Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] any help would be great

[Fixed] Hijackthis! Logs - [Resolved] any help would be great posted in the Security & Safety forums; Originally Posted by drkyello hi joe5 the link that you sent me xcp was an udate link..couldn't find the program you wanted me to install That is a good thing ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 11-21-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by drkyello
hi joe5
the link that you sent me xcp was an udate link..couldn't find the program you wanted me to install


That is a good thing , that means that the program is not present.

as for the unhackme i got a reference to fm2order.exe and cous2 32.exe under the process line
i tried to right click and "kill process" but it keep comming up if unhack me is on. but on the top corner of the program it states "ATTENTTION, an invisible software service is found. It suspicious to the torjan class: AFX2005 or FU rootkit. i also pressed stop which told me that i needed to restart my computer for it to delete. which i did, but still give me the same message

Thats what i was afraid of... and that Unhackme cant do anything with them also isn;t a good sign i think..

Try to remove them with these apps:

http://www.pchelpforum.com/anti-viru...-revealer.html

http://www.pchelpforum.com/anti-viru...aler-beta.html


i also downloaded a program to remove www.ad-a-w-a-r-e.com, but it part of my start up, then it tells me that i have to uninstall norton for it to run. how can i remove this program from my start up?

Im not sure what you mean here , did you download ad-a-w-a-r-e? Or an uninstaller for it? The url you posted doesn't go anywhere.

do you mean this app?

http://www.lavasoftusa.com/software/adaware/

But don't uninstall Norton ofcourse , you can disable startup items trough start/run/msconfig , but first if you could please explain exactly whats going on.




And also try atleast one or more , online AV scans see for a link below. And report back the results.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #9  
Old 11-21-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

It looks like Unhackme should be able to remove the AFX rootkit , but also delete this file:

AFX RootKit uses the driver "mc21.tmp" located in the Temp folder.
See here for more detailes:
http://www.greatis.com/unhackme/afxrootkitremoval.htm





__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #10  
Old 11-21-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 46
drkyello - See this Members User comments on their Profile page
Default

i have done the online av, they found a buch of spyware, all coookies, i had them deleted

on the blacklight program (i tried to attached is the log file for it but it too big) i tried to rename, but nothing happend, still pops up on unhackme, along with others
one of the files is C:\PROGRAM FILES\NOIAHOO!\FM2ORDER.EXE, i cannot get this folder of cannot find this folder

not sure what eles, i hope i do not have to re install everything, but looks like i might have to what do you think??

dom



Last edited by drkyello; 12-28-2005 at 06:03 PM.
  #11  
Old 11-22-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

I can kill pretty much any virus worm trojan ect , but im sorry to say i don't have alot of knowledge of rootkits...:undecided And rootkits are pretty nasty..


But i would like to see the blacklight log , can you split it , or zip/rar it?
How big is it?


But you can try to delete the files/folder it detected with Killbox:

download KillBox by Option^Explicit from HERE.


Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

Like the one you posted:

C:\PROGRAM FILES\NOIAHOO!

Click the red circle with the white x and allow your computer to reboot.



Or for multiple files at once:

Create a full list of files to delete and copy them into the windows clipboard.

Start Killbox and place a tick next to [x] delete on reboot.

Back in Killbox go > file > paste from clipboard,

Click the red highlighted X button and say yes to the prompt, then click OK.

Exit Killbox and restart your PC.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 11-22-2005 at 12:55 AM.
  #12  
Old 11-22-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 46
drkyello - See this Members User comments on their Profile page
Default

ive added the blacklight log file along with my most recent HJT file

i've tried to place (sorry don't know how to use the quote box on the forums)
C:\PROGRAM FILES\NOIAHOO! on killbox, but nothing happens when i press the red sign with the white x on it, does nothing at all.



Last edited by drkyello; 12-28-2005 at 06:03 PM.
  #13  
Old 11-23-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 46
drkyello - See this Members User comments on their Profile page
Default

i recently ran spyware doctor in safe mode and it seem to get rid of a lot and then i ran blacklight and it didn't find anything.
now im hoping that nothing happens from here on


is there some advice that might help me prevent this from happening
some program that i need to get rid of or help my computer run a little better?

i have sent my latest hjt file as well. but i do get a startup file everytime i boot how do i remove it? not sure what it is or the name of the file is, so i cannot trace it. is there a way to check startup files and delete it?



Last edited by drkyello; 12-28-2005 at 06:03 PM.
  #14  
Old 11-23-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by drkyello
i've tried to place (sorry don't know how to use the quote box on the forums)
C:\PROGRAM FILES\NOIAHOO! on killbox, but nothing happens when i press the red sign with the white x on it, does nothing at all.
Sometimes Killbox doesn't reboot automaticly , i don't know why really. But it probebly did its job anyway the first time you rebooted after that.


Originally Posted by drkyello
but i do get a startup file everytime i boot how do i remove it? not sure what it is or the name of the file is, so i cannot trace it. is there a way to check startup files and delete it?
I don't really understand what you mean here , does a program or a page start up or open?

Anyway check youre "startup" folder in youre start menu , or have a look at start/run/msconfig/startup tab and see if you can find it there.


Originally Posted by drkyello
is there some advice that might help me prevent this from happening
some program that i need to get rid of or help my computer run a little better?
You actually have youre computer pretty well protected it seems , looks like windows is up to date , and you have an AV and firewall.

Only what i mentioned before you have severall anti spyware apps running , that can cause performence and conflict problems wich can make them uselless. So i would recommend to choose just one.


Originally Posted by drkyello
i recently ran spyware doctor in safe mode and it seem to get rid of a lot and then i ran blacklight and it didn't find anything.
now im hoping that nothing happens from here on

As i mentioned , i think Killbox did its job anyway and looking at the blacklight log , almost all the "bad" files where in that folder. but not all..

So let's see if we can get them all.



Please download CCleaner

Download Ewido Security Suite
  • Install Ewido Security Suite.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu
  • Launch Ewido, there should be a big "E" icon on your desktop, double-click it.
  • The program will prompt you to update click the "OK" button
  • The program will now go to the main screen
  • You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
  • The update will start and a progress bar will show the updates being installed.*
  • After the updates are installed, exit ewido.

Don't run Ewido yet.




Boot youre pc in safemode again:


Start Killbox and place a tick next to [x] delete on reboot.

Copy this list to the windows clipboard:

C:\WINDOWS\SYSTEM32\COUS2_32.EXE
C:\PROGRAM FILES\NOIAHOO!
C:\WINDOWS\system32\drivers\nmnmusbd.sys

Back in Killbox go > file > paste from clipboard,

Click the red highlighted X button and say yes to the prompt, then click OK.

Exit Killbox and restart your PC.



Then boot in safemode again and fix this line with hjt:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html

Then run Ccleaner , and ewido:

Close all open windows/programs/folders and then run Ewido.* Have nothing else open while ewido performs its scan!
  • Click on Scanner , Settings
  • Under "How to scan" all boxes should be selected
  • Under "Possibly unwanted software" all boxes should be selected
  • Under "What to scan" select scan every file
  • Click OK, Complete system scan
  • Let the program scan the machine
  • If ewido finds anything, it will pop up a notification.*
NOTE:* We have been finding some cases of false positives with the new version of Ewido, so you need to step through the fixes one-by-one.* If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged.* In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action.*

DO NOT check "Perform action with all infections."* If you are unsure of an entry, select "none" for the time being.* We will see that in the log when you post it later and let you know if ewido needs to be run again.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report.

Click Save report. Save the report to your desktop, exit ewido


Note:

If during your scan Ewido "crashes" or "hangs", please try scanning again. Before running the scan, click on 'Scanner' (the 3rd bar from the top on the left) and Choose 'Settings'. Uncheck 'Scan in NTFS Alternate Data Streams' as this can cause problems in overly infected systems. Click 'OK' and run a new scan.

Then please post a new hjt log plus the Ewido log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 11-23-2005 at 02:13 AM.

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 04:22 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top