Free PC Performance Scan

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Please help, HJT log inside

[Fixed] Hijackthis! Logs - [Resolved] Please help, HJT log inside posted in the Security & Safety forums; I have been getting random virus warnings from Norton, and am having trouble sorting it out. Here is my log : Thanks! Brandon...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 05-06-2006
Bronze Member
 
Join Date: May 2006
Posts: 3
BHLeonard - See this Members User comments on their Profile page
Default [Resolved] Please help, HJT log inside

I have been getting random virus warnings from Norton, and am having trouble sorting it out. Here is my log :



Thanks!
Brandon
Attached Files
File Type: txt brandonHJT.txt (7.4 KB, 1 views)



Last edited by ladygreenwitch; 05-06-2006 at 11:24 PM.
  #2  
Old 05-06-2006
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,769
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hi Brandon,

Welcome to PCHF. We have a very expert team of techs on this site, and I am sure that we will be able to get your PC cleaned up.

In future, please make sure to post all logs as attachments, infected HJT logs can be a danger to others. I have already converted yours for you.

However, I need you to carefully follow the instructions in PreWork from my signature. It appears that you have an older version of HJT (HijackThis) and doing the prework will actually take care of some of your infection. Please make sure to save the ewido log, and unzip the new version of HijackThis into its own folder.

Then we will be able to further troubleshoot your issues.

Looking forward to your reply,

TTFN

LGW


  #3  
Old 05-07-2006
Bronze Member
 
Join Date: May 2006
Posts: 3
BHLeonard - See this Members User comments on their Profile page
Default Log files

Thanks for the help. I've done all as you said, and am attaching my new log.. Thanks for any help you can give me, this is driving me nuts. My main problem is internet explorer won't load pages, just hangs. Outlook does the same thing. I can reboot and its good for a few pages, then it does it again.

Thanks
Brandon
Attached Files
File Type: txt Scan report_20060506.txt.txt (2.7 KB, 2 views)
File Type: log hijackthis.log (7.7 KB, 2 views)


  #4  
Old 05-08-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Brandon.

Looks pretty good , but i would disable the windows messenger service;

Please download Shoot The Messenger

Download and run the small (22 kbyte) "ShootTheMessenger.exe" utility. It will display the current status of your system's Messenger Service. The button near the bottom of its window will allow you to set the service to whichever state — running or disabled — that you desire.

If, for any reason, you should ever choose to re-enable the Windows Messenger Service, simply re-run ShootTheMessenger to do so.

Then boot in safemode again and fix this entry with hijackthis:

O4 - HKCU\..\Run: [MoneyAgent] "÷wàÕöwÿÿÿÿ²õw¬Âwmnyexpr.exe"
Reboot , see if you are still redirected , and post a new hjt log please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 05-08-2006
Bronze Member
 
Join Date: May 2006
Posts: 3
BHLeonard - See this Members User comments on their Profile page
Default

Thanks guys/gals.. I did as directed above and am attaching my latest HJT log. When I logged onto windows after rebooting, the Ewido caught a malware program this time.. I don't see it affecting me now though.. Let me know what you all think.

Brandon
Attached Files
File Type: txt HTJ_50706.txt (6.5 KB, 3 views)


  #6  
Old 05-08-2006
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,769
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hey Guys,

@Joe, haven't seen this as a service before, O23 - Service: winupd - Unknown owner - C:\WINDOWS\winupd.exe, is it legit? Only coming up with slightly different names under services.

@Brandon, other than the item I am asking Joe about, your log looks clean. However, if you ran Shoot the Messenger, it didn't take.

I would however, highly recommend that you upgrad to SP2, it really is the best way to keep up on all of the security patches.

Also, I didn't see a firewall listed, you really must use a firewall if you want to protect yourself. In the article PCHF Protect Your PC, in my signature, you will find a section on free firewalls. They are all good, just depends on personal taste.

After you upgrade, try running Shoot the Messenger again, and see if we can't get that thing shut off. It leaves you vulnerable to Popup attacks.

Once Joe gives us an answer on the 023 entry, you should be clean.

Let us know if any of the symptoms are persisting.

Look forward to your reply,

TTFN

LGW


  #7  
Old 05-08-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Yup , thats a bad one for sure , and that also shows the importence of updating windows and installing a firewall because this is a new infection again. It wasn't present in youre previous logs.


Click Start>Run and type in: services.msc
Click OK
In the Services window find: winupd
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Open HJT and click config > misc tools > “delete an NT service”
Copy and past: winupd
Click OK.


After that i would install a firewall , we have free ones in our download section , and then its time to update windows.

When done , post a new hjt log to check please.
(out of regular mode , not safemode)


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 11:32 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top