Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Pending] Strange Activity!

[Fixed] Hijackthis! Logs - [Pending] Strange Activity! posted in the Security & Safety forums; Ok so I just tell you alittle about the problems I was having. Mozzilla amongs other programs would crash. Then not allow me to reopen them. I always get some ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 05-20-2007
Bronze Member
 
Join Date: Nov 2005
Posts: 76
sumodeluxe - See this Members User comments on their Profile page
Default [Pending] Strange Activity!

Ok so I just tell you alittle about the problems I was having. Mozzilla amongs other programs would crash. Then not allow me to reopen them. I always get some kind of registry backup msg when I first boot into windows. So I disabled system restore and went into safe mode to do my normal pre work.

I ran CCleaner. I ran AVG. I ran Spy-Bot S&D. but when I when to spySweeper I got a message saying the the exe was corrupt and that I need to scan right away for viruses and malware.

So I then went back into windows and had even more problems. I have Norton ( which I never use but still continue to update) and it gave me a msg saying that somthing had alterd its files along with SB S&D. So ..... I reinstalled then Updated all the programs. Went back into safe mode and ran Spybot in diagnostics mode(safe mode setting) Got almost all the way done with the scan when my computer suddenly restarts.

So I booted back into regular windows and tired to run it just to see if I would get the same results that I had seen before it rebooted itself. Sure enough the trojan it found was there. But it being the Trial all it would do is quarenteen. So I found the location of the registry key it idenfifyed then deleted it. Went back into safe mode and tired to find it in the registry (reassuring that it was gone) and I was unable to find anything. So For the third time I tired to run Spy Bot it rebooted again.

So here is a current HJT log. AVG updated cannot find anything.
Attached Files
File Type: log hijackthis.log (10.0 KB, 4 views)


  #2  
Old 05-21-2007
upgrader's Avatar
Site Manager
My PC
 
Join Date: Jul 2006
Location: /home/upgrader/
Posts: 6,457
PC Experience: Some Experience
upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page
Send a message via MSN to upgrader Send a message via Skype™ to upgrader
Default

OK Sumo someone will be along soon to help


__________________
PCHF Rules--PCHF Prework--PCHF Downloads
  #3  
Old 05-21-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,628
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

hello sumo, and welcome to the forums..... if you could click the 'prework' link in my signature and follow the steps there, you should come out with 3 logs to attach; a spy sweeper log, an AVG log (be sure to choose ‘delete’ or ‘quarantine’ for all that it finds), and an HJT log. Please attach all 3 as .txt files, and I will be more than happy to parse them for you.
Thanks,
v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #4  
Old 05-21-2007
Bronze Member
 
Join Date: Nov 2005
Posts: 76
sumodeluxe - See this Members User comments on their Profile page
Default

If you read my first post you will see that I was unable to run any of those because of how bad this infection is. I will try to produce more logs for you when I get off work.


  #5  
Old 05-21-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,628
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

Originally Posted by sumodeluxe
If you read my first post you will see that I was unable to run any of those because of how bad this infection is. I will try to produce more logs for you when I get off work.
that's what got me wondering. Your log is pretty clean, avg reports nothing, the next step is to try a rootkit revealer, I guess.

your avg is not the anti-virus, correct? Two anti-virus on the same machine would cause all sorts of havoc and would result in many of the problems you state.

What is the exact name of the trojan you had?

see you when work is done.

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #6  
Old 05-22-2007
Bronze Member
 
Join Date: Nov 2005
Posts: 76
sumodeluxe - See this Members User comments on their Profile page
Default

where might I find this rootkit revealer you speak of.... Everytime I boot into windows safe mode or not it tells me windows had to restore to a previous registry. I get all kinds of entry point errors.... this is really strange.


  #7  
Old 05-23-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,628
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

let's do this first:

go to start > run > eventvwr.msc. That will open an explorer like window with applications, security, and system in the left pane. Click on system and see if there are any exclamation points near to when it last froze; if so, double click on the item in the right pane, click on the two pieces of paper to copy it to your clipboard, and then come back here and paste the results. Then do the same for the applications folder; look for any exclamation marks that are near in time to when your pc is freezing.

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 01:34 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top