Webmaster Forum

Sponsored Reviews   High Bandwidth Dedicated Servers   V7N Directory
Go Back   Webmaster Forum > The Webmaster Forums > Forum Lobby > Computers & Internet
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Computers & Internet For all those computer related discussions.

Reply
 
LinkBack Thread Tools Display Modes
Old 05-06-2006, 10:30 AM   #61 (permalink)
Zap
Human Tripod
 
Zap's Avatar
 
Join Date: 01-15-06
Location: WEBTALKFORUMS.COM
Posts: 9,881
iTrader: 0 / 0%
Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
@Henny:

You can remove...

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

(The line above is not dangerous, but unnecessary, unless you need Quicktime to load fast because of frequent usage)

The following line alters your DNS servers...
O17 - HKLM\System\CCS\Services\Tcpip\..\{51508C5E-72F4-4DC7-AAFD-3375D32F1249}: NameServer = 68.238.1.12,68.238.112.12

(If you know why, then that's fine. In and of itself, it's not a problem, but could indicate a problem - Again, if you know why your nameservers might have been altered by something you installed, then that's fine. Your system looks clean, so I wouldn't worry about this one anomoly)
__________________
BIG Gaming Forum

Toronto Forum
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-06-2006, 03:18 PM   #62 (permalink)
Inactive
 
Henny's Avatar
 
Join Date: 04-19-06
Posts: 37
iTrader: 0 / 0%
Latest Blog:
None

Henny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the rough
Send a message via MSN to Henny
Wow! Thanks ZAP!
Henny is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-06-2006, 03:25 PM   #63 (permalink)
Zap
Human Tripod
 
Zap's Avatar
 
Join Date: 01-15-06
Location: WEBTALKFORUMS.COM
Posts: 9,881
iTrader: 0 / 0%
Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
Quote:
Originally Posted by Henny
Wow! Thanks ZAP!
NP. Didn't really help you much. You're clean.
__________________
BIG Gaming Forum

Toronto Forum
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-07-2006, 10:21 AM   #64 (permalink)
Inactive
 
Henny's Avatar
 
Join Date: 04-19-06
Posts: 37
iTrader: 0 / 0%
Latest Blog:
None

Henny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the rough
Send a message via MSN to Henny
Yeah, but peice of mind is worth a thank-you , isn't it?
Henny is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-07-2006, 11:27 AM   #65 (permalink)
Zap
Human Tripod
 
Zap's Avatar
 
Join Date: 01-15-06
Location: WEBTALKFORUMS.COM
Posts: 9,881
iTrader: 0 / 0%
Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
Well, you're welcome. You have no worries. Your hijackthis! log is one of the cleaner ones I've seen.
__________________
BIG Gaming Forum

Toronto Forum
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-07-2006, 02:10 PM   #66 (permalink)
v7n Mentor
 
cashcannon's Avatar
 
Join Date: 01-26-06
Location: netherlands
Posts: 2,077
iTrader: 0 / 0%
Latest Blog:
None

cashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest order
Send a message via ICQ to cashcannon
I got a log to, pc at home is running at constant 100% cpu and I have no idea why

ran avast and gave me a list of warnings of files it couldnt open
mostly mtuser.dat files

hope you see something fishy

thnx
Attached Files
File Type: txt hijackthisloggie.txt (5.2 KB, 100 views)
cashcannon is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-07-2006, 02:53 PM   #67 (permalink)
NeO
Contributing Member
 
NeO's Avatar
 
Join Date: 01-07-06
Location: 127.0.0.1
Posts: 928
iTrader: 0 / 0%
NeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest order
Is this the log from the pc that's running @100% ?

I didn't see anything other than all of the music software that your using that would indicate a hijack of any type...

Zap you see anything that is potentially hazardous?

NeO
__________________
I can levitate birds....No one cares...

Top SEO Consultants | Beginning SEO Podcast
NeO is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-07-2006, 03:41 PM   #68 (permalink)
Zap
Human Tripod
 
Zap's Avatar
 
Join Date: 01-15-06
Location: WEBTALKFORUMS.COM
Posts: 9,881
iTrader: 0 / 0%
Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
@Cashcannon:

You can remove...

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\RunServices: [Sasser Patch v1 ] msconf.exe
O4 - HKCU\..\Run: [Sasser Patch v1 ] msconf.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)


The 2 references to the Sasser patch stand out at me. It is possible that you have a virus because you also complain of 100% CPU usage. I found one virus write up that might fit the bill for you.

Read This and download the removal tool zipfile attached to this post. Remove the tool from the zipfile and run it. Let it remove anything it finds.

Then update your antivirus software definitions and do a full scan of your computer.

Then scan your computer again with hijackthis! and post a new hijackthis! log here.
Attached Files
File Type: zip FxGaobot.zip (164.5 KB, 26 views)
__________________
BIG Gaming Forum

Toronto Forum
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-07-2006, 11:52 PM   #69 (permalink)
v7n Mentor
 
cashcannon's Avatar
 
Join Date: 01-26-06
Location: netherlands
Posts: 2,077
iTrader: 0 / 0%
Latest Blog:
None

cashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest order
Send a message via ICQ to cashcannon
thanks for your time Zap, much appreciated, I'll post the hijack log in the evening
cashcannon is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-08-2006, 08:24 AM   #70 (permalink)
Inactive
 
Join Date: 04-06-06
Posts: 33
iTrader: 0 / 0%
Latest Blog:
None

kiraz is an unknown quantity at this point
Quote:
Originally Posted by Zap
@Kiraz:

You can get rid of... *Removed but kindly put in a text file for you :-)*


When you are done removing those items, update your antivirus software and do a complete scan of your computer. Remove anything it finds and then rescan with hijackthis! and post the new log here. There is a lot on your system and I want to make sure you're not infected at that time.
thanks so much. my computer is throwing a fit, and now it wont turn on, so i dont even know where to starrt with thaty problem. it was fine when i left, i came home and it was off, and now it wont turn on. no wire are moved or detached, as far as i can tell everthing is fine. if anyone has had this proglem before, i would love some advice.

ill post my log once i get my computer working again.
Attached Files
File Type: txt kiraz.txt (2.0 KB, 93 views)

Last edited by G10 : 05-09-2006 at 10:16 AM. Reason: Removed log file and put in a text file
kiraz is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-08-2006, 08:26 AM   #71 (permalink)
Zap
Human Tripod
 
Zap's Avatar
 
Join Date: 01-15-06
Location: WEBTALKFORUMS.COM
Posts: 9,881
iTrader: 0 / 0%
Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
@Kiraz: Did you even get a chance to delete the offending items?
__________________
BIG Gaming Forum

Toronto Forum
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-08-2006, 08:30 AM   #72 (permalink)
Inactive
 
Join Date: 04-06-06
Posts: 33
iTrader: 0 / 0%
Latest Blog:
None

kiraz is an unknown quantity at this point
ZAP: No, I just now got on a differant computer, and found your post. Its been down for a few days, It was probably all that crap that corrupted it.
$1500 custom build by me...

I just have no knowledge what so ever on how to fi these kind of situations.
kiraz is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-08-2006, 09:30 AM   #73 (permalink)
Zap
Human Tripod
 
Zap's Avatar
 
Join Date: 01-15-06
Location: WEBTALKFORUMS.COM
Posts: 9,881
iTrader: 0 / 0%
Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
Quote:
Originally Posted by kiraz
ZAP: No, I just now got on a differant computer, and found your post. Its been down for a few days, It was probably all that crap that corrupted it.
$1500 custom build by me...

I just have no knowledge what so ever on how to fi these kind of situations.
I don't think it's hardware related.

It could have happened to anybody. Don't be so hard on yourself.
__________________
BIG Gaming Forum

Toronto Forum
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 09:58 AM   #74 (permalink)
v7n Mentor
 
cashcannon's Avatar
 
Join Date: 01-26-06
Location: netherlands
Posts: 2,077
iTrader: 0 / 0%
Latest Blog:
None

cashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest order
Send a message via ICQ to cashcannon
hey zap, I ran the gaobot, but it didnt turn up any results,

when running avast it found some files it couldnt open


C:\WINDOWS\system32\config\DEFAULT
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\default.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SOFTWARE
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\software.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SYSTEM
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\system.LOG
[WARNING] The file could not be opened!

any advice on this ?

thanks
cashcannon is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 10:18 AM   #75 (permalink)
G10
Super Moderator
 
G10's Avatar
 
Join Date: 05-10-04
Location: UK - Cheshire
Posts: 15,993
iTrader: 0 / 0%
Latest Blog:
None

G10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster material
Guys, if you're going to put your files up here, please save them in a text file
__________________

.: I WAS BORN WITH NOTHING...AND I STILL HAVE MOST OF IT LEFT!! :.
G10 is online now  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 11:05 AM   #76 (permalink)
v7n Mentor
 
cashcannon's Avatar
 
Join Date: 01-26-06
Location: netherlands
Posts: 2,077
iTrader: 0 / 0%
Latest Blog:
None

cashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest order
Send a message via ICQ to cashcannon
sorry bout that
cashcannon is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 01:57 PM   #77 (permalink)
Zap
Human Tripod
 
Zap's Avatar
 
Join Date: 01-15-06
Location: WEBTALKFORUMS.COM
Posts: 9,881
iTrader: 0 / 0%
Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
@Cashcannon: Those files are nothing to worry about. It's perfectly normal for them to be open (and, therefore, uncopyable/undeleteable). They are part of your user profile and are needed by Windows.

What concerns me is the 100% CPU usage in combination with the 2 Sasser patch referenced in your hijackthis! log....

O4 - HKLM\..\RunServices: [Sasser Patch v1 ] msconf.exe
O4 - HKCU\..\Run: [Sasser Patch v1 ] msconf.exe


These files are not normal and should not be there. The file may have been a legitimate Windows file that was infected. But, it is autoloaded twice? by Windows at startup. It's unnecessary and the whole thing looks fishy to me. If it's not Gaobot, then try the sysclean utility attached. Then reboot and rescan your computer with hijackthis! and post the fresh log here.
Attached Files
File Type: zip sysclean.zip (2.86 MB, 35 views)
__________________
BIG Gaming Forum

Toronto Forum
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 02:05 PM   #78 (permalink)
Zap
Human Tripod
 
Zap's Avatar
 
Join Date: 01-15-06
Location: WEBTALKFORUMS.COM
Posts: 9,881
iTrader: 0 / 0%
Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
@Cashcannon: You'll also need to download the lpt413.zip file from the following link and place it in the same directory as the sysclean utility.

lpt413.zip
__________________
BIG Gaming Forum

Toronto Forum

Last edited by Zap : 05-09-2006 at 02:13 PM. Reason: Wrong Attachment
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 02:15 PM   #79 (permalink)
v7n Mentor
 
cashcannon's Avatar
 
Join Date: 01-26-06
Location: netherlands
Posts: 2,077
iTrader: 0 / 0%
Latest Blog:
None

cashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest ordercashcannon is a web professional of the highest order
Send a message via ICQ to cashcannon
I removed what you said, and cpu seems to be normal now, also did a scan with spyhunter and adaware, seems to be acting normal now.

let you know in a jif what the sysclean does
cashcannon is offline  
Add Post to del.icio.us
Reply With Quote