something in my pc I think,hijack this log included.

cracker2

Member
The family desktop is having some problems.I never get on it much so I don't know whats all been downloaded on it.I ran avast(free ver) full scan,found & deleted 38 infected files with sucess.Got tdss killer to run,said no threats found.Tried to download malwarebytes and I get 2 different errors when trying.Hijack this worked.
Whatever is in the pc still is causing pages to load slow,& or it will redirect to a completly different site.Also when I go to select turn off compter,it takes 3-4 mins before it shows up the options.I will run a sfc /scannow soon,but if it has to be under admin to run I might be screwed on that for the moment.
 
Last edited:
Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.
  • Download this file here :

    Combofix

  • When the page loads click on the blue combofix download link next to the BleepingComputer Mirror.
  • Save the file to your windows desktop. The combofix icon will look like this when it has downloaded to your desktop.

    cf-icon.jpg
  • We are almost ready to start ComboFix, but before we do so, we need to take some preventative measures so that there are no conflicts with other programs when running ComboFix. At this point you should do the following:

  • Close all open Windows including this one.
  • Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix. Instructions on disabling these type of programs can be found here.
    Once these two steps have been completed, double-click on the ComboFix icon found on your desktop. Please note, that once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. In fact, when ComboFix is running, do not touch your computer at all. The scan could take a while, so please be patient.
  • Please click on I agree on the disclaimer window.
  • ComboFix will now install itself on to your computer. When it is done, a blue screen will appear as shown below.

    cf-preparing.jpg

  • ComboFix is now preparing to run. When it has finished ComboFix will automatically attempt to create a System Restore point so that if any problems occur while using the program you can restore back to your previous configuration. When ComboFix has finished creating the restore point, it will then backup your Windows Registry as shown in the image below.

    erunt.jpg

  • Once the Windows Registry has finished being backed up, ComboFix will attempt to detect if you have the Windows Recovery Console installed. If you already have it installed, you can skip to this section and continue reading. Otherwise you will see the following message as shown below:

    recovery-console-prompt.jpg

  • At the above message box, please click on the Yes button in order for ComboFix to continue. Please follow the steps and instructions given by ComboFix in order to finish the installation of the Recovery Console.
  • Please click on yes in the next window to continue scanning for malware.
  • ComboFix will now disconnect your computer from the Internet, so do not be surprised or concerned if you receive any warnings stating that you are no longer on the Internet. When ComboFix has finished it will automatically restore your Internet connection.
  • ComboFix will now start scanning your computer for known infections. This procedure can take some time, so please be patient.
  • While the program is scanning your computer, it will change your clock format, so do not be concerned when you see this happen. When ComboFix is finished it will restore your clock settings to their previous settings. You will also see the text in the ComboFix window being updated as it goes through the various stages of its scan. An example of this can be seen below.

    still-scanning-clockchanges.jpg

  • When ComboFix has finished running, you will see a screen stating that it is preparing the log report.
  • This can take a while, so please be patient. If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt.
  • When ComboFix has finished, it will automatically close the program and change your clock back to its original format. It will then display the log file automatically for you.
  • Now you just click on the edit menu and click on select all, then click on the edit menu again and click on copy. Then come to the forum in your reply and right click on your mouse and click on paste.


In your next reply please post:
  • The ComboFix log
  • A fresh HiJackThis log
  • An update on how your computer is running
 
Looks like you had remnants of the mpk keylogger. Now try running Malwarebytes and post its log. I'll finish going through the combofix log and give you the next step.

Also at this time, navigate to c:\qoobox and in that folder will be a file named add-remove programs.txt. Please open that file and then copy the contents and paste it back here.
 
Looks like you had remnants of the mpk keylogger. Now try running Malwarebytes and post its log. I'll finish going through the combofix log and give you the next step.

Also at this time, navigate to c:\qoobox and in that folder will be a file named add-remove programs.txt. Please open that file and then copy the contents and paste it back here.

Thanks johnb35!I really appreciate your help:good:!I will report back shortly
Edit:I am having trouble with malwarebytes still,A popup with a exclamation logo shows.vbAccelerator SGridII Control:Run-time error'0'.I click ok then,malwarebytes:Runtim error'372'.Failed to load control 'vbalGrid' from vbalsgrid6.ocx.Says it may be outdated.

add-remove programs.txt
Acrobat.com
Active@ DVD Eraser v 1.1
Adobe AIR
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Adobe Reader 9.4.5
Adobe Shockwave Player 11.5
Advanced SystemCare 4
America Online (Choose which version to remove)
AOL Connectivity Services
AOL Spyware Protection
AOL You've Got Pictures Screensaver
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
Athlon 64 Processor Driver
avast! Free Antivirus
BitTorrent
Bonjour
BufferChm
Business Contact Manager for Outlook 2007
Camfrog Video Chat 5.3
CCleaner
Destinations
DeviceFunctionQFolder
DeviceManagementQFolder
Digital Media Reader
DivX Setup
E.M. Youtube Video Download Tool 3.13
Eraser 6.0.7.1893
eSupportQFolder
Free Window Registry Repair
FrostWire 4.17.2
GameTap
Google Chrome
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB960043)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB942288-v3)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
HP Deskjet 5400 series
HP Imaging Device Functions 5.0
HP Print Diagnostic Utility
HP Software Update
HP Solution Center & Imaging Support Tools 5.0
HPDeskjet5400Series
HPProductAssistant
ImgBurn
IMVU Inc Toolbar
iolo Memory Mechanic
iTunes
J2SE Runtime Environment 5.0 Update 2
Java Auto Updater
Java(TM) 6 Update 23
Java(TM) 6 Update 7
Junk Mail filter update
League of Legends
LimeWire 5.5.10
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office Click-to-Run 2010
Microsoft Office Home and Business 2010 - English
Microsoft Office Small Business Connectivity Components
Microsoft Primary Interoperability Assemblies 2005
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox (3.6.8)
MSVCRT
MSXML 6.0 Parser
My BootDisk 3.02
My Lockbox 1.2 for Windows 2000/XP
MySpaceIM
Napster
Napster Burn Engine
Nero Burning ROM 10
Nero BurnRights
Nero BurnRights 10
Nero Control Center 10
Nero Core Components 10
Nero OEM
NVIDIA Control Panel 275.33
NVIDIA Drivers
NVIDIA Graphics Driver 275.33
NVIDIA Install Application
NVIDIA nView 135.85
NVIDIA nView Desktop Manager
NVIDIA Update 1.3.5
NVIDIA Update Components
OpenOffice.org Installer 1.0
Pando Media Booster
Philips PC Camera
Pure Networks Port Magic
QuickTime
Realtek AC'97 Audio
Recovery Software Suite Gateway
Revo Uninstaller Pro 2.4.1
Search Settings v1.2.3
Security Task Manager 1.7h
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Segoe UI
Shape Collage
SoftV92 Data Fax Modem with SmartCP
SolutionCenter
Sonic Encoders
Spelling Dictionaries Support For Adobe Reader 9
Status
System Requirements Lab
TrayApp
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB953356)
Update Rollup 2 for Windows XP Media Center Edition 2005
VC80CRTRedist - 8.0.50727.4053
VDownloader 2.7.322
Viewpoint Media Player
WebFldrs XP
WebReg
Windows Backup Utility
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Media Center Edition 2005 KB925766
Windows XP Service Pack 3
WinRAR archiver
Y!Supra v1.0.0.60
Yahoo! Messenger
Yahoo! Software Update

I think I may have found a solution for malwarebytes error.Ill give you the links im looking at.
It installs normaly,but the errors popup when I try to run it.
http://www.ocxdump.com/download-ocx-files_new.php/ocxfiles/V/vbalsgrid6.ocx/2.00.00408/download.html
http://forums.malwarebytes.org/index.php?showtopic=6207
I downloaded rootrepeal in #4,from last post in the forum of mwb and following the instructions.
It just showed 1 .sys file. hiberfil.sys Status:Locked to the windows API! .I think im alright their.
 
Last edited:
Please uninstall the following entries in add/remove programs.

Ask Toolbar
Free Window Registry Repair
J2SE Runtime Environment 5.0 Update 2
Java Auto Updater
Java(TM) 6 Update 23
Java(TM) 6 Update 7
Search Settings v1.2.3
Viewpoint Media Player
WebFldrs XP
WebReg

You should also uninstall the following p2p software as this is most likely what got you infected in the first place.

BitTorrent
FrostWire 4.17.2
LimeWire 5.5.10

After uninstalling the following programs download the latest version of Java here.

http://www.java.com/en/download/index.jsp

I noticed you have Ccleaner installed. Please run it and then try installing malwarebytes again.
 
I have got rid of All but the ask toolbar.I did everything I know to delete it.Doesn't show under C:programs.But still showsup in the uninstallers.If I try delete entry,error.Said something like cannot delete MUI I believe.When I run uninstall,it repeats "please close all browsers" when obviously their all closed.Did some searching and it actualy seems to be a common problem,didn't find any solution though.
I updated java.Still can't install malwarebytes,same set of errors like I posted earlier.Is it possible to run safe w/networking and trying it that way?
 
Last edited:
Back
Top