Review my Hijackthis file

Discussion in 'Malware Help (A Specialist Will Reply)' started by uncled, Jun 18, 2006.

  1. uncled

    uncled Private E-2

    I'm new to forums but I have done all the "Read and run me first before asking for support". My kids somhow disabled my firewall and I got all kinds of bad stuff which I was able to remove except for a nagging problem with my windows\?icrosoft\spool32.exe file. My AVG virus software keeps identifying this as a problem and attempts to delete it.

    Anyway, I was hoping someone would help me review my hijackthis file, attached.
    Thanks,
    uncled
     

    Attached Files:

  2. AbbySue

    AbbySue MajorGeeks Administrator

    Welcome to MajorGeeks!:)

    Looks like you missed some steps in the read and run me first which are necessary steps if we are to effectively help you.

    Why isn't Windows Defender installed? Was there a problem? If so, you should proceed with installing CounterSpy which is listed as an alternative.

    Did you just install SpyBot or had you already been using it? You have the TeaTimer enabled and we ask that you not enable it during install.

    Your HJT log indicated you did not complete the online scans in step 6 (Bitdefender & Panda Active Scan). Please do so now. If there is a problem completing the scans you need to tell us what the problem is so we can help you resolve it so you can do them.

    You are also running HJT exactly how we ask you not to run it, from the zip file in a temporary location. You have it here -> C:\Documents and Settings\Owner\Desktop\HijackThis.exe Please follow the instructions in the Downloading, Installing, and Running HijackThis thread to install HJT properly so your backups are safe if they need to be restored.

    Once you have completed ALL the steps in the READ & RUN ME FIRST Before Asking for Support attach a new HJT log along with the logs from Bitdefender & ActiveScan.


     
  3. uncled

    uncled Private E-2

    Dear AbbySue,
    Thank you so much for your help.
    I was able to install Windows Defender. It balked at installing until I was able to verify the authenticy of my Windows software.

    I have been running SpyBot for some time. I checked and the TeaTimer is disabled. So I'm confused if it is showing as enabled on HJT.

    I was also able to run Bitdefender and Panda Active Scan, but only after reinstalling Windows Internet Explorer. (I use Mozilla Firefox).

    As a result of these steps, my AVG virus scanner no longer detects a problem with my windows\?icrosoft\spool32.exe file. This is the first time AVG has had a clean report in some time.

    Finally, I reinstalled my HJT executable in its own folder under the Programs Folder and created a log file attached. I have also attached the Bitdefender and Panda ActiveScan logs.

    Thanks again for all your help. I finally feel like I'm making progress.
    Uncled
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Internet Explorer is an integral part of Windows XP, the act of uninstall IE will render Windows unstable. Besides it is needed to run Windows Update.

    Our cleaning procedures called for running the BitDefender online scan. You now have 2 anti-virus packages installed on your computer, which our instructions cleary state not to do. One AV program is all you need. Having more than one on your system will create conflicts and effect sytem performance. Pick one uninstall the other.

    Follow the directions for Look2Me VX2 Removal.

    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Post the Look2Me Destroyer log and a fresh HijackThis log.
     
  5. uncled

    uncled Private E-2

    ShadowPutterDude,
    Thank you so much for your help.
    I have nixed the duplicate AV programs and now am just running AVG.
    I used the Look2M removal tool.
    I did a system scan with HijackThis and asked the program to "Fix Checked on the items you identified. However, the following file was not listed:

    O20 - Winlogon Notify: Run - C:\WINDOWS\system32\kt66l7js1.dll (file missing)

    I am posting the Look2Me Destroyer log and 2 hijackthis logs. The first is prior to fixing the line items you suggested and the second (hijackthis2.log) is after fixing them.

    Again, Thank you for assisting me and being so patient.

    I'm going on vacation for about a week, so I may not respond to your next message right away.
    Uncled
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your log shows parts of BitDefender are still installed and actively running. Other than that your log is clean.
     
  7. uncled

    uncled Private E-2

    SPD,
    Thank you for your patience assistance in helping me remove my viruses. I now get a clean report from my AVG antivirus software and can rest confortably for now.

    You folks at Major Geeks provide a valuable public service.
    Thanks Again,
    Uncled
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds