Recommended Driver Scanner

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Please Help... I cant get rid of filost

[Fixed] Hijackthis! Logs - [Resolved] Please Help... I cant get rid of filost posted in the Security & Safety forums; Hi, I've been struggling with this problem for 2 days now and cant get rid of "filost" problem. I'm assuming that this is a trojan. I have tried many scans ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-07-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 10
dave88 - See this Members User comments on their Profile page
Default [Resolved] Please Help... I cant get rid of filost

Hi,
I've been struggling with this problem for 2 days now and cant get
rid of "filost" problem. I'm assuming that this is a trojan.
I have tried many scans with different packages but none
have been able to get rid of filost pop-up. My internet dialing settings were changed by this problem also.

I have followed previous instructions i found on this forum regarding
scaning with ewido in safe mode. Ewido didnt find any problems.
My Hijackthis scan is shown below.

I would be grateful for any help and advice you have on this

Thanks,
Dave

Logfile of HijackThis v1.99.1
.
.
.



Last edited by joe5; 01-07-2006 at 09:12 PM.
  #2  
Old 01-07-2006
merlin's Avatar
Trusted Security Analyst
My PC
 
Join Date: Jul 2005
Location: Wisconsin
Posts: 2,616
PC Experience: Computers Fear Me
merlin - See this Members User comments on their Profile page merlin - See this Members User comments on their Profile page
Send a message via Yahoo to merlin
Default

Howdy Dave 88. And Welcome to PCHF hope you enjoy your stay..

could you do us a favor and click Prework in my signature and start there.
And when you post the next hijackthis log can you upload it through the attachment viewer as a .txt

We will have you up in running in no time.
Merlin


__________________
QuickTime Alternative..Hijackthis..SpeedFan..ATI Tool..Whats Running..Everest..Absolute Control..All Drivers
If you feel we saved you some money please help support this site by DONATING as this site is funded by great people like you

OUT FOR LUNCH


  #3  
Old 01-07-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 10
dave88 - See this Members User comments on their Profile page
Default Spybot & Adaware tests complete. New Hijackthis report

Hi Merlin,

Followed your instructions.
Adaware got rid of 5 issues.
Spybot only brought up 2 issues regarding Windows Firewall & Virus scan
not being activated. I took no action on this as I believe these are disabled to allow my McAfee programs to run.
New Hijackthis report attached.

Hope you can help.
Thanks in advance
Dave
Attached Files
File Type: txt Scan report_20060107.txt.txt (584 Bytes, 2 views)


  #4  
Old 01-07-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 10
dave88 - See this Members User comments on their Profile page
Default Oops wrong file. Correct Hijackthis file

Sorry, attached previous ewido report.
Heres the new hijackthis report.
Attached Files
File Type: log hijackthis.log (9.2 KB, 6 views)


  #5  
Old 01-07-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Dave , welcome to PCHF from me to.


Lets clean that up. :smiley:


Please download Process Explorer by Systernals from HERE.

Also download KillBox by Option^Explicit from HERE.

Download Smitrem to your desktop:

http://noahdfear.geekstogo.com/click...click.php?id=1

Run the installer and then press Start to Extract the
files to the desktop, Do not run it yet.



Reboot into safe mode (Reboot and keep tapping F8 then
choose safe mode from the list)


Run SmitRem:

Open the SmitRem folder and double click the "RunThis.bat"
file to start the tool , Follow the prompts on
screen. Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of the drive that you ran the batch file on, eg; Local Disk C: or partition where your operating system is installed. Please attach this log to your next reply



Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.
Once you see this screen click on each instance of vbsys2.dll once and then click the kill button.
After you have killed all of the vbsys2.dll's under winlogon click OK.

Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of vbsys2.dll then click the kill button.

Once you have done that click OK again.



Then fix these with hjt:
(if still present)

R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (file missing)
O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpF237.tmp (file missing)
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O15 - Trusted Zone: http://secure.gestrip.com (HKLM)
O15 - Trusted Zone: http://update.randhi.com (HKLM)
O16 - DPF: {33331111-1111-1111-1111-611111193423} - http://www.www2.p0rt2.com/files/777.cab
O16 - DPF: {33331111-1111-1111-1111-611111193429} - http://www.www2.p0rt2.com/files/_ipsec_.cab
O16 - DPF: {33331111-1111-1111-1111-615111193427} -
O16 - DPF: {33331111-1131-1111-1111-611111193428} -
O16 - DPF: {33331111-1234-1111-1111-615111193427} - http://www.www2.p0rt2.com/files/epl80bd.cab
O16 - DPF: {43331111-1111-1111-1111-611111195622} - http://www.www2.p0rt2.com/files/MirarSetup-875498.cab
O16 - DPF: {71057C18-0507-4747-86BC-E11CE7512C5F} (mailhelper Class) - https://register.btinternet.com/temp...control013.cab
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - https://register.btinternet.com/temp...control024.cab
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\system32\vbsys2.dll
Delete the files in bold (if still present) and run Ccleaner again.



Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

C:\WINDOWS\system32\vbsys2.dll

Click the red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)



After your computer has rebooted please run Hijackthis again and post a new Hijackthis log plus the Smitrem log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #6  
Old 01-07-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 10
dave88 - See this Members User comments on their Profile page
Default Still no joy.

Hi,
I've followed the last set of instructions.
Ran Smitrem. Report attached
Ran Process Explorer but no matches for vbsys.dll
I then ran hjt. I found R3 - URLSearchHook.. & deleted it.
Was not sure whether to delete 02 - BHO: Homepage as it looked a bit different.
I finished with Killbox.
I re booted my machine ran hijackthis (report Attached)
I then went online to access this forum and received another pop up screen.

Please advise what i should do?

Thanks
Dave
Attached Files
File Type: txt smitfiles.txt (1.4 KB, 1 views)
File Type: log hijackthis.log (9.0 KB, 1 views)


  #7  
Old 01-07-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

You seem to have missed a couple.. lol: :icon_joke


O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O15 - Trusted Zone: http://secure.gestrip.com (HKLM)
O15 - Trusted Zone: http://update.randhi.com (HKLM)
O16 - DPF: {33331111-1111-1111-1111-611111193423} - http://www.www2.p0rt2.com/files/777.cab
O16 - DPF: {33331111-1111-1111-1111-611111193429} - http://www.www2.p0rt2.com/files/_ipsec_.cab
O16 - DPF: {33331111-1111-1111-1111-615111193427} -
O16 - DPF: {33331111-1131-1111-1111-611111193428} -
O16 - DPF: {33331111-1234-1111-1111-615111193427} - http://www.www2.p0rt2.com/files/epl80bd.cab
O16 - DPF: {43331111-1111-1111-1111-611111195622} - http://www.www2.p0rt2.com/files/MirarSetup-875498.cab
O16 - DPF: {71057C18-0507-4747-86BC-E11CE7512C5F} (mailhelper Class) - https://register.btinternet.com/temp...control013.cab
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - https://register.btinternet.com/temp...control024.cab
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\system32\vbsys2.dll
You are supposed to fix all the items i listed with hjt , and then manually delete the two bolded files from youre pc.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 06:07 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top