Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Internet error message

[Fixed] Hijackthis! Logs - [Resolved] Internet error message posted in the Security & Safety forums; Hey Guys, @Leo, my most sincere apologies for the delay in answering your post. I would also like to extend my welcome to PCHF. I see that you posted an ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 02-03-2007
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hey Guys,

@Leo, my most sincere apologies for the delay in answering your post. I would also like to extend my welcome to PCHF.

I see that you posted an HJT log, but did you complete the PreWork? If not would you please follow the instructions from my signature. If yes, could you please post the AVG log as well.

Looking forward to your reply,

TTFN

LGW

PS, I will be gone for most of the day, but will make this thread my priority upon my return. Thanks for understanding. LGW


  #9  
Old 02-03-2007
Bronze Member
 
Join Date: Jan 2007
Posts: 17
LEOMAG - See this Members User comments on their Profile page
Default

Thank you for responding. AVG turned up with nothing, so that's why i didn't post it.


  #10  
Old 02-04-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,866
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Hello.

I see remnants of Look2Me in your HijackThis log...

Download ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
If you use Firefox browser, do this also:
  • Click Firefox at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser, do this also:
  • Click Opera at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


Next download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task.
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button.
  • You will receive a Done Scanning message, click OK.
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
http://www.ascentive.com/support/new...b/MSWINSCK.OCX


  #11  
Old 02-04-2007
Bronze Member
 
Join Date: Jan 2007
Posts: 17
LEOMAG - See this Members User comments on their Profile page
Default

Thanks chiawaikian,

Both cleaners seem to have worked fine, although my problem still persists, and if anything, my pc is slower. Here are my log files
Attached Files
File Type: log hijackthis.log (7.8 KB, 3 views)
File Type: txt Look2Me-Destroyer.txt (1.2 KB, 3 views)


  #12  
Old 02-04-2007
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hey Leo,

I see that you have Spy Sweeper, Dr. Web, Windows Defender, and AVG running on your PC, other than the AVG which you installed for us, are any of these new? It is possible that you are experiencing a conflict with your scanning software on top of the infections. Usually this is only a problem if two or more AVs are running, but it's possibly part of your slowdown. Once we are sure that your PC is clean, we'll do a thorough cleaning of your PC, and make sure the registry is cleaned, then we will be in a better position to test that out.

When you do a full scan with Spy Sweeper, do you have it check for everything listed in the Custom Sweep options? If not would you please also run a full system scan with those options checked, and post the log back here?

There also appears to be a worm that didn't get taken care of in the other two scans. Please look in Task Manager and see if you can locate a process called rundll.exe (not Rundll32.exe), and end the process.

Then delete the file, C:\Windows\rundll.exe

Next go to Start, Run, and type in services.msc click OK
In the Services window find: rundll.exe
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK

Open HJT and click config > misc tools > Delete an NT service
Type in rundll.exe
Click OK.

Looking forward to your reply,

TTFN

LGW


  #13  
Old 02-04-2007
Bronze Member
 
Join Date: Jan 2007
Posts: 17
LEOMAG - See this Members User comments on their Profile page
Default

Thanks for all the advice.
I succesfully deleted rundll.exe. While i was looking for it, i saw that i was running 2 rundll32.exe processes. Is that normal? Anyway, spysweeper did not find anything, and its not very good anyway because its the free version and i can't seem to be able to use many of it's processes or save some sort of a log file. This is very evasive spyware!


  #14  
Old 02-04-2007
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hey Leo,

Actually, SpySweeper's trial version is full functioning, it is a 14 day trial, that gives you access to all of it's functionality. Are you sure that you didn't miss the location of the button for saving a log file? It is in the bottom left corner of the screen, and sometimes is overlooked.

What exactly is it telling you that you can't access? That actually concerns me a bit more, as it could be malware interfereing.

Please be really specific, OK?

Looking forwrad to your reply,

TTFN

LGW



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 08:35 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com