Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Hijack this and ewido logs

[Fixed] Hijackthis! Logs - [Fixed] Hijack this and ewido logs posted in the Security & Safety forums; Hello everyone. I am a first time poster in dire need of help. I have been bombarded by popups for the past month or so. I used to be completely ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-20-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 3
feeltheforce103 - See this Members User comments on their Profile page
Default [Fixed] Hijack this and ewido logs

Hello everyone. I am a first time poster in dire need of help. I have been bombarded by popups for the past month or so. I used to be completely free of them until I clicked one wrong thing. Anyway, I have gone through a lot of the methods prescribed in a lot of threads and nothing seems to work for me. So it's time to bring it to the experts. Here are my logs. Thanks in advance.
Attached Files
File Type: log hijackthis.log (2.4 KB, 1 views)
File Type: txt Scan report_20051219.txt.txt (858 Bytes, 1 views)


  #2  
Old 12-20-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Welcome to PCHF , Feeltheforce103.


Before fixing things with HijackThis Please Do the Following:


Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.


Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.



Please download CCleaner

And also download: http://www.simplytech.it/L2MRemover/index_e.htm


Then boot in safemode and run the Look2me remover.


Click Start>Run and type in: services.msc
Click OK
In the Services window find: Chvrvck_fdin
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Open HJT and click config > misc tools > ?delete an NT service?
Copy and past: Chvrvck_fdin Click OK.

After that fix these with hjt if still present:

O15 - Trusted Zone: http://*.reliablestats.com
O15 - Trusted Zone: http://*.winantispyware.com
O15 - Trusted Zone: http://*.winantivirus.com
O15 - Trusted Zone: http://*.winantiviruspro.com
O15 - Trusted Zone: http://*.winnanny.com
O15 - Trusted Zone: http://*.winsoftware.com
O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\system32\f20o0cd3ef0.dll
O23 - Service: Chvrvck_fdin - Unknown owner - (no file)

Delete these files if still present:

C:\WINDOWS\system32\f20o0cd3ef0.dll
C:\WINDOWS\system32\dzspex.dll

And then run ccleaner.


After that reboot and post a new Ewido and hjt log please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 12-20-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 3
feeltheforce103 - See this Members User comments on their Profile page
Default ok

I followed your every instruction. There was a problem though: I was unable to run l2mremover in safe mode. It crashed over and over. So I ran that in regular mode and it deleted 2 keys. Then I went and did everything else in safemode. So far, everything is running smoothly. I don't want to jinx myself though. I just ran the logs again and the winantivirus files are still there. Here they are.

Thanks.
Attached Files
File Type: log hijackthis.log (1.9 KB, 3 views)
File Type: txt Scan report_20051220.txt.txt (2.0 KB, 2 views)


  #4  
Old 12-20-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

The look2me remover did its job.

Only the trusted zone entry's came back , but we'll fix those to.


Copy the data from the code box below to a notepad file.

Save to the DESKTOP (so you can find it) as ALL FILES, with the name of KILLTRUSTED.REG
Then double click the file - when it asks say yes to merging with the registry.

Code:
REGEDIT4 
 
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains] 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains] 
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges] 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges] 
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains] 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains] 
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges] 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
Then post an new log to check if there gone.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 12-21-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 3
feeltheforce103 - See this Members User comments on their Profile page
Default wow

Thanks a billion. You have no idea how many different scanners I went through in safe mode this month. Years of safe browsing w/"safe" browsers were erased in one click. lol. Anyway it looks like your registry program did the trick w/the safe entries. Thanks.
Attached Files
File Type: log hijackthis.log (2.0 KB, 2 views)


  #6  
Old 12-21-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looks great from here

If you dont have any problems anymore then where done i think.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 04:19 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top