This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PLEASE HELP - My Hijack This log

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The log: # version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=2932 (20080309) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.064 (20070717) # EOSSerial=f322c0a695e8fe47bfb4277bd140d773 # end=finished # remove_checked=false # unwanted_checked=true # utc_time=2008-03-09 03:39:36 # local_time=2008-03-08 10:39:36 (-0500, Eastern Standard Time) # country="United States" # osver=5.1.2600 NT Service Pack 2 # scanned=428905 # found=14 # scan_time=9382 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip multiple infiltrations C2A960473767487931CDC5283C8075FA C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/autorun.exe Win32/TrojanDownloader.FakeAlert.G trojan 00000000000000000000000000000000 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/DrvCD.dll a variant of Win32/TrojanClicker.Agent.NCU trojan 00000000000000000000000000000000 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/findfast.exe Win32/TrojanDownloader.FakeAlert.G trojan 00000000000000000000000000000000 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/printer.exe Win32/TrojanDownloader.FakeAlert.G trojan 00000000000000000000000000000000 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/shell.exe Win32/TrojanDownloader.FakeAlert.G trojan 00000000000000000000000000000000 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/spoolvs.exe Win32/TrojanDownloader.FakeAlert.G trojan 00000000000000000000000000000000 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/tmp46366046.exe Win32/TrojanDropper.Agent.EYA trojan 00000000000000000000000000000000 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/tmp46368187.exe Win32/TrojanDropper.Agent.EYA trojan 00000000000000000000000000000000 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/tmp46374406.exe Win32/TrojanDropper.Agent.EYA trojan 00000000000000000000000000000000 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/ucleaner_setup.exe Win32/Adware.UltimateCleaner application 00000000000000000000000000000000 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/udefender_setup.exe Win32/Adware.UltimateDefender application 00000000000000000000000000000000 C:\Documents and Settings\Eri\Desktop\SDFix\SDFix\backups\backups.zip »ZIP »backups/wowfx.dll Win32/TrojanDownloader.FakeAlert.G trojan 00000000000000000000000000000000 C:\Program Files\Trend Micro\HijackThis\backups\backup-20080305-211542-584.dll Win32/Adware.HotBar application B80762BC677605CEC9C17A19A61664D2
Your log looks clean. If you have no more malware-related problems that you are aware of, just give me the OK and we can start the final but essential cleanup procedures and recommendations.

Trevuren
Congratulations, your logs look CLEAN

There are a few things you must do once you system is completely clean:

Time for some housekeeping
  • First, DELETE the following folder and all its content: C:\SDFix.
  • Next, click START then RUN
  • Now type Combofix /u in the runbox and click OK


  • [external image: Posted Image]



The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.


Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Use and Update an Anti-Virus Software - I can not overemphasize the need for you to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. FIREWALL
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here

Do not install more than one firewall program because they will conflict with each other

4. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

5. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

6. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

7. Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware

8. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
Thank you so much :D :notworthy: One question though, should i download the spware and virus protections you gave me? Only because i have McAfee and it's both a virus and spyware protection.
My pleasure. There is no problem in having more than one antimalware program on your machine at the same time. There is a big problem if you activate their "resident" shields. Use McAfee's as resident protection and run the others evry now and then as theu all pick up scumware that the others do not. Safe Surfing, Trevuren
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI