Recommended Driver Scanner

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] HiJackThis Log

[Fixed] Hijackthis! Logs - [Fixed] HiJackThis Log posted in the Security & Safety forums; It keeps changing its name... now it is: O4 - HKLM\..\Run: [dmziz.exe] C:\WINDOWS\system32\dmziz.exe Try to fix it in normal mode this time. Or if it changed name again , look ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #15  
Old 01-14-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

It keeps changing its name... now it is:

O4 - HKLM\..\Run: [dmziz.exe] C:\WINDOWS\system32\dmziz.exe

Try to fix it in normal mode this time.

Or if it changed name again , look for an entry like this: (*= random)

O4 - HKLM\..\Run: [dm***.exe] C:\WINDOWS\system32\dm***.exe


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 01-14-2006 at 11:31 PM.
  #16  
Old 01-14-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 14
AndiAndi - See this Members User comments on their Profile page
Default Serious Problem With Hijackthis

OK, reran Hijackthis in regular mode, found and removed the file, and then just tried Google again. Still hijacks it. Then ran Hijack this again, and the file was back! Removed it again w/HJT and tried to save log. When I look on my computer at the saved log, it is a .txt file. When I try and "manage attachments" on this site, and upload the exact file, it shows as a .txt file, but when I click on it, another page of pchelp comes up. I think the file is attaching, but I am getting hijacked even when I try and look at a .txt file. Please let me know if the attached file is showing the above referenced file as removed (as I have removed it w/HJT). Thanks.
Attached Files
File Type: log hijackthis.log (9.6 KB, 2 views)


  #17  
Old 01-15-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Its gone this time.
Can you now run another fixwareout scan and post the log from that?

I pretty sure that the file we just removed was tied to the wareout infection , and it looks like it kept bringing the wareout infection back. First time i have seen it doing that though... i think it might be a new variant.

But after removing that file with hjt , it shouldn't come back anymore.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #18  
Old 01-15-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 14
AndiAndi - See this Members User comments on their Profile page
Default problem still there

I ran another fixwareout scan and I think it ran another HJT scan and I removed the file that came back:
C:\WINDOWS\SYSTEM32\DMZIZ.EXE

I saved the fixwareout log and am attaching it.
Any ideas why it keeps coming back? Strange. My homepage also keeps resetting to MSN.
Thanks.
Attached Files
File Type: txt report.txt (466 Bytes, 1 views)


  #19  
Old 01-15-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

You can delete this file:

C:\WINDOWS\SYSTEM32\DMZIZ.EXE

And can you upload this file:

C:\WINDOWS\SYSTEM32\IPSEC6.EXE

to this site and report back the result?

http://www.virustotal.com/flash/index_en.html



Also please post a new hjt log. But ill have to do some searching on this one.. im pretty sure this is a new variant of wareout , normally the fixwareout has to be run once and youre done.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #20  
Old 01-17-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 14
AndiAndi - See this Members User comments on their Profile page
Default problem still there

Deleted the DMZIZ.exe; uploaded the IPSEC6.EXE to VirusTotal and it said "No Virus Found" for all. Attached is a new HJT log.

I had recently also downloaded and ran Microsoft's AntiSpyware program. It found the following:

Aureate Group Mail (Adware):
C:\Windows\system32\gmaglue.exe

JumpJobby:
C\:Windows\system32\ajj.exe

JumpJobby:
C:\ProgramFiles\groupmail\ajj.exe

Possible Hosts File Hijack (Spyware):
C:\windows\hosts

Thank you for helping!
Attached Files
File Type: log hijackthis.log (9.9 KB, 1 views)


  #21  
Old 01-17-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

I dont see anything wrong running atm , and did you let MS AS fix those entry's?

And can you run a Panda active scan here and post the log from it:

http://www.pandasoftware.com/product...ACHEHINT=Guest


Also have a look if the fixwareout still finds the infection.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Fixed] HiJackThis Log Sniper [Fixed] Hijackthis! Logs 22 12-17-2005 05:17 PM
[Fixed] My HijackThis Log ClareB [Fixed] Hijackthis! Logs 1 07-28-2005 10:34 PM
[CLEAN] hijackthis log jnickfab [Fixed] Hijackthis! Logs 1 05-09-2005 11:15 PM

All times are GMT +1. The time now is 05:44 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top