Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Prework attached - Can someone check please

[Fixed] Hijackthis! Logs - [Resolved] Prework attached - Can someone check please posted in the Security & Safety forums; I'd be extremely grateful if someone check my attached prework logs/reports. I'm pretty sure I have some horrible stuff on my PC that I'd like to be rid of....

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 06-03-2007
Bronze Member
 
Join Date: May 2007
Posts: 29
oddbod35 - See this Members User comments on their Profile page
Default [Resolved] Prework attached - Can someone check please

I'd be extremely grateful if someone check my attached prework logs/reports.
I'm pretty sure I have some horrible stuff on my PC that I'd like to be rid of.
Attached Files
File Type: txt bugreport.txt (28.2 KB, 2 views)
File Type: log hijackthis.log (4.3 KB, 2 views)
File Type: txt Report-Scan-20070527-120403.txt (2.0 KB, 4 views)


  #2  
Old 06-04-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

hey oddbod, welcome to the forums....for some reason, avg is set to ignore all the problems. Please do the following, post the new avg log and a new hjt log.

First download AVG Anti-Spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program. After the trial period, the scanner will continue to work, and you will still be able to receive updates; however, certain advanced setting will no longer be available unless purchsased
  1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
  2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
  3. On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  4. Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  6. Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  1. Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  2. Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  4. AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  5. If you have any infections you will prompted, then select "Apply all actions"
  6. Next select the "Reports" icon at the top.
  7. Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  8. Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the results of the AVG Anti-Spyware report scan as well as a new hjt log.
.


Thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #3  
Old 06-04-2007
Bronze Member
 
Join Date: May 2007
Posts: 29
oddbod35 - See this Members User comments on their Profile page
Default

Hi
Sorry for the delay.
Here are the new logs.
Attached Files
File Type: txt Report-Scan-20070604-214743.txt (3.5 KB, 2 views)
File Type: log hijackthis.log (3.7 KB, 2 views)


  #4  
Old 06-06-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

log looks pretty clean. What are the problems you are experiencing?

Let's do this as well:

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #5  
Old 06-06-2007
Bronze Member
 
Join Date: May 2007
Posts: 29
oddbod35 - See this Members User comments on their Profile page
Default

Thanks for your time,
I'm getting this box on start up -



any ideas what this is?

(I did have Spylocked but followed a procedure to get rid of it which seemed to work.
I also accidently downloaded Spyware Bot instead of Spybot S&D (doh!) but I wasn't sure if this has been erradicated)


  #6  
Old 06-07-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

weird error. Try this: Go to start > run > regedit.exe > that will bring up the registry,which looks sort of like the explorer window > expand the following ( \ marks mean click the plus sign next to the file)

HKEY_CURRENT_USERS \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon

click on winlog, see if there is a file called 'shell' in the right hand pane....let me know if it's there or not.....

be CAREFUL in the registry. Do NOT delete anything, or modify anything unless explicity instructed to; you mess something up in there, bad things can happen in a hurry.

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #7  
Old 06-07-2007
Bronze Member
 
Join Date: May 2007
Posts: 29
oddbod35 - See this Members User comments on their Profile page
Default

Okay, there is a file called Shell

The Type is - REG_SZ

The Data column - rundll32 "C:\DOCUME~\Tim\LOCALS~1\Temp\systems.dll" X4,explorer.exe


Is that good or bad?

Thanks



Last edited by oddbod35; 06-07-2007 at 10:23 PM.

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 09:08 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top