TechSpot

HijackThis log file

By rawad
Nov 25, 2006
  1. Can anyone please decode the log of HJT, I think I have spywars, the log file is attached.
    Thx
     

    Attached Files:

  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    Please rename HijackThis.exe to HijackThis1991.exe rescan and post a fresh HJT log. This is because some malware can hide from HijackThis.exe.

    Regards Howard :wave: :wave:

    This thread is for the use of rawad only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. rawad

    rawad TS Rookie Topic Starter

    thx for ur reply, here is the new file
    Rawad

    hello again,
    I just did a scan by spyware dr ( i have avast on my PC), and since i am not registered, i can only see the infected files but i cant do any action, I copied the information in a txt file. Maybe it will be of some help, and I anyone ca help me understand and delete the bad infecion, i will be gratefull, i have 58 infected files.
    cheers
     
  4. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Your HJT log is clean.

    However, I`m not sure what to make of the Spyware dr logfile.

    Just to be on the safe side do the following.

    Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

    Post fresh HJT and AVG Antispyware logs as attachments into this thread, only after doing the above.


    Regards Howard :)


    This thread is for the use of rawad only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  5. rawad

    rawad TS Rookie Topic Starter

    Thanks

    thank you for taking the time for decoding my HJT log file.
    Do you think that spyware Dr. and avast are complementary or it is too much on a same PC?
    Thx again
     
  6. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    The thing is, Spyware dr`s free trial isn`t actually any good is it? What`s the point in having a programme that says you`re infected, but won`t do anything about it?

    If I were you, I`d uninstall Spyware dr, then follow the instructions in the link I gave you. All the tools and applications in that link are free and work very well.

    Regards Howard :)

    This thread is for the use of rawad only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  7. rawad

    rawad TS Rookie Topic Starter

    Re

    Thanks again,
    I uninstalled spyware Dr and I am currently doing all the cleaning and anti-... that you wrote in the other threa.
    Cheers
     
  8. rawad

    rawad TS Rookie Topic Starter

    using the 4 tools in the Viruses/Spyware/Malware, preliminary removal instructions.

    Hello again,

    after downloading and using the first Tool of the 4 u mention (/SmitfraudFix), i didn't download the others yet, but /SmitfraudFix asks me to reboot in a safe mode after using the search and creat report in /SmitfraudFix. Do i reboot in safe mode now, or i use the other 3 tools before then reboot in safe mode and continue ?
    are those 4 tools really necessary for my pc, I have avast since i bought it, and i rarely download application, what do you think after seeing my HJT log ?
    thanks
     
  9. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    You should follow the instructions for using each tool exactly. Each tool should be used in the order in which I have put them.

    You might as well follow all the instructions, then nothing gets left out.

    Like I said previously, your HJT log is clean. However, according to Spyware dr, your system is not clean, hence the instructions, just to be on the safe side.

    Regards Howard :)

    This thread is for the use of rawad only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  10. rawad

    rawad TS Rookie Topic Starter

    Followed the instruction (but forgot something)

    Dear Howard,

    I followed the instruction and downloaded all the tools needed and did the scanning in the order mentionned.
    It took avast 6 hours but found 40 infected files, and 2 hours for the AVG Antispyware, anyways, it took all day long. but like an ***** I forgot before going to safe mode to uncheck the "hide extesions foir known files" and "hide protected OS sys files" I just unchecked the "do not show hidden files -> show hidden files". I wil attach the HJT log file and the AVG Antispyware lof file. If you think I should redo everything with the unchecking that i forgot, plz tell me, i will do it asap.
    For now, I hope everything is ok with the logs.
    Finally, I want to ask you if you know why Avast wont work for a minute or so (it has a red button)and i cant connect to my ADSL provider before avast runs (by itself) if I start my Pc with the ethernet cable plugged (but if I use the USB instead, there is no problem) and there is no problem if i plug the Ethernet cable after windows starts. (so i have to remove the cable everytime i turn off my pc).
    Thanks for ur help.
     
  11. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Your HJT log is clean as a whistle.

    However, it appears you`re not running any firewall software. I suggest you get some asap. Either the free Zonealarm or Kerio firewall programmes are very good.

    It also appears, you still have a Symantc/Norton service running in the background. This might be the source of your Avast problems, so let`s get rid of it.

    Click start/run and type services.msc into the run box and press the enter key.

    When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    SymWMI Service

    Close the services window.

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

    Click on the processes tab and end process for(if there).

    SymWSC.exe

    Close task manager.


    Run HJT with no other programmes open. Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    Click on the fix checked button.

    Close HJT.

    Locate and delete the following bold files and/or directories(if there).

    C:\Program Files\Common Files\Symantec Shared<Delete the entire folder.

    Reboot your computer.

    Let me know how your system is running.

    Regards Howard :)

    This thread is for the use of rawad only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  12. rawad

    rawad TS Rookie Topic Starter

    I started this whole thing because I suspect that someone is hacking my internet to use my telephone, I have ADSL, and i keep on getting "Audiotel" phone calls in my bills that I didn; t make.
    I did what you told me, I found the folder C:\Program Files\Common Files\Symantec Shared and I shift deleted it, but I didn't found it in HJt.
    Someone advised me to install spy sweeper, and this is the log file ( it found 5 files that I quarantied them). Do I keep the software (trial 30 days), I installed it with the anti-virus option.
    the firewall is always telling me, on reboot, that sonic update manager is trying to access internet, what do I do ?
    My Avast problem is still the same!!! (maybe because of spy sweeper ?!!)
    I have in my Add remove programs "Norton WMI update"is this the same as Norton anti virus
    I dont have much space in my HD, what do I keep in all that, in the softwars that i downloaded before (the 4 tools and others) to have a good privacy and a good security. Finally, I hate firewalls, they always annoy by stopping and asking for access, and I dont know, always, what I should allow, I used to have one and I removed it. Do you think it s really important?
    Thx for helping decoding all this, I think this is all, I hipe i am clear in what i am saying.
    N.B: Do you think that I have to do the same procedure as today with uncheck the "hide extesions for known files" and "hide protected OS sys files" ? Is this very important ?
     
  13. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Uninstall Norton WMI update from add remove programmes.

    Delete all files that you quarantined in spysweeper.

    Uninstall Spysweeper and disable the AVG Antispyware guard.

    I don`t know what`s causing your Avast problems, but if after doing the above you`re still having the problem, then maybe you should uninstall Avast and use AVG free antivirus instead.

    It`s very important that you use a firewall, as this prevents people from hacking into your computer.

    Your HJT log is still clean.

    Regards Howard :)

    This thread is for the use of rawad only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...