Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] any help would be great

[Fixed] Hijackthis! Logs - [Resolved] any help would be great posted in the Security & Safety forums; done all the wares, ad ware spyware and all that. not too sure what next to do. any help would be great thanks...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-21-2005
drkyello's Avatar
Bronze Member
 
Join Date: Nov 2005
Posts: 37
drkyello - See this Members User comments on their Profile page
Default [Resolved] any help would be great

done all the wares, ad ware spyware and all that. not too sure what next to do. any help would be great
thanks



Last edited by drkyello; 12-28-2005 at 06:03 PM.
  #2  
Old 11-21-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hi there Dr Kyello , welcome to PCHF.


Let's see if we can clean that up.




Before using HijackThis Please Do the Following:



Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.


Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.


Please download Process Explorer by Systernals from HERE.


Then boot up in SAFE MODE and stay in safe mode (hit f8 when booting up), untill the entire fix is done.



Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.
Once you see this screen click on each instance of msupdate32.dll once and then click the kill button.
After you have killed all of the msupdate32.dll's under winlogon click OK.

Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of msupdate32.dll then click the kill button.

Once you have done that click OK again.


Next run HijackThis and place a check beside each of the following:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
O20 - Winlogon Notify: msupdate - msupdate32.dll (file missing)
And then delete the file in bold , and do a manuall search for msupdate32.dll and delete what you find.

I would also recommend to disable the Messenger service if you don't use it:

Please download Shoot The Messenger

Download and run the small (22 kbyte) "ShootTheMessenger.exe" utility. It will display the current status of your system's Messenger Service. The button near the bottom of its window will allow you to set the service to whichever state — running or disabled — that you desire.

If, for any reason, you should ever choose to re-enable the Windows Messenger Service, simply re-run ShootTheMessenger to do so.
And i also see that you have severall anti spyware apps running atm , its better to have one running in the background , to prevent conflicts and performence issues , and then use the others to scan manually every now and then.


When youre done please post a new hjt log to check.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 11-21-2005
drkyello's Avatar
Bronze Member
 
Join Date: Nov 2005
Posts: 37
drkyello - See this Members User comments on their Profile page
Default here the result

thanks for the help
hope it helped
here is the file



Last edited by drkyello; 12-28-2005 at 06:03 PM.
  #4  
Old 11-21-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

It is not completely gone yet , let's try it with a little more muscle:



First download KillBox by Option^Explicit from HERE.

Then boot in safemode again and fix this one with hjt:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html

Now double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

c:\secure32.html

Click the red circle with the white x and allow your computer to reboot.

And then post an other hjt log to check again.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 11-21-2005
drkyello's Avatar
Bronze Member
 
Join Date: Nov 2005
Posts: 37
drkyello - See this Members User comments on their Profile page
Default still there

still seem to be there
however there doen't seem to be a file in the c drive
killbox didn't seem to do much, not sure if it was going to reboot by itself, i had to exit the program and manualy reboot

i do appeciate all the help



Last edited by drkyello; 12-28-2005 at 06:03 PM.
  #6  
Old 11-21-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

The only real references i can find about "secure32.html" involves other running services "tool2exe" and "paytime.exe"..

Maybe there is a rootkit on youre pc that is hiding running services , can you first install this "cloaking technology remover" (From Sony...) from here:

http://updates.xcp-aurora.com/

And then run Unhackme and report back if it finds anything:

http://www.pchelpforum.com/anti-viru...s-scanner.html

And post a new hjt log please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Great Tools (Look) merlin Utilities 12 02-28-2008 10:23 PM
The Great Big Book of Computer Terms Spaceman3750 Various Tutorials 5 03-21-2006 03:08 PM
[Tech News] The Playlist: Great Online Sources for Finding New Music Newsie IT News 0 11-18-2005 10:31 AM
Great community! hometea Your Thoughts... 4 10-06-2005 09:50 PM
And yet another great time waster site ladygreenwitch The Lounge 11 08-12-2005 02:05 PM


All times are GMT +1. The time now is 07:57 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top