User User name Password  
   
Saturday 6.9.2025 / 17:46
Search AfterDawn Forums:        In English   Suomeksi   På svenska
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > need help reviewing hijackthis log.
Show topics
 
Forums
Forums
Need help reviewing Hijackthis log.
  Jump to:
 
Posted Message
Member
_
14. July 2007 @ 13:39 _ Link to this message    Send private message to this user   
@Auttaja - See, the uninstaller leaves behind LOTS of registry keys and folders.

@melanieG - Norton isn't causing the problems - but it's like improperly removed malware - sits there doing nothing whatsoever, wasting space.

Install another antivirus program - a computer without one will keep getting infected. AntiVir (http://www.free-av.com) is pretty good, has excellent heuristics and the highest detection rate of any free antivirus. Sometimes it gets kind of annoying, but that's cause it rocks so much :D

Don't edit the registry on a regular basis, you could screw something up :) The registry scripts I gave you should have done it.

What happens when you try to edit msconfig?

There's not much more left to try... you likely don't have a rootkit, as can be confirmed by the BlackLight scan... let's try another scan for rootkits, since you don't seem to have any other recognizable mawlare.

Please download AVG Anti-Rootkit. Install it, and do a scan with it. It should tell you if hidden objects are found. It should also create a log, post that log in a reply please.

Do you have your original Windows XP Installation CD? I'm not looking to reformat - try to avoid that unless we have absolutely no other options.

Edit - just thought of something else of interest. Please open your start menu > Run. In the box, type system.ini. A notepad window should open - DO NOT CHANGE ANYTHING!! Copy the contents of that window and post it into your reply.

Geeks to Go - Trusted Helper

Please do not PM for help - please post on the forums.

This message has been edited since posting. Last time this message was edited on 14. July 2007 @ 13:42

Advertisement
_
__
windmaker
Newbie
_
15. July 2007 @ 08:21 _ Link to this message    Send private message to this user   
why would you add yet another AV ?

have the last bit of Nortons AV been removed ?

Part of Nortons AV
Quote:

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccRegVfy]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccRegVfy"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe"
"inimapping"="0"

Have/had LOP infection
Quote:

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\site ford roam vc]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Eggs 1"
"hkey"="HKLM"
"command"="C:\\Documents and Settings\\All Users\\Application Data\\DEBUGFLAPSITEFORD\\Eggs 1.exe"
"inimapping"="0"

resident AV ?
Quote:

TrendMirco AntiVirus
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Trend Micro AntiVirus 2007]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="tavui"
"hkey"="HKLM"
"command"="C:\\Program Files\\Trend Micro\\AntiVirus 2007\\tavui.exe -1 --delay 15"
"inimapping"="0"

CA through Yahoo as well


you can't see me but sometimes can hear me
Member
_
15. July 2007 @ 08:23 _ Link to this message    Send private message to this user   
An anti-rootkit is not an AV.

Geeks to Go - Trusted Helper

Please do not PM for help - please post on the forums.
windmaker
Newbie
_
15. July 2007 @ 09:52 _ Link to this message    Send private message to this user   
Didn't say it was
I was referring to
Quote:

Install another antivirus program - a computer without one will keep getting infected. AntiVir (http://www.free-av.com) is pretty good, has excellent heuristics and the highest detection rate of any free antivirus. Sometimes it gets kind of annoying, but that's cause it rocks so much :D



you can't see me but sometimes can hear me
melanieG
Newbie
_
16. July 2007 @ 08:42 _ Link to this message    Send private message to this user   
Hi Fredl. I apologize for my delay in keeping up with this. I downloaded and ran the avg and no rootkits were found. Also downloaded and installed the antivirus you suggested, nothing found.

Here is the info form system.ini: ; for 16-bit app support
[drivers]
wave=mmdrv.dll
timer=timer.drv
[mci]
[driver32]
[386enh]
woafont=dosapp.FON
EGA80WOA.FON=EGA80WOA.FON
EGA40WOA.FON=EGA40WOA.FON
CGA80WOA.FON=CGA80WOA.FON
CGA40WOA.FON=CGA40WOA.FON
Member
_
16. July 2007 @ 15:01 _ Link to this message    Send private message to this user   
You have me stumped...

Reboot into Safe Mode and delete this folder:

C:\Documents and Settings\All Users\Application Data\DEBUGFLAPSITEFORD

You will have to enable Hidden Files via Start > Control Panel > Folder Options > View.

How is the computer running?

Geeks to Go - Trusted Helper

Please do not PM for help - please post on the forums.
melanieG
Newbie
_
16. July 2007 @ 15:24 _ Link to this message    Send private message to this user   
I'm about to perform that deletion. I wanted to tell you the most annoying thing about my computer is the mouse problem. If I idel for more that a couple of minutes, sometimes not even that, it locks up, I have to hit control+Alt+ delete. I don't have to delete anything, I just have to do it. It also starts acting even more strange by acting as if I have right clicked permanently on the desktop, then I have to click my choice of action. So if I want open my email, I have to click "open outlook express" I really hate that!!!
Advertisement
_
__
 
_
Member
_
16. July 2007 @ 15:40 _ Link to this message    Send private message to this user   
Hmm... can you go to Start > Control Panel > Mouse > Buttons. Make sure that both the checkboxes are un-checked. Also, make sure the correct drivers for your mouse are installed (they usually come in a CD when you bought your mouse). I'm not an expert with mice, so you might have to post in the hardware forum :)

Geeks to Go - Trusted Helper

Please do not PM for help - please post on the forums.
 
Related links
Download the latest version of HijackThis now!
 
Related forum topics Posts Last post Forum room
HijackThis 101 1 11. September 2013 Windows - Virus and spyware problems
Had Department of Justice money pack virus. Now computer is acting strange. Could someone take a look at my hijackthis log? 64 6. January 2013 Windows - Virus and spyware problems
ComboFix/HIJackThis Log Help 9 10. April 2012 Windows - Virus and spyware problems
Please review HiJackThis log and help 1 11. November 2011 Windows - Virus and spyware problems
HijackThis Log File! 3 27. June 2011 Windows - Virus and spyware problems
please help read hijackthis log 1 7. April 2011 Windows - Virus and spyware problems
HijackThis Log, Please Help ! 5 4. April 2011 Windows - Virus and spyware problems
HiJackThis log...pls help 1 2. April 2011 Windows - Virus and spyware problems
My Hijackthis log file, please help 2 20. February 2011 Windows - Virus and spyware problems
Malware help! hijackthis log provided. 6 29. September 2010 Windows - Virus and spyware problems

 
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > need help reviewing hijackthis log.
 

Digital video: AfterDawn.com | AfterDawn Forums
Music: MP3Lizard.com
Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
Software: Software downloads
Blogs: User profile pages
RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
International: AfterDawn in Finnish | AfterDawn in Swedish | AfterDawn in Norwegian | download.fi
Navigate: Search | Site map
About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
Contact us: Send feedback | Contact our media sales team
 
  © 1999-2025 by AfterDawn Ltd.

  IDG TechNetwork