Webmaster Forum


Go Back   Webmaster Forum > The Webmaster Forums > Tech Talk

Tech Talk Discuss computer issues, tech gadgets and hardware, operating systems, browsers, broadband and wireless, virus, trojan, and spyware help.


Reply
 
LinkBack Thread Tools Display Modes
Share |
  #61 (permalink)  
Old 05-06-2006, 10:30 AM
Zap's Avatar
Zap Zap is offline
Super Moderator
Latest Blog:
None

 
Join Date: 01-15-06
Location: Canada
Posts: 13,029
iTrader: 5 / 100%
@Henny:

You can remove...

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

(The line above is not dangerous, but unnecessary, unless you need Quicktime to load fast because of frequent usage)

The following line alters your DNS servers...
O17 - HKLM\System\CCS\Services\Tcpip\..\{51508C5E-72F4-4DC7-AAFD-3375D32F1249}: NameServer = 68.238.1.12,68.238.112.12

(If you know why, then that's fine. In and of itself, it's not a problem, but could indicate a problem - Again, if you know why your nameservers might have been altered by something you installed, then that's fine. Your system looks clean, so I wouldn't worry about this one anomoly)
__________________
Toronto Wedding Cakes ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ GET FREE EXPOSURE FOR YOUR BLOG!

"Whatever doesn't kill you, makes you smaller." - Mario
 
Reply With Quote
  #62 (permalink)  
Old 05-06-2006, 03:18 PM
Henny's Avatar
Junior Member
 
Join Date: 04-19-06
Posts: 27
iTrader: 0 / 0%
Wow! Thanks ZAP!
 
Reply With Quote
  #63 (permalink)  
Old 05-06-2006, 03:25 PM
Zap's Avatar
Zap Zap is offline
Super Moderator
Latest Blog:
None

 
Join Date: 01-15-06
Location: Canada
Posts: 13,029
iTrader: 5 / 100%
Quote:
Originally Posted by Henny
Wow! Thanks ZAP!
NP. Didn't really help you much. You're clean.
__________________
Toronto Wedding Cakes ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ GET FREE EXPOSURE FOR YOUR BLOG!

"Whatever doesn't kill you, makes you smaller." - Mario
 
Reply With Quote
  #64 (permalink)  
Old 05-07-2006, 10:21 AM
Henny's Avatar
Junior Member
 
Join Date: 04-19-06
Posts: 27
iTrader: 0 / 0%
Yeah, but peice of mind is worth a thank-you , isn't it?
 
Reply With Quote
  #65 (permalink)  
Old 05-07-2006, 11:27 AM
Zap's Avatar
Zap Zap is offline
Super Moderator
Latest Blog:
None

 
Join Date: 01-15-06
Location: Canada
Posts: 13,029
iTrader: 5 / 100%
Well, you're welcome. You have no worries. Your hijackthis! log is one of the cleaner ones I've seen.
__________________
Toronto Wedding Cakes ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ GET FREE EXPOSURE FOR YOUR BLOG!

"Whatever doesn't kill you, makes you smaller." - Mario
 
Reply With Quote
  #66 (permalink)  
Old 05-07-2006, 02:10 PM
Tomassi's Avatar
v7n Mentor
Latest Blog:
None

 
Join Date: 01-26-06
Location: Alkmaar
Posts: 2,506
iTrader: 0 / 0%
I got a log to, pc at home is running at constant 100% cpu and I have no idea why

ran avast and gave me a list of warnings of files it couldnt open
mostly mtuser.dat files

hope you see something fishy

thnx
Attached Files
File Type: txt hijackthisloggie.txt (5.2 KB, 228 views)
 
Reply With Quote
  #67 (permalink)  
Old 05-07-2006, 02:53 PM
NeO's Avatar
NeO NeO is offline
v7n Mentor
 
Join Date: 01-07-06
Location: City of Subdued Excitement
Posts: 319
iTrader: 1 / 100%
Is this the log from the pc that's running @100% ?

I didn't see anything other than all of the music software that your using that would indicate a hijack of any type...

Zap you see anything that is potentially hazardous?

NeO
__________________
Learn SEO 101 from yours truly. Or just follow a dude with a 'stache' - it's cool, either way.
 
Reply With Quote
  #68 (permalink)  
Old 05-07-2006, 03:41 PM
Zap's Avatar
Zap Zap is offline
Super Moderator
Latest Blog:
None

 
Join Date: 01-15-06
Location: Canada
Posts: 13,029
iTrader: 5 / 100%
@Cashcannon:

You can remove...

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\RunServices: [Sasser Patch v1 ] msconf.exe
O4 - HKCU\..\Run: [Sasser Patch v1 ] msconf.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)


The 2 references to the Sasser patch stand out at me. It is possible that you have a virus because you also complain of 100% CPU usage. I found one virus write up that might fit the bill for you.

Read This and download the removal tool zipfile attached to this post. Remove the tool from the zipfile and run it. Let it remove anything it finds.

Then update your antivirus software definitions and do a full scan of your computer.

Then scan your computer again with hijackthis! and post a new hijackthis! log here.
Attached Files
File Type: zip FxGaobot.zip (164.5 KB, 47 views)
__________________
Toronto Wedding Cakes ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ GET FREE EXPOSURE FOR YOUR BLOG!

"Whatever doesn't kill you, makes you smaller." - Mario
 
Reply With Quote
  #69 (permalink)  
Old 05-07-2006, 11:52 PM
Tomassi's Avatar
v7n Mentor
Latest Blog:
None

 
Join Date: 01-26-06
Location: Alkmaar
Posts: 2,506
iTrader: 0 / 0%
thanks for your time Zap, much appreciated, I'll post the hijack log in the evening
 
Reply With Quote
  #70 (permalink)  
Old 05-08-2006, 08:24 AM
Junior Member
 
Join Date: 04-06-06
Posts: 27
iTrader: 0 / 0%
Quote:
Originally Posted by Zap
@Kiraz:

You can get rid of... *Removed but kindly put in a text file for you :-)*


When you are done removing those items, update your antivirus software and do a complete scan of your computer. Remove anything it finds and then rescan with hijackthis! and post the new log here. There is a lot on your system and I want to make sure you're not infected at that time.
thanks so much. my computer is throwing a fit, and now it wont turn on, so i dont even know where to starrt with thaty problem. it was fine when i left, i came home and it was off, and now it wont turn on. no wire are moved or detached, as far as i can tell everthing is fine. if anyone has had this proglem before, i would love some advice.

ill post my log once i get my computer working again.
Attached Files
File Type: txt kiraz.txt (2.0 KB, 225 views)

Last edited by G10; 05-09-2006 at 10:16 AM. Reason: Removed log file and put in a text file
 
Reply With Quote
  #71 (permalink)  
Old 05-08-2006, 08:26 AM
Zap's Avatar
Zap Zap is offline
Super Moderator
Latest Blog:
None

 
Join Date: 01-15-06
Location: Canada
Posts: 13,029
iTrader: 5 / 100%
@Kiraz: Did you even get a chance to delete the offending items?
__________________
Toronto Wedding Cakes ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ GET FREE EXPOSURE FOR YOUR BLOG!

"Whatever doesn't kill you, makes you smaller." - Mario
 
Reply With Quote
  #72 (permalink)  
Old 05-08-2006, 08:30 AM
Junior Member
 
Join Date: 04-06-06
Posts: 27
iTrader: 0 / 0%
ZAP: No, I just now got on a differant computer, and found your post. Its been down for a few days, It was probably all that crap that corrupted it.
$1500 custom build by me...

I just have no knowledge what so ever on how to fi these kind of situations.
 
Reply With Quote
  #73 (permalink)  
Old 05-08-2006, 09:30 AM
Zap's Avatar
Zap Zap is offline
Super Moderator
Latest Blog:
None

 
Join Date: 01-15-06
Location: Canada
Posts: 13,029
iTrader: 5 / 100%
Quote:
Originally Posted by kiraz
ZAP: No, I just now got on a differant computer, and found your post. Its been down for a few days, It was probably all that crap that corrupted it.
$1500 custom build by me...

I just have no knowledge what so ever on how to fi these kind of situations.
I don't think it's hardware related.

It could have happened to anybody. Don't be so hard on yourself.
__________________
Toronto Wedding Cakes ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ GET FREE EXPOSURE FOR YOUR BLOG!

"Whatever doesn't kill you, makes you smaller." - Mario
 
Reply With Quote
  #74 (permalink)  
Old 05-09-2006, 09:58 AM
Tomassi's Avatar
v7n Mentor
Latest Blog:
None

 
Join Date: 01-26-06
Location: Alkmaar
Posts: 2,506
iTrader: 0 / 0%
hey zap, I ran the gaobot, but it didnt turn up any results,

when running avast it found some files it couldnt open


C:\WINDOWS\system32\config\DEFAULT
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\default.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SOFTWARE
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\software.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SYSTEM
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\system.LOG
[WARNING] The file could not be opened!

any advice on this ?

thanks
 
Reply With Quote
  #75 (permalink)  
Old 05-09-2006, 10:18 AM
G10's Avatar
G10 G10 is offline
Super Moderator
Latest Blog:
None

 
Join Date: 05-10-04
Location: UK - Cheshire
Posts: 11,427
iTrader: 5 / 100%
Guys, if you're going to put your files up here, please save them in a text file
__________________
Click Here for Chester Carpet Cleaners
 
Reply With Quote
  #76 (permalink)  
Old 05-09-2006, 11:05 AM
Tomassi's Avatar
v7n Mentor
Latest Blog:
None

 
Join Date: 01-26-06
Location: Alkmaar
Posts: 2,506
iTrader: 0 / 0%
sorry bout that
 
Reply With Quote
  #77 (permalink)  
Old 05-09-2006, 01:57 PM
Zap's Avatar
Zap Zap is offline
Super Moderator
Latest Blog:
None

 
Join Date: 01-15-06
Location: Canada
Posts: 13,029
iTrader: 5 / 100%
@Cashcannon: Those files are nothing to worry about. It's perfectly normal for them to be open (and, therefore, uncopyable/undeleteable). They are part of your user profile and are needed by Windows.

What concerns me is the 100% CPU usage in combination with the 2 Sasser patch referenced in your hijackthis! log....

O4 - HKLM\..\RunServices: [Sasser Patch v1 ] msconf.exe
O4 - HKCU\..\Run: [Sasser Patch v1 ] msconf.exe


These files are not normal and should not be there. The file may have been a legitimate Windows file that was infected. But, it is autoloaded twice? by Windows at startup. It's unnecessary and the whole thing looks fishy to me. If it's not Gaobot, then try the sysclean utility attached. Then reboot and rescan your computer with hijackthis! and post the fresh log here.
Attached Files
File Type: zip sysclean.zip (2.86 MB, 48 views)
__________________
Toronto Wedding Cakes ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ GET FREE EXPOSURE FOR YOUR BLOG!

"Whatever doesn't kill you, makes you smaller." - Mario
 
Reply With Quote
  #78 (permalink)  
Old 05-09-2006, 02:05 PM
Zap's Avatar
Zap Zap is offline
Super Moderator
Latest Blog:
None

 
Join Date: 01-15-06
Location: Canada
Posts: 13,029
iTrader: 5 / 100%
@Cashcannon: You'll also need to download the lpt413.zip file from the following link and place it in the same directory as the sysclean utility.

lpt413.zip
__________________
Toronto Wedding Cakes ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ GET FREE EXPOSURE FOR YOUR BLOG!

"Whatever doesn't kill you, makes you smaller." - Mario

Last edited by Zap; 05-09-2006 at 02:13 PM. Reason: Wrong Attachment
 
Reply With Quote
  #79 (permalink)  
Old 05-09-2006, 02:15 PM
Tomassi's Avatar
v7n Mentor
Latest Blog:
None

 
Join Date: 01-26-06
Location: Alkmaar
Posts: 2,506
iTrader: 0 / 0%
I removed what you said, and cpu seems to be normal now, also did a scan with spyhunter and adaware, seems to be acting normal now.

let you know in a jif what the sysclean does
 
Reply With Quote
  #80 (permalink)  
Old 05-09-2006, 03:27 PM
Tomassi's Avatar
v7n Mentor
Latest Blog:
None

 
Join Date: 01-26-06
Location: Alkmaar
Posts: 2,506
iTrader: 0 / 0%
it found zero virusses, and cpu didnt freak out, Im going to bed now

thanks alot for the trouble!
 
Reply With Quote
Go Back   Webmaster Forum > The Webmaster Forums > Tech Talk

Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
hide identity/ip from logs? River Internet Legal Issues 1 07-13-2007 11:53 PM
Logs PaulHarris Marketing Forum 2 06-06-2004 12:09 PM


V7N Network
Get exposure! V7N I Love Photography V7N SEO Blog V7N Directory


All times are GMT -7. The time now is 01:22 AM.
Powered by vBulletin
Copyright © 2000-2013 Jelsoft Enterprises Limited.
Copyright © 2003 - 2013 Escalate Media LP




Search Engine Optimization by vBSEO 3.6.0 RC 2 ©2011, Crawlability, Inc.