Home   News  Product reviews  Website reviews  Forums   Competitions  Subscribe 

Security >> HijackThis logs help and analysis

 |  Print Thread
bricatModerator
HijackThis Helper


Reg'd: Wed
Posts: 29173
Loc: belfast
Re: Spyware has infected my computer and I need help to remove it.
      Wed Apr 16 2008 09:58 AM

we still have a bit more work to do to clean this up.

Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

It's IMPORTANT to carry out the instructions in the sequence listed below.


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


Open *notepad* and copy/paste the text in the quotebox below into it:

Quote:



Killall::

File::
C:\Documents and Settings\William A. Hudson\DesktopTrojan.Win32.BlackBird.PIF
C:\WINDOWS\system32\rsmjacyj.dll
C:\WINDOWS\system32\rjyltlvp.dll
C:\WINDOWS\dsktbwfe.dll
C:\WINDOWS\nslbvxpgtkn.dll
C:\WINDOWS\ogxtsepr.dll
C:\WINDOWS\sgoblxtm.dll
C:\WINDOWS\system32\sloxafkp.exe
C:\WINDOWS\spnkfwad.exe
C:\WINDOWS\hookdllX.dll
C:\WINDOWS\.prj
C:\WINDOWS\system32\lwrkjolo.exe
C:\WINDOWS\iun6002.exe

Registry::
[-HKEY_LOCAL_MACHINE\~\BrowserHelperObjects\{97EBE3CC-10A7-4619-B127-9B5D4FA476A8}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{57ABA3CE-E927-4C81-BE2E-E20CAEC6645F}"=-
[-HKEY_CLASSES_ROOT\clsid\{57aba3ce-e927-4c81-be2e-e20caec6645f}]
[-HKEY_CLASSES_ROOT\sgoblxtm.1]
[-HKEY_CLASSES_ROOT\TypeLib\{CBA0A72A-C5B0-47F8-9BD7-307B7708A58D}]
[-HKEY_CLASSES_ROOT\sgoblxtm]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"zxcrqdht"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uaextvrz"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"kEU1gkL26I"=-
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
[-HKEY_LOCAL_MACHINE\software\microsoft\windowsnt\currentversion\winlogon\notify\efcDUmjj]






Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.




Referring to the picture above, drag CFScript.txt into ComboFix.exe

Restart your computer.

When finished, it shall produce a log for you at C:\ComboFix.txt

Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please and
let me know how it is running.


*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall*

then :-

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

--------------------
MY HELP IS FREE,BUT PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST SPYWARE.

You don't stop laughing when you get old, you get old when you stop laughing!

Post Extras Print Post   Remind Me!     Notify Moderator
Rate this thread

Jump to


Entire topic
Subject Posted by Posted on
* Spyware has infected my computer and I need help to remove it. God_Is_The_Light Tue Apr 15 2008 07:24 PM
. * * Re: Spyware has infected my computer and I need help to remove it. bricatModerator   Tue Apr 15 2008 11:57 PM
. * * Re: Spyware has infected my computer and I need help to remove it. God_Is_The_Light   Wed Apr 16 2008 02:29 AM
. * * Re: Spyware has infected my computer and I need help to remove it. bricatModerator   Wed Apr 16 2008 09:58 AM
. * * Re: Spyware has infected my computer and I need help to remove it. God_Is_The_Light   Thu Apr 17 2008 01:01 AM
. * * Re: Spyware has infected my computer and I need help to remove it. bricatModerator   Thu Apr 17 2008 01:45 AM
. * * Re: Spyware has infected my computer and I need help to remove it. God_Is_The_Light   Thu Apr 17 2008 05:57 AM
. * * Re: Spyware has infected my computer and I need help to remove it. bricatModerator   Thu Apr 17 2008 09:41 AM
. * * Re: Spyware has infected my computer and I need help to remove it. God_Is_The_Light   Thu Apr 17 2008 04:14 PM
. * * Re: Spyware has infected my computer and I need help to remove it. bricatModerator   Thu Apr 17 2008 06:38 PM
. * * Re: Spyware has infected my computer and I need help to remove it. God_Is_The_Light   Fri Apr 18 2008 02:14 AM
. * * Re: Spyware has infected my computer and I need help to remove it. bricatModerator   Fri Apr 18 2008 09:52 AM
. * * Re: Spyware has infected my computer and I need help to remove it. God_Is_The_Light   Sat Apr 19 2008 05:10 AM
. * * Re: Spyware has infected my computer and I need help to remove it. bricatModerator   Sat Apr 19 2008 11:09 AM
. * * Re: Spyware has infected my computer and I need help to remove it. God_Is_The_Light   Sat Apr 19 2008 06:34 PM
. * * Re: Spyware has infected my computer and I need help to remove it. bricatModerator   Sat Apr 19 2008 07:13 PM
. * * Re: Spyware has infected my computer and I need help to remove it. God_Is_The_Light   Sat Apr 19 2008 08:12 PM
. * * Re: Spyware has infected my computer and I need help to remove it. MouseModerator   Sun Apr 20 2008 12:00 AM
. * * Re: Spyware has infected my computer and I need help to remove it. God_Is_The_Light   Sun Apr 20 2008 12:58 AM
. * * Re: Spyware has infected my computer and I need help to remove it. bricatModerator   Sun Apr 20 2008 10:01 AM
. * * Re: Spyware has infected my computer and I need help to remove it. God_Is_The_Light   Tue Apr 22 2008 09:47 AM
. * * Re: Spyware has infected my computer and I need help to remove it. bricatModerator   Tue Apr 22 2008 10:11 AM
. * * Re: Spyware has infected my computer and I need help to remove it. God_Is_The_Light   Wed Apr 23 2008 06:06 AM
. * * Re: Spyware has infected my computer and I need help to remove it. bricatModerator   Wed Apr 23 2008 09:18 AM

Extra information
0 registered and 10 anonymous users are browsing this forum.

Moderator:  putasolutions, greysts, bricat, AndrewC, Joe_London, John_McKenna, Mouse, Hello_There, TheFatControlleR, Nanook, Noviciate 


Print Thread
Forum Permissions
      You cannot start new topics
      You cannot reply to topics
      HTML is disabled
      Mark-up is enabled

Rating:
Thread views: 0

Contact Us | Privacy statement Main website
Hitwise Top 10 Award Winner - Jan-Mar 2005

About us | Contact us | Link to us | Terms & Conditions | Privacy Policy
© Copyright IPC Media Limited, All rights reserved