Recommended Driver Scanner

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Answered] crash and the missing folder.

[Fixed] Hijackthis! Logs - [Answered] crash and the missing folder. posted in the Security & Safety forums; there are a few things in your hjt log that are bad. In my signature, follow all the steps in the prework link, culminating with the posting another hjt log ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 02-13-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

there are a few things in your hjt log that are bad. In my signature, follow all the steps in the prework link, culminating with the posting another hjt log as well as the AVG log.

Thanks,

v


__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

  #9  
Old 02-13-2007
Bronze Member
 
Join Date: Aug 2005
Posts: 56
joker123 - See this Members User comments on their Profile page
Default

ok attached are the reports as requested.
Attached Files
File Type: txt hijackthis2.txt (7.9 KB, 1 views)
File Type: txt Report-Scan-20070213-150415.txt (3.3 KB, 1 views)


  #10  
Old 02-13-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key. Click on the processes tab and end process for (if present);

ALCXMNTR.EXE

To end the process, right click on the process and choose ‘end process’.

Close task manager.

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent HijackThis from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose "Yes" at the Warning prompt.
  • Expand the "Tools" menu.
  • Click "Resident".
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • In the File menu click "Exit" to exit Spybot Search & Destroy.
Run hijackthis again and put a tick next to the following and click ‘fix checked’


O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)




Click on the fix checked button.

Close HJT.


Now reboot into safe mode. To get into the Safe mode as the computer is booting press and hold your "F8 Key". Use your arrow keys to move to "Safe Mode" and press your Enter key.

Once in safe mode, navigate to the following files/folders and delete what is indicated.


C:\WINDOWS\ALCMTR.EXE <-- only the file

Reboot into normal mode, restart Teatimer, and please post another hijack this logfile.


Go to start > run > dxdiag > display tab and tell me the full name under the device box (upper left hand corner). Want to make sure this isn’t something as easy as a driver issue.

Thanks,

v


__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

  #11  
Old 02-13-2007
Bronze Member
 
Join Date: Aug 2005
Posts: 56
joker123 - See this Members User comments on their Profile page
Default

In system process there was a file also called alcwzrd.exe i ended the process to this also.

When in safe mode i deleted the file as specified however there were another two files called alcfdrtm and alcwzrd both with the same icon as the one i deleted. I have left them but I am expecting that you are going to tell me to go back and delete them too

After reboot alcwzrd.exe is running in system processes

The other topic about graphics card:
The name under device name is: radeon x300/550 series
by ati technologies

I hope I have told you all you need to know.

J

ps thanks for rapid responce
Attached Files
File Type: txt hijackthis3.txt (7.5 KB, 3 views)


  #12  
Old 02-13-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

nah, the alcwzrd is fine. It is part of RealTek as was the other one I had you remove, but this one doesn't phone home like the other did. The other one walked that fine line between good and bad; if they (RealTek) had given you an option to have it report back, as many companies do, it would be totally fine, but they do NOT give you the option, and it does report back, so that makes it malware in my book.

Regardless, let me look at your new log, and check out to make sure you have the correct driver.

v


__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

  #13  
Old 02-13-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

download and install the driver from here:

Catalyst® 7.1 Display Driver for Windows XP Professional/Home Edition

just the driver, don't need the entire catalyst suite. Let me know how it goes.


__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

  #14  
Old 02-14-2007
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 545
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default

Hello joker123,

Besides what valis as asked you to do, please do the following also:

Please do an online scan with Kaspersky WebScanner
Note: This Scanner is for Internet Explorer Only!

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then begin downloading the latest definition files:
Once the files have been downloaded click on NEXT

Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (if available otherwise Standard)
Scan Options:Scan Archives
Scan Mail Bases

Click OK

Now under select a target to scan:Select My Computer
This will program will start and scan your system.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Then attach the results from the Kapersky scan.


__________________
Steve

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On