Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Multiple Pops and switch sever error

[Fixed] Hijackthis! Logs - [Fixed] Multiple Pops and switch sever error posted in the Security & Safety forums; I have been getting mutliple pop-ups and server busy switch to different server pop-ups. I have been continually running ad-aware, spy-bot and ewdio software to clean up my system but ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-10-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 3
tpearson - See this Members User comments on their Profile page
Default [Fixed] Multiple Pops and switch sever error

I have been getting mutliple pop-ups and server busy switch to different server pop-ups. I have been continually running ad-aware, spy-bot and ewdio software to clean up my system but nothing seems to help. Could please look at my hijackthis.log to see what might help.

Thanks
Attached Files
File Type: log hijackthis.log (10.2 KB, 1 views)


  #2  
Old 01-10-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hy there T Pearson , welcome to PCHF.

You have indeed a bunch of nasty little buggers on there , lets first clean up the easy way abit. When did you run Ewido last?


please run an Panda active scan here:

http://www.pandasoftware.com/products/activescan.htm

And save the log from it.

Then run Spysweeper:

Please download and install the trial version of Webroot SpySweeper (8.3mg)
http://www.webroot.com/shoppingcart/...011&vcode=DT02

When SpySweeper starts, please accept any prompts to update definitions.
Configure it as follows:

From the left pane, click Options
Select the Sweep Options tab & ensure the following are ticked:

*Sweep Memory
*Sweep Registry
*Sweep Cookies
*Sweep All Users accounts
*Do Not Sweep System Restore Folder
*Enable Direct Disk Sweeping
*Sweep contents of compressed files
*Sweep For Rootkits

-After that's done, select Sweep from the left pane & click on the Start button

Allow Spysweeper to reboot your machine to remove the infected files.
After rebooting, launch SpySweeper & select Results from the left pane
Click the 'Session Log' tab & choose Save to File to create a log.

Then please post that log , the Panda log and a new hjt log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 01-11-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 3
tpearson - See this Members User comments on their Profile page
Default

I usually ran Ewido at least once a day, I was also running ad-aware and spy-bot too.

I followed your request and here are the 3 logs that you asked for.

Thanks,

T
Attached Files
File Type: txt Activescan.txt (20.8 KB, 1 views)
File Type: log hijackthis.log (10.8 KB, 1 views)
File Type: txt Spy Sweeper Session Log.txt (48.5 KB, 1 views)


  #4  
Old 01-11-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Lets have a go at cleaning that up.


Before fixing things with HijackThis Please Do the Following:


Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.

Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.


Please download CCleaner


Then uninstall Viewpoint Toolbar in add/remove programs.


After that boot in safemode and fix these with hjt:
O2 - BHO: (no name) - {1768B6BA-2E00-5684-2BB2-7395CCABDC9E} - C:\WINDOWS\System32\kuvrun.dll (file missing)
O2 - BHO: (no name) - {A12DC733-55AB-2E7F-879B-71A2A8F766B5} - C:\WINDOWS\System32\vla.dll (file missing)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe /server"
O4 - HKCU\..\Run: [Uahe] "C:\Program Files\csaa\srai.exe" -vt ndrv
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/Activ...veLauncher.cab
Then delete the files in bold if present , and run ccleaner. Also delete these files:

C:\WINDOWS\System32\kii.dll
C:\WINDOWS\inf\biU.inf
C:\WINDOWS\system32\??sembly\spoolsv.exe (you wont see question marks , but letters or numbers , if unsure , post what you find first)

And do you know what these two are from? :

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 172.34.1.5;
O17 - HKLM\System\CCS\Services\Tcpip\..\{4667A043-1022-4AE6-A1E6-32E2F48C0A16}: NameServer = 172.16.2.116

Also are you aware that there is a bunch of remote/vpn software running on youre pc?
If you use them youreself then it is ok , but it could also mean that someone else uses them to control youre pc.

PLSRemote Service
DameWare Mini Remote Control
iSeries Access for Windows Remote Command
Cisco Systems, Inc. VPN Service
pcAnywhere Host Service

Please post a new hjt log when done.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 01-12-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 3
tpearson - See this Members User comments on their Profile page
Default

Things seem to be running smoother. The remote/vpn software is installed because I use this pc to access our network where I work at, that is als why you see the 172.x.x.x subnet items.

Here is the latest log after running the fixes and cleanup.

Thanks,

T
Attached Files
File Type: log hijackthis.log (10.9 KB, 1 views)


  #6  
Old 01-12-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looking good , i see no more problems. :smiley:

Only i would disable the windows messenger service:

Please download Shoot The Messenger

Download and run the small (22 kbyte) "ShootTheMessenger.exe" utility. It will display the current status of your system's Messenger Service. The button near the bottom of its window will allow you to set the service to whichever state ? running or disabled ? that you desire.

If, for any reason, you should ever choose to re-enable the Windows Messenger Service, simply re-run ShootTheMessenger to do so.

Also i would recommend to update windows , but other then that it looks good from here.

Do you still have any problems?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 05:44 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top