Hijackthis log

Discussion in 'Windows - Virus and spyware problems' started by PWNed100, Jul 6, 2006.

  1. PWNed100

    PWNed100 Guest

    umm... i jus recover from a HUGE virus invasion i was wondering if anything was still wrong... heres a log

     
  2. the_jong

    the_jong Member

    Joined:
    Jul 3, 2006
    Messages:
    17
    Likes Received:
    0
    Trophy Points:
    11
    O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - (no file)
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{85339906-A169-4A82-B36E-E8962CBFA2AA}: NameServer = 4.2.2.2,4.2.2.3

    just go to www.hijackthis.de to check if you have problems
     
  3. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    @the_jong: Once again www.hijackthis.de showed that it's just crap :)
    Three lines you listed are legit and that analyzator missed many bad ones.

    You want eg. that PWNEd100's internet connection gets broken?

    O17 - HKLM\System\CCS\Services\Tcpip\..\{85339906-A169-4A82-B36E-E8962CBFA2AA}: NameServer = 4.2.2.2,4.2.2.3

    Those are name servers of his ISP.

    @PWNEd100:

    Move Hjt into own folder -> c:\hjt

    Fix with HjT:


    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    Please download the http://www.downloads.subratam.org/KillBox.zip
    Killbox.
    Unzip it to the desktop

    Please run Killbox.

    Select "Delete on Reboot".

    Copy the file names below to the clipboard by highlighting them and pressing Control-C:

    C:\WINDOWS\g265046.dll
    C:\WINDOWS\SYSTEM32\winmfu32.dll

    Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

    Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

    If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe to download and run missingfilesetup.exe. Then try TheKillbox again..

    If your computer does not restart automatically, please restart it manually.
     

Share This Page