Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [In Progress] HiJackThis! Logs
Register for a Free Account

[In Progress] HiJackThis! Logs - Help please! :( posted in the Security & Safety forums; yep better now. thanks. how would i know if its clean? what else do i need to do sir?...


Reply
Scan your PC for Errors
Old 09-27-2009   #22
Bronze Member
 
Join Date: Sep 2009
Posts: 27
PC Experience: Some Experience
Default Re: Help please! :(

yep better now. thanks. how would i know if its clean? what else do i need to do sir?
Scarlet_ is offline   Reply With Quote
Advertisement - Register to Remove
Old 09-27-2009   #23
Tech Support Team
 
Crush's Avatar
 
Join Date: Sep 2008
Location: Caldwell, New Jersey
Posts: 10,112
PC Experience: Always Learning New Things
Default Re: Help please! :(

Scarlet,

Can I see a new DDS log please? Let's see what remains
__________________
Crush aka Chris
[Prework][Afterwork][PCHF Rules][BSOD's][SFC][Screenshots][PC Specs][Donate]
I am in fact, quite cool. My graphing calculator confirms this

Crush is offline   Reply With Quote
Old 09-27-2009   #24
Bronze Member
 
Join Date: Sep 2009
Posts: 27
PC Experience: Some Experience
Default Re: Help please! :(

DDS (Ver_09-09-24.01) - NTFSx86
Run by Theresa 21 at 10:47:03.46 on Mon 09/28/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.372 [GMT -7:00]

AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\ZakFromAnotherPlanet\Yazak Chat\yazak.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Theresa 21\Desktop\dds.scr

============== Pseudo HJT Report ===============

uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\theres~1\applic~1\mozilla\firefox\prof iles\qvgfvrt1.default\

============= SERVICES / DRIVERS ===============

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboo t.sys [2009-9-27 28544]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-3-19 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfw tdir.sys [2009-3-19 93848]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-3-19 731840]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\theresa 21\desktop\sysprot\SysProtDrv.sys [2009-9-26 44288]

=============== Created Last 30 ================

2009-09-28 08:23 212,240 -------- c:\windows\system32\Richtx32.ocx
2009-09-28 08:23 124,688 -------- c:\windows\system32\Mswinsck.ocx
2009-09-28 08:23 1,081,616 -------- c:\windows\system32\Mscomctl.ocx
2009-09-28 08:23 608,448 -------- c:\windows\system32\Comctl32.ocx
2009-09-28 08:23 152,848 -------- c:\windows\system32\comdlg32.ocx
2009-09-28 08:23 132,880 -------- c:\windows\system32\MSINET.OCX
2009-09-28 08:23 <DIR> --d----- c:\program files\ZakFromAnotherPlanet
2009-09-28 05:23 <DIR> --d----- c:\program files\MYGAME Launcher
2009-09-28 04:44 <DIR> --d----- c:\program files\MYGAME
2009-09-28 00:03 12 a------- c:\windows\YAHVOX_ignore.ini
2009-09-27 23:11 28,544 a------- c:\windows\system32\drivers\pavboot.sys
2009-09-26 14:42 <DIR> --d----- c:\program files\Panda Security
2009-09-26 14:08 <DIR> --d----- c:\docume~1\theres~1\applic~1\Malwarebytes
2009-09-26 14:08 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-26 14:08 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-09-26 14:08 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-09-26 14:08 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-09-26 03:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\AVS4YOU
2009-09-26 03:43 82,944 a------- c:\windows\system32\vct3216.acm
2009-09-26 03:43 13,239 a------- c:\windows\system32\Scg726.acm
2009-09-26 03:43 <DIR> --d----- c:\program files\common files\AVSMedia
2009-09-26 03:43 81,920 a------- c:\windows\system32\AC3ACM.acm
2009-09-26 03:43 38,912 a------- c:\windows\system32\alf2cd.acm
2009-09-26 03:42 <DIR> --d----- c:\program files\AVS4YOU
2009-09-26 02:58 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Autorun Eater
2009-09-26 02:58 <DIR> --d----- c:\program files\Autorun Eater
2009-09-26 02:54 <DIR> --d----- c:\program files\Smart Virus Remover
2009-09-25 23:36 0 a------- c:\windows\YAHELITE_cookie.INI
2009-09-25 23:28 5,907 a------- c:\windows\YAHELITE.INI
2009-09-25 23:23 <DIR> --d----- c:\program files\YahELite
2009-09-25 23:02 <DIR> --d----- c:\program files\ESET
2009-09-25 00:13 <DIR> --d----- c:\program files\Yahoo!
2009-09-25 00:06 <DIR> --ds---- c:\documents and settings\theresa 21\UserData
2009-09-25 00:03 111,956 ---shr-- C:\w9uxx92.exe
2009-09-24 21:50 332,672 a------- c:\windows\system32\wgatray.exe.bak
2009-09-24 21:49 1,488,688 a------- c:\windows\system32\legitcheckcontrol.dll.bak
2009-09-24 21:49 200,064 a------- c:\windows\system32\wgalogon.dll.bak
2009-09-24 21:47 <DIR> --d----- c:\documents and settings\Theresa 21
2009-09-24 21:45 <DIR> --ds---- c:\windows\system32\Microsoft
2009-09-24 21:45 8,192 a------- c:\windows\REGLOCS.OLD
2009-09-24 21:43 101,376 ac------ c:\windows\system32\dllcache\srusbusd.dll
2009-09-24 21:42 10,129,408 ac------ c:\windows\system32\dllcache\hwxkor.dll
2009-09-24 21:41 68,608 ac------ c:\windows\system32\dllcache\iisext51.dll
2009-09-24 21:40 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-09-24 21:40 <DIR> --ds---- c:\windows\Downloaded Program Files
2009-09-24 21:40 <DIR> --d--r-- c:\windows\Offline Web Pages
2009-09-24 21:40 488 a---hr-- c:\windows\system32\WindowsLogon.manifest
2009-09-24 21:40 488 a---hr-- c:\windows\system32\logonui.exe.manifest
2009-09-24 21:39 <DIR> --d-h--- c:\program files\WindowsUpdate
2009-09-24 21:39 <DIR> --d----- c:\program files\common files\MSSoap
2009-09-24 21:37 <DIR> --d----- c:\program files\Online Services
2009-09-24 21:37 <DIR> --d----- c:\program files\Messenger
2009-09-24 21:37 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-09-24 21:36 <DIR> --d----- c:\program files\Windows NT

==================== Find3M ====================

2009-09-28 09:56 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-09-24 21:37 21,640 a------- c:\windows\system32\emptyregdb.dat

============= FINISH: 10:47:22.01 ===============
Scarlet_ is offline   Reply With Quote
Old 09-27-2009   #25
Bronze Member
 
Join Date: Sep 2009
Posts: 27
PC Experience: Some Experience
Default Re: Help please! :(

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-24.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 9/24/2009 9:44:32 PM
System Uptime: 9/28/2009 7:42:52 AM (3 hours ago)

Motherboard: Compaq | | 0804h
Processor: Intel(R) Pentium(R) 4 CPU 2.00GHz | XU1 PROCESSOR | 1992/400mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 29 GiB total, 24.237 GiB free.
D: is FIXED (NTFS) - 120 GiB total, 26.593 GiB free.
I: is CDROM (CDFS)

==== Disabled Device Manager Items =============

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Ethernet Controller
Device ID: PCI\VEN_8086&DEV_1039&SUBSYS_00910E11&REV_81\4&252 96D99&0&40F0
Manufacturer:
Name: Ethernet Controller
PNP Device ID: PCI\VEN_8086&DEV_1039&SUBSYS_00910E11&REV_81\4&252 96D99&0&40F0
Service:

==== System Restore Points ===================

RP1: 9/24/2009 9:47:46 PM - System Checkpoint
RP2: 9/25/2009 11:02:17 PM - Installed ESET NOD32 Antivirus
RP3: 9/28/2009 3:07:22 AM - System Checkpoint

==== Installed Programs ======================

Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Autorun Eater v2.4
AVS DVD Player version 2.4
AVS Update Manager 1.0
AVS4YOU Software Navigator 1.3
ESET NOD32 Antivirus
Malwarebytes' Anti-Malware
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.5.3)
MYGAME Launcher(Remove Only)
Panda ActiveScan 2.0
Special Force(Remove only)
VBRunDLL 3.3
WebFldrs XP
Winamp
WinRAR archiver
YahELite 330.1
Yahoo! Messenger
Yazak Chat 8.86.69

==== Event Viewer Messages From Past Week ========

9/26/2009 2:44:37 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ehdrv Fips intelppm
9/26/2009 2:43:21 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
9/25/2009 12:02:57 AM, error: W32Time [34] - The time service has detected that the system time needs to be changed by -57825 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com (ntp.m|0x1|112.203.79.83:123->207.46.197.32:123) is working properly.

==== End Of File ===========================
Scarlet_ is offline   Reply With Quote
Old 09-27-2009   #26
Tech Support Team
 
Crush's Avatar
 
Join Date: Sep 2008
Location: Caldwell, New Jersey
Posts: 10,112
PC Experience: Always Learning New Things
Default Re: Help please! :(

All that looks fine . Are you still experiencing the issues you posted about in your first post? If not, we'll just do some cleanup, and you can be on your way
__________________
Crush aka Chris
[Prework][Afterwork][PCHF Rules][BSOD's][SFC][Screenshots][PC Specs][Donate]
I am in fact, quite cool. My graphing calculator confirms this

Crush is offline   Reply With Quote
Old 10-05-2009   #27
Bronze Member
 
Join Date: Sep 2009
Posts: 27
PC Experience: Some Experience
Default Re: Help please! :(

Sorry i couldnt reply to you for days, there had been a bad typhoon here (philippines) hehe. Anyway, yeah i think computer is going good. what do i need to do next?
Scarlet_ is offline   Reply With Quote
Old 10-05-2009   #28
Tech Support Team
 
Crush's Avatar
 
Join Date: Sep 2008
Location: Caldwell, New Jersey
Posts: 10,112
PC Experience: Always Learning New Things
Default Re: Help please! :(

Scarlet,

Glad to hear you've made it through okay

Please download and run OTC (formerly OTCleanIt) from here:
http://oldtimer.geekstogo.com/OTC.exe

Click the Clean Up! button
This will remove any files and folders associated with some of the more destructive programs I have had you run
A reboot will be required to complete the removal.
__________________
Crush aka Chris
[Prework][Afterwork][PCHF Rules][BSOD's][SFC][Screenshots][PC Specs][Donate]
I am in fact, quite cool. My graphing calculator confirms this

Crush is offline   Reply With Quote

Reply


Bookmarks

Tags
autorun.inf, Fixed:, keylogger, trojan, virus

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 09:31 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2