TechSpot

Would appreciate advice

By ToniB
Aug 7, 2007
  1. HJLog -- Would appreciate advice

    Hi,

    My hard drive had a mechanical problem so Iam starting mostly from scratch with relatively old software from the box that needed all updates from the past 3 years or so. Reinstalled my virus protector but perhaps a few minutes too late as I've already experienced some problems and a few files that couldn't be deleted (winpop, retadpu72, etc. ) that were seemingly removed here along the way.

    Followed all directions as indicated in the posting Viruses/Spyware/Malware, preliminary removal instructions. Other requested logs are attached here but, for some reason, I can't upload my hijack this log (tried saved as a log file, text file, and renamed log file -- none will work.) Get message that upload has failed. Should I cut and paste or ??? Just after it saves, it tries to open an Editor window which says something like "this file can't be reached".

    For some reason, though, the virus protector has continued to pick up the hijackThis -- get following messages... I presume that this should can be added to files to ignore in the virus protector?

    "Beim Öffnen der Datei "C:\Programme\HiJackThis\hijackthis.log" wurde der Virus "Exploit.HTML.Mht" von der Engine "KAV" entdeckt. Datei gesäubert: nein. Datei gelöscht: nein. Quarantäne: nein.
    Beim Öffnen der Datei "C:\Programme\HiJackThis\hijackthis7-08-2007.log" wurde der Virus "Exploit.HTML.Mht" von der Engine "KAV" entdeckt. Datei gesäubert: nein. Datei gelöscht: nein. Quarantäne: nein."

    Please let me know if you need help with the German. (am running Windows in German version, installed spyware, adaware detectors in English).

    I've uploaded the AVG Antispyware and Combofix logs, the Antirootkit scan came back clean.

    Thanks for any help you might provide!

    Toni
     

    Attached Files:

  2. momok

    momok TS Rookie Posts: 2,265

    Hi,

    You have not posted your HijackThis log or the results of the AVG antirootkit scan. Please do so in your next reply.

    Download the attached "CFScript.txt" (from my attachment) and save it to the same folder as Combofix.

    Referring to the image below, drag the CFScript.txt that you downloaded earlier over on to Combofix.exe and release.

    [​IMG]

    This will ask Combofix to execute the instructions within my file. Let Combofix run normally and do its job. Attach the resultant log in your reply.

    Thereafter, please post fresh HJT and AVG Antispyware logs from normal mode and the ComboFix log from the instructions earlier as attachments into this thread.


    Regards,
    Your friendly momok =)

    This thread is for the use of ToniB only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. ToniB

    ToniB TS Rookie Topic Starter

    Thanks, will do

    Thanks Momok!

    Will get to that asap, but the only reason I didn't post the HJL was that I couldn't upload it. If it (yet again) won't upload, can I just post (cut and paste) it?

    Rootkit just came back with a message that said "congratulations, all was clean" or something similar. Tried to cut and paste but it wouldn't let me (one of those standardized pop-up windows).

    Anything else I should be doing there differently?
     
  4. momok

    momok TS Rookie Posts: 2,265

    Hi,

    Do try and upload the HJT log again in your next reply. If it still doesn't work, then copy and paste your log and I'll attach it for you. It's a good thing that Rootkit shows an all clear. Do carry on with the rest of my instructions.


    Regards,
    Your friendly momok =)

    This thread is for the use of ToniB only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  5. ToniB

    ToniB TS Rookie Topic Starter

    logs finally...

    Hi Momok,

    sorry for the delay -- I was unable to get on here for the last several days but the computer was used very little at all in the meantime. I've attached the AVG scans from both days as it did find something new today (surprised to see it found something new in the D drive restore files (I am running off C).

    The ComboFix log run per the board instructions is attached to my original email -- please let me know if you need me to go through the whole process again. I did get a few more Windows/Office updates in the meantime, I think, and my son unfortunately installed his Sims2Deluxe.

    In trying to do these uploads, my computer crashed but after the new 'drag and drop' combofix and newest AVG scan logs were attached. As a result, I can't attach those 2 to this email but it does show on my account under my uploaded files. Let me know if you can't find them and I'll try to upload them in another posting.

    Finally, I was for some unknown reason also able to attach the old HJT log (generated in the middle of the procedure that was posted on the board) that wouldn't upload before so I added that as well.

    Thanks!

    Toni
     
  6. ToniB

    ToniB TS Rookie Topic Starter

  7. ToniB

    ToniB TS Rookie Topic Starter

    virus checker problem

    Just in case you have any insight. My virus checker is no longer working -- it keeps shutting itself off several minutes after starting and the event log just says that it is still running. Not sure if this had anything to do with what I did here but as I haven't been using the computer... As I wrote earlier, the virus watcher kept flagging the hijackthis logs. (I read a posting about that but now can't find it again). I added a 'skip these files' for hijack*.* so I wouldn't get a virus warning every hour. Sat when my virus scanner repeatedly kicked off and, I thought that might be part of the problem, so I changed it to hijack*.txt and hijack*.log. Problem was still there so I got rid of the "skip this" on the hijack files. Darn thing still kicks out.

    Any ideas? (I assume I'll have to contact the vendor but not sure if maybe something could have hacked into the hijack logs?) Sorry, I'm technically in the dark... ;o/

    I'm running AntiVirenKit2004 (with updates as they provided) copywrite G Data Software, KAV engine by Kaspersky, BD engine by Softwin
     
  8. momok

    momok TS Rookie Posts: 2,265

    Hi,

    For some reason, I am not able to view your ComboFix log. Could you try re attaching the log? Your HijackThis log looks fine though. I'm not sure what could be the problem regarding your AntiVirenKit2004 software. In any case, I do encourage the use of more run-of-the-mill software like Avast or AVG, unless you already have Kaspersky antivirus.

    Perhaps you should just remove the virus watcher that is causing the problems and switch brands.


    Regards,
    Your friendly momok =)

    This thread is for the use of ToniB only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  9. ToniB

    ToniB TS Rookie Topic Starter

    Here's the log again -- Hope you can read this one. If not I'll rerun...? Or I can cut and paste. (just tried to open it and I could on this computer.)

    Thanks again for the support!

    Toni
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...