Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [FIXED] My HijackThis Log

[Fixed] Hijackthis! Logs - [FIXED] My HijackThis Log posted in the Security & Safety forums; By scanning my computer for virii, I found a couple of pesky individuals who refuse to leave. I really hope that it attached itself, if it didn't, then I'll just ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 10-18-2005
Gray's Avatar
Silver Member
 
Join Date: Oct 2005
Location: Where the President never stays...
Posts: 177
Gray - See this Members User comments on their Profile page
Send a message via Yahoo to Gray
Default [FIXED] My HijackThis Log

By scanning my computer for virii, I found a couple of pesky individuals who refuse to leave. I really hope that it attached itself, if it didn't, then I'll just try again.

Well, here is my HijackThis Log:
Attached Files
File Type: txt My log.txt (15.1 KB, 7 views)



Last edited by Gray; 10-18-2005 at 08:51 PM.
  #2  
Old 10-18-2005
merlin's Avatar
Trusted Security Analyst
My PC
 
Join Date: Jul 2005
Location: Wisconsin
Posts: 2,622
PC Experience: Computers Fear Me
merlin - See this Members User comments on their Profile page merlin - See this Members User comments on their Profile page
Send a message via Yahoo to merlin
Default

Welcome To PCHF,
Did you upload the HJT log as a.txt file? Cant seem to see it.


__________________
QuickTime Alternative..Hijackthis..SpeedFan..ATI Tool..Whats Running..Everest..Absolute Control..All Drivers
If you feel we saved you some money please help support this site by DONATING as this site is funded by great people like you

OUT FOR LUNCH


  #3  
Old 10-18-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Let's see what we can do for you.

Please download Process Explorer by Systernals from HERE
Download Ccleaner from the link below in my sig.
Also download KillBox by Option^Explicit from HERE

Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original Hosts file.

Go to add and remove programs and uninstall "MarketBrowser".



Don't remove this one yet , but do you know and use it?

O4 - Startup: TClock2.lnk = C:\Program Files\Tclock2\tclock2.exe



Before using HijackThis Please Do the Following:

Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.
Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
Then boot up in SAFE MODE and stay in safe mode untill the entire fix is done.(hit f8 when booting up)


Click Start>Run and type in: services.msc
Click OK
In the Services window find:

scheduler

and also:

System Manager Service

Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Open HJT and click config > misc tools > “delete an NT service”
Copy and past:

schedul3.exe

and the same for:

SMSC

Click OK.




Unzip Process Explorer and double click on procexp.exe
In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.
Once you see this screen click on each instance of ssqrr.dll and jkhfg.dll once and then click the kill button.
After you have killed all of the ssqrr.dll's and jkhfg.dll's under winlogon click OK.
Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of ssqrr.dll and jkhfg.dll then click the kill button.
Once you have done that click OK again.
Next run HijackThis and place a check beside each of the following.

All 01 entry's
O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\System32\ssqrr.dll
O2 - BHO: MSEvents Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:\WINDOWS\System32\jkhfg.dll
O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB57.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB57.dll
O4 - HKLM\..\Run: [MP10_EnsureFileVer] C:\WINDOWS\inf\unregmp2.exe /EnsureFileVersions
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O20 - Winlogon Notify: jkhfg - C:\WINDOWS\System32\jkhfg.dll
O20 - Winlogon Notify: ssqrr - C:\WINDOWS\SYSTEM32\ssqrr.dll
O23 - Service: scheduler (schedul3.exe) - Unknown owner - C:\WINDOWS\schedul3.exe
O23 - Service: System Manager Service (SMSC) - Unknown owner - C:\WINDOWS\smsc.exe (file missing)
Now click fix checked and close HijackThis. After that delete the files in bold and run Ccleaner.


Please copy the text in the quote below, and paste it into a blank notepad window.
Save it as vundo.reg and in the save as type box choose all files.
Once you have saved it double click it and allow it to merge with the registry.

REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B5527 4-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB 5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\CLSID\{581F22DA-7202-4F21-AEF3-114787156016}]
[-HKEY_CLASSES_ROOT\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents]
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEve nts]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEve nts.1]

Double click on Killbox.exe and then check the delete on reboot button.
Enter the following filepath and filename into the Full path of file to delete box

C:\WINDOWS\System32\jkhfg.dll
and also:
C:\WINDOWS\System32\ssqrr.dll

Click the red circle with the white x and allow your computer to reboot.

After your computer has rebooted please run Hijackthis again and post a new HijackThis log.

I would also recommend to pay Winupdate a visit.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 10-18-2005 at 09:58 PM.
  #4  
Old 10-19-2005
Gray's Avatar
Silver Member
 
Join Date: Oct 2005
Location: Where the President never stays...
Posts: 177
Gray - See this Members User comments on their Profile page
Send a message via Yahoo to Gray
Default

I've followed the instructions up to where it says to boot up in Safe Mode. Whenever I try, I get this brief message that pops up and then disappears and nothing else loads up after that. Instead of doing it in Safe Mode if there is no solution, can I just perform it in normal Windows?


  #5  
Old 10-19-2005
Hengis's Avatar
PCHF Founder & Owner
My PC
 
Join Date: Jan 2004
Location: Berkshire, England
Posts: 11,040
PC Experience: Always learning
Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page
Send a message via Skype™ to Hengis
Default

What is the message? If it displays too quickly can you at least note down a part of the message that will enable us to discover the problem.


__________________
> Pre-Work > System File Checker
> Did we help you? If we did, please consider A Donation
  #6  
Old 10-19-2005
Gray's Avatar
Silver Member
 
Join Date: Oct 2005
Location: Where the President never stays...
Posts: 177
Gray - See this Members User comments on their Profile page
Send a message via Yahoo to Gray
Default

Okay, I'll give it a shot. I hope you're still around once it's through...

After trying it three times, I still couldn't see what it said exactly. All I know is that there's a yellow exclamation point and a Yes/No option. I hope that helps...



Last edited by Gray; 10-19-2005 at 08:40 AM.

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Pending] HijackThis Log.....Please help chalk61 [Fixed] Hijackthis! Logs 3 09-02-2005 11:57 PM
[Fixed] My HijackThis Log ClareB [Fixed] Hijackthis! Logs 1 07-28-2005 10:34 PM
[CLEAN] hijackthis log jnickfab [Fixed] Hijackthis! Logs 1 05-09-2005 11:15 PM


All times are GMT +1. The time now is 10:12 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top