TechSpot

Attacked by many virus and here is my HijackThis log file

By scpoh123
Jun 7, 2007
  1. Hi,
    Recently, my NAV keep prompting me on virus detection and quarantine.
    Did a scan, it says no virus found. It made my IE6 almost unusable.
    Here is my HijackThis log file and hopefully someone can give some advice.
    Thanks.
     
  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    Your system is infected with malware.

    Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

    If after reading the above, you wish to clean your system, do the following.

    Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

    Post fresh HJT, AVG Antispyware and Combofix logs as attachments into this thread, only after doing the above.

    Also, let me know the results of the AVG Antirootkit scan.

    Regards Howard :wave: :wave:

    This thread is for the use of scpoh123 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. scpoh123

    scpoh123 TS Rookie Topic Starter

    Here are my logs after going thru the procedures

    Howard,
    Thanks for your response.
    Here are my logs. Although my comp seem to be more stable, somehow I still find something strange. When refreshly launch a IE, it is likely to tell me there is some problem and it will be closed.
    Attach are my logs.
    The anti root kit never report anything unusual.
    Hope to hear from you soon.
     
  4. momok

    momok TS Rookie Posts: 2,265

    Hi,

    Your system is definitely still quite horribly infected. It is the same infection, but apparently it has been spawning several different files all over your windows directory. (you can take a look at my attachment file to see how many related files to be fixed)

    I noticed that your AVG log displays 'No Action Taken' for all the files detected.
    I suggest you run AVG again and quarantine the files. Pictorial instructions HERE. Do this after the following instructions.

    You may wish to copy and paste these instructions on notepad for easier reference later.

    Download the attached "Combofix-Do.txt" (from my attachment) and save it to the same folder as Combofix.

    Boot into safe mode under your normal user name. See how HERE

    Next turn on "Show all files and folders, including hidden and system". See how HERE

    Go to start > run and type services.msc. Press the enter key.
    Search for the following services. Double click to select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    Windows InstallService

    After that, run HijackThis and fix the following entries, if found (do this by placing a tick in the check boxes beside these entries and clicking "Fix checked"):

    O2 - BHO: Thunder Browser Helper - {86578351-986B-4CF0-9DCC-638E44F50D25} - C:\WINDOWS\iecom.dll

    O2 - BHO: (no name) - {C74CDF30-68C2-49B4-9918-EBD66B8D9FBF} - C:\WINDOWS\system32\hnpqbcicohkfy.dll

    O2 - BHO: Flash Assistant - {E29F0B13-0D84-45aa-81EC-CC629BC07566} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\Flasher0.dll (file missing)

    O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?

    O23 - Service: Windows InstallService (Removable Storage) - Unknown owner - C:\WINDOWS\System32\serveter.exe

    Close HJT.

    Please follow these instructions carefully.

    Drag the attachment file "Combofix-Do.txt" you downloaded earlier over on to Combofix.exe and release.

    This will start Combofix and it will thus run the instructions within my file. Let Combofix run normally and do its job.

    Run your AVG Antispyware scan here. Remember to quarantine all infections before saving the log.

    Reboot into normal mode and rehide your protected OS files.

    Thereafter, please post fresh HJT, ComboFix and AVG Antispyware logs from normal mode as attachments into this thread.


    Regards,
    Your friendly momok =)

    This thread is for the use of scpoh123 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  5. scpoh123

    scpoh123 TS Rookie Topic Starter

    Hi Momok, Howard and the Techspot team,
    Thanks for all the help and fast response.
    My comp seem to be back to normal.
    I will defenitely introduce friends to seek help from this site. Great job.
    Attach are my logs.
    Do let me know if there are any other thing I should do although my comp seem stable now.
     
  6. momok

    momok TS Rookie Posts: 2,265

    Hi,

    It appears all those files are still there. I'd like to clarify; have you followed my previous instructions properly? You have to download my attachment into your system. Then click-drag it over to ComboFix.exe and release. Is that the latest ComboFix.txt file that you have? If not, please attach the latest one you have in your next reply.

    That said, please have HijackThis fix this entry:
    O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?

    Post a fresh HijackThis and ComboFix log in your next reply. Thanks.


    Regards,
    Your friendly momok =)

    This thread is for the use of scpoh123 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...