Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] My HijackThis log

[Fixed] Hijackthis! Logs - [Fixed] My HijackThis log posted in the Security & Safety forums; Hi there, I recently attempted to an AdAware scan, but as soon as the scan stats a pop up appears stating the computer must terminate and it shuts down. I've ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 09-03-2006
Bronze Member
 
Join Date: Sep 2006
Posts: 5
supreme_tom - See this Members User comments on their Profile page
Default [Fixed] My HijackThis log

Hi there,
I recently attempted to an AdAware scan, but as soon as the scan stats a pop up appears stating the computer must terminate and it shuts down.

I've attempted a few other programs but none seem to do the job as well.

Any help would be much appreciated.

Tom
Attached Files
File Type: log hijackthis.log (18.0 KB, 4 views)


  #2  
Old 09-04-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Tom, welcome to PCHF.


First look in your add/remove programs for any of these:

Oin
OuterInfo
Yazzle by OIN
Cowabanga by OIN
PuritySCAN By OIN
Snowballwars by OIN
ipwins
Zolero
Tizzletalk
MediaTickets
Forethought
Quicklinks
or anything similar with Oin or Outerinfo in it.


If any of those names are found, click on it, and click remove.
Reboot and delete this folder if found:
C:\Program Files\PurityScan

If not listed, download and run this uninstaller:
http://www.outerinfo.com/OiUninstaller.exe
Tutorial for the uninstaller if needed:
Uninstaller
Reboot when done and delete this folder if found:
C:\Program Files\PurityScan




Run HijackThis , select to do a "system scan only" and then place a check beside each of the following:

R3 - URLSearchHook: (no name) - {F394FB63-3182-1076-A4AB-6C1347DD6DE2} - C:\WINDOWS\System32\tfxshde.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {06754ADA-1B20-4CF0-B9B1-86A721028AC1} - C:\WINDOWS\System32\yabaw.dll (file missing)
O2 - BHO: (no name) - {F394FB63-3182-1076-A4AB-6C1347DD6DE2} - C:\WINDOWS\System32\tfxshde.dll
O20 - Winlogon Notify: windvw32 - windvw32.dll (file missing)
O20 - Winlogon Notify: yabaw - C:\WINDOWS\System32\yabaw.dll (file missing)
Now first close all windows and browsers other then HiJackThis , then click fix checked and close HijackThis.

Manually delete this file:

C:\WINDOWS\System32\tfxshde.dll

Reboot your pc, and post a new HJT log please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 09-04-2006
Bronze Member
 
Join Date: Sep 2006
Posts: 5
supreme_tom - See this Members User comments on their Profile page
Default

Hey thanks for a quick response, sorry mine's a bit slow.

Here's that new log, but are all those O18 Logitech protocols normal?

Thanks, Tom.
Attached Files
File Type: log hijackthis.log (17.3 KB, 1 views)


  #4  
Old 09-04-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by supreme_tom
but are all those O18 Logitech protocols normal?
Yes and no, they are normal for the Logitech desktop messenger but it shouldn't create so many entry's. I don't know why it does that but you can uninstall it without problems in add/remove programs to get rid of it if you want.


Did you find any of these in add/remove programs?

Oin
OuterInfo
Yazzle by OIN
Cowabanga by OIN
PuritySCAN By OIN
Snowballwars by OIN
ipwins
Zolero
Tizzletalk
MediaTickets
Forethought
Quicklinks
or anything similar with Oin or Outerinfo in it.


And if not, did you download and run the Purityscan uninstaller? It's still there I'm afraid.

Let's try it an other way:

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 09-04-2006
Bronze Member
 
Join Date: Sep 2006
Posts: 5
supreme_tom - See this Members User comments on their Profile page
Default

I didn't find any of the following
Oin
OuterInfo
Yazzle by OIN
Cowabanga by OIN
PuritySCAN By OIN
Snowballwars by OIN
ipwins
Zolero
Tizzletalk
MediaTickets
Forethought
Quicklinks
or anything similar with Oin or Outerinfo in it.


and I ran the Purityscan uninstaller.

Heres that log from Combofix.

Cheers for all the help
Attached Files
File Type: txt ComboFixLog.txt (9.5 KB, 3 views)


  #6  
Old 09-04-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Please copy the text in the code box below, and paste it into a blank notepad window.
Save it as Fix.reg and in the "save as" type box choose "all files".
Once you have saved it, double click it, and allow it to merge with the registry.

Code:
REGEDIT4 
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ncao"=-
"Ftmdrspx"=-
"Aeae"=-
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=-
 
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\LDM]
Download Pocket Killbox:
http://www.atribune.org/downloads/KillBox.exe

Start Killbox and place a tick next to [x]delete on reboot.
And press the "all files" button. (just above the yellow triangle)
Copy this list into the windows clipboard:
(highlight the text , and select "copy")


C:\WINDOWS\unvise32.exe
C:\Documents and Settings\Tom\Application Data\GDIPFONTCACHEV1.DAT
C:\WINDOWS\system32\oins.exe
C:\WINDOWS\system32\wabay.bak1
C:\WINDOWS\system32\dvdplay.dll
C:\WINDOWS\system32\qommnom.dll
C:\WINDOWS\bwUnin-7.2.0.157-8876480SL.exe


Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt, then click OK.

Exit Killbox and restart your PC.


Post a new HJT log when done please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #7  
Old 09-05-2006
Bronze Member
 
Join Date: Sep 2006
Posts: 5
supreme_tom - See this Members User comments on their Profile page
Default

Ok, that's all done, here's that log.
Attached Files
File Type: log hijackthis.log (17.1 KB, 3 views)



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 01:49 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top