|
|
|
|
#1 (permalink) |
|
New Member
![]() Join Date: May 2006
Posts: 8
|
Here is my HJT log.
Logfile of HijackThis v1.99.1 Scan saved at 2:50:44 PM, on 5/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\AntiVir PersonalEdition Classic\avcenter.exe C:\Program Files\WinRAR\WinRAR.exe C:\DOCUME~1\PAUL~1.PAU\LOCALS~1\Temp\Rar$EX00.078\ HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O20 - Winlogon Notify: SMDEn - C:\WINDOWS\system32\c6002gdmg60a2.dll O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe |
|
|
|
|
|
#2 (permalink) |
|
Silver Member
![]() Join Date: Nov 2005
Posts: 167
|
C:\Program Files\AntiVir PersonalEdition Classic\avcenter.exe - Unknown FINE NOTHING WRONG WITH THAT ONE.
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto - Nasty VERY NASTY. THAT IS THE RESULT OF THE RADO VIRUS AND MUST BE REMOVED O20 - Winlogon Notify: SMDEn - C:\WINDOWS\system32\c6002gdmg60a2.dll - Unknown LEASVE THAT ONE UNTIL BUZZ1627 CHECK THIS ONE |
|
|
|
|
|
#3 (permalink) |
|
Bronze Member
![]() Join Date: May 2006
Posts: 92
|
Before you follow his instructions we need to properly install HiJackThis.
* Click here to download HJTsetup.exe
|
|
|
|
|
|
#5 (permalink) |
|
Bronze Member
![]() Join Date: May 2006
Posts: 92
|
C:\DOCUME~1\PAUL~1.PAU\LOCALS~1\Temp\Rar$EX00.078\ HijackThis.exe
That is a temperary folder. If he cleans his temp folder it will delete all backups and he will not be able to restore anything he deletes. It will also delete HiJackThis. C:\Program Files\winupdate\winupdate.exe You can't just remove it. Their are special programs designed to remove this. |
|
|
|
|
|
#6 (permalink) |
|
New Member
![]() Join Date: May 2006
Posts: 8
|
Here's my new log and downloading Hijack This once again.
Logfile of HijackThis v1.99.1 Scan saved at 10:14:01 PM, on 5/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O20 - Winlogon Notify: IME - C:\WINDOWS\system32\fp8q03l5e.dll O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe |
|
|
|
|
|
#7 (permalink) |
|
New Member
![]() Join Date: May 2006
Posts: 8
|
The previous post was after redownloading hijack this.
I had already fixed the one below as of ComputerGenius' advice. O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto - Nasty VERY NASTY. THAT IS THE RESULT OF THE RADO VIRUS AND MUST BE REMOVED |
|
|
|
|
|
#9 (permalink) |
|
New Member
![]() Join Date: May 2006
Posts: 8
|
okay. Thanks alot for the help. Doesn't seem to have major problems, but the internet page that I'm on changes to an ad every couple of minutes. I have to press the "back" button the get to the page that I was on. What can I do to fix it?
|
|
|
|
|
|
#10 (permalink) |
|
Bronze Member
![]() Join Date: May 2006
Posts: 92
|
1. Please download Ewido Anti-Malware
ewido manual updates 2. Please download Brute Force Uninstaller to your desktop.
Save it in the same folder you made earlier (c:\BFU). Do not do anything with these yet! Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping F8 until a menu appears. Highlight Safe Mode and hit enter. 4. Once in Safe Mode, Open Ewido:
5. Then, please go to Start > My Computer and navigate to the C:\BFU folder.
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|