PC finally clean? Log File Attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by mold13, Aug 27, 2005.

  1. mold13

    mold13 Private E-2

    All removal steps have been completed. Attached is the hijack this log file.

    Is it clean?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run ALL the steps. I can see that the BitDefender online scan was not run. Is there a reason why you did not run it. In the future please follow forum guidelines.....No HJT logs are to be posted unless they are requested. Why are you posting a log? What problems are you having?

    Based on your log, the below two line should be fixed using HJT:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/WebsiteAccess/ie/Bridge-c139.cab
     
  3. mold13

    mold13 Private E-2

    sorry. not sure how i missed bitdefender.

    problems i was having. avg updates disabled. rav picked up following infections:
    kansup.reg
    kans.reg

    infected:
    e5ygh.exe
    g64fff4.exe
    |9uk7fh.exe
    lg.exe

    mcfee stinger picked up sdbot.worm

    bitdefender picked up above kansup and kans again and said pc still infected

    fixed items in hijack log you noted.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post logs from RAV and BitDefender to show what they are finding. I assume you are saying they did not fix the problems. Did you run both of them in safe mode?
     
  5. mold13

    mold13 Private E-2

    Attached are log files for RAV and BitDefender. Both run in Safe Mode.

    Bitdefender was the one that said your pc is still infected even though it said it deleted the infected files.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot into safe mode and make sure no browsers are opened. The locate the below files (using Windows Explorer) and delete them.

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OT6N85YN\lg[1].exe
    C:\e5ygh.exe
    C:\g64fff4.exe
    C:\l9uk7fh.exe
    C:\lg.exe

    Now run CCleaner (make sure the option for Internet Explorer and Temporary Internet Files is selected and then click run Cleaner).
    Now tell me where things stand.
     
  7. mold13

    mold13 Private E-2

    Booted in Safe Mode. Deleted those files. Ran CCleaner. Everything looks good. The AVG is automatically updating upon boot. ZoneAlarm is requesting permission again for unknown incoming and outgoing traffic.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But I'm not clear from the above message whether you are saying you have any problems or not. What is the unknown traffic you are referring to?
     
  9. mold13

    mold13 Private E-2

    I just mean ZoneAlarm is working again and blocking unauthorized attempts as it is suppose to.

    Doesn't appear that I have any problems.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. mold13

    mold13 Private E-2

    Thanks so much for all your help!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds