Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs
Register for a Free Account

[Fixed] Hijackthis! Logs - [Resolved] HiJack This log posted in the Security & Safety forums; Hi, Any help here is appreciated....


Reply
Scan your PC for Errors
Old 11-25-2005   #1
PCHF Donator
 
Join Date: Sep 2005
Posts: 11
Default [Resolved] HiJack This log

Hi,

Any help here is appreciated.
Attached Files
File Type: txt hijackthis.txt (4.7 KB, 7 views)
mjfontec is offline   Reply With Quote
Advertisement - Register to Remove

Old 11-25-2005   #2
Elite Member
 
joe5's Avatar
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,025
Default

Hya Mjfontec :smiley: , you have the same type of infection as the last time i see , so you know the drill by now: :icon_joke



Please download Process Explorer by Systernals from HERE.

Also download KillBox by Option^Explicit from HERE.

Then boot up in SAFE MODE and stay in safe mode (hit f8 when booting up), untill the entire fix is done.

Unzip Process Explorer and double click on procexp.exe
In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.
Once you see this screen click on each instance of geeba.dll once and then click the kill button.
After you have killed all of the geeba.dll's under winlogon click OK.

Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of geeba.dll then click the kill button.
Once you have done that click OK again.


Next run HijackThis and place a check beside each of the following:

O2 - BHO: MSEvents Object - {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - C:\WINDOWS\system32\geeba.dll
O20 - Winlogon Notify: geeba - C:\WINDOWS\system32\geeba.dll
Now click fix checked and close HijackThis.

Please copy the text in the quote below, and paste it into a blank notepad window.
Save it as vundo.reg and in the "save as" type box choose "all files".

Once you have saved it double click it and allow it to merge with the registry.


REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B5527 4-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB 5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\CLSID\{581F22DA-7202-4F21-AEF3-114787156016}]
[-HKEY_CLASSES_ROOT\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents]
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEve nts]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEve nts.1]



Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

C:\WINDOWS\system32\geeba.dll

Click the red circle with the white x and allow your computer to reboot.



After your computer has rebooted please run Hijackthis again and post a new Hijackthis log.
__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

joe5 is offline   Reply With Quote
Old 11-26-2005   #3
PCHF Donator
 
Join Date: Sep 2005
Posts: 11
Default New Logfile

Thanks - here is the new log file.
Attached Files
File Type: txt hijackthis2.txt (4.5 KB, 1 views)
mjfontec is offline   Reply With Quote
Old 11-26-2005   #4
Elite Member
 
joe5's Avatar
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,025
Default

Looks good to me. O0


Do you still have any problems?
__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

joe5 is offline   Reply With Quote

Reply

Bookmarks

Tags
hijack, log, Resolved
Similar discussions...
Thread Thread Starter Forum Replies Last Post
Pending: WinAntiSpyware 2005 Hijack 4sarge Spyware / AdWare 1 09-18-2005 11:23 PM
[FIXED] HiJack This Log...What to Fix.... rocksteady81 [Fixed] Hijackthis! Logs 6 08-21-2005 09:48 PM
[FIXED] Hijack This Log---cursors possessed Dreams [Fixed] Hijackthis! Logs 11 08-12-2005 04:41 PM

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 12:16 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2