Home   News  Product reviews  Website reviews  Forums   Competitions  Subscribe 

Security >> HijackThis logs help and analysis

 |  Print Thread
ourwilly
HijackThis Helper


Reg'd: Sun
Posts: 2872
Loc: England.
Re: Trojan problem
      Sat May 24 2008 07:48 AM

Hello ryanjo34

Thank you for doing that. Please Copy and Paste this 'Fix' into either Notepad or Wordpad for future reference as you will be required to closed down you browser when following these steps.

1. Open HijackThis again, select "Do a System Scan only" and place a checkmark in the boxes before the following entries:

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O20 - Winlogon Notify: wvUnMDWN - wvUnMDWN.dll (file missing)

Close all other open windows and click on Fix checked, then exit HijackThis.


2. Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).



3. Please Open notepad - don't use any other text editor

I would like you to now Copy/paste the text in the quotebox below into notepad:

Quote:

File::
C:\WINDOWS\system32\scvhost.exe
C:\WINDOWS\SYSTEM32\28.tmp
C:\WINDOWS\SYSTEM32\blackster.scr
C:\startup.exe

Driver::
Windows Action Script

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvUnMDWN]







Name the file CFScript and Save it to your Desktop


Refering to the picture above, drag CFScript.txt into ComboFix.exe

Run ComboFix again and post the resultant log along with a new HijackThis log and SDFix report

Post Extras Print Post   Remind Me!     Notify Moderator
Rate this thread

Jump to


Entire topic
Subject Posted by Posted on
* Trojan problem ryanjo34 Thu May 22 2008 03:33 PM
. * * Re: Trojan problem ourwilly   Fri May 23 2008 07:36 PM
. * * Re: Trojan problem ryanjo34   Sat May 24 2008 05:18 AM
. * * Re: Trojan problem ourwilly   Sat May 24 2008 07:48 AM
. * * Re: Trojan problem ryanjo34   Sat May 24 2008 03:47 PM
. * * Re: Trojan problem ourwilly   Sat May 24 2008 09:16 PM
. * * Re: Trojan problem ryanjo34   Sun May 25 2008 02:33 PM
. * * Re: Trojan problem ourwilly   Sun May 25 2008 03:21 PM
. * * Re: Trojan problem ryanjo34   Mon May 26 2008 02:07 PM
. * * Re: Trojan problem ourwilly   Tue May 27 2008 06:18 AM
. * * Re: Trojan problem ryanjo34   Wed May 28 2008 04:14 PM
. * * Re: Trojan problem ourwilly   Wed May 28 2008 04:41 PM
. * * Re: Trojan problem ryanjo34   Wed May 28 2008 06:52 PM

Extra information
2 registered and 13 anonymous users are browsing this forum.

Moderator:  putasolutions, greysts, bricat, AndrewC, Joe_London, John_McKenna, Mouse, Hello_There, TheFatControlleR, Nanook, Noviciate 


Print Thread
Forum Permissions
      You cannot start new topics
      You cannot reply to topics
      HTML is disabled
      Mark-up is enabled

Rating:
Thread views: 0

Contact Us | Privacy statement Main website
Hitwise Top 10 Award Winner - Jan-Mar 2005

About us | Contact us | Link to us | Terms & Conditions | Privacy Policy
© Copyright IPC Media Limited, All rights reserved