HiJackThis! Log for examination

Status
Not open for further replies.
Hello and welcome to Techspot.

Your system has been hijacked and you`re running HJT from the wrong location. You also need to rename HijackThis.exe as per the instructions.

Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

If after reading the above, you wish to clean your system, do the following.

Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

Then, Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

Post fresh HJT, AVG Antispyware and Combofix logs as Attachments into this thread, only after doing the above.

Also, please post the C:\fixwareout\report.txt.

Also, let me know the results of the Panda Antirootkit scan.

Regards Howard :wave: :wave:

This thread is for the use of awhite16 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Don`t the instructions tell you that?

Oh! yes they do, look at steps 4 and 5 lol.

Regards Howard :)

This thread is for the use of awhite16 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Taken from HERE.

[CENTER]STEP4:

Make sure you have the LATEST version of HJT (currently v2.0.0.2) from HERE.[/center]

The above link will download the HijackThis installer. Run the HijackThis Installer and it will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe. It will also automatically OPEN HJT, close it.

-----------------------------------------------------------------------------------------------------------------------------------
[CENTER]STEP5:

THIS IS VERY IMPORTANT.
[/CENTER]
Open the C:\Program Files\TrendMicro\HijackThis folder in program files. Rename the Hijackthis.exe file to Crusty.exe. This is because some malware can hide from HijackThis.exe. Right click the HijackThis.exe file and choose rename. Click in the title box and press the delete key to clear what`s there, type Crusty.exe and press the enter key. Right click the Crusty.exe file and choose send to desktop(create shortcut).

[CENTER]Under no circumstances should you add any items to the HJT ignore list.

Do not run a HJT scan, until step15 of this thread.[/center]

Regards Howard :)

This thread is for the use of awhite16 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Alright thanks for that. Sorry I didn't see it before. I am going to have to wait until this weekend to perform these operations since the computer in question is my dad's laptop and he will be away all week until Friday night. The reason it was running from the desktop is I went to the HJT site and downloaded the exe file directly. I must take this opportunity to say that crusty.exe is a very interesting thing to rename the file to.
 
Fixed!!

I ran all the tools and SS&D found three Trojans and a couple of adware programs. I got rid of them and now the computer works like it did when it was new! It even performs better (startup/shutdown times were greatly reduced). The Panda Antirootkit scan found nothing. THe question I have is: do you still want me to post the logs from AVG, HJT, and Combofix even though the problem is solved?
 
Yes please post them. Some nasties may still be lurking in the depths of your system files.
 
Status
Not open for further replies.
Back