Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] HiJackThis Log

[Fixed] Hijackthis! Logs - [Fixed] HiJackThis Log posted in the Security & Safety forums; I have http://www.filost.com/stop.htm and can't get rid of it! Here is my HiJackThis Log, Logfile of HijackThis v1.99.1 Scan saved at 12:25:47 PM, on 11/20/2005 Platform: Windows XP SP1 (WinNT ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-20-2005
Sniper's Avatar
Bronze Member
 
Join Date: Nov 2005
Posts: 18
Sniper - See this Members User comments on their Profile page
Default [Fixed] HiJackThis Log

I have http://www.filost.com/stop.htm and can't get rid of it!
Here is my HiJackThis Log,
Logfile of HijackThis v1.99.1
Scan saved at 12:25:47 PM, on 11/20/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Attached Files
File Type: txt log.txt (6.5 KB, 2 views)



Last edited by Hengis; 11-20-2005 at 07:49 PM.
  #2  
Old 11-20-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Sniper , welcome to PCHF.

You have severall nasty's in there , but we should get that clean with no problems.





Before using HijackThis Please Do the Following:



Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.
Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.

Please download Process Explorer by Systernals from HERE.

Also download KillBox by Option^Explicit from HERE.

And download CCleaner

Then boot up in SAFE MODE and stay in safe mode (hit f8 when booting up), untill the entire fix is done.

Unzip Process Explorer and double click on procexp.exe
In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.
Once you see this screen click on each instance of vbsys2.dll once and then click the kill button.

After you have killed all of the vbsys2.dll's under winlogon click OK.

Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of vbsys2.dll then click the kill button.

Once you have done that click OK again.



Next run HijackThis and place a check beside each of the following:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://lookfor.cc/sp.php?pin=28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lookfor.cc?pin=28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://lookfor.cc/sp.php?pin=28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://lookfor.cc/sp.php?pin=28129
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [usbn] C:\WINDOWS\SYSTEM32\usbn.exe -go -c200 -w1
O4 - HKCU\..\Run: [MicroSoft Remote Secure Service] MSRSS.exe
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\kyepilms.exe
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab
O16 - DPF: {43331111-1111-1111-1111-611111195622} - file://c:\ex.cab
O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll
Then delete the files in bold and run Ccleaner.

Do a manuall search for "MSRSS.exe" and delete all you find. (also search in hidden and system folers)




Now double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

C:\WINDOWS\System32\vbsys2.dll

Click the red circle with the white x and allow your computer to reboot.



After your computer has rebooted please run Ewido:

Download Ewido Security Suite
  • Install Ewido Security Suite.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu
  • Launch Ewido, there should be a big "E" icon on your desktop, double-click it.
  • The program will prompt you to update click the "OK" button
  • The program will now go to the main screen
  • You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
  • The update will start and a progress bar will show the updates being installed.*
  • After the updates are installed, exit ewido.
Once the updates are installed do the following:
  • If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
  • Reboot into Safe Mode, restart your computer, tap the F8* key. Use your up arrow key to highlight Safe Mode, then hit enter.
Close all open windows/programs/folders and then run Ewido.* Have nothing else open while ewido performs its scan!
  • Click on Scanner , Settings
  • Under "How to scan" all boxes should be selected
  • Under "Possibly unwanted software" all boxes should be selected
  • Under "What to scan" select scan every file
  • Click OK, Complete system scan
  • Let the program scan the machine
  • If ewido finds anything, it will pop up a notification.*
NOTE:* We have been finding some cases of false positives with the new version of Ewido, so you need to step through the fixes one-by-one.* If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged.* In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action.*

DO NOT check "Perform action with all infections."* If you are unsure of an entry, select "none" for the time being.* We will see that in the log when you post it later and let you know if ewido needs to be run again.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report.

Click Save report. Save the report to your desktop, exit ewido


Note:

If during your scan Ewido "crashes" or "hangs", please try scanning again. Before running the scan, click on 'Scanner' (the 3rd bar from the top on the left) and Choose 'Settings'. Uncheck 'Scan in NTFS Alternate Data Streams' as this can cause problems in overly infected systems. Click 'OK' and run a new scan.


Then run HijackThis choosing the top option to save a log file, save it to your desktop. When you post, please include a description of the problem you are having, and Attach your HijackThis log plus the Ewido log.

And do you recoqnize this info/company?

OrgName: GCR Company
OrgID: GCRC
Address: P.O. Box 511
City: South Boston
StateProv: VA
PostalCode: 24592
Country: US
NetRange: 65.254.160.0 - 65.254.175.255



I also would recommend to pay winupdate a visit. When youre done please post the Ewido log and a new Hjt log to check.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 11-22-2005
Sniper's Avatar
Bronze Member
 
Join Date: Nov 2005
Posts: 18
Sniper - See this Members User comments on their Profile page
Default New log

New log, what should be removed?
Attached Files
File Type: log hjt.log (6.5 KB, 1 views)



Last edited by joe5; 11-22-2005 at 03:15 AM.
  #4  
Old 11-22-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looks like you posted the old hjt log again , can you post a new one , and also the Ewido log?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 11-22-2005
Sniper's Avatar
Bronze Member
 
Join Date: Nov 2005
Posts: 18
Sniper - See this Members User comments on their Profile page
Default

Joe, I don't have ewido but I do have HiJackThis Log. I removed what you said. Here is the new HiJackThis log, tell me if I should remove anything else. Thanks for all your help

Post of Log removed, See attachment
Attached Files
File Type: txt Snipers newest HJT.txt (5.6 KB, 1 views)



Last edited by ladygreenwitch; 11-22-2005 at 05:41 AM.
  #6  
Old 11-22-2005
ladygreenwitch's Avatar
Elite Member
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,642
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hey Guys,

@Sniper, could you please look to see if the log is in the ewido folder (may be called security suite) under Reports, it is important to see what if anything ewido found.

Also, please do not post HijackThis logs in any form other than an attachment, they can potentially cause infections in unsuspecting users. Thanks

We look forward to your response.

TTFN

LGW



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[FIXED] HiJackThis! Log Mesh631 [Fixed] Hijackthis! Logs 6 10-31-2005 01:53 AM
[FIXED] My HijackThis! Log [Fixed] Hijackthis! Logs 9 09-15-2005 12:13 AM
[Fixed] hijackThis Log Ryanm [Fixed] Hijackthis! Logs 50 08-13-2005 01:30 AM
[FIXED] My HiJackThis Log File olliewolly [Fixed] Hijackthis! Logs 5 08-01-2005 08:26 PM


All times are GMT +1. The time now is 02:32 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top