Welcome! Register for a free account (or login) > How does it work?
|
|


Oct 14 2008, 06:03 PM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 5 Joined: 12-October 08 From: Nevada Member No.: 81,936 Operating System: XP |
Please help:
I am having trouble trying to remove some spy/malware. Initially it would hijack my browser to CoolWebSearch as well as others and it would change IE settings. I worked around this until I noticed excessive activity on my modem and router. Ad-Aware found some infected items but others reappeared after rebooting. I found I could not update definition from A-Ad-Aware or AVG. I unplugged the computers network cable at the router. When I attempt to boot in safe mode I get the blue screen with the message like: must perform physical memory dump. In MSCONFIG I disabled all unnecessary startup items – which were most of them. Found suspicious startup items: msmsgs, svchost, Utility Tray, Reboot. The only way I was able to install / run ERANT and HijackThis were with all startup services disabled. Logfiles are as follows: Logfile of HijackThis v1.99.1 Scan saved at 4:52:38 PM, on 10/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Hijackthis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.3.1_18) - http://javadl-esd.sun.com/update/1.3.1/jinstall-13-win32.cab O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://content.embarq.synacor.com/gigantes...anner/fscax.cab Brian Heitzinger EDIT removed email address |
|
|
|
laubri [Resolved] HijackThis logfile Oct 14 2008, 06:03 PM
LDTate You need to enable everything you disabled in Msco... Oct 14 2008, 06:25 PM
laubri 1. Enabled everything in Msconfig
2. Reran ERUNT a... Oct 15 2008, 11:56 PM
LDTate Do you have an anti-virus program?
Are you postin... Oct 16 2008, 05:57 AM
laubri I do not have an anti-virus program installed. (I ... Oct 16 2008, 06:25 PM
LDTate HijackThis v1.99.1 version is outdated.
Lets get t... Oct 16 2008, 06:41 PM
laubri I have resolved my issues with the missing items i... Oct 16 2008, 11:21 PM
LDTate Here's my usual all clean post
Make your Int... Oct 19 2008, 01:21 PM
LDTate Since this issue appears to be resolved ... this T... Oct 22 2008, 10:18 AM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
5 | tomryan222 | 71 | Yesterday, 04:52 PM Last post by: oldman960 |
|||
![]() |
15 | tiancheng | 479 | Yesterday, 06:46 AM Last post by: Blade81 |
|||
![]() |
15 | Angel2121 | 495 | Yesterday, 05:46 AM Last post by: jpshortstuff |
|||
![]() |
16 | jester421 | 359 | 20th March 2010 - 09:18 AM Last post by: CatByte |
|||
|
Time is now: 22nd March 2010 - 05:03 AM |