Page 2 of 2 FirstFirst 12
Results 11 to 15 of 15

Thread: My HiJackThis Scan (Need Help)

  1. Registered TeamPlayer enf's Avatar
    Join Date
    03-15-07
    Posts
    12,497
    Post Thanks / Like
    Blog Entries
    1
    Stat Links

    My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help)
    Gamer IDs

    Steam ID: enf11
    #11

    Re: My HiJackThis Scan (Need Help)

    I dont have enough time to go through the whole list but if you want to be sparkling clean, there are still a lot of lines Im questionable about. Any time you see an exe coming from your System32 or sysWOW64 folder, you should google the exe file to see if its legit or not.

    C:\Windows\system32\rundll32.exe -- usually legit

    C:\Windows\system32\FBAgent.exe -- ehhhhhh (upon googling this its just ASUS FastBoot, but you can never be too sure and also need to make sure the file is in the right location that the website lists because these viruses like to mask their files as the same name but a different location.

    And even if they are legit, they might be services you dont need running in the background to bog down your computer. Usually Ill see like RealPlayer, expired tools that came with the computer, etc...
    Last edited by enf; 04-06-12 at 08:32 AM.
    Quote Originally Posted by ATEXANnHISGUN View Post
    given the right set of circumstances I can motivate myself to eat a plate full of shit.

  2. Administrator Kanati's Avatar
    Join Date
    05-15-08
    Location
    Pekin, Illinois, United States
    Posts
    17,724
    Post Thanks / Like
    Stat Links

    My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help)
    #12

    Re: My HiJackThis Scan (Need Help)

    rundll32.exe is just a shell to run executable code from a dll file. So while rundll32.exe is usually legit, the code it's running from a dll might not be.



    If you add the command line column to your task manager's processes tab you can see what dll is being accessed by rundll32.exe and then look up the dll itself to see if it's legit. (Go to View->Select Columns. It's towards the bottom.)

    Krakkens and shit. stop tempting them.
    -- Bigdog

  3. Registered TeamPlayer
    Join Date
    09-15-07
    Posts
    1,559
    Post Thanks / Like
    Stat Links

    My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help)
    #13

    Re: My HiJackThis Scan (Need Help)

    If the system is still screwed up, you should consider the following:
    1. How comfortable and how long will it take you to rebuild the whole OS and reinstall your apps
    2. How much more time are you willing to expend to try to eliminate the virus

    If 1 is less than 2...

    Also, do you have a second computer you can add this drive to as a secondary to run a sweep from a clean system?

  4. Administrator Kanati's Avatar
    Join Date
    05-15-08
    Location
    Pekin, Illinois, United States
    Posts
    17,724
    Post Thanks / Like
    Stat Links

    My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help)
    #14

    Re: My HiJackThis Scan (Need Help)

    Quote Originally Posted by RhysJD3 View Post
    Also, do you have a second computer you can add this drive to as a secondary to run a sweep from a clean system?
    Seconded. If it's rootkitted you might not find it without pulling the drive and running a scan from a clean machine. Assuming it's not clean, which you indicated you thought it was.

    Krakkens and shit. stop tempting them.
    -- Bigdog

  5. Registered TeamPlayer SOPEK's Avatar
    Join Date
    10-14-07
    Location
    SF Bay Area
    Posts
    574
    Post Thanks / Like
    Stat Links

    My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help) My HiJackThis Scan (Need Help)
    Gamer IDs

    Gamertag: sopeksopek Steam ID: sopek_ SOPEK's Originid: SOPEK_SOPEK
    #15

    Re: My HiJackThis Scan (Need Help)

    Quote Originally Posted by Mr_Blonde_OPS View Post
    Well it looks like I got rid of it. From your help and some research of my own, my computer seems to be virus free. Thanks for all your help.

    I don't see anyone bring up the analyzer but did you use it? HijackThis Logfileauswertung

    I also use autoruns to see and spot process and CCleaner

    for what it's worth

Page 2 of 2 FirstFirst 12

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Title