Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » Spyware / AdWare » [Answered] Not sure infected or not

Spyware / AdWare - [Answered] Not sure infected or not posted in the Security & Safety forums; Hi, I am not sure whether my notebook has been infected or not. However, my server is badly infected with trojan horse until it has to be formatted. I have ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 08-26-2005
Bronze Member
 
Join Date: Aug 2005
Posts: 4
thankyou1st - See this Members User comments on their Profile page
Default [Answered] Not sure infected or not

Hi,

I am not sure whether my notebook has been infected or not. However, my server is badly infected with trojan horse until it has to be formatted.

I have tried to update the window but not successful. From the checking by window update via internet, it detected that I have one update but the update files is 0kb! I try to install anyway, it show the file to update is service pack 2. However, when I try to install it, it just hang when checking my system.

Attached my hijack log.

JOHN
Attached Files
File Type: txt hijackthis.txt (7.1 KB, 2 views)


  #2  
Old 08-26-2005
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: Not sure infected or not

Hi Thankyou1st,

Welcome to PCHF. Let me take a look at your HJT log and I'll get right back to you.

TTFN

T


  #3  
Old 08-26-2005
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: Not sure infected or not

:-) Hi John,

I see just a couple of things in your HJT log. You certainly have the right protection on your PC

Let's get you cleaned up completely and see if we can't get your update to run.

To start with I would like you to do this:


First disable system restore to prevent re-infection.
(you can turn it back on when youre pc is clean).


How to disable system restore:

WinXP.

Click the Start button.
Right-click My Computer, and then click Properties.
On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.

Then please delete your temporary files by deleting all files and folders that are in those folders:
(do not delete the temp folder itself)
(if there are "files in use" then empty these folders in safemode(hit f8 when booting up)

empty the C:\windows\prefetch folder ,
empty the C:\windows\temp folder ,
empty the C:\Documents and Settings\Your Account\Local Settings\Temp folder ,
empty the C:\Documents and Settings\Your Account\Local Settings\Temporary Internet Files folder EXCEPT the content.ie5 folder (may be hidden).


And close all instances of IE and OE ,then go to: Control Panel / Internet Options / General tab.
Click the "Delete Files" button.
When prompted place a check in: "Delete all offline content", click OK. This removes the junk files such as downloaded files, zero byte files created by Outlook Express and many other hidden files that reside in your cache.

Then please do this since it?s better to use automated tools to get rid of the bad stuff use these programs first before doing the final cleaning with HJT.

Open ewido and update, then click on scanner, then settings, make sure all options are selected and that scan all files is also selected. Run your ewido scan fixing everything it finds.

Spybot: Search And Destroy:
If you do not have version 1.4 please;
1.Download the new version (1.4) of 'Spybot: Search And Destroy'.

2. Install it according to the instructions in 'How To Setup Spybot SD'.

3. Next, 'Search for Updates' as the definitions are not likely to be up-to-date.

4. Close ALL windows except Spybot SD.

5. Click the "Check for Problems" button.

6. Click 'Fix Selected Problems' and fix only the RED items.

7. REBOOT to finish removing what Spybot SD found and clear memory.


Ad-Aware SE by Lavasoft:
If you do not have the most recent update please;
1. Download 'Ad-Aware SE'.

2. Install according to the instructions in "How To Setup Ad-Aware SE"

3. Next, 'Check for Updates' by clicking on the 'world globe' second from the right at the top of your Ad-Aware SE window.

4. Install the updates.

5. Close ALL windows except Ad-Aware SE.

6. Click on 'Start' and choose 'full scan' for a full scan.

7. Quarantine anything that it finds and SAVE the log file.

8.REBOOT to finish removing what Ad-Aware SE found and clear memory.

Then rerun HijackThis and fix any of these items that are still showing

R3 - Default URLSearchHook is missing
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearc...p=ZNxdm119YYMY
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

Then we'll look at some things that could also be blocking your install.

Look forward to your reply.

TTFN

T


  #4  
Old 08-26-2005
Bronze Member
 
Join Date: Aug 2005
Posts: 4
thankyou1st - See this Members User comments on their Profile page
Default Re: Not sure infected or not

thank for your prompt reply.

Let me try out first.

JOHN


  #5  
Old 08-26-2005
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: Not sure infected or not

:-) OK Great,

I have to log off for tonight. Joe and Merlin are on right now and more than likely one of them will follow up with you on this tonight. If not I will check back in the morning and see how it worked out.

TTFN

T


  #6  
Old 08-26-2005
Bronze Member
 
Join Date: Aug 2005
Posts: 4
thankyou1st - See this Members User comments on their Profile page
Default Re: Not sure infected or not

Hi,

Done.

But noted 3 things.

1. while deleting temp folder, one file could not be deleted and finally it get deleted, the file recreate itself with the aphabet JET infront eg. JET9D41, JET3D5C

2. Ad ware seems to have problem to remove spyware.. websearch..keep on coming back
3. if u look at the hijackthis log, there linking to //red.clientapps.yahoo/customise.. is this a problem? I notice that my infected server auto link to this shortcut via IE.

Thanks for your assistance

Attached is my log.
Attached Files
File Type: txt hijackthis2.txt (6.8 KB, 1 views)


  #7  
Old 08-26-2005
merlin's Avatar
Trusted Security Analyst
My PC
 
Join Date: Jul 2005
Location: Wisconsin
Posts: 2,616
PC Experience: Computers Fear Me
merlin - See this Members User comments on their Profile page merlin - See this Members User comments on their Profile page
Send a message via Yahoo to merlin
Default Re: Not sure infected or not

We can go this route as well..


Please download ewido Security Suite[list] [*]Install ewido security suite [*]When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu." [*]Launch ewido, there should be a big "E" icon on your desktop, double-click it. [*]The program will prompt you to update click the "OK" button [*]The program will now go to the main screen

You will need to update ewido to the latest definition files.
[*]On the left hand side of the main screen click update [*]Click on Start

The update will start and a progress bar will show the updates being installed. After the updates are installed, exit ewido.

Once the updates are installed do the following:
[*]If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
[*]Reboot into Safe Mode, you can do this by restarting your computer, then contiunally tapping F8 until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter. Then, run ewido.
[*]Close all open windows/programs/folders. Have nothing else open while ewido performs its scan!
[*]Click on scanner [*]Click on Settings
  • Under "How to scan" all boxes should be selected
  • Under "Possibly unwanted software" all boxes should be selected
  • Under "What to scan" select scan every file
  • Click OK
[*]Click on Complete system scan [*]Let the program scan the machine
[*]If ewido finds anything, it will pop up a notification. NOTE: We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged. In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action. DO NOT check "Perform action with all infections." If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report.
[*]Click Save report [*]Save the report to your desktop [*]Exit ewido

And post the Ewido log back here...


__________________
QuickTime Alternative..Hijackthis..SpeedFan..ATI Tool..Whats Running..Everest..Absolute Control..All Drivers
If you feel we saved you some money please help support this site by DONATING as this site is funded by great people like you

OUT FOR LUNCH



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 11:22 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top