Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Hijackthis checkup
![]() |
| Thread Tools |
|
#1
|
|||
|
|||
|
Hijackthis checkup
So i wiped my whole computer clean installed a few things on it and as i share this with my brother his online game wasnt working so he randomly downloads stuff trying to fix it (things that have nothing to do with the game in general)
last time i fixed it for him there was a game keylogger in the file he needed just checking that he hasnt got that on here before i logon to some stuff ![]() Thanks in adavance ~Richard. |
|
#2
|
|||
|
|||
|
I don't see any keyloggers, but I see a lot of junk and conflicting programs that you might want to re construct.
AVG Antispyware 7.5 hasn't been supported for six weeks, so it is useless. You have AOL antispyware (probably McAfee) AVG 8.0 ( which is pretty much useless nowadays). One of those should go. I would take off both and get a decent antivirus package such as Antivir Adaware doesn't appear to be up to date. Zone Alarm has been in conflict with Microsoft too often lately. Are you in Real Estate, or otherwise, what is Voyager? You have Windows Live as well as AOL. Those will conflict You might wish to rethink your security... Firewall, Antispyware, Antivirus, but you will need to decide what to do about AOL first. Either use AOL security, or remove it and add MBAM MalwareBytes or SuperAntiSpyware, Adaware 2008, and Avast or Antivir antispyware. Then defrag your system. |
|
|
|
#3
|
||||
|
||||
|
If you plan on defragmenting make sure to run a ChkDsk by going to Start > My Computer and right clicking your main drive ( If unpartioned, it's C:\ ) and click Properties and click on the Tools Tab. Click on Check now and put a check mark on the both objects, it will ask for a restart. After you restart it should run the ChkDsk for about a hour or so depending on how large your hard drive space is, after it's finished it will reboot one or two times. Now, you can run a Defragment tool such as the Built in one with Microsoft or a free-to-use program like JKDefrag ( Highly recommended ).
|
|
#4
|
||||
|
||||
|
hey ok first follow the steps below this looks weird to me
O17 - HKLM\System\CCS\Services\Tcpip\..\{90DC1203-D41D-4F00-98B1-67E8D2C15BB7}: NameServer = 92.31.242.20 92.31.242.21 <------This looks like a hijack O17 - HKLM\System\CS1\Services\Tcpip\..\{0DA02CE8-A747-419E-AF9E-8EA04F67C049}: NameServer = 205.188.146.145 <---------- This is from AOL Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. -------------------------------- ComboFix
Caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Combofix is a very powerful tool so please do NOT do anything without instruction Combofix will automatically save the log file to C:\combofix.txt --------------------------------- SmitfraudFix
|
|
#5
|
|||
|
|||
|
Thanks for your time
here are the logsEDIT: just went to log onto my game now my game wont connect and AOL spyware popped up saying it detected something called bifrost? high security lvl? mind you that thing is allways chucking out false positives just thought id mention it anyway. Last edited by Richard132; 07-18-2008 at 09:17 PM. |
|
#6
|
||||
|
||||
|
Can you attache the MBAM log. Also I still se the entries I asked you to remove did you remove them?
Last edited by xxdanielxx; 07-18-2008 at 11:00 PM. |
|
#7
|
|||
|
|||
|
sorry forgot to post it and was it the things highlighted in red you wanted me to remove? just the one that looks like hijack or both?
Coz you didnt ask me to remove it :S |
|
#8
|
||||
|
||||
|
just this one
O17 - HKLM\System\CCS\Services\Tcpip\..\{90DC1203-D41D-4F00-98B1-67E8D2C15BB7}: NameServer = 92.31.242.20 92.31.242.21 <------This looks like a hijack |
|
#9
|
|||
|
|||
|
Ok removed it but it just comes back on restart? new log
![]() |
|
|
|
#10
|
||||
|
||||
|
I did more searching on it and it is nothing bad like malware.
Please run an on-line virus scan at http://www.kaspersky.com/virusscanne...can</font></b> or if that doesnt work, you can use TrendMicro or BitDefender. (Please post the results of the scan(s) in your next reply) +++++ If you are unable to run the activeX Antivirus Scanners, lets try this Java based solution from Trend Micro. |
|
#11
|
|||
|
|||
|
Found some things :P
Coming up with the .exe you asked me to download and run? The files it says are on the desktop aint visable? guessing they are hidden? but the .exe on desktop/antivirus is visable. Last edited by Richard132; 07-21-2008 at 10:37 AM. |
|
#12
|
||||
|
||||
|
no that is a false positive. Well your last log look clean can you post one last hijackthis log to make sure. Also how is your computer running
|
|
#13
|
|||
|
|||
|
Fine
![]() log attached ![]() |
|
#14
|
||||
|
||||
|
hey it looks clean just remove the 2 items below
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) Now its time for the clean up Please download ATF Cleaner by Atribune. This program is for XP and Windows 2000 only
For Technical Support, double-click the e-mail address located at the bottom of each menu. ------------------------------------------ Now we need to create a new System Restore point. Click Start Menu > Run > type (or copy and paste) %SystemRoot%\System32\restore\rstrui.exe Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close. Next goto Start Menu > Run > type cleanmgr Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created. To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window. ----------------------------------------- Uninstall ComboFix
The above procedure will Delete the following:
------------------------------------------------------------------ OTCleanit! by Oldtimer
--------------------------------------------------- The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
|
|
#15
|
|||
|
|||
|
Thanks very much for your help you've been great! keep up the good work daniel
![]() |
|
#16
|
||||
|
||||
|
anytime, if you still have problems post back here
|
![]() |
«
Previous Thread
|
Next Thread
»
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Checkup (hjt) | navieko | Security and the Web | 6 | 03-14-2008 12:02 PM |
| System checkup request | arx2431 | Security and the Web | 2 | 06-29-2007 01:45 AM |
| System Checkup: CiD Popup Help | Orannis117 | Security and the Web | 6 | 03-06-2007 09:08 PM |
| computer checkup | bolun | Security and the Web | 2 | 02-09-2007 08:14 PM |
| checkup | gjkinn | Security and the Web | 1 | 10-04-2006 08:28 AM |
All times are GMT -4. The time now is 01:09 AM.





here are the logs

