Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Atands HJT Logs

[Fixed] Hijackthis! Logs - [Fixed] Atands HJT Logs posted in the Security & Safety forums; I am having also a problem with this trojan. If you have found a solution. Kindly email it to XXX . thx. Edit: As this thread was originally posted in ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-31-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 5
atands - See this Members User comments on their Profile page
Default [Fixed] Atands HJT Logs

I am having also a problem with this trojan. If you have found a solution. Kindly email it to XXX . thx.

Edit: As this thread was originally posted in another users thread, here is the original for clarification [url=http://www.pchelpforum.com/spyware-adware/14376-spyware-wont-go-away.html#post107495]Spyware-wont-go-away[url]

@Atands, it is not a good idea to post your personal email in a post, we answer all questions here in the forums. Thx.

LGW



Last edited by ladygreenwitch; 01-01-2006 at 04:46 AM.
  #2  
Old 12-31-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 5
atands - See this Members User comments on their Profile page
Default hijack log file

Originally Posted by atands
I am having also a problem with this trojan. If you have found a solution. Kindly email it to altomc@yahoo.com . thx.
here is the Hijackthis log file:

Edited by Double A Ron:

Please read the PCHF RULES

ALL "Log" attachments MUST be posted as attachments and not pasted into posts
I've fixed it for you, don't worry too much about it this time.

How to Attach Files
Attached Files
File Type: txt Hijack This Log.txt (5.4 KB, 3 views)



Last edited by double_a_ron; 12-31-2005 at 06:29 PM.
  #3  
Old 12-31-2005
double_a_ron's Avatar
Elite Member
My PC
 
Join Date: Sep 2005
Location: Canada
Posts: 901
PC Experience: Very Experienced
double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page
Default

Hi Atands, Welcome to the PC Help Forum.

We have an excellent team of security specialists who will be glad to help you out.

Though you've already submitted your Hijack This Log could you please follow the instructions in the *Prework* Link in my signature.

We'll get through tis together :azn:

PS. Sorry bout the lengthy edit on your post. I'm still trying to find the tutorial to posting those:computer_.


__________________
//Prework\\\///PCHF RULES\\\///Did we help? Please Donate\\\

CompTIA A+ Certified, MCDST



Did we help? Please hit that Thanks button.
  #4  
Old 12-31-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 5
atands - See this Members User comments on their Profile page
Default trojan.downloader.ffz

Thanks Guys.

Yes. I have now followed the "prework" instructions (disabling restore and running the various programs and am attaching the log file for Ewido and Hijackthis.

Regards
Attached Files
File Type: txt Ewido and Hijackthis scans.txt (22.4 KB, 4 views)


  #5  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Make sure you still have Ccleaner , and still have hidden files set to show and system restore disabled.

Please download FixWareout from one of these sites:

http://downloads.subratam.org/Fixwareout.exe
http://swandog46.geekstogo.com/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
When your system reboots, follow the prompts. Afterwards, Hijack This will launch. Close Hijack This, and click OK to proceed.
At the end of the fix, you may need to restart your computer again.

Then uninstallthese in add/remove programs if present:

RXToolbar
nSpyPC

And now boot in safemode and then fix these with hjt:

R3 - URLSearchHook: (no name) - {3B1DA251-EE8C-A657-EA48-C8BD67024681} - nmdllw.dll (file missing)
O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\PROGRA~1\RXTOOL~1\sfcont.dll (file missing)
O4 - HKLM\..\Run: [bhoserv] stuffmon.exe
O4 - HKLM\..\Run: [InpriseMon] UserSp1.exe
O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
O4 - HKCU\..\Run: [teqq32] powerdll.exe
O4 - HKCU\..\Run: [TRPT] sysmon12.exe
O4 - HKCU\..\Run: [MsNetHelper] powerdll.exe
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/inst...l/pinstall.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{05C1EFEC-FA2D-41AB-9667-F8929F1DF111}: NameServer = 85.255.116.42,85.255.112.185
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF795C81-2112-478F-B883-1A2DB7A38C4E}: NameServer = 85.255.116.42,85.255.112.185
O17 - HKLM\System\CS1\Services\Tcpip\..\{05C1EFEC-FA2D-41AB-9667-F8929F1DF111}: NameServer = 85.255.116.42,85.255.112.185
O17 - HKLM\System\CS2\Services\Tcpip\..\{05C1EFEC-FA2D-41AB-9667-F8929F1DF111}: NameServer = 85.255.116.42,85.255.112.185
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\PROGRA~1\RXTOOL~1\sfcont.dll

Then run Ccleaner and delete the files in bold. Also do a manuall search for , and delete these:

stuffmon.exe
UserSp1.exe
powerdll.exe
sysmon12.exe
powerdll.exe
nmdllw.dll

Finally, please post the contents of the logfile C:\fixwareout\report.txt and a new hjt log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #6  
Old 01-02-2006
Bronze Member
 
Join Date: Dec 2005
Posts: 5
atands - See this Members User comments on their Profile page
Default Latest hijackthis log

Thanks,

I followed your instructions above and am attaching the latest hijackthis logs 3 and 4. I think that the problem is solved!!

If so, thanks so much to your team. What a great service! Will let my associates know about it and try to promote you as much as possible.

Regards

Atands
Attached Files
File Type: txt hijackthis log3.txt (4.4 KB, 1 views)
File Type: txt hijackthis log4.txt (3.2 KB, 1 views)


  #7  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

The log3 is from before you followed the fix instructions it seems? Log4 is completely clean.

But can you also post the fixwareoutlog to check?
(C:\fixwareout\report.txt)


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
where did you get trained to read HJT logs? coltm4carbine The Lounge 3 09-22-2005 09:40 PM
[Tech News] MPAA sifts through tracker logs for lawsuit ammo merlin The Lounge 2 08-29-2005 09:32 PM
HiJack This! Logs Go One Forum Up! Thank You! Spaceman3750 Spyware / AdWare 0 08-02-2005 08:53 PM

All times are GMT +1. The time now is 06:00 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top