My computer is a mess, hijack this log included

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Ashtan, Jan 21, 2005.

  1. Ashtan

    Ashtan Private E-2

    Hi all,

    Hope someone can shed some light on the subject here. My old version of Norton was apparently not doing its job, as when I upgraded to 2005 I found somewhere like 60 odd viruses and a load of spyware adware.

    After using almost every remover I can get my hands on, I'm still getting some pop ups.

    Norton keeps finding BTGrab.dll & INTLRECO.exe but doesn't seem to be able to remove them, a manual delete attempt doesn't work either.

    Some programs have claimed to have removed them, and yet they pop back up again.

    Any help is GREATLY appreciated guys :)

    Logfile of HijackThis v1.99.0
    Scan saved at 02:32:55, on 22/01/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Edit by chaslang: Unrequested inline log deleted! Please follow forum guidelines. Read the stickies.
     
    Last edited by a moderator: Jan 22, 2005
  2. Quinndrew5

    Quinndrew5 Corporal

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And you still have some trojans in there too! Run the thread Quinndrew5 point you to.

    If you still have problems after that, state what your problems are and do the below.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  4. Ashtan

    Ashtan Private E-2

    I figured there would be one, but it was 2am and I was desperate :) Plus I couldn't see a Read Me First post straight away, so I gave up pretty quick :)

    Allow me to re-sort it :)
     
  5. Ashtan

    Ashtan Private E-2

    Ok,

    I've followed the tutorial now (wow) and I think i've improved the situation.

    Though a couple things in HiJack this i'm not sure about, if anyone could give the log a once over i'd really appreciate it :)

    Thanks!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
    O4 - HKLM\..\Run: [lahxoc] C:\WINDOWS\system32\mxkyoa.exe
    O4 - HKLM\..\Run: [lolxqyogv] C:\WINDOWS\system32\mxkyoa.exe
    O4 - HKLM\..\Run: [azzndugfzj] C:\WINDOWS\system32\mxkyoa.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\BTGrab.dll
    C:\WINDOWS\system32\mxkyoa.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. Ashtan

    Ashtan Private E-2

    Hello,
    again, thanks for your time and assistance.

    Ok i followed you unstructions, BTGrab.dll seemed to delete with a problem, mxykoa.exe however, I couldn't find at all.

    I also notice it seems to have re-appeared in the log?

    New log included anyway :)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Download the following program Pocket KillBox and unzip to its own. Do not run yet.

    Run HJT and have it fix the following line:

    O4 - HKLM\..\Run: [lahxoc] C:\WINDOWS\system32\mxkyoa.exe

    Exit HJT

    Run Pocket Killbox. Select the option to Delete on Reboot.

    1) Now, Copy and Paste C:\WINDOWS\system32\mxkyoa.exe into the box
    2) Now, Click the Red X and Yes to the confirmation message.
    3) A message will ask if you want to reboot now – Click Yes and allow your machine to reboot Normally.


    After reboot get a new HijackThis log and post it here. Tell me if you had any problems doing any of this.
     
  9. Ashtan

    Ashtan Private E-2

    Ok it goes smoothly up until running Pocket Killbox.

    When I hit the red X, and confirm I get a pop up saying.

    PendingFileRenameOperations Registry Data has been Removed by External Process!

    That seems to be the most I can get out of it =/
     
  10. Ashtan

    Ashtan Private E-2

    Although that said, I have rebooted manually, and it "seems" that hijack this has got rid of the offending line?

    Log included:
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. Ashtan

    Ashtan Private E-2

    Fantastic! Thankyou again :)

    Its amazing, you think your clean and safe, I have always patched windows, always updated norton anti-virus & firewall and yet, I still had more problems than I knw about :)

    Thankyou!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds