Scan your PC for Errors

Member Panel


Sponsors and Ads

Noticeboard

[Fixed] Hijackthis! Logs - Hackit.RootKit posted in the Security & Safety forums; Recently i came to know that my system was affected by this Troj & it was informed by Norton Corporate Anti Vir. It was not able to delete the Trojan ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-11-2008
Bronze Member
 
Join Date: Jan 2008
Posts: 12
PC Experience: Some Experience
vivek - See this Members User comments on their Profile page
Default Hackit.RootKit

Recently i came to know that my system was affected by this Troj & it was informed by Norton Corporate Anti Vir.
It was not able to delete the Trojan & i had done partially using ZoneAlarm & fully using KasperSky(gr8 work)

But still some problems are there
1. When i acces my drives The open with dialog is displayed.
2.The hidden folders cannot be seen..I tried to set the Hidden Key from registry to 1 but it gets to 0 once the registry is refreshed
3.the instance of the iexplorer do remain ( i can see it thro Task manager) even if i close the explorer..

Plz provide a solution. . Im attaching the HijackThis Log ..
Attached Files
File Type: txt hijackthis.log.txt (5.5 KB, 2 views)
File Type: txt startuplist.txt (3.9 KB, 0 views)


  #2  
Old 01-11-2008
ih8bills's Avatar
Tech Team Leader
My PC
 
Join Date: Feb 2006
Location: coastal Rhode Island
Posts: 4,580
PC Experience: More Stubborn than any PC
ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page
Default Re: Hackit.RootKit

Hi --welcome to PCHF


Please be patient as a memeber of our security team will need to ananlyze these logs... they are very busy of late.


__________________


Without music, life would be a mistake
Friedrich Nietzsche
  #3  
Old 01-12-2008
Bronze Member
 
Join Date: Jan 2008
Posts: 12
PC Experience: Some Experience
vivek - See this Members User comments on their Profile page
Default Re: Hackit.RootKit

Thank U . .. . .


  #4  
Old 01-13-2008
ih8bills's Avatar
Tech Team Leader
My PC
 
Join Date: Feb 2006
Location: coastal Rhode Island
Posts: 4,580
PC Experience: More Stubborn than any PC
ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page
Default Re: Hackit.RootKit

BUMP....


__________________


Without music, life would be a mistake
Friedrich Nietzsche
  #5  
Old 01-13-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: Hackit.RootKit

hello vivek, and welcome to the forums...

well, whatever you scanned with did a pretty good job, but there's still some work to be done.

You may want to print these out. please close all other applications, start hjt again, click 'perform system scan only', place a tick next to the following and click 'fix checked'

You may want to print these out. please close all other applications, start hjt again, click 'perform system scan only', place a tick next to the following and click 'fix checked'

O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O8 - Extra context menu item: Show all images in original quality - C:\Program Files\www.cproxy.com\originalAll.htm
O8 - Extra context menu item: Show image in original quality - C:\Program Files\www.cproxy.com\original.htm


Is stiserver your ISP/Domain?

finally, Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall




thanks,

v


__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

  #6  
Old 01-25-2008
Bronze Member
 
Join Date: Jan 2008
Posts: 12
PC Experience: Some Experience
vivek - See this Members User comments on their Profile page
Default Re: Hackit.RootKit

Hi,
Sorry for a late reply . I was not healthy & had to take a long leave .. . I had formatted my C drive alone & reinstalled WINDOWS.. .
Now the other Drives D & E cannot be opened by clicking them.. How to solve this.. .
Iam uploading the Log File .. .
Attached Files
File Type: log hijackthis.log (4.1 KB, 1 views)


  #7  
Old 01-28-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: Hackit.RootKit

no worries, I was on holiday anyhow.

As for formatting the hd, that wiped out all malware. Now for the d and e drives, are they being recognized in bios? Did you add all the drivers? Do they show in disk manager? If they are not showing in disk manager, you may need to readd them. Easiest way to try that is just to unplug the power cords from them, reboot, turn the pc off, add the power cords, reboot and see if the system recognizes them. It should, but as this is windows, it's always an adventure.

v


__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 11:44 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top