Scan your PC for Errors

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] help with trojan

[Fixed] Hijackthis! Logs - [Fixed] help with trojan posted in the Security & Safety forums; my computer has been infected with the newmalware.j virus. i think i have it cleaned only to find it has returned the next day. i followed the instructions and ran ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 03-03-2006
PCHF $ Donor
 
Join Date: Mar 2006
Posts: 3
amilfor - See this Members User comments on their Profile page
Default [Fixed] help with trojan

my computer has been infected with the newmalware.j virus. i think i have it cleaned only to find it has returned the next day. i followed the instructions and ran ewido and hijack this. here are my logs and any help would be greatly appreciated. thanks also a 16 bit dos prompt keeps poping up and seems to be trying to run a program over and over. very annoying it starts as
dos prompt labeled c:/windows/temp/h91746.exe then a window pops up saying the NTVDM CPU has encountered an illegal instruction.
CS>0db3 IP:01d4 OP:63 63 65 2f 31 chose close to terminate the application. with option to close or ignore.
Attached Files
File Type: txt log.txt (8.5 KB, 1 views)



Last edited by Hengis; 03-03-2006 at 09:57 PM.
  #2  
Old 03-03-2006
Hengis's Avatar
PCHF Head Honcho
My PC
 
Join Date: Jan 2004
Location: Southern England
Posts: 11,459
PC Experience: Always learning
Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page
Send a message via Skype™ to Hengis
Default

Hi there and welcome to the forum.

I have edited your post as we do not accept pasted logs. All logs must be submitted as attachments, thank you.

One of the Security Team will look at your logs shortly.


__________________

Pre-Work
/ System File Checker / Help promote PCHF! / What's inside your PC? / Did we help you? If we did, please consider A Donation
  #3  
Old 03-03-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hi there Amilfor.

Let's see if we can get rid of that.


Download Smitrem to your desktop:
http://noahdfear.geekstogo.com/click...click.php?id=1

Run the installer and then press Start to Extract the files to the desktop, Do not run it yet.


Reboot into safe mode.
(hit f8 when booting up)

Then fix these with hijackthis:

O4 - HKLM\..\Run: [hyjsbqt] C:\WINDOWS\hyjsbqt.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
And manually delete the file in bold.


Now run SmitRem:

Open the SmitRem folder and double click the "RunThis.bat"
file to start the tool , Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of the drive that you ran the batch file on, eg; Local Disk C: or partition where your operating system is installed. Please attach this log to your next reply.




You will need to reload your wallpaper as the SmitRem
tool will reset it, you can do this by right clicking
desktop and choosing properties, First check Theme and
set it to Windows XP then click the Desktop tab and
choose the one you want to use and press apply.


When done please post a new , and full hjt log , there seems to be a part cut off of this one , and out of normal mode instead of safemode. Also post the smitrem log.

Also it seems you have no AV and no firewall , have a look in our download section for some free ones. You really should have those to be better protected from things like this.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #4  
Old 03-06-2006
PCHF $ Donor
 
Join Date: Mar 2006
Posts: 3
amilfor - See this Members User comments on their Profile page
Default

thanks for the help joe. here is the hijack this log. i did not get a smitrem log. i havent had any problems for a couple of days. it seems to have helped.
Attached Files
File Type: log hijackthis.log (7.1 KB, 1 views)


  #5  
Old 03-06-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Yup , the trojan is gone. And for the smitrem log , have a look for it at C:\smitfiles.txt. But it looks like you are clean so it isn't really importend if it isn't there.

Do you still have any problems?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #6  
Old 03-06-2006
PCHF $ Donor
 
Join Date: Mar 2006
Posts: 3
amilfor - See this Members User comments on their Profile page
Default

no more problems. thanks for the help. donations headed your way


  #7  
Old 03-06-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Thats great to hear. And thanks alot for helping keeping the site up , much apreciated.


Marked as Fixed , and you know where to find us if you need us again.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 03:05 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top