Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

[Fixed] Hijackthis! Logs - A friend's HJT log. posted in the Security & Safety forums; My friend has been having Spyware problems. I ran many scans etc so here's the HJT log....

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 07-17-2007
Vamp's Avatar
Gold Member
My PC
 
Join Date: Dec 2005
Posts: 207
Vamp - See this Members User comments on their Profile page
Default A friend's HJT log.

My friend has been having Spyware problems. I ran many scans etc so here's the HJT log.
Attached Files
File Type: log hijackthis.log (8.4 KB, 5 views)


  #2  
Old 07-18-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,606
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

are you at the pc? If so, click on the prework link in my signature and follow the steps there; that will spit you out the other end with a new hjt log and an AVG log that will help ID some of the culprits. If you are not at the pc, have them run the prework and post back, if possible......or, if they don't have internet, let me know, and we can work around that.....

thanks

v (the other v, not you )


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #3  
Old 07-18-2007
Vamp's Avatar
Gold Member
My PC
 
Join Date: Dec 2005
Posts: 207
Vamp - See this Members User comments on their Profile page
Default

He told me he got the virus from a friend on MSN Messenger, when the friend doesn't even know they've sent it.

I've heard of this before and I gather that it's quite common. I un-installed Messenger straigt away and have been running Super Anti Spyware for the las 2 days. Before I posted the log, SASpyware found nothing, and AVG found 1 virus.


  #4  
Old 07-18-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,606
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

well, from afar it's never easy, but let's try this. Next time you are at the pc, start hjt, click 'perform system scan only', close ALL other windows, including the internet, place a tick next to the following and click 'fix checked'.

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9C76F41F-51D7-4138-ACFF-2B0479199D8E} - (no file)
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\jqwrsofv.dll",realset


reboot and post a new log.

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #5  
Old 07-18-2007
Vamp's Avatar
Gold Member
My PC
 
Join Date: Dec 2005
Posts: 207
Vamp - See this Members User comments on their Profile page
Default

Thanks here you are.
Attached Files
File Type: log hijackthis.log (7.2 KB, 1 views)


  #6  
Old 07-19-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,606
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

lookin' good. How's the rig running?

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 07:09 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top