Recommended Driver Scanner

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [FIXED] - HijackThis Logfile, Help Please

[Fixed] Hijackthis! Logs - [FIXED] - HijackThis Logfile, Help Please posted in the Security & Safety forums; Here is my logfile and i have run spyware programs, virus programs, gone in safe mode and use said programs and this little monster is still lurking. I am about ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-20-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 3
shadow63 - See this Members User comments on their Profile page
Default [FIXED] - HijackThis Logfile, Help Please

Here is my logfile and i have run spyware programs, virus programs, gone in safe mode and use said programs and this little monster is still lurking. I am about to lose what sanity i have, please help. Thank you. All my programs are current on the virus, spayware programs.
Attached Files
File Type: txt log.txt (10.6 KB, 0 views)



Last edited by Hengis; 11-20-2005 at 07:46 PM.
  #2  
Old 11-20-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Shadow63 , welcome to PCHF.

Looks pretty clean and youre Mcafee A S , either blocked or removed a "Trojan.Elitebar" and a "Zango Toolbar" infection. O0

But you do have a Vundo infection on there im afraid. The second of today but we'll remove that ****** easely. :smiley:





Please download Process Explorer by Systernals from HERE

Also download KillBox by Option^Explicit from HERE

Then boot up in SAFE MODE and stay in safe mode untill the entire fix is done.(hit f8 when booting up)

Unzip Process Explorer and double click on procexp.exe
In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.
Once you see this screen click on each instance of vturq.dll once and then click the kill button.
After you have killed all of the vturq.dll's under winlogon click OK.

Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of vturq.dll then click the kill button.
Once you have done that click OK again.

Next run HijackThis and place a check beside each of the following.

O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\system32\vturq.dll
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c11.cab
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} (elitectl.DemoCtl) - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O20 - Winlogon Notify: vturq - C:\WINDOWS\system32\vturq.dll
Now click fix checked and close HijackThis.

Please copy the text in the quote below, and paste it into a blank notepad window.
Save it as vundo.reg and in the save as type box choose all files.

Once you have saved it double click it and allow it to merge with the registry.

REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B5527 4-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB 5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\CLSID\{581F22DA-7202-4F21-AEF3-114787156016}]
[-HKEY_CLASSES_ROOT\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents]
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEve nts]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEve nts.1]

Double click on Killbox.exe and then check the delete on reboot button.
Enter the following filepath and filename into the Full path of file to delete box

C:\WINDOWS\system32\vturq.dll

Click the red circle with the white x and allow your computer to reboot.

After your computer has rebooted please run Hijackthis again and post a new HijackThis log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 11-20-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 3
shadow63 - See this Members User comments on their Profile page
Default

Thanks for the help. Everything went great until I got to the Killbox.exe and put in the filepath and clicked on the red circle with the white x. It would not do anything and the computer would not reboot. I ended up exiting the program and rebooting. Below is the new log. Please advise as to if I need to redo anything. Thanks again for your help.
Attached Files
File Type: txt log.txt (9.8 KB, 0 views)



Last edited by Hengis; 11-20-2005 at 07:47 PM.
  #4  
Old 11-20-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

The infection is gone , and youre log is clean. :smiley:


You can have a look if this file is still present:

C:\WINDOWS\system32\vturq.dll

and try to delete it manually ,but it doesn't do anything anymore so its harmless now , i don't know why killbox didn't want to delete it though.



Do you still experience any problems?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 11-20-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 3
shadow63 - See this Members User comments on their Profile page
Thumbs up

No I am not experiencing any problems what so ever :hello2: . Thank you so much for your help O0 . I thought I was going to lose it . I don't know why the last part did not work but hey everything else did and I am one happy camper :-) . Thanks again for all your help, this is an awesome site .


  #6  
Old 11-20-2005
Friend of PCHF
 
Join Date: Sep 2004
Location: Right here !
Posts: 2,149
Zimbo - See this Members User comments on their Profile page
Default

Good work Joe5, and thanks for the compliments shadow63.

Remember to bookmark us and tell all your mates. :evil:

Marking as fixed.


  #7  
Old 11-20-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

No prob Shadow :azn: , glad i could help.

You know where to find us if you run in to anything else. O0


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[FIXED] - Hijackthis logfile help please Conlan [Fixed] Hijackthis! Logs 7 11-20-2005 12:01 AM
[Fixed] hijackThis Log Ryanm [Fixed] Hijackthis! Logs 50 08-13-2005 01:30 AM
[FIXED] My HiJackThis Log File olliewolly [Fixed] Hijackthis! Logs 5 08-01-2005 08:26 PM
[Fixed] My HiJackThis! Log.... Help please... lessakilla [Fixed] Hijackthis! Logs 5 06-28-2005 09:44 PM
[Fixed] hijack this logfile Smitty02 [Fixed] Hijackthis! Logs 2 06-25-2005 03:27 AM

All times are GMT +1. The time now is 06:12 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top