Free PC Performance Scan

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Need Help on this

[Fixed] Hijackthis! Logs - [Fixed] Need Help on this posted in the Security & Safety forums; Hi i helped remove some of the things in my friend's laptop but i just submit 2 logs just to double comfirm that everything is clean. Hope Joe you can ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 04-24-2006
Gold Member
 
Join Date: Nov 2005
Location: Somewhere where God exists.
Posts: 333
Matt87 - See this Members User comments on their Profile page
Default [Fixed] Need Help on this

Hi i helped remove some of the things in my friend's laptop but i just submit 2 logs just to double comfirm that everything is clean. Hope Joe you can help me out with this one

P.S when i start I.E it always have this website http://www.securitybulletin.net/ although i set the homepage to www.yahoo.com
Attached Files
File Type: log hijackthis.log (7.2 KB, 1 views)
File Type: txt Scan report_20060424.txt.txt (7.2 KB, 1 views)


__________________


If any of the staff helped u in a certain way and u want to thank them, press the "Thanks" Button below the post.

Your Friendly PCHF Mod

Last edited by Matt87; 04-24-2006 at 01:34 PM.
  #2  
Old 04-24-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Mat.


Indeed severall problems on there , first run Smitrem:

Download Smitrem to your desktop:
http://noahdfear.geekstogo.com/click...click.php?id=1

Run the installer and then press Start to Extract the
files to the desktop, Do not run it yet.

Reboot into safe mode (Reboot and keep tapping F8 , then
choose safe mode from the list)

Run SmitRem:
Open the SmitRem folder and double click the "RunThis.bat" file to start the tool. Follow the prompts on screen , wait for the tool to complete , and disk cleanup to finish.

The tool will create a log named smitfiles.txt on the drive that you ran Smitrem on, eg; "C:\smitfiles.txt" , or the partition where your operating system is installed on.

Please attach this log to your next reply.

Note: XP users using the XP theme may ex-perience a change to the Classic Windows theme. This can be changed on the themes tab of desktop properties.


You will need to reload your wallpaper as the SmitRem
tool will reset it, you can do this by right clicking
desktop and choosing properties, First check Theme and
set it to Windows XP then click the Desktop tab and
choose the one you want to use and press apply.

Download and run cwshredder:

http://cwshredder.net/bin/CWShredder.exe

Please go to add/remove programs and uninstall NewdotNet. If you don't have that option or if you have difficulties then please follow the instructions on this site


And does youre friend know that this keylogger is running on his pc?

Free KGB Key Logger

Also does he know that LogMeIn Remote Control software is installed and running on his pc?

And last , it seems he has no firewall , you know where to find free ones im sure.


When done , please post the Smitrem log plus a new hjt log to get the rest.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 04-25-2006
Gold Member
 
Join Date: Nov 2005
Location: Somewhere where God exists.
Posts: 333
Matt87 - See this Members User comments on their Profile page
Default

Hi Joe, Thanks for ya excellent Help

The Free KGB Key Logger installed legitly as he wanted to track who is using his laptop.

The LogMeInRemote Control is also a legit software as sometimes he wanted to remote access his laptop from places outside.

Attached below is the 2 logs.

Matt
Attached Files
File Type: txt smitfiles.txt (3.5 KB, 2 views)
File Type: log hijackthis.log (7.3 KB, 2 views)


__________________


If any of the staff helped u in a certain way and u want to thank them, press the "Thanks" Button below the post.

Your Friendly PCHF Mod
  #4  
Old 04-25-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looking good , most of it is gone.

First run this tool:

http://siri.urz.free.fr/Fix/SmitfraudFix.zip

As instructed here:

http://siri.urz.free.fr/Fix/SmitfraudFix_En.php

Then boot in safemode.

Click Start>Run and type in: services.msc
Click OK
In the Services window find: npkcsvc
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Open HJT and click config > misc tools > ?delete an NT service?
Copy and past: npkcsvc
Click OK.

And after that fix these with hjt if still present:

O2 - BHO: Nothing - {edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e} - C:\WINDOWS\system32\hpFFF2.tmp (file missing)
O20 - Winlogon Notify: winabe32 - winabe32.dll (file missing)
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
When done , post a new hjt log to check please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 04-25-2006
Gold Member
 
Join Date: Nov 2005
Location: Somewhere where God exists.
Posts: 333
Matt87 - See this Members User comments on their Profile page
Default

Attached is the log
Attached Files
File Type: log hijackthis.log (6.9 KB, 1 views)


__________________


If any of the staff helped u in a certain way and u want to thank them, press the "Thanks" Button below the post.

Your Friendly PCHF Mod
  #6  
Old 04-25-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looking even better. Everything is gone. BUT there is a new entry.. and i dont know what it is..


C:\mJeXPerience\Mp3Junction.exe

Do you or youre friend know whats its from?

If not , then upload the file to this site and report back the result:

http://www.virustotal.com/en/indexf.html

PS , dont forget a firewall.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 04-25-2006 at 04:08 PM.
  #7  
Old 04-26-2006
Gold Member
 
Join Date: Nov 2005
Location: Somewhere where God exists.
Posts: 333
Matt87 - See this Members User comments on their Profile page
Default

Hi Joe, the mp3junction is a mirc script legitly, so no worries.

So is this the HJT completed or ? If i get the go ahead from you , i move this topic to the completed HJT side.


__________________


If any of the staff helped u in a certain way and u want to thank them, press the "Thanks" Button below the post.

Your Friendly PCHF Mod

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 10:07 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top