HJT logfile, pretty bad, please help :P

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by LockForward, Mar 1, 2005.

  1. LockForward

    LockForward Private E-2

    Something particularly nasty was misclicked and saved on my computer while browing one day. 28[1].bin and Trojan.Dropper keep getting blocked by Norton.

    Logfile of HijackThis v1.99.1
    Scan saved at 12:54:09 PM, on 3/1/2005
    Platform: Windows 2000 SP2 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 SP2 (5.00.2920.0000)

    Edit by chaslang: Unrequested inline log deleted
     
    Last edited by a moderator: Mar 1, 2005
  2. AndrewVolz

    AndrewVolz Private E-2

    well right off the bat:

    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Creative\ShareDLL\MediaDet.Exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Stop-the-Pop-Up Lite\stopthepop.exe

    but viewpoint can be uninstalled from add/remove usually and may take care of a few of these.

    realsched.exe is not spyware but is eating resources along with many other processess on your list.

    I would start with an msconfig if this is XP and disable a majority of your startup items.
     
  3. LockForward

    LockForward Private E-2

    stop the pop is for my sanity's sake righ tnow as it's blocked 120 popups in less than an hour. Once I get my comp cleaned up, I'll ditch it.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These are not the cause of the users problems. While they are not really necessary they are not problems unless you have a resources issue or do not need them (some people do use them).

    mediadet.exe is a process associated with Creative Labs systems. Normally installed with their sound card products, this process detects the insertion of an audio CD and then loads the appropriate application.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LockForward,

    HJT is not the first step and we have guidelines on when and how to post a log. And on how to use HJT. You have a number of problems and need to follow the procedures below.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one AND that you have any/all updates for the programs. TIP: Create a folder on your C:\ drive for the tools/utilities you will need to use. For example: Navigate to your Program Files directory, right click on a blank spot in the window > choose New > Folder. Name this folder Spyware Tools. Now you can save the needed tools to this folder and if you prefer, create sub-folders named for each individual utility.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything along with details about any problems you may have encountered in completing the steps. The more details you can provide the better.

    If after doing ALL of the above you still have a problem:

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an ATTACHMENT. All instructions are covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting


    Now post a Hijack This log as an ATTACHMENT to your message (Do NOT copy/paste the log into your post). Please close unnecessary running programs before you run HijackThis. You must close each of the following: your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc.

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    To Repeat: Please be sure to reply in this thread if you need further assistance or have any questions. Someone WILL be along to help you as soon as they can. You can help us help you by following the above instructions and providing detailed information as to the difficulties you are having and/or continuing to have after you have completed the Basic Spyware, Trojan And Virus Removal tutorial. Just telling us you followed the tutorial does not give us enough information. You need to let us know the results...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    We all recognize that if you are here asking for help you are probably frustrated and maybe even angry that your computer has been taken over by some malicious program. Rest assured, we want to help you but that we get frustrated too when we are not given the requested information or when instructions are not followed. Don't be afraid to ask for additional help if you don't understand something! There is no such thing as a dumb question and we do not expect everyone who comes here to have vast computer knowledge, however you will be more educated and better prepared to prevent re-infestation when you leave here!http://forums.majorgeeks.com/images/smilies/smile.gif

    Good luck!http://forums.majorgeeks.com/images/smilies/smile.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds