Recommended Driver Scanner

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] popups and general weirdness

[Fixed] Hijackthis! Logs - [Fixed] popups and general weirdness posted in the Security & Safety forums; after a huge amount of viruses which i thought were all cleaned up, still having problems. any thoughts please...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 03-07-2006
Elite Member
My PC
 
Join Date: Nov 2004
Location: Top Secret... really
Posts: 527
spellbyte - See this Members User comments on their Profile page
Send a message via MSN to spellbyte Send a message via Skype™ to spellbyte
Default [Fixed] popups and general weirdness

after a huge amount of viruses which i thought were all cleaned up, still having problems.

any thoughts please
Attached Files
File Type: log hijackthis.log (6.2 KB, 4 views)


  #2  
Old 03-07-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya SB.

Yup , indeed a bunch of nasty's on there. First please do a Panda AV scan here:

http://www.pandasoftware.com/products/activescan

And save the log from it. Then please follow the Prework instructions and post the Panda log , the Ewido log and a new hjt log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 03-08-2006
Elite Member
My PC
 
Join Date: Nov 2004
Location: Top Secret... really
Posts: 527
spellbyte - See this Members User comments on their Profile page
Send a message via MSN to spellbyte Send a message via Skype™ to spellbyte
Default

after rebooting into normal mode, I got yet another virus alert. so there's still stuff looming here. hope these reports point it out
Attached Files
File Type: txt Activescan.txt (11.1 KB, 1 views)
File Type: txt ewido report.txt (9.6 KB, 1 views)
File Type: log hijackthis.log (4.8 KB, 1 views)


  #4  
Old 03-08-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Indeed still a hole bunch left , but we'll get them.



Please download Process Explorer by Systernals from HERE.

Also download KillBox by Option^Explicit from HERE.


Download Smitrem to your desktop:

http://noahdfear.geekstogo.com/click...click.php?id=1

Run the installer and then press Start to Extract the
files to the desktop, Do not run it yet.


Reboot into safe mode (Reboot and keep tapping F8 then choose safe mode from the list)


Run Smitrem:

Open the SmitRem folder and double click the "RunThis.bat"
file to start the tool , Follow the prompts on
screen. Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of the drive that you ran the batch file on, eg; Local Disk C: or partition where your operating system is installed. Please attach this log to your next reply.


Reboot in safemode again.

Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

Once you see this screen click on each instance of winrso32.dll once and then click the kill button.
After you have killed all of the winrso32.dll's under winlogon click OK.

Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of winrso32.dll then click the kill button.

Once you have done that click OK again.



Then fix these entry's with hjt:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {38CA6F55-A4BC-D410-CF4A-DBEF460EA2E5} - C:\WINDOWS\system32\supexda.dll
O20 - Winlogon Notify: winrso32 - C:\WINDOWS\SYSTEM32\winrso32.dll
Delete the file in bold , and run Ccleaner again.


Also manually delete these files if still present:

C:\Documents and Settings\Mark\Local Settings\Temp\ddl17F1.tmp.exe
C:\Documents and Settings\Mark\My Documents\Windows_98_SE_OEM_and_Office_2000_Serial_Keys_Coll ection_www.crack.cd_.zip[kje.exe]
c:\Program Files\srar
C:\Documents and Settings\All Users\Application Data\Starware
C:\Documents and Settings\Mark\My Documents\?icrosoft



Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

C:\WINDOWS\SYSTEM32\winrso32.dll

Click the red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)


You will need to reload your wallpaper as the SmitRem
tool will reset it, you can do this by right clicking
desktop and choosing properties, First check Theme and
set it to Windows XP then click the Desktop tab and
choose the one you want to use and press apply.



install and run RegSupremePro. It will want to make a backup of your registry , let it. Once it has finished, click on the Registry Cleaner tab, select Aggressive. When it has completed, click on Select, choose All. Click on Fix, and let it fix everything that it finds.

http://www.majorgeeks.com/download4256.html


Now please post a new hjt log (out of regular mode , not safemode) , and the smitrem log.

I would also recommend to have a firewall installed , see our download section for free ones.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 03-08-2006
Elite Member
My PC
 
Join Date: Nov 2004
Location: Top Secret... really
Posts: 527
spellbyte - See this Members User comments on their Profile page
Send a message via MSN to spellbyte Send a message via Skype™ to spellbyte
Default

while im updating the cache with regsupreme i thought i owuld post the logs
Attached Files
File Type: log hijackthis.log (6.3 KB, 1 views)
File Type: txt smitfiles.txt (3.2 KB, 1 views)


  #6  
Old 03-08-2006
Elite Member
My PC
 
Join Date: Nov 2004
Location: Top Secret... really
Posts: 527
spellbyte - See this Members User comments on their Profile page
Send a message via MSN to spellbyte Send a message via Skype™ to spellbyte
Default

as for the firewall, which is the best(easiest) to setup regards a home network, the other machine on the network is running win 98se on a wireless setup


  #7  
Old 03-08-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Its not gone yet , download and run this tool:

http://www.purityscan.com/ps_uninstaller.exe

Then (in safemode) fix these with hjt:
If still pesent.

R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {3A33165F-D3B5-AE48-CC7B-AD98B111F0BD} - C:\WINDOWS\system32\rfdhad.dll (file missing)
O4 - HKCU\..\Run: [Tcua] "C:\Program Files\srar\dtat.exe" -vt yax
O4 - HKCU\..\Run: [Oiapjb] C:\Documents and Settings\Mark\My Documents\?icrosoft\w?nlogon.exe
O20 - Winlogon Notify: winrso32 - winrso32.dll (file missing)
And delete the files in bold.

Then post a new hjt log please.


And as for a firewall , i would recommend Zonealarm. Also have a look here for installation guides:

http://www.pchelpforum.com/installation-guides/


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 10:47 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top