Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] PeteTheToad HJT Log

[Fixed] Hijackthis! Logs - [Fixed] PeteTheToad HJT Log posted in the Security & Safety forums; Originally Posted by PeteTheToad I am not sure what you mean with the "fixwareout log." I did everything it said to do in the Wareout fix Oops , sorry. My ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by PeteTheToad
I am not sure what you mean with the "fixwareout log." I did everything it said to do in the Wareout fix
Oops , sorry. My fault , i didn't read LGW's post good enough. I thought she posted the removal tool for the wareout infection , but i see now that she posted a link for the manuall removal instructions.


Originally Posted by PeteTheToad
Edit: Also, I didn't find O4 - HKLM\..\Run: [dmhbx.exe] C:\WINDOWS\system32\dmhbx.exe but I found a very similar entry and deleted it. When I booted up before, the thing was trying to gain access.
It sounds like it morphed and renamed itself , good job on spotting that.

And it is gone , youre hjt log is clean. But the reason i said i didn't think you run the fixwareout removal tool is because there is still an entry in youre Ewido log from wareout. But as i said above , my mistake. To remove that:


Please download FixWareout from one of these sites:

http://downloads.subratam.org/Fixwareout.exe
http://swandog46.geekstogo.com/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
When your system reboots, follow the prompts. Afterwards, Hijack This will launch. Close Hijack This, and click OK to proceed.

At the end of the fix, you may need to restart your computer again.


Finally, please post the contents of the logfile C:\fixwareout\report.txt
(thats the one i meant , lol)


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #9  
Old 01-02-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 8
PeteTheToad - See this Members User comments on their Profile page
Default OK, I downloaded fixwareout.exe

and I ran it as instructed. But it didn't seem to do anything. There were no prompts; I wasn't asked to reboot... nothing. Fixwareout doesn't show in Add/Remove programs. I downloaded it again and ran it with the same result. I then ran it in Safe Mode... same result.

So I went ahead and ran the edwino in Safe Mode again (man what a long process). Both of those logs are attached. There is no logfile from fixwareout on my PC, because the thing didn't run as you indicated it should run.

It seems that the redirect on websites with long URLs is fixed. Also, the AVG isn't picking up that virus in C:\windows\system32\sphlp32.exe any more. I ran Microsoft Anti-spyware and AVG didn't pick it up this time. I am concerned that the virus was on my PC and that one program indicated it was a "password stealer."

Should I change all of my passwords now? And is my PC clean now?
Attached Files
File Type: txt ewido Scan report_20060101.txt (1.4 KB, 2 views)
File Type: log hijackthis.log (6.8 KB, 2 views)


  #10  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Im afraid it is still there , do you maybe have a firewall blocking the fixwareout from net acess?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #11  
Old 01-02-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 8
PeteTheToad - See this Members User comments on their Profile page
Default Yep. I was able to run it

as requested this time after disabling just about everything that was running. Several messages popped up (I think as a function of CounterSpy) when I rebooted. I denied all access to everything.
Attached Files
File Type: txt report.txt (1.3 KB, 3 views)


  #12  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

It could indeed have been an app like counterspy that blocked it , but this time it worked. The wareout has been removed.


And you can just delete the folder on youre C: disk from fixwareout , no need to uninstall it.

Changing passwords might not be a bad idea.


Do you still have any problems?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #13  
Old 01-02-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 8
PeteTheToad - See this Members User comments on their Profile page
Default No more problems

that I can discern. You guys have been a tremendous help. I cannot thank you enough.


  #14  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Always glad to help. And good to hear everything runs ok again.



Marked as Fixed , and see you around the forum. :smiley:


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 05:39 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top