Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

[Fixed] Hijackthis! Logs - Help torjan posted in the Security & Safety forums; Ok I'm new so I'm going to explain this the best i can then i will post the hijack this log file...please help if you can I look at my ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-01-2007
Bronze Member
My PC
 
Join Date: Dec 2007
Posts: 4
PC Experience: I'm soso
sniffer024 - See this Members User comments on their Profile page
Default Help torjan

Ok I'm new so I'm going to explain this the best i can then i will post the hijack this log file...please help if you can


I look at my processes that are running and i see WEIRD .exe files running under system32 and "john"...files are like jkhsfjhd.exe tixxixr.exe (these are examples...every time i reboot they CHANGE NAMES) I then restart in safe mode....run all the cleaners i have ranging from avast,spy bot,a-squared,spy counter, many others that i would just download to use the scan...I then find Trojans like "Virtumonde.dcc" , "Virtumonde" , "Adware.win32.virtumode.aps" , "Troj.Tiny.en". these files are all found and deleted. upon reboot i ran a scan before boot with avast and deleted more Troj.Tiny.exe files and then i continue to restart and look at processes and still see wired files like jlkhsfka.exe htlidsj.exe and then i restart and run all the things (cleaners) again and they find all the same problems that i deleted and i don't understand what keeps making these files pop back up. so here is my last option before a full reinstall.

some notes
system restore has always been shut off on my computer,so i cant just restore.

When i reboot in safe mode it says click yes to continue or no to do a system restore, if i chose yes i don't get a start button or desktop icons. I must choose NO and then not restore (no spots to restore since i shut it off) safe mode then works fine..

So the problem is not stopping the process,not deleted the Trojans i find that run these process, but finding what makes these Trojans run and stop the MAIN item then kill all the others problems after that. Again i hope i explain this well and hope you all can help in anyway.



Attached Files
File Type: txt Winpatrol.txt (28.6 KB, 1 views)
File Type: txt HiJAck.txt (3.8 KB, 0 views)


  #2  
Old 12-01-2007
Hengis's Avatar
PCHF Founder & Owner
My PC
 
Join Date: Jan 2004
Location: Berkshire, England
Posts: 11,114
PC Experience: Always learning
Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page
Send a message via Skype™ to Hengis
Default Re: Help torjan

Welcome to PCHF - moved to HJT logs for analysis.


__________________
> Pre-Work > System File Checker
> Did we help you? If we did, please consider A Donation
  #3  
Old 12-04-2007
Bronze Member
My PC
 
Join Date: Dec 2007
Posts: 4
PC Experience: I'm soso
sniffer024 - See this Members User comments on their Profile page
Default Something wrong??

Em i doing something wrong? i have posted two threads and now one has responded at them at all...I look at all these other forums I see how people respond right away.....so how can i fix this?


  #4  
Old 12-04-2007
madmatt2006's Avatar
PC Dinosaur
 
Join Date: Dec 2006
Location: Shepparton
Posts: 2,598
PC Experience: Elite PC Guru
madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page
Default Re: Something wrong??

Hi I will have a look at them for you I must have missed them


  #5  
Old 12-04-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,583
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default Re: Help torjan

Hello Sniffer, and sorry for the delay.

I have merged one thread here, and deleted the other one. We like to keep things neat here.


Please download VundoFix.exe
to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please attach C:\vundofix.txt and a new HiJackThis log in your new reply.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above
instructions starting from "Click the Scan for Vundo button." when
VundoFix appears at reboot.


  #6  
Old 12-04-2007
Bronze Member
My PC
 
Join Date: Dec 2007
Posts: 4
PC Experience: I'm soso
sniffer024 - See this Members User comments on their Profile page
Default Re: Help torjan

thanks but i found another fix, i was reading other threads and found a program called SUPERantispyware. This program detected the hack like others but it also deleted it!!! YEAH! thanks for your help.....

PS
I ran the vundoFix just in case and it came up clean . thanks again


  #7  
Old 12-05-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,583
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default Re: Help torjan

Great. You may like to read the Prework for tips on keeping your computer clean and secure:http://www.pchelpforum.com/hijackthi...afterwork.html

Good luck, and safe surfing.



Last edited by chiaz; 12-13-2007 at 02:39 AM.

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 05:57 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
Home Loan
Home loan help from Ocean Finance.

Loans
Loans information and advice from money expert.

Myspace Proxy
Fastest proxy for Myspace