Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > HijackThis Log Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

HijackThis Log Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Reply
 
Thread Tools
Old 11-22-2004, 04:28 AM   #21 (permalink)
Knower of all that is MS
 
CTSNKY's Avatar
 
Join Date: Aug 2004
Posts: 10,755
OS: (multiple machines) 95, 98, 2K & XP Home & Pro


We'll get the respect after running the table in the SEC again this year. We kinda prefer being ranked a bit lower until March. Puts the pressure on Kansas or UNC, etc.........you already see what id does to some of them (UNC/AZ losses).

Here we go......

Boot into Safe Mode.

Run SD again in the same fashion.

For each of these entries, highlight each, one at a time, and click the Delete button:

`[rename]
`NUL=C:\WINDOWS\wupdsnff.exe
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\4c71e87.DLL
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\CORECOMP.INI
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\CTL3D32.DLL
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\DLGIMAGE.BMP
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\ReadMe.txt
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\Register.log
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\SETUP.INI
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\setup.ins
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\UNINST.EXE
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\_INSIS30.INZ
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\_ISREG32.DLL
`NUL=C:\WINDOWS\TEMP\_ISTMP0.DIR\_SETUP.LIB
`NUL=C:\WINDOWS\TEMP\_INS0432._MP
`NUL=C:\WINDOWS\TEMP\_INZ0432._MP
`NUL=C:\WINDOWS\TEMP\_WUTL95.DLL
======
*C:\mssys.com
*C:\WINDOWS\mssys.com


Then, delete:

C:\WINDOWS\wupdsnff.exe
C:\WINDOWS\TEMP\ <<<Entire contents of folder, not folder itself.
C:\mssys.com
C:\WINDOWS\mssys.com


Reboot and report on your machine's condition.
__________________


GO BIG BLUE!!
CTSNKY is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 11-22-2004, 09:52 PM   #22 (permalink)
Registered User
 
Join Date: Oct 2004
Posts: 13
OS: windows XP


uh oh

I rebooted into same mode-SD-config-check all-uncheck Nt services and n kernel and it would not let me delete any of them. what now? I could see them but not delete any of them .got an error n53 message.

Help
Lauren29 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 11-23-2004, 02:29 AM   #23 (permalink)
Knower of all that is MS
 
CTSNKY's Avatar
 
Join Date: Aug 2004
Posts: 10,755
OS: (multiple machines) 95, 98, 2K & XP Home & Pro


Try skipping the SD part and concentrate on deleting those files....Safe or Normal Mode.
__________________


GO BIG BLUE!!
CTSNKY is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-02-2004, 04:10 PM   #24 (permalink)
Registered User
 
Join Date: Oct 2004
Posts: 13
OS: windows XP


thanks wildcat

Ive saved all of my pertinent files to CD( pictures, spreadsheets word documents etc). This is my home computer and Im tired of struggling with it. It is so slow over the last couple of weeks. It is less than a year old and has plenty of power. Something is running in the background causing all sorts of problems If i do a system restore will that eliminate the problems. then I can bring it back up to speed. What do you think? Ill spend less time reloading my software than fighting these hijacker, trojans etc. although Im sure they will be back at some point. Also any recommendations on security to keep from having the hijacker problems? you guys do great work.

thanks

Lauren
Lauren29 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-03-2004, 10:26 PM   #25 (permalink)
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
 
MicroBell's Avatar
 
Join Date: Sep 2004
Location: Carmichaels, PA-USA
Posts: 6,954
OS: Windows XP-Pro SP2


Send a message via ICQ to MicroBell Send a message via MSN to MicroBell
Hi Lauren29:

I'm not sure system restore would help as we dont know how long the infection has been in the system. We are working on a process to remove this hijack..and it's a bit complicated. To protect yourself Please read through the spyware prevention section on how to protect yourself from spyware/adware Here Use the recommend methods and programs!

If you want to try and FIX this hijack following the instructions below. If not I would recommend a reinstall of the OS. The choice is yours....so read through the first step of the fix and then decide.

For the Fix...

You will need some programs for the removal process so I will group them for you to download before the fix.

Programs Needed::

Kill2Me http://www.hijackthislogs.com/dl/kill2me.zip
PV http://www.hijackthislogs.com/dl/pv.zip
VX2Finder(126) http://www.hijackthislogs.com/dl/VX2Finder(126).exe
Hoster http://members.aol.com/toadbee/hoster.zip
CleanUp http://cleanup.stevengould.org/
KillBox http://www.greyknight17.com/spy/killbox.zip


==================================================

Process

1. Download Kill2Me from here and run
http://www.hijackthislogs.com/dl/kill2me.zip

2. Download this version of pv and unzip it to your desktop. (**Note** It MUST be on the desktop!) It will create it's own folder.

http://www.hijackthislogs.com/dl/pv.zip

Then proceed below..

1. Double click the runme.bat file.
2. Select option 3 and hit enter. Save the log that was generated.
3. Then select option 5. Save the log that was generated.

Copy and paste each of them into the next your next post.

3. Copy and paste the text below inside the quote box to notepad.
Save it to your desktop as type "all files" and name it notify.bat.


Quote:
regedit /e notify.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify"
notify.txt
Then doublclick to run it. It will generate a text file named notify.txt. Copy and paste the contents into your next reply.

4. Download the latest vx2 finder here

http://www.hijackthislogs.com/dl/VX2Finder(126).exe

Click the "Find Vx2.Betterinternet" button. Click the Make Log button a post that log in your next reply.

So I need ALL 4 of these logs from the infected PC. Please note that during this removal process this PC can NOT be turned off or REBOOTED. Doing so...makes all 3 logs useless as the rootkits DLL (the baddie) file name will change. So if you have to wait a day to proceed with the next step in the fix..just make sure the PC is not rebooted.

If you must reboot or turn the PC off you will need to start over in the process section and do it again. The logs and the fix must be done at the same time without the PC being rebooted.
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!





Spyware/Adware Removal Tools
Hijackthis
Ad-aware SE
Spybot Search&Destroy
SpywareBlaster
CWShredder
MicroBell is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-04-2004, 01:59 PM   #26 (permalink)
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
 
MicroBell's Avatar
 
Join Date: Sep 2004
Location: Carmichaels, PA-USA
Posts: 6,954
OS: Windows XP-Pro SP2


Send a message via ICQ to MicroBell Send a message via MSN to MicroBell
EDIT:::

I also need you to list the files located in the Downloaded Programs File Folder. It might be located at....

C:\WINDOWS\Downloaded Program Files\ as well as here

C:\Program Files\Internet Explorer\ <== You may not have a download folder in here...but check. We are looking for any randomly named files
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!





Spyware/Adware Removal Tools
Hijackthis
Ad-aware SE
Spybot Search&Destroy
SpywareBlaster
CWShredder
MicroBell is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 01:06 PM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82