Something has my PC good, My Hi-Jack This log

Discussion in 'Malware Help (A Specialist Will Reply)' started by BryPaulD, Nov 19, 2005.

  1. BryPaulD

    BryPaulD Private E-2

    I have updated and ran Ad-aware, CW Shredder, Spy-bot,Ewido, and AVG. I have deleted the things that come up as infected, (which something came up on every one of those Prog.s) I did those in safe mode also. Well upon re-start I still get runner error messages, and because I'm on cable, something opens IE browser to sites. And sometimes the PC just turns off and back on by itself. Can someone please help me? Thank you. Here is my fresh Hi-Jack This log.
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please download Spy Sweeper
    • Click the link above to download the program.
    • Install it. Once the program is installed, it will open.
    • It will prompt you to update to the latest definitions, click Yes.
    • Once the definitions are installed, click Options on the left side.
    • Click the Sweep Options tab.
    • Under What to Sweep please put a check next to the following:
      • Sweep Memory
      • Sweep Registry
      • Sweep Cookies
      • Sweep All User Accounts
      • Enable Direct Disk Sweeping
      • Sweep Contents of Compressed Files
      • Sweep for Rootkits
      • Please UNCHECK Do not Sweep System Restore Folder.
    • Click Sweep Now on the left side.
    • Click the Start button.
    • When it's done scanning, click the Next button.
    • Make sure everything has a check next to it, then click the Next button.
    • It will remove all of the items found.
    • Click Session Log in the upper right corner, copy everything in that window.
    • Click the Summary tab and click Finish.
    • Paste the contents of the session log you copied into notepad and save it as spysweeper.txt and attach it to your next post along with a fresh HJT log.
     
  3. BryPaulD

    BryPaulD Private E-2

    thank you for your responce. :) I did that stuff and here are the 2 logs. well I guess here is the new Hi-jack log. The webroot log, the uploader says my file size is too big at 107.3 kb and I'm only allowed 97.7. ??
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Since it was so big, get the current updates and run another full sweep. Then attach fresh logs to your next post.
     
  5. BryPaulD

    BryPaulD Private E-2

    Ok, let's see if it will work. Here is the spysweep log, then hi-jack. Thank you again for your help. Nope. file size is 111 kbs. :( what to do?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Compress the file by putting it into a ZIP file. Then upload the ZIP file. Also note that each time you run a scan with SpySweeper I believe they default to appending to the log file. This will make it larger each time you scan unless you rename (or delete but rename is better to keep the info around) the previous scans first.
     
  7. BryPaulD

    BryPaulD Private E-2

    Ok, here is the zip of 2nd spy sweeper and the fresh hi-jack log..
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would now save the current spysweeper log to a new name or delete it. Then I would run a new scan. You had some linger items getting fixed each time. You must delete the old log first to avoid it being too big to upload again. Then you will be ready for BJ when he gets back on later.
     
  9. BryPaulD

    BryPaulD Private E-2

    Thank you. I will just delete all the logs of spysweeper and hi jack, then run new scans on both. Is that good or bad?
     
  10. BryPaulD

    BryPaulD Private E-2

    Ok, after re-boot and delete of old logs, here are the 2 new logs. Thank you again. :)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not delete the previous SpySweeper data. The log you attached still has all scans.

    You are running multiple antivirus applications (F-Secure and Symantec). See step 3 of the READ ME. You should uninstall one of them.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [NTCommLib3] C:\WINDOWS\System32\NTCommLib3.exe
    O4 - HKCU\..\Run: [wkqk] C:\PROGRA~1\COMMON~1\wkqk\wkqkm.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\System32\NTCommLib3.exe
    C:\Program Files\Common Files\wkqk <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Nov 22, 2005
  12. BryPaulD

    BryPaulD Private E-2

    I un-installed Norton through the control panel/add/remove programs before I put f-secure in. Symantec is lingering somewhere?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry....I meant to say AVG (not even close to the spelling of Symantec :eek: ) You need to decide whether you want AVG or F-Secure. Looks like you have AVG scanning emails too.
     
  14. BryPaulD

    BryPaulD Private E-2

    :) That's right, I uninstalled Norton before f-secure, but then I uninstalled f-secure before installing AVG. F-secure is not showing up in the add/remove prog.s, and come to think of it, all my errors started about the time I installed f-secure. That's why I got rid of it.? I'll still do what you recomended above? Or does this info change anything? Thank you again for all of your help on this matter. :)
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Complete the steps I gave you but you will have to get F-Secure completely removed. Manual steps will be needed if it is not in Add/Remove programs. The below show in your log:


    C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe

    O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe

    The services will have to be stopped and disabled. Then you will be able to delete the files.
    Anyone here can help you with that. I have to run out for a bit. If BJ gets back in he can continue with you.
     
  16. BryPaulD

    BryPaulD Private E-2

    Ok, I just did the show file extension thing. I'll check back about the manual removal on f-secure. Funny reading those two things about the backweb, because on start up, I get an error message about an invalid backweb application.
     
  17. BryPaulD

    BryPaulD Private E-2

    Alright, I think I did this all correctly. :) Here is the new hi-jack log.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here is how we will remove the F-Secure services.

    1) Deleting F-Secure 2006
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to F-Secure 2006 (or if not found look for BackWeb Plug-in - 4476822) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste F-Secure 2006 into the box that opens, and press "OK". If that does not work try entering the short name: BackWeb Plug-in - 4476822
    2) Deleting fsbwsys - F-Secure Corp.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to any one of the below that you find:
      • fsbwsys
      • fsbwsys - F-Secure Corp.
      • F-Secure Corp.
    • then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste one of the below into the box (one of them should work:
      • fsbwsys
      • fsbwsys - F-Secure Corp.
      • F-Secure Corp.
    • and then press "OK".
    Now exit HJT and then reboot. After reboot post a new HJT log so we can verify that they are gone..

    Also delete the below folder if found:
    C:\Program Files\F-Secure Internet Security
     
  19. BryPaulD

    BryPaulD Private E-2

    Alright, I got that done. Here is the new Hi-Jack log.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good! How is everything working now? Are you having any additional problems?
     
  21. BryPaulD

    BryPaulD Private E-2

    Thank you sooo much again. The se pop-up thingy's haven't been around at all. Good feeling to know the machine is clean. I appreciate all your help. I have been reading through the preventing read me and trying to hook some that stuff up. I had a problem with manually deleting the Microsoft Java. An error popped up about the run file, so I was going to look at the other option.? When the box on that prog. pops up, what is the location I type in for location of extracted files?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! If you run into problems with that, you may be better off seeing if you can get help on it in the Software Forum.
     
  23. BryPaulD

    BryPaulD Private E-2

    Alright, One more thank you, and I will keep an eye on this thing. Read more on this site. I appreciate it. :)
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds