Member Panel


Sponsors and Ads

Noticeboard

[Fixed] Hijackthis! Logs - HiJackThis log posted in the Security & Safety forums; Had numerous antisypware popups and a wallpaper that overlayed mine for a "protect your privacy" site. After running Super AntiSpyware, all have disappeared. Browser also was slow to open (Mozilla). ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-27-2007
mickeywess's Avatar
Bronze Member
 
Join Date: Nov 2007
Location: Ky
Posts: 6
PC Experience: Some Experience
mickeywess - See this Members User comments on their Profile page
Default HiJackThis log

Had numerous antisypware popups and a wallpaper that overlayed mine for a "protect your privacy" site. After running Super AntiSpyware, all have disappeared. Browser also was slow to open (Mozilla). Thank you for your help
Mickey Wesselman
Attached Files
File Type: log hijackthis.log (12.7 KB, 1 views)


  #2  
Old 11-27-2007
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 3,595
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: HiJackThis log

This will help to identify any malware on your system.
Please download Combofix from HERE or HERE

Save ComboFix to the desktop.
1. Double click on combo.exe & follow the prompts.
2. When finished, it will produce a logfile located at C:\ComboFix.txt.
3. Copy and Paste the contents of that log in your next reply with a new hijackthis log. Do not use Code or html unless asked for.
Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #3  
Old 12-04-2007
mickeywess's Avatar
Bronze Member
 
Join Date: Nov 2007
Location: Ky
Posts: 6
PC Experience: Some Experience
mickeywess - See this Members User comments on their Profile page
Default Re: HiJackThis log

Seemed to be cleaned up, then started getting popups again. Reran everything plus Combofix. All logs attached. Thanks for your help.........Mickey W
Attached Files
File Type: txt Combofix log 12-3-07.txt (8.7 KB, 1 views)
File Type: txt hijackthis 12-3-07.txt (12.2 KB, 1 views)
File Type: log SUPERAntiSpyware Scan Log - 12-03-2007 - 21-13-50.log (3.6 KB, 1 views)


  #4  
Old 12-04-2007
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 3,595
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: HiJackThis log

Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.

O21 - SSODL: gormet - {FE545377-9726-445C-A69D-DFB42914C239} - D:\WINDOWS\gormet.dll (file missing)

============================

Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below.
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Open *notepad* and copy/paste the text in the quotebox below into it:
KillAll::
File::
D:\WINDOWS\pmkret.dll
D:\WINDOWS\monhop.exe
D:\WINDOWS\MSVB.DLL
D:\WINDOWS\SYSDX.DLL
D:\WINDOWS\NSDUO.DLL
D:\WINDOWS\MSMHOST.DLL
Folder::
D:\Program Files\Viewpoint
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad]
"gormet"=-
Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.


Refering to the picture above, drag CFScript.txt into ComboFix.exe
Restart your computer.
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please.

*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall*


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #5  
Old 12-04-2007
mickeywess's Avatar
Bronze Member
 
Join Date: Nov 2007
Location: Ky
Posts: 6
PC Experience: Some Experience
mickeywess - See this Members User comments on their Profile page
Default Re: HiJackThis log

Logs attached as instructed
Attached Files
File Type: txt ComboFix log 12-4.txt (12.3 KB, 2 views)
File Type: txt hijackthis log 12-4.txt (11.6 KB, 2 views)


  #6  
Old 12-04-2007
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 3,595
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: HiJackThis log

This is the last items to fix....

Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.

O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - D:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O23 - Service: Viewpoint Manager Service - Unknown owner - D:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #7  
Old 12-05-2007
mickeywess's Avatar
Bronze Member
 
Join Date: Nov 2007
Location: Ky
Posts: 6
PC Experience: Some Experience
mickeywess - See this Members User comments on their Profile page
Default Re: HiJackThis log

Followed last instructions. Computer is running great, fast, no popups. Many,many thanks!! Have and will recommend this site to friends and family.



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 11:27 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top