Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Friends log

[Fixed] Hijackthis! Logs - [Resolved] Friends log posted in the Security & Safety forums; Hey, could you check these logs pls?...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-21-2006
Jeroen's Avatar
Mac User
My PC
 
Join Date: Oct 2005
Location: Hong Kong
Posts: 312
PC Experience: Diversely Experienced
Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page
Send a message via MSN to Jeroen
Default [Resolved] Friends log

Hey, could you check these logs pls?
Attached Files
File Type: log hijackthis.log (20.3 KB, 2 views)
File Type: txt Scan rapport_20060121.txt.txt (47.7 KB, 1 views)


__________________
Rules - Prework - Reputation System - Dark Style - Publish PC Specs
Been helped by anyone? Click and consider a Donation!
Always have a copy of Knoppix handy!
  #2  
Old 01-23-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Make sure you still have hidden files set to show , system restore disabled and that you still have ccleaner.


1. Go to Add/Remove programs. Double click on "Messenger Plus!" (or click on Remove) (see quote below!)

2. The "Messenger Plus! - Setup" is now displayed. Click on the Uninstall button. Note: options displayed on the first screen are not related to the sponsor program.

3. The sponsor screen is now displayed (if you don't see it, search for it in your Task Bar). To prove that someone is currently reading the screen, you have to type the code that is displayed. Once you enter the code, press Uninstall.

4. If you entered the code properly, the program will ask you to confirm that you want to uninstall. You must answer "Yes" to this question, else, you won't have another chance of uninstalling.

5. To complete the uninstallation, follow the instructions that are displayed (the first one is to close all your Internet Explorer windows, that's very important). When everything is complete, restart your computer and, hopefully one nasty infection is gone.


When removing Lop.com from the Add/Remove screen it may not show up as Messenger Plus instead also look for these and remove them:

Window Search
Window Searching
Lop.com
LOP SEARCH
Browser Enhancer
Ultimate Browser Enhancer
L.O P. Un insta11
L O.P. Un instal1
Live 0n line Portal
Live.0nli ne Porta1
Window Active

Finally there is a step in the removal process of Messneger Plus where the sponsor asks if you want to uninstall that aswell, You have to click YES to this part of the removal process

If you dont do this corretly then you will have no other choice but to reinstall Messenger Plus and then go through the whole removal process again from the start.

Then i would uninstall Logitech\Desktop Messenger in add/remove programs.



Then boot in safemode (hit f8 when booting up) and fix these with hjt:
(if still present)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.mitahahoyasmjkhexiwykimxx...TyGnJ0R3sc.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.unmpmsfymmjjjmglw.com/xWR...Wom6byM4E.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O2 - BHO: (no name) - {C4A1377C-16BE-3D61-ED4E-FBDBDCF74284} - C:\DOCUME~1\RENEEL~1\APPLIC~1\ProcLove\poll eggs.exe
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
O4 - HKCU\..\Run: [ball less] C:\DOCUME~1\LISETT~1\APPLIC~1\SETTIN~1\partextrameal.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKCU\..\RunServices: [win-xp] winis.exe
O4 - HKCU\..\RunServices: [virtual-machine] wini.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)


O18 - Protocol: bw+0 - {9E7E2DE0-AC2C-4E58-9BB0-809E84BD2C7E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

Plus all other 018 Logitech\Desktop Messenger entry's.(all 018 , except the last one)

Then delete the files in bold , run ccleaner and then do a manuall search for and delete these:


winis.exe
wini.exe


Then run a new ewido scan and save the log from it.


After that reboot to normal mode and post the ewido log and a new hjt log.

Also i see you have no no firewall and windows isn't updated , i would recommend to pay winupdate a visit , and have a look in our download section for free firewalls.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Tech News] Analysis: Windows Live Needs Friends Newsie IT News 0 12-23-2005 10:30 PM
[Fixed] Yet another friend's HJT log... Gray [Fixed] Hijackthis! Logs 10 12-15-2005 03:26 PM
[Resolved] A friend's log Gray [Fixed] Hijackthis! Logs 1 12-01-2005 12:59 AM
[Resolved] i think i destroyed my friends notebook... girl in uniform Spyware / AdWare 16 07-16-2005 05:11 PM
You sure know who your friends are... Hengis The Lounge 4 02-25-2005 09:55 AM

All times are GMT +1. The time now is 05:37 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top