Recommended Driver Scanner

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] System Tray Spyware - HJT

[Fixed] Hijackthis! Logs - [Resolved] System Tray Spyware - HJT posted in the Security & Safety forums; Already explained issue; here is log....

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 05-02-2006
Bronze Member
 
Join Date: May 2006
Posts: 6
Josh - See this Members User comments on their Profile page
Default [Resolved] System Tray Spyware - HJT

Already explained issue; here is log.
Attached Files
File Type: log hijackthis.log (5.8 KB, 4 views)


  #2  
Old 05-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Josh.

Download Smitrem to your desktop:
http://noahdfear.geekstogo.com/click...click.php?id=1
Run the installer and then press Start to Extract the
files to the desktop, Do not run it yet.

Reboot into safe mode (Reboot and keep tapping F8 , then
choose safe mode from the list)

Run SmitRem:
Open the SmitRem folder and double click the "RunThis.bat" file to start the tool. Follow the prompts on screen , wait for the tool to complete , and disk cleanup to finish.

The tool will create a log named smitfiles.txt on the drive that you ran Smitrem on, eg; "C:\smitfiles.txt" , or the partition where your operating system is installed on.
Please attach this log to your next reply.

Note: XP users using the XP theme may ex-perience a change to the Classic Windows theme. This can be changed on the themes tab of desktop properties.




Then fix these with hjt: (in safemode)

F3 - REG:win.ini: run=F:\WINDOWS\inet20004\services.exe
O2 - BHO: Nothing - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - F:\WINDOWS\System32\hpEAA9.tmp
O20 - Winlogon Notify: winm32 - winm32.dll (file missing)
Delete the folder in bold manually , reboot and post a fresh hjt log please.






You will need to reload your wallpaper as the SmitRem
tool will reset it, you can do this by right clicking
desktop and choosing properties, First check Theme and
set it to Windows XP then click the Desktop tab and
choose the one you want to use and press apply.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 05-02-2006
Bronze Member
 
Join Date: May 2006
Posts: 6
Josh - See this Members User comments on their Profile page
Default

Here you go !
Attached Files
File Type: log hijackthis.log (5.8 KB, 1 views)


  #4  
Old 05-03-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Can you also post the Smitrem log?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 05-03-2006
Bronze Member
 
Join Date: May 2006
Posts: 6
Josh - See this Members User comments on their Profile page
Default

Alrighty, here it is; problem seems to be calm..
Attached Files
File Type: txt Scan report_20060502.txt.txt (976 Bytes, 1 views)


  #6  
Old 05-03-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hi Josh.

That is an Ewido log , not the Smitrem log. And there is still some malware left in youre hjt log. I would rather have seen the Smitrem log first but lets continue anyway:

Download Brute Force Uninstaller http://www.merijn.org/files/bfu.zip and unzip it to it’s own folder (c:\BFU).

Run the program and click the Web button located on the top right corner.
Copy and paste the below web address into the address bar of the Download script window:

ht tp://metallica.geekstogo.com/alcanshorty.bfu
(after copying and pasting , remove the space between "ht" and "tp")

Checkmark the following boxes:

Use settings specified in script for the above option.
Show log after script ends.

Execute the script by clicking the Execute button.

When it finishes running, click the Save button for a copy of the log. Post the log created by the script when you have completed the fix.

Post that log , a new hjt log , and the Smitrem log please. (should be located here: C:\Smitfiles.txt)


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #7  
Old 05-03-2006
Bronze Member
 
Join Date: May 2006
Posts: 6
Josh - See this Members User comments on their Profile page
Default

Sorry; here it is!
Attached Files
File Type: txt smitfiles.txt (3.7 KB, 1 views)



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 03:03 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top