Member Panel


Sponsors and Ads

Noticeboard

[Fixed] Hijackthis! Logs - [Resolved] Slow comp posted in the Security & Safety forums; Hi Chiaz, I could not find the following in add/remove HotBar 180Solutions New.net or NewDotNet I ran uninstall6_90.exe all ok there. Please find attached AVg with every thing ticked ( ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 06-07-2007
cartandpeg's Avatar
Moderator
 
Join Date: Nov 2005
Location: Victoria,Australia
Posts: 841
cartandpeg - See this Members User comments on their Profile page cartandpeg - See this Members User comments on their Profile page
Default slow comp

Hi Chiaz,

I could not find the following in add/remove
HotBar
180Solutions
New.net or NewDotNet

I ran uninstall6_90.exe all ok there.


Please find attached AVg with every thing ticked ( was so much easier to see in norm mode.) I had to redownload AVG, done updates etc ran as per request.

Omg after looking at both reports they might have come out the same,I set How To Act to Quarantine and checked it twice more b4 i did scan.PS. yes i rebooted the comp and checked all was set as u asked and AVG shows no quarantine in it? Thats all I could see in the AVG programme to set to Quarantine.
Srry Chiaz??

Thanks Chiaz.
Attached Files
File Type: txt Report-Scan-20070607-152255.txt (58.1 KB, 2 views)



Last edited by cartandpeg; 06-07-2007 at 07:00 AM.
  #9  
Old 06-07-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,733
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

It's OK.

Go to Control Panel > Add/Remove Programs and remove this if found:
Macrogaming SweetIM

Next boot to safe mode, and delete the following files/folders:
C:\Documents and Settings\Deborah\My Documents\RealVegasInstaller.exe
C:\Documents and Settings\Sara\Application Data\Hotbar
C:\Program Files\Macrogaming


Reboot back to normal mode. Remember the tool called CCleaner that you downloaded while following the instructions in Prework? Run this tool. Click on Analyze, then Run Cleaner. Repeat until either no further files appear needing to be cleaned, or the same files keep reappearing.


Finally, run a new scan of AVG Anti-Spyware and HijackThis, in normal mode. I'll be awaiting the two logs.


  #10  
Old 06-07-2007
cartandpeg's Avatar
Moderator
 
Join Date: Nov 2005
Location: Victoria,Australia
Posts: 841
cartandpeg - See this Members User comments on their Profile page cartandpeg - See this Members User comments on their Profile page
Default report

Hi Chiaz,
first my apoligies, I was not completing the final stages in AVG hopefully this one is quarantined.

Macrogaming sweetim.....removed from add/remove

RealvagasInstall exe.....I could not actually see anything that said exe in it, but there was an Realvagas icon in there so I deleted it.

Hotbar, i could not find this in safe mode, however i did look in normal mode and found a folder in windows,I did delete it.

Macrogaming........deleted.

Cc Cleaner all done and AVG and HJT attached.

Thanks Chiaz
Attached Files
File Type: txt Report-Scan-20070607-205212.txt (1.0 KB, 3 views)
File Type: log hijackthis.log (16.8 KB, 2 views)


  #11  
Old 06-07-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,733
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Yep, many things have been disinfected. Run HijackThis and place a tick by the following entries:
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)


Close all other windows except HijackThis and press "Fix Checked". Then close HijackThis and restart the computer. Post back with a new log. How is your computer running now?


  #12  
Old 06-08-2007
cartandpeg's Avatar
Moderator
 
Join Date: Nov 2005
Location: Victoria,Australia
Posts: 841
cartandpeg - See this Members User comments on their Profile page cartandpeg - See this Members User comments on their Profile page
Default HJT log

Hi Chiaz,
Ok deleted what u asked for in HJT ( report attached ).

Still about the same on start up, takes about 12 mins to boot right up.

Chiaz during boot up the windows update icon shows, I have tried to update but it tells me I need Microsoft Office Xp Prof with front page, it asks for a disk, which I know my friend does not have as this comp came preloaded with everything, then it tells me ' the path to microsoft xp pro with front page cannot be found, try to find installation package PROPLUS.MSI in folder and install Microsoft Office Xp pro front page.

I have stuff trying to load up when I am booting up, something that pops up and says windows loading and a very persistant Picture gallery box trying to load, all I do is just keep hitting the cancel button untill it stops.

Not sure if this is relevant to anything.

Ok Chiaz report attached below.
Thankyou again.
Attached Files
File Type: log hijackthis.log (16.5 KB, 3 views)


  #13  
Old 06-08-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,733
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Chiaz during boot up the windows update icon shows, I have tried to update but it tells me I need Microsoft Office Xp Prof with front page, it asks for a disk, which I know my friend does not have as this comp came preloaded with everything, then it tells me ' the path to microsoft xp pro with front page cannot be found, try to find installation package PROPLUS.MSI in folder and install Microsoft Office Xp pro front page.
It is my belief that even if a computer comes preloaded with everything the shop will give the OEM discs to the owner?

something that pops up and says windows loading
Do you mean this happens when your desktop background already loads?

a very persistant Picture gallery box trying to load
I'm sure I encountered something like this before, but I can't remember what the problem was now.


Try this first:
go to the Run box on the Start Menu and type in:
sfc /scannow

This command will immediately start the Windows File Protection service to scan all protected files and verify their integrity, replacing any files with which it finds a problem.


  #14  
Old 06-08-2007
cartandpeg's Avatar
Moderator
 
Join Date: Nov 2005
Location: Victoria,Australia
Posts: 841
cartandpeg - See this Members User comments on their Profile page cartandpeg - See this Members User comments on their Profile page
Default

Ok Chiaz,
I will set up the sick comp and do that, in regards to the discs, even my comp and the wifes comp where not supplied with discs, seems to be the norm over here, buy a comp with every thing on it with no discs. The picture gallery tries to load when my desk top is already up and my desktop icons r loaded,there is a lot of garbage on this comp Chiaz, games that will not uninstall etc I have yet to get into that part. I will let u know how things wnet after the scannow....Thanks



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 07:55 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top