Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Alrigty one more Log for you

[Fixed] Hijackthis! Logs - [Resolved] Alrigty one more Log for you posted in the Security & Safety forums; My fault , sorry. Both don't work on win98. Give this a try: Here are a couple of steps to try and run HijackThis. Follow them in order. If one ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 10-27-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

My fault , sorry. Both don't work on win98.

Give this a try:

Here are a couple of steps to try and run HijackThis. Follow them in order. If one step doesn't work, continue to the next step:

Step # 1

Rename the latest version of HijackThis.exe to H.exe. Try a scan. If it works, post the log back here. If not, proceed to the next step.

Step # 2

(you can skip this step as you already did that)


Step # 3

Click here and download Itty Bitty Process Manager (IBProcMan.zip): ibprocman.

Unzip it to it's own directory and try running it - it will provide a 'taskmanager' like process viewer in which you can stop running processes. Don't stop any yet, just list all that it has so whe can check them and give advice. Post the list back here.
and also:

Download http://www.silentrunners.org/Silent%20Runners.zip [/u]]Silent Runners

Unzip into its own file, then double click to run it. After a couple of minutes, a log will open in notepad. Paste the contents here please


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #9  
Old 10-27-2005
idigfoo9's Avatar
Bronze Member
 
Join Date: Jul 2005
Posts: 83
idigfoo9 - See this Members User comments on their Profile page
Send a message via AIM to idigfoo9
Default

Process list saved on 8:19:51 PM, on 10/26/05
Platform: Win9x 4.10.2222 A

[pid] [full path to filename] [file version] [company name]
-15733631 C:\WINDOWS\SYSTEM\KERNEL32.DLL 4.10.0.2222 Microsoft Corporation
-17635 C:\WINDOWS\SYSTEM\MSGSRV32.EXE 4.10.0.2222 Microsoft Corporation
-21075 C:\WINDOWS\SYSTEM\MPREXE.EXE 4.10.0.1998 Microsoft Corporation
-108827 C:\WINDOWS\SYSTEM\mmtask.tsk 4.3.0.1998 Microsoft Corporation
-113671 C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE 8.0.0.12 Networks Associates Technology, Inc
-69687 C:\WINDOWS\EXPLORER.EXE 4.72.3110.1 Microsoft Corporation
-140491 C:\WINDOWS\SYSTEM\SYSTRAY.EXE 4.10.0.2222 Microsoft Corporation
-137475 C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE 7.1.0.355 GRISOFT, s.r.o.
-240943 C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE 7.1.0.360 GRISOFT, s.r.o.
-245719 C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE 7.1.0.357 GRISOFT, s.r.o.
-261007 C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE 5.0.0.2 McAfee, Inc
-299319 C:\WINDOWS\SYSTEM\WMIEXE.EXE 5.0.1755.1 Microsoft Corporation
-276491 C:\WINDOWS\SYSTEM\MSTASK.EXE 4.71.1972.1 Microsoft Corporation
-450675 C:\PROGRAM FILES\AIM\AIM.EXE 5.9.3861.0 America Online, Inc.
-418243 C:\WINDOWS\SYSTEM\DDHELP.EXE 4.9.0.900 Microsoft Corporation
-587471 C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE 1.0.6.0 Mozilla
-638211 C:\UNZIPPED\IBPROCMAN\IBPROCMAN.EXE 1.4.0.0 Soeperman Enterprises Ltd.



Alrighty and the other thing you wanted me to download took me to a whatUseek web search site


__________________
Do you know where you are going when you leave this earth?

The Podunks
  #10  
Old 10-27-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Also no problems there.

And here is a working link for the other one;

Silent Runners


Does AVG give a name for the virus it finds?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #11  
Old 10-27-2005
idigfoo9's Avatar
Bronze Member
 
Join Date: Jul 2005
Posts: 83
idigfoo9 - See this Members User comments on their Profile page
Send a message via AIM to idigfoo9
Default

Yes, AVG gives the virus name - C:\MSDIRE~1.SYS


__________________
Do you know where you are going when you leave this earth?

The Podunks
  #12  
Old 10-27-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Now where getting somewhere , that is from "Trojan.Win32.Rootkit.h" and that little ****** hiddes system services..

download KillBox by Option^Explicit from HERE

Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box


C:\msdirectx.sys


Click the red circle with the white x and allow your computer to reboot.

And then do a scan here and report back the results:

http://housecall60.trendmicro.com/en...rp.asp?id=scan


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #13  
Old 10-27-2005
idigfoo9's Avatar
Bronze Member
 
Join Date: Jul 2005
Posts: 83
idigfoo9 - See this Members User comments on their Profile page
Send a message via AIM to idigfoo9
Default

What we checked:
Whether personal information was tracked and reported by spyware. Spyware is often installed secretly with legitimate programs downloaded from the Internet. Results:
We have detected 12 spyware(s) on your computer. Only 0 out of 0 spywares are displayed.
Spyware Name
Spyware Type
Action
COOKIE_45
Cookie
PassRemove
COOKIE_281
Cookie
PassRemove
COOKIE_442
Cookie
PassRemove
COOKIE_1020
Cookie
PassRemove
COOKIE_1543
Cookie
PassRemove
COOKIE_1802
Cookie
PassRemove
COOKIE_2250
Cookie
PassRemove
COOKIE_2798
Cookie
PassRemove
COOKIE_2921
Cookie
PassRemove
SPYW_PPNETWORK.A
Spyware
RemovePass
ADW_SWIND.A
Adware
RemovePass
SPYW_PPNETWORK.B
Spyware


__________________
Do you know where you are going when you leave this earth?

The Podunks
  #14  
Old 10-27-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Did Killbox work? And does AVG still popup?

And where those files found also deleted?


Also run this:

Download and unzip BFU.zip from here.

Run the program and click the Web button as shown by the blue arrow below:



Use this URL to copy into the address bar of the Download script window:

http://metallica.geekstogo.com/p2pnetwork.bfu

Execute the script by clicking the Execute button.
If you have any questions about the use of BFU please read here:
http://metallica.geekstogo.com/BFUinstructions.html


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 06:06 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top