Webmaster Forum

Go Back   Webmaster Forum > The Webmaster Forums > Tech Support Forum

Tech Support Forum Discuss computer issues, tech gadgets and hardware, operating systems, browsers, broadband and wireless, virus, trojan, and spyware help.


Reply
 
LinkBack Thread Tools Display Modes
Old 05-06-2006, 11:30 AM   #61 (permalink)
Zap
Super Moderator
 
Zap's Avatar
 
Join Date: 01-15-06
Location: BTWIMHO.COM
Posts: 10,622
iTrader: 4 / 100%
Latest Blog:
Game bloopers

Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
@Henny:

You can remove...

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

(The line above is not dangerous, but unnecessary, unless you need Quicktime to load fast because of frequent usage)

The following line alters your DNS servers...
O17 - HKLM\System\CCS\Services\Tcpip\..\{51508C5E-72F4-4DC7-AAFD-3375D32F1249}: NameServer = 68.238.1.12,68.238.112.12

(If you know why, then that's fine. In and of itself, it's not a problem, but could indicate a problem - Again, if you know why your nameservers might have been altered by something you installed, then that's fine. Your system looks clean, so I wouldn't worry about this one anomoly)
__________________
Toronto Forum ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ FREE Norton 360 Up For Grabs!
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-06-2006, 04:18 PM   #62 (permalink)
Junior Member
 
Henny's Avatar
 
Join Date: 04-19-06
Posts: 27
iTrader: 0 / 0%
Latest Blog:
None

Henny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the rough
Send a message via MSN to Henny
Wow! Thanks ZAP!
Henny is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-06-2006, 04:25 PM   #63 (permalink)
Zap
Super Moderator
 
Zap's Avatar
 
Join Date: 01-15-06
Location: BTWIMHO.COM
Posts: 10,622
iTrader: 4 / 100%
Latest Blog:
Game bloopers

Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
Quote:
Originally Posted by Henny
Wow! Thanks ZAP!
NP. Didn't really help you much. You're clean.
__________________
Toronto Forum ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ FREE Norton 360 Up For Grabs!
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-07-2006, 11:21 AM   #64 (permalink)
Junior Member
 
Henny's Avatar
 
Join Date: 04-19-06
Posts: 27
iTrader: 0 / 0%
Latest Blog:
None

Henny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the roughHenny is a jewel in the rough
Send a message via MSN to Henny
Yeah, but peice of mind is worth a thank-you , isn't it?
Henny is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-07-2006, 12:27 PM   #65 (permalink)
Zap
Super Moderator
 
Zap's Avatar
 
Join Date: 01-15-06
Location: BTWIMHO.COM
Posts: 10,622
iTrader: 4 / 100%
Latest Blog:
Game bloopers

Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
Well, you're welcome. You have no worries. Your hijackthis! log is one of the cleaner ones I've seen.
__________________
Toronto Forum ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ FREE Norton 360 Up For Grabs!
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-07-2006, 03:10 PM   #66 (permalink)
v7n Mentor
 
Tomassi's Avatar
 
Join Date: 01-26-06
Location: Amsterdam
Posts: 2,487
iTrader: 0 / 0%
Latest Blog:
None

Tomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest order
Send a message via ICQ to Tomassi
I got a log to, pc at home is running at constant 100% cpu and I have no idea why

ran avast and gave me a list of warnings of files it couldnt open
mostly mtuser.dat files

hope you see something fishy

thnx
Attached Files
File Type: txt hijackthisloggie.txt (5.2 KB, 166 views)
Tomassi is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-07-2006, 03:53 PM   #67 (permalink)
NeO
v7n Mentor
 
NeO's Avatar
 
Join Date: 01-07-06
Location: 127.0.0.1
Posts: 297
iTrader: 1 / 100%
NeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest order
Is this the log from the pc that's running @100% ?

I didn't see anything other than all of the music software that your using that would indicate a hijack of any type...

Zap you see anything that is potentially hazardous?

NeO
__________________
I can levitate birds....No one cares...

Top SEO Consultants | Beginning SEO Podcast
NeO is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-07-2006, 04:41 PM   #68 (permalink)
Zap
Super Moderator
 
Zap's Avatar
 
Join Date: 01-15-06
Location: BTWIMHO.COM
Posts: 10,622
iTrader: 4 / 100%
Latest Blog:
Game bloopers

Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
@Cashcannon:

You can remove...

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\RunServices: [Sasser Patch v1 ] msconf.exe
O4 - HKCU\..\Run: [Sasser Patch v1 ] msconf.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)


The 2 references to the Sasser patch stand out at me. It is possible that you have a virus because you also complain of 100% CPU usage. I found one virus write up that might fit the bill for you.

Read This and download the removal tool zipfile attached to this post. Remove the tool from the zipfile and run it. Let it remove anything it finds.

Then update your antivirus software definitions and do a full scan of your computer.

Then scan your computer again with hijackthis! and post a new hijackthis! log here.
Attached Files
File Type: zip FxGaobot.zip (164.5 KB, 35 views)
__________________
Toronto Forum ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ FREE Norton 360 Up For Grabs!
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-08-2006, 12:52 AM   #69 (permalink)
v7n Mentor
 
Tomassi's Avatar
 
Join Date: 01-26-06
Location: Amsterdam
Posts: 2,487
iTrader: 0 / 0%
Latest Blog:
None

Tomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest order
Send a message via ICQ to Tomassi
thanks for your time Zap, much appreciated, I'll post the hijack log in the evening
Tomassi is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-08-2006, 09:24 AM   #70 (permalink)
Junior Member
 
Join Date: 04-06-06
Posts: 27
iTrader: 0 / 0%
Latest Blog:
None

kiraz is an unknown quantity at this point
Quote:
Originally Posted by Zap
@Kiraz:

You can get rid of... *Removed but kindly put in a text file for you :-)*


When you are done removing those items, update your antivirus software and do a complete scan of your computer. Remove anything it finds and then rescan with hijackthis! and post the new log here. There is a lot on your system and I want to make sure you're not infected at that time.
thanks so much. my computer is throwing a fit, and now it wont turn on, so i dont even know where to starrt with thaty problem. it was fine when i left, i came home and it was off, and now it wont turn on. no wire are moved or detached, as far as i can tell everthing is fine. if anyone has had this proglem before, i would love some advice.

ill post my log once i get my computer working again.
Attached Files
File Type: txt kiraz.txt (2.0 KB, 159 views)

Last edited by G10; 05-09-2006 at 11:16 AM.. Reason: Removed log file and put in a text file
kiraz is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-08-2006, 09:26 AM   #71 (permalink)
Zap
Super Moderator
 
Zap's Avatar
 
Join Date: 01-15-06
Location: BTWIMHO.COM
Posts: 10,622
iTrader: 4 / 100%
Latest Blog:
Game bloopers

Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
@Kiraz: Did you even get a chance to delete the offending items?
__________________
Toronto Forum ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ FREE Norton 360 Up For Grabs!
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-08-2006, 09:30 AM   #72 (permalink)
Junior Member
 
Join Date: 04-06-06
Posts: 27
iTrader: 0 / 0%
Latest Blog:
None

kiraz is an unknown quantity at this point
ZAP: No, I just now got on a differant computer, and found your post. Its been down for a few days, It was probably all that crap that corrupted it.
$1500 custom build by me...

I just have no knowledge what so ever on how to fi these kind of situations.
kiraz is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-08-2006, 10:30 AM   #73 (permalink)
Zap
Super Moderator
 
Zap's Avatar
 
Join Date: 01-15-06
Location: BTWIMHO.COM
Posts: 10,622
iTrader: 4 / 100%
Latest Blog:
Game bloopers

Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
Quote:
Originally Posted by kiraz
ZAP: No, I just now got on a differant computer, and found your post. Its been down for a few days, It was probably all that crap that corrupted it.
$1500 custom build by me...

I just have no knowledge what so ever on how to fi these kind of situations.
I don't think it's hardware related.

It could have happened to anybody. Don't be so hard on yourself.
__________________
Toronto Forum ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ FREE Norton 360 Up For Grabs!
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 10:58 AM   #74 (permalink)
v7n Mentor
 
Tomassi's Avatar
 
Join Date: 01-26-06
Location: Amsterdam
Posts: 2,487
iTrader: 0 / 0%
Latest Blog:
None

Tomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest order
Send a message via ICQ to Tomassi
hey zap, I ran the gaobot, but it didnt turn up any results,

when running avast it found some files it couldnt open


C:\WINDOWS\system32\config\DEFAULT
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\default.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SOFTWARE
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\software.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SYSTEM
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\system.LOG
[WARNING] The file could not be opened!

any advice on this ?

thanks
Tomassi is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 11:18 AM   #75 (permalink)
G10
Super Moderator
 
G10's Avatar
 
Join Date: 05-10-04
Location: UK - Cheshire
Posts: 10,020
iTrader: 0 / 0%
Latest Blog:
None

G10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster material
Guys, if you're going to put your files up here, please save them in a text file
__________________

.: I WAS BORN WITH NOTHING...AND I STILL HAVE MOST OF IT LEFT!! :.
G10 is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 12:05 PM   #76 (permalink)
v7n Mentor
 
Tomassi's Avatar
 
Join Date: 01-26-06
Location: Amsterdam
Posts: 2,487
iTrader: 0 / 0%
Latest Blog:
None

Tomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest order
Send a message via ICQ to Tomassi
sorry bout that
Tomassi is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 02:57 PM   #77 (permalink)
Zap
Super Moderator
 
Zap's Avatar
 
Join Date: 01-15-06
Location: BTWIMHO.COM
Posts: 10,622
iTrader: 4 / 100%
Latest Blog:
Game bloopers

Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
@Cashcannon: Those files are nothing to worry about. It's perfectly normal for them to be open (and, therefore, uncopyable/undeleteable). They are part of your user profile and are needed by Windows.

What concerns me is the 100% CPU usage in combination with the 2 Sasser patch referenced in your hijackthis! log....

O4 - HKLM\..\RunServices: [Sasser Patch v1 ] msconf.exe
O4 - HKCU\..\Run: [Sasser Patch v1 ] msconf.exe


These files are not normal and should not be there. The file may have been a legitimate Windows file that was infected. But, it is autoloaded twice? by Windows at startup. It's unnecessary and the whole thing looks fishy to me. If it's not Gaobot, then try the sysclean utility attached. Then reboot and rescan your computer with hijackthis! and post the fresh log here.
Attached Files
File Type: zip sysclean.zip (2.86 MB, 44 views)
__________________
Toronto Forum ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ FREE Norton 360 Up For Grabs!
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 03:05 PM   #78 (permalink)
Zap
Super Moderator
 
Zap's Avatar
 
Join Date: 01-15-06
Location: BTWIMHO.COM
Posts: 10,622
iTrader: 4 / 100%
Latest Blog:
Game bloopers

Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
@Cashcannon: You'll also need to download the lpt413.zip file from the following link and place it in the same directory as the sysclean utility.

lpt413.zip
__________________
Toronto Forum ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ FREE Norton 360 Up For Grabs!

Last edited by Zap; 05-09-2006 at 03:13 PM.. Reason: Wrong Attachment
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 03:15 PM   #79 (permalink)
v7n Mentor
 
Tomassi's Avatar
 
Join Date: 01-26-06
Location: Amsterdam
Posts: 2,487
iTrader: 0 / 0%
Latest Blog:
None

Tomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest order
Send a message via ICQ to Tomassi
I removed what you said, and cpu seems to be normal now, also did a scan with spyhunter and adaware, seems to be acting normal now.

let you know in a jif what the sysclean does
Tomassi is offline  
Add Post to del.icio.us
Reply With Quote
Old 05-09-2006, 04:27 PM   #80 (permalink)
v7n Mentor
 
Tomassi's Avatar
 
Join Date: 01-26-06
Location: Amsterdam
Posts: 2,487
iTrader: 0 / 0%
Latest Blog:
None

Tomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest orderTomassi is a web professional of the highest order
Send a message via ICQ to Tomassi
it found zero virusses, and cpu didnt freak out, Im going to bed now

thanks alot for the trouble!
Tomassi is offline  
Add Post to del.icio.us
Reply With Quote
Go Back   Webmaster Forum > The Webmaster Forums > Tech Support Forum

Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
hide identity/ip from logs? River Internet Legal Issues 1 07-14-2007 12:53 AM
All right kids, time to look at your logs Henny Forum Lobby 21 04-28-2006 03:31 PM
Logs PaulHarris Marketing Forum 2 06-06-2004 01:09 PM


Sponsor Links
Get exposure! Contextual Links V7N SEO Blog V7N Directory


All times are GMT -7. The time now is 11:19 AM.
© Copyright 2008 V7 Inc
Powered by vBulletin
Copyright © 2000-2009 Jelsoft Enterprises Limited.


Search Engine Optimization by vBSEO 3.3.0 ©2009, Crawlability, Inc.