Scan your PC for Errors

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] need some help here

[Fixed] Hijackthis! Logs - [Fixed] need some help here posted in the Security & Safety forums; Hello Joe, I just got back from work and finished what you told me to do so here is the report from the website... and the hijackthis log. Also I ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #15  
Old 03-13-2006
PCHF $ Donor
 
Join Date: Mar 2006
Posts: 19
bluecanvas - See this Members User comments on their Profile page
Default

Hello Joe,
I just got back from work and finished what you told me to do so here is the report from the website... and the hijackthis log. Also I found some names in the add/remove and i'm not really sure what they are ... such as broadjump client foundation, DA920EN, Easy-WebPrint, Modem Helper, Quicklinks. I need your advice what to do with them.
Attached Files
File Type: log hijackthis.log (9.3 KB, 2 views)
File Type: txt Activescan.txt (5.8 KB, 1 views)



Last edited by bluecanvas; 03-13-2006 at 05:58 AM.
  #16  
Old 03-13-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by bluecanvas
Also I found some names in the add/remove and i'm not really sure what they are ... such as broadjump client foundation, DA920EN, Easy-WebPrint, Modem Helper, Quicklinks. I need your advice what to do with them.
Those are all legit , but im not 100% sure about the last one.


DA920EN
Dell AIO Printer A920

broadjump client foundation
program is a tool used to diagnose problems when attempting to install a new broadband connection to the internet.

Easy-WebPrint
Canon Easy-WebPrint toolbar software

Modem Helper
a 'Stand alone' modem test and repair tool integrated onto your system

Quicklinks
Seems to be a p2p related plugin of some sort , not sure though.
http://coranto.gweilo.org/go/download/addons/quicklinks





Download Smitrem to your desktop
http://noahdfear.geekstogo.com/click...click.php?id=1
Run the installer and then press Start to Extract the
files to the desktop, Do not run it yet.


Download Pocket Killbox:
http://www.atribune.org/downloads/KillBox.exe

Then boot in safemode again

Run SmitRem:

Open the SmitRem folder and double click the "RunThis.bat"
file to start the tool , Follow the prompts on
screen. Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of the drive that you ran the batch file on, eg; Local Disk C: or partition where your operating system is installed. Please attach this log to your next reply


And fix these lines with hjt in safemode:
(if still present)

O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\SYSTEM32\owinrrag.exe CORN001
O4 - HKLM\..\RunOnce: [PPCInst6.230] C:\WINDOWS\system32\unPPC6000.EXE ppcremovefiles
O4 - HKCU\..\Run: [CU1]
O4 - HKCU\..\Run: [CU2]
O4 - Startup: Zeno.lnk = C:\WINDOWS\SYSTEM32\owinrrag.exe
O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - http://www.peoplepc.com/ppcos/isp60/...ad/ppcwebi.cab
O18 - Filter: text/html - {CEA53356-C414-4331-A35E-AA4CE9D8DFA2} - C:\WINDOWS\system32\w9seq.dll
And manually delete the files in bold.



Start Killbox and place a tick next to [x]delete on reboot.
And press the "all files" button. (just above the yellow triangle)
Copy this list into the windows clipboard:


C:\Documents and Settings\Felma\My Documents\Startup\Zeno.lnk
C:\WINDOWS\SYSTEM32\unPPC.exe
C:\WINDOWS\gimmygames.dat
C:\PROGRAM FILES\COMMON FILES\VCClient
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\NetMon
C:\PROGRAM FILES\COMMON FILES\Windows

Back in Killbox go > file > paste from clipboard,

Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.


After that please post the Smitrem log plus a new hjt log.



You will need to reload your wallpaper as the SmitRem
tool will reset it, you can do this by right clicking
desktop and choosing properties, First check Theme and
set it to Windows XP then click the Desktop tab and
choose the one you want to use and press apply.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #17  
Old 03-14-2006
PCHF $ Donor
 
Join Date: Mar 2006
Posts: 19
bluecanvas - See this Members User comments on their Profile page
Default the two logs

I hope I followed the instruction right. Here is the two logs you requested. :read2:
Attached Files
File Type: log hijackthis.log (8.3 KB, 1 views)
File Type: txt smitfiles.txt (3.1 KB, 1 views)



Last edited by bluecanvas; 03-14-2006 at 08:19 AM. Reason: i needed to attached the logs
  #18  
Old 03-14-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looking pretty good , boot in safemode again and fix these with hjt:


O4 - HKCU\..\Run: [CU1]
O4 - HKCU\..\Run: [CU2]
O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - http://www.peoplepc.com/ppcos/isp60/...ad/ppcwebi.cab
O18 - Filter: text/html - (no CLSID) - (no file)
And post a new log again to check please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #19  
Old 03-14-2006
PCHF $ Donor
 
Join Date: Mar 2006
Posts: 19
bluecanvas - See this Members User comments on their Profile page
Default

Hello...Here is the log... so am I almost clean?
Attached Files
File Type: log hijackthis.log (6.7 KB, 1 views)


  #20  
Old 03-14-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Well , almost. But the last dont seem to go away.. There still there.

Normally the smitrem would remove the Vcclient/surfsidekick infection , but since Ewido removed most of it already , the smitrem doesn't see the remaines of it im afraid.

Please run this regfix by unzipping it and double clicking on it and allowing it to merge with the registry , and then try to fix those entry's with hjt again:
Attached Files
File Type: rar fixssk.rar (508 Bytes, 1 views)


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #21  
Old 03-14-2006
PCHF $ Donor
 
Join Date: Mar 2006
Posts: 19
bluecanvas - See this Members User comments on their Profile page
Default

Okay I did what you told me to do.. and used hijackthis again to delete the other files... here is the log... Thank you so much for taking your time and helping me out. I'll try and donate later on once my pc is fully clean :grin:
Attached Files
File Type: log hijackthis.log (5.1 KB, 1 views)



Last edited by bluecanvas; 03-14-2006 at 07:11 PM.

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 03:51 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top