TechSpot

Need a little help please hjt enclosed

By stack3136
Jun 18, 2007
  1. Been having problems with internet explorer just comes up with page cannot be displayed.If i log onto another account it seems to work fine.Got something going on and need some help please here is my hijack this log.

    Any help would be great thanks
     
  2. momok

    momok TS Rookie Posts: 2,265

    Hi,

    Note: Please do not copy and paste your logs. Instead post the .log or .txt files as attachments to the thread.

    Important: Please read this thread HERE before you decide whether to clean or reformat your system.

    Should you decide to clean your computer, have HijackThis fix these entries:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:2323
    O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Advanced System Optimizer\iehelper.dll
    O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
    Close HJT.

    Next, please go ahead to Viruses/Spyware/Malware, preliminary removal instructions and follow the steps given. Do follow all the instructions exactly. They will provide logs for analysis of your system so I will know how to instruct you to proceed.

    Thereafter, please post fresh HijackThis, AVG Antispyware and Combofix logs as attachments into this thread. Do not copy and paste your logs if not it will be ignored and/or removed.

    Also, please let me know the results of the AVG Antirootkit scan

    Regards,
    Your friendly momok =)

    This thread is for the use of stack3136 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. stack3136

    stack3136 TS Rookie Topic Starter

    thanks

    Sorry about pasting logs won't happen again.thanks for the help.
     
  4. momok

    momok TS Rookie Posts: 2,265

    Hi,

    Please follow the given instructions and post the required logs as attachments.

    Regards,
    Your friendly momok =)

    This thread is for the use of stack3136 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  5. stack3136

    stack3136 TS Rookie Topic Starter

    here is my log files for you to look at again thanks.My antispyware log did not come out.Did have some infection that did get cleaned on the online scan.My internet explorer is now working thanks.
     
  6. momok

    momok TS Rookie Posts: 2,265

    Hi,

    I would not recommend SpywareBeGone to use on your system as it has had a dubious repute. There are several better choices out there anyway. Let me know if you wish to remove it completely from your system and can't.

    Download the attached "Combofix-Do.txt" (from my attachment) and save it to the same folder as Combofix.
    Drag the Combofix-Do.txt that you downloaded earlier over on to Combofix.exe and release.

    This will ask Combofix to execute the instructions within my file. Let Combofix run normally and do its job. Attach the resultant log in your reply.

    Thereafter, please post fresh stack3136 HJT and AVG Antispyware logs from normal mode and the ComboFix log from the safe mode instructions as attachments into this thread.
     
  7. stack3136

    stack3136 TS Rookie Topic Starter

    I did uninstall spywarebegone seems like no problem.i have new logs for you i am not sure how to get log on avg anti spyware.Had it do it scan and found trojan.delf.li and adware newdotnet stuff.here is the other logs anyway.Does the combo fix make its own folder where the log is in. Hopefully have right log.will not let me upload hjt log says i already have it in this thread.
     
  8. momok

    momok TS Rookie Posts: 2,265

    Hi,

    The log for AVG AS can be found in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports.

    Please navigate to this folder and delete it:
    C:\spywarebegone

    Then either rename your HijackThis logs or remove the previous attachments so that you can post the fresh logs here.


    Regards,
    Your friendly momok =)

    This thread is for the use of stack3136 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  9. stack3136

    stack3136 TS Rookie Topic Starter

    I did a rescan with avg anti spyware made sure i checked to save a report and it did not.here is my hjt log.
     
  10. momok

    momok TS Rookie Posts: 2,265

    Hi,

    You may wish to copy and paste these instructions on notepad for easier reference later.

    Boot into safe mode under your normal user name. See how HERE

    Next turn on "Show all files and folders, including hidden and system". See how HERE

    Go to start > run and type services.msc. Press the enter key.
    Search for the following services. Double click to select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    Spyware Begone

    Go to start > Control Panel > Add and Remove Programs.
    Remove anything related to the following:

    SpywareBegone

    Open your task manager by pressing holding ctrl, alt and pressing del. Alternatively, use ctrl + shift + esc. Go to the processes tab, and end the following processes, if found:

    SpywareBeGone.exe

    After that, run HijackThis and fix the following entries, if found (do this by placing a tick in the check boxes beside these entries and clicking "Fix checked"):

    O4 - HKCU\..\Run: [Spyware Begone] "C:\spywarebegone\SpywareBeGone.exe" -FastScan

    Close HJT.


    Navigate in Windows Explorer and delete the following files and folders in bold.

    C:\spywarebegone\

    I'd like you to try running a full AVG system scan again now. Remember to quarantine the files. Pictorial instructions HERE.

    Reboot into normal mode and rehide your protected OS files.

    Thereafter, please post fresh HJT, ComboFix and AVG Antispyware logs as attachments into this thread. I need the HJT and ComboFix logs from normal mode please.


    Regards,
    Your friendly momok =)

    This thread is for the use of stack3136 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  11. stack3136

    stack3136 TS Rookie Topic Starter

    Okay hi again i dont know what im doing wrong with avg virus scan.Did everything in that tutorial and still won't save log i even quarentine files and there not in quarentine.but here are the other logs.
     
  12. momok

    momok TS Rookie Posts: 2,265

    Hi,

    Please note that the program log I need to see is from AVG Anti-Spyware. It is not the Antivirus software from the same parent company, Grisoft. Please check that you got the right software. The folder can be located in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports

    Download the attached "Combofix-Do.txt" (from my attachment) and save it to the same folder as Combofix.
    Drag the Combofix-Do.txt that you downloaded earlier over on to Combofix.exe and release.

    This will ask Combofix to execute the instructions within my file. Let Combofix run normally and do its job. Attach the resultant log in your reply.

    Thereafter, please post fresh HJT, ComboFix and AVG Antispyware logs from normal mode as attachments into this thread.


    Regards,
    Your friendly momok =)

    This thread is for the use of stack3136 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  13. stack3136

    stack3136 TS Rookie Topic Starter

    Hi momok took a couple days off.I do have the right software avg anti-spyware.I followed guide even though pretty self explaintory.I uninstalled it an reinstalled and it will still doesn't save a log and now there is no report folder in the anti spyware folder.I kinda tossed my hands in the air i don't know what to do I will go ahead and leave these other logs.I really thank you for all you're help.
     
  14. momok

    momok TS Rookie Posts: 2,265

    Hi,

    That is quite weird indeed. I have never come across such a problem. Perhaps the installation was faulty. I would suggest you try downloading a new setup file to install. Your logs do look clean though.

    Delete all files in AVG Antispyware Quarantine folder. (located in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine)

    You may also delete the C:\VundoFix Backups folder and its contents.

    Turn off system restore (XP/ME only). Learn how to do that HERE.
    This will remove all the remaining nasties from your old restore points.

    After that turn system restore back on.
    This would have created a new safe and clean restore point for your system.

    Often times, an infection can occur again not due to the incompetence of programs, but because of user habits.
    May I recommend you to read this article.
    This can help to prevent future infections.

    Should you have any further problems, please post in this thread.


    Regards,
    Your friendly momok =)

    This thread is for the use of stack3136 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  15. stack3136

    stack3136 TS Rookie Topic Starter

    Thanks

    Thanks Momok for the help.
     
  16. momok

    momok TS Rookie Posts: 2,265

    No problems, glad to be of help. =)
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...