We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Think I've a virus - What should I delete from Hijack this?

Hi

I think I've a virus on my laptop. Strange emails are being sent from my hotmail account to my contacts - I've changed my password now in hotmail and run scans but it hasn't found anything.

Should I remove anything from this Hijack this? I've tried to remove the last yahoo entry but it won't let me?

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:40:39, on 22/09/10
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Ralink\Common\RaRegistry.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Documents and Settings\Desktop\FirefoxPortable.exe
C:\Documents and Settings\Desktop\FirefoxPortable\App\firefox\firefox.exe
C:\Documents and Settings\Desktop\FirefoxPortable\App\firefox\plugin-container.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files\Ralink\Common\RaRegistry.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 4004 bytes
«1

Comments

  • Knarf44
    Knarf44 Posts: 557 Forumite
    Suggest you run an up to date Malwarebytes scan first and post the log from it. Make sure you update its definitions first though. Once you've posted that I'm sure further advice will be forthcoming.
  • Have you deleted things from the hijackthislog then? What did you remove. I hope you didn't remove anything important...

    Also first thing to do in these cases is to download malwarebytes, install the program, go to the UPDATE tab and CHECK FOR UPDATES. Then run a quick scan and post the log on here. Download Malwarebytes Anti-Malware 1.46 - FileHippo.com
  • sunni
    sunni Posts: 804 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    Items were deleted from Hijackthis several months ago, nothing been deleted since.

    I downloaded Sypbot Search & Destroy and it found things which I deleted - now I keep getting a box saying it has detected an important registry entry that has been changed - allow change or deny change - not sure what to select here?

    Here's the Malwarebytes log from earlier:

    Malwarebytes' Anti-Malware 1.46
    https://www.malwarebytes.org

    Database version: 4672

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    22/09/10 15:52:07
    mbam-log-2010-09-22 (15-52-07).txt

    Scan type: Quick scan
    Objects scanned: 146208
    Time elapsed: 20 minute(s), 24 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
  • What virus software are you using? Make sure your running the both the virus scan and Spyware scans in safe mode.
  • I didn't think it was necessary to run the scans in safe mode...

    Can you UPDATE definitions in malwarebytes, CHECK FOR UPDATES then run a FULL SCAN this time. Please post log here.

    Also can you post the logs from spybot which shows the virus/malware?
  • Its not necessary but running in safe mode runs alls services and processes at bare minimum and any viruses/spyware attached to a services or process may not be detected whilst running in normal mode.
  • Knarf44
    Knarf44 Posts: 557 Forumite
    Guys

    Lifted this from the Malwarebytes Forum:

    "Safe mode doesn't let MBAM load all it's drivers which are often necessary for the best detection and removal results. MBAM works in safe mode but is crippled, so if at all possible it should be used in normal mode in an admin account."

    Hope this helps.
  • sunni
    sunni Posts: 804 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    I'm using Avast anti virus. Not sure where the logs are in Spybot?

    Currently running a Full Scan in Malwarebytes and will post the log when it's finished.
  • spud17
    spud17 Posts: 4,452 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    edited 22 September 2010 at 11:17PM
    I downloaded Sypbot Search & Destroy and it found things which I deleted - now I keep getting a box saying it has detected an important registry entry that has been changed - allow change or deny change - not sure what to select here?
    That sounds like the Spybot teatimer, personally I don't like it , to disable, open Spybot, (if Vista or 7 Right click Spybot, run as administrator), mode, switch to advanced, (accept warning), on LHS, expand tools, click resident, then untick tea timer on rhs.
    Move along, nothing to see.
  • sunni
    sunni Posts: 804 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    Thanks spud17 that seems to have worked :)

    Should I just leave the Hijackthis log as it is?

    Here's the log from the Full Scan in Malwarebytes - nothing found

    Malwarebytes' Anti-Malware 1.46
    https://www.malwarebytes.org

    Database version: 4673

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    22/09/10 23:56:42
    mbam-log-2010-09-22 (23-56-42).txt

    Scan type: Full scan (C:\|D:\|)
    Objects scanned: 199054
    Time elapsed: 1 hour(s), 43 minute(s), 15 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 354.4K Banking & Borrowing
  • 254.4K Reduce Debt & Boost Income
  • 455.4K Spending & Discounts
  • 247.3K Work, Benefits & Business
  • 604K Mortgages, Homes & Bills
  • 178.4K Life & Family
  • 261.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.