HJT Log file - please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by prophet66, Dec 7, 2005.

  1. prophet66

    prophet66 Private E-2

    Looking for assistance to remove this Spyaxe form my PC.
     

    Attached Files:

  2. prophet66

    prophet66 Private E-2

    I followed the steps for smitRem.exe. So far all looks good, No pop-ups or redirects to Spyaxe homepage.

    crossing my fingers........
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Happy to hear it helped you but I still see some items we need to fix. I'll post the fixes as soon as I can. However the links for SpyAxe and Smitfraud removal do not ask you to post a HijackThis log. They ask for the output from running smitRem.exe which is called smitfiles.txt. HijackThis logs must only be posted after following standard cleaning procedures in the below sticky thread:

    READ & RUN ME FIRST Before Asking for Support
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have installed SpywareCleaner, you should goto Add/Remove programs and uninstall it. This is not a very useful program and has been on a rogue list for awhile. See: http://www.spywarewarrior.com/rogue_anti-spyware.htm


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: HomepageBHO - {724510c3-f3c8-4fb7-879a-d99f29008a2f} - C:\WINDOWS\system32\hpBE6E.tmp
    O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
    O23 - Service: SpywareCleanerService - Unknown owner - C:\Program Files\Spyware Cleaner\SCService.exe (file missing)


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\WINDOWS\system32\hpBE6E.tmp
    C:\Program Files\Spyware Cleaner <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. prophet66

    prophet66 Private E-2

    Looks like things are working. Enclosed is new HJT log file. Let me know

    Thanks :)
     

    Attached Files:

  6. prophet66

    prophet66 Private E-2

    sorry, disregard previous HJT log file. This is the correct one after running HJT again.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why is it that message # 1 had HJT installed properly in:

    C:\Program Files\HJT\HijackThis.exe

    and you last two messages have it wrong?

    C:\Documents and Settings\Justin\Desktop\hijackthis\HijackThis.exe

    At anyrate, your log is clean and you should now work thru the below:

    How to Protect yourself from malware!

    I would also suggest that you uninstall one of the below:
    MS Antispyware
    Spy Sweeper

    Personally I would keep SpySweeper but it is not free. And you really need to buy it to keep full capabilities and get updates. If you plan on buying it, uninstall MS Antispyware. Otherwise, uninstall Spy Sweeper. You do not want to have both of these running as a long term solution.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds