also @ TechSpot: AMD Radeon HD 7770 & Radeon HD 7750 Review
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > Tech Support > Virus and Malware Removal

Collaborate in the cloud with Office, Exchange, SharePoint, and Lync

My Hijackthis log - what to delete?

Thread Tools Search this Thread
  #1  
Old 06-26-2005
Newcomer, in training
 
Member since: Jun 2005, 4 posts
My Hijackthis log - what to delete?

Hello experts of the forum,

I found this site after discovering I have a trojan virus called twink64 or WIN32.delt.trojan.b or something like that. When I press control + alt + delete, I only see "comm" and "winamp" and "twink64" in the window, not the usual applications at all.

Anyway, I followed the instructions on the site, made a HJT root folder on my C drive and ran the program. I saved the log in the same HJT folder.

Here's my log in the txt attachment. What should I delete??

THANKS!
PJ
Attached Files
File Type: txt hijackthis.log.txt (4.9 KB, 10 views)
  #2  
Old 06-27-2005
TechSpot Evangelist
 
Location: has left the building
Member since: Aug 2003, 8,165 posts
Go to this post here first, and follow the instructions EXACTLY, especially about UPDATING and HJT-location.
How to remove Begin2Search/Coolwebsearch and Other Nasties

While in HJT, mark the twink-program as well to be fixed.

Then see How to post your Hijackthis log-files as an attachment.
  #3  
Old 06-29-2005
Newcomer, in training
 
Member since: Jun 2005, 4 posts
Followed instructions, PLEASE check HJT log

Quote:
Originally Posted by realblackstuff
Go to this post here first, and follow the instructions EXACTLY, especially about UPDATING and HJT-location.
How to remove Begin2Search/Coolwebsearch and Other Nasties

While in HJT, mark the twink-program as well to be fixed.

Then see How to post your Hijackthis log-files as an attachment.

Hi realblackstuff,

I followed all the instructions and ran Adaware and Spybot. Then Hijackthis again and deleted a lot of files, I think I got the twink64 file and some others too.

Can you please check my HJT this? I think there is still something because when I press control+alt+delete I don't see any applications listed at all, as I normally would in the dialog box. I had one error message pop called "explorer" up with the message "this program has performed an illegal operation and will be shut down...". That was strange.

Also, the "Running Processes" you see in my log don't show up in the HJT this where you could check them for fixing.

Anyway, please check my log, it's realy short!!
Thanks so much
PJ
Attached Files
File Type: txt hijackthis5june29.log.txt (1.7 KB, 9 views)
  #4  
Old 06-29-2005
TechSpot Maniac
 
Location: London
Member since: Apr 2005, 1,267 posts
Tick & fix the following

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://216.194.90.249/search.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O1 - Hosts: 140.99.106.182 auto.search.msn.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

Post a fresh log.

Last edited by IronDuke; 06-29-2005 at 06:57 PM.. Reason: Remove entry
  #5  
Old 06-29-2005
TechSpot Evangelist
 
Location: has left the building
Member since: Aug 2003, 8,165 posts
I'm not sure about your new log, it has a funny smell...
No Antivirus, way too many things gone after your first log...
Clean format/install, before any other programs? You're wasting my time, if so.
  #6  
Old 06-30-2005
Newcomer, in training
 
Member since: Jun 2005, 4 posts
Quote:
Originally Posted by realblackstuff
I'm not sure about your new log, it has a funny smell...
No Antivirus, way too many things gone after your first log...
Clean format/install, before any other programs? You're wasting my time, if so.

Sorry, but I really don't understand what you mean by "Clean format/install, before any other programs?". I ran Adaware and Spybot and HJT and "fixed" all the files that seemed dangerous according to the instructions. I also uninstalled (correctly from the control panel) a few programs like Adobe Reader that I can easily download from the net once this is all over, just to clean things up and make more sense of my log. I DO have an Antivirus installed on my computer.

Anyway, I'll delete the files that IronDuke said and repost my log. I'm a little worried because if I delete all those files there really won't be much left!!

Thanks
PJ
  #7  
Old 07-01-2005
TechSpot Evangelist
 
Location: has left the building
Member since: Aug 2003, 8,165 posts
You removed Norton-Symantec/Zonealarm/Real Player/your printer/FTP-stuff/StarOffice and some other stuff.
Your log LOOKS like a fresh install without any other programs added (yet), which made me suspicious.
For all your efforts, it would probably have been easier to really do a fresh install.

Anyway, after IronDuke's advised changes have been made, your PC is clean.
  #8  
Old 07-02-2005
Newcomer, in training
 
Member since: Jun 2005, 4 posts
OK, I fixed all the entries in my HJT log that IronDuke said to. I also re-installed my Antivirus and Acrobat Reader and set my homepage in MS Explorer to yahoo.com. Strangely, I still don't see any entries listed when I press Control+Alt+Delete. Let's hope there are no more problems.

I'm reposting my log for a final check, as IronDuke suggested. There are a lot more Running Processes than before.

Thanks so much to IronDuke & realblack stuff for the help!!!!

PJ
Attached Files
File Type: txt hijackthisjuly02.log.txt (1.7 KB, 5 views)
  #9  
Old 07-02-2005
TechSpot Maniac
 
Location: London
Member since: Apr 2005, 1,267 posts
There's nothing there that shouldn't be. Once again it seems uncharacteristicly brief.
You need to put a firewall back.
Try also Ewido
  #10  
Old 07-02-2005
TechSpot Evangelist
 
Location: has left the building
Member since: Aug 2003, 8,165 posts
IronDuke, don't forget that W98se never showed much in HJT to start with.

PJPJ, the log is clean indeed.
Stop using IE, except for Windows-updates.
Get Firefox instead! from www.getfirefox.com
Closed Thread

Similar Topics
Topic Replies Forum
Delete Windows.0 - where's the ini file to delete 3 Windows OS
How do I delete? 11 Site Feedback and Suggestions
can't delete some entries using hijackthis 2 Virus and Malware Removal
Want to Delete a .dll 4 Windows OS

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 09:49 AM.