Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] HJT log. Suspects in windows and system32 folders

[Fixed] Hijackthis! Logs - [Fixed] HJT log. Suspects in windows and system32 folders posted in the Security & Safety forums; I think I've got some spyware/downloader... I've found some unknown new files in my windows and system32 folders... Please have a look: suspects are: dwnrpofk.dll kdftlboerfg.dll norlatmx.exe qvdntlmw.dll vbgtorfd.dll rs.txt ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 03-25-2008
Bronze Member
My PC
 
Join Date: Feb 2008
Posts: 12
PC Experience: Experienced
raph76 - See this Members User comments on their Profile page
Default [Fixed] HJT log. Suspects in windows and system32 folders

I think I've got some spyware/downloader... I've found some unknown new files in my windows and system32 folders...

Please have a look:

suspects are:
dwnrpofk.dll
kdftlboerfg.dll
norlatmx.exe
qvdntlmw.dll
vbgtorfd.dll
rs.txt
gxkjwlob.exe

I attach a HJT log aswell.
Attached Files
File Type: log hijackthis.log (12.9 KB, 0 views)


  #2  
Old 03-26-2008
Bronze Member
My PC
 
Join Date: Feb 2008
Posts: 12
PC Experience: Experienced
raph76 - See this Members User comments on their Profile page
Default Re: HJT log. Suspects in windows and system32 folders

New log after a long fight...
Attached Files
File Type: log hijackthis.log (12.5 KB, 0 views)


  #3  
Old 03-28-2008
Bronze Member
My PC
 
Join Date: Feb 2008
Posts: 12
PC Experience: Experienced
raph76 - See this Members User comments on their Profile page
Default Re: HJT log. Suspects in windows and system32 folders

I coulnd't wait... I think I get rid of most infections... Here's today HJT log.

Thanks for having a look.

I still have this kpkfmdil.exe, what is it?


Cheers!
Attached Files
File Type: log hijackthis.log (12.6 KB, 0 views)


  #4  
Old 03-28-2008
Zachary's Avatar
Mod Squad!
My PC
 
Join Date: Nov 2006
Location: San Antonio, TX
Posts: 958
PC Experience: Experienced
Zachary - See this Members User comments on their Profile page Zachary - See this Members User comments on their Profile page Zachary - See this Members User comments on their Profile page Zachary - See this Members User comments on their Profile page Zachary - See this Members User comments on their Profile page Zachary - See this Members User comments on their Profile page Zachary - See this Members User comments on their Profile page Zachary - See this Members User comments on their Profile page Zachary - See this Members User comments on their Profile page Zachary - See this Members User comments on their Profile page Zachary - See this Members User comments on their Profile page
Default Re: HJT log. Suspects in windows and system32 folders

Hi raph76,
I'm sorry your thread was missed but I'll let the security staff know.
You should never use HiJackThis on your own unless you're 100% sure of what you're doing, you can do a lot of damage quickly and it may not be fixable except by a reformat.


__________________
  #5  
Old 03-28-2008
ih8bills's Avatar
Tech Team Leader
My PC
 
Join Date: Feb 2006
Location: coastal Rhode Island
Posts: 4,456
PC Experience: More Stubborn than any PC
ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page
Default Re: HJT log. Suspects in windows and system32 folders

Originally Posted by Zachary View Post
Hi raph76,
I'm sorry your thread was missed but I'll let the security staff know.
You should never use HiJackThis on your own unless you're 100% sure of what you're doing, you can do a lot of damage quickly and it may not be fixable except by a reformat.

That is actually true of most of the specialized security tools you may see in HJT threads.
You can instantly make your PC unbootable....


__________________


Without music, life would be a mistake
Friedrich Nietzsche
  #6  
Old 03-28-2008
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 3,555
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: HJT log. Suspects in windows and system32 folders

Ok.We need to download ComboFix.exe. This will give a better view to the files running and also hidden on your computer.
Please visit this webpage for download links, and instructions for running the tool

When the tool is finished, it will produce a report for you. Please copy and paste the "C:\ComboFix.txt" along with a new HijackThis log so that we can continue to do any further cleaning that your system may require.
Caution: Never run and remove files with Combofix unless supervised by a security analyst.
NOTE: Combofix prevents autorun of all CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #7  
Old 03-29-2008
Bronze Member
My PC
 
Join Date: Feb 2008
Posts: 12
PC Experience: Experienced
raph76 - See this Members User comments on their Profile page
Default Re: HJT log. Suspects in windows and system32 folders

Hi!

Thx for your answer...

Note that I didn't delete or change anything anything with HJT, just used antivirus, windows defender and spybot... Thans for the advices anyway ;o)

Here are the latest logs...

Cheers.
Attached Files
File Type: log hijackthis.log (12.5 KB, 1 views)
File Type: txt ComboFix.txt (18.4 KB, 1 views)



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 02:20 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top