Need help reading hijackthis log

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jwchuggs, Sep 7, 2004.

  1. jwchuggs

    jwchuggs Private E-2

    The webpage spotresults.com keeps on popping up in my internet explorer. i've run a hijack log, but now i'm at a loss of what to do next. Can someone help me read my logfile? Advice as to what should be eliminated would be appreciated! Thanks for your help!!
     

    Attached Files:

    Last edited by a moderator: Sep 7, 2004
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I removed your hijack this log and attached it as a text file per instructions found here:

    http://forums.majorgeeks.com/showthread.php?t=38752

    Take note you ran Hijack This from a temporary directory and did not bother closing any running programs. These steps, followed by the steps in the next paragraph usually cut a logfile down to as small as it can be on your machine, making it much easier to analyze for us and getting you better, faster results.

    Hijack This is not a spyware removal tool, but is a sweet tool to identify stubborn browser hijacks and trojans. Hence, we ask you give your system a going over before we get into Hijack This so we can address a specific issue in the hopes you eliminate some of your issues first. Here you go:

    http://forums.majorgeeks.com/showthread.php?t=35407

    Please check back, myself or Chaslang will get back to you ASAP.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a bunch of problems. First do the stuff in the READ ME FIRST link MA gave to you. Then look in Add/Remove programs for WinTools and uninstall it. If that does not work, see this:
    http://www.pchell.com/support/wintools.shtml

    Then you need to download LSPFix (http://www.cexx.org/lspfix.htm) and run it. Click on lspak.dll on the left window and click on the arrow pointing to the right. Click Finish and follow the prompts. Delete the following file:
    c:\windows\system32\lspak.dll

    lspak.dll is malware Virtumundo

    Now have HJT fix the following lines:
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/0162917e73449f269514/netzip/RdxIE601.cab
    O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab

    You also have BackWeb which need to be removed. See: http://www.pestpatrol.com/pestinfo/b/backweb.asp

    That's a start. Let's see where this gets us.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds