop Links. All were removed EXCEPT the Desktop Links, which showed an unexpected failure removing objects.
    CWShredder - None Present
    Kill2Me - None Present

    Bitdefender, Panda, and Hijack this logs are attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have quite a few nasty infections remaining. One of them is a newer form of a Qoologic infection that has a load of hidden processes and files. We need to run a couple more scanning tools to help us identify some problems.


    Download & run Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that looks like fsbl-xxxxxxx.log
    • Please attach the Blacklight log file here.
    Now download FindQool by LonnyRJones
    • Extract the files and place the FindQool folder into root folder of your hard disk. This is usually C:\
    • Open the folder and run Qlocate.bat
    • Post the contents of the txt.log which will open wen the scan is finished.
     
  6. mvirella

    mvirella Private E-2

    I downloaded those 2 things, and I had the logfile from the first one, but then windows defender started going off like crazy, and then it said in order to protect my computer it had to reboot it. This came from the defender, so I rebooted. When it started back up, my Anti Virus was disabled and would not start up, my email would not open, and my internet was blocked. All of my windows programs started shutting down on their own. I had no choice at that point but to crash the computer. Obviously everything is ok now, but I lost alot.
    Can you tell me, how I could have contracted all of these things? The pc was fine, and I walked away to make dinner.... by the time I got back, the entire screen was covered with pop ups, and thats when it all started. It seemed the more anti spyware and malware things I used, the worse the popups got. I know it sounds silly but it almost seemed like i was ticking off the viruses and they were getting worse every time I tried to remove them. So, I was wondering what could have happened, and also now that my computer is up and running without the viruses, what I should put on it to keep myself protected.

    Thank you so much for your help!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just have a bunch of bad stuf that you picked up from some place you have been surfing or downloading from. The antispyware tools are not the problem. The malware and the conflicts that the malware is causing with the antispyware tools are the problem.

    I need the results from those to scans before we can get anywhere. If necessary, just disable Windows Defender before starting the scans this time.

    NOTE: You are not clean!!!!!
     
  8. mvirella

    mvirella Private E-2

    I crashed the computer, wiped everything and started from scratch.. I couldnt open anything, navigate anything, couldnt use my IE, couldnt do anything at all.... all I had were Virus Alerts and Worm Alerts popping up like crazy wiht random IE popups.... everything is gone already :( Including all the things I downloaded per your instructions last night, but I can redownload them if you need me to and post a new log... but since I completely crashed (re-formatted) the pc everything should be gone now right?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also, just to give you an idea of some of your problems, I listing them below. But NOTE that I said some. You had more hiding and that was what the other scans were going to look for:

     
  11. mvirella

    mvirella Private E-2

    Thanks :) That's what I'm working on now. I've been trying to read through as much of this as I can. I thought I had gained a pretty good understanding of how to protect myself and how to work through these problems, but I see after these last few days that I have a long long long way to go lol. Thanks alot for your help, and I will try to get everything done on the instruction page. My husband doesnt like Firefox, so I'm going to have to stay with IE, but I do know that when I used Firefox when I had my own computer, it was much better. Also, your first step says to use SP2, which I thought we were using, but when i checked, its SP1. I checked the requirements, and I meet them all, but it is still not an option at update. Anyway, I appreciate your time Chas :)
     
  12. mvirella

    mvirella Private E-2

    lol your post came up same time as my last one. When I said "thats what I'm working on now" I meant the page you directed me to, to prevent malware. That last post really looks a mess.... I hope I can keep it from happening again, but am sooo grateful for this website!!
     
  13. mvirella

    mvirella Private E-2

    ok, SP2 is installing now.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can still install FireFox and use it as desired. You can use it and your husband can use IE. It does not cause a problem to have them both installed.
     
  15. mvirella

    mvirella Private E-2

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Doing the happy dance? :)

    Make sure that SP2 does truly get installed by looking at your first few lines of a HijackThis log. Many times people try updating and think that it was successful when it was not.
     
  17. mvirella

    mvirella Private E-2

    lol why yes I am.... and thnx, I will DL HJT again :) *high five*

    p.s.... how come Burger Time got taken out of the arcade? That was the BEST game ever lol
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know! I pay no attention to the Arcade. I have never have time to play computer games anyway! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds