Unsolved

This post is more than 5 years old

62 Posts

408

August 28th, 2005 19:00

HGT won't run

I believe I have a worm and am trying to run Hijack This. I followed the instructions in the FAQ above. But when I double click on HJT in it's folder it opens and closes within a second.

I have already run Ad-aware, Spybot S&D, Trogan Hunter, Avast!, AVG, and maybe others. I have found two trojan horses, other spyware, and adware that are cleaned out. There is something left still though. With Spybot the registry entry: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
always shows up, and can't be fixed. That has lead me to web pages that say it could be a worm sending passwords out.

Other problems are, I can't load Norton AntiVirus. Couldn't load XP SP2, but did get it installed from Safe Mode. Hasn't helped though.

A reinstall of the OS was done before I started investigating the problem. The worm, or whatever probably survived that.

This is in a Dimension 4600C with 40GB HD. I'm thinking replacing the HD would be easiet now.

Thanks for any help or ideas,

Jim A.

2 Intern

 • 

5.9K Posts

August 29th, 2005 23:00

Get this program and extract it to your desktop then run it.  It may let you run HJT after that. http://www.safer-networking.org/files/delcwssk.zip

If not you may need this file:
 
 
If all else fails then get:
 
 
and see if it will work instead.  It will create a log in the same folder if you ask it to Save.  You can post that instead.
 
Ron

62 Posts

August 30th, 2005 00:00

Thanks for the reply. I finally gave up and we have done an fdisk, which considering everything was lost before this anyway, was the easiest thing to do. Hopefully that got rid of the worm we were trying to get rid of. It had survived a reinstall of Windows, but I guess that doesn't do a low level format. Or we will find out if it survived again. If that's the case, we will get a new hard drive.

Jim

2 Intern

 • 

5.9K Posts

August 30th, 2005 12:00

First thing you need to do before putting it on line is to make sure the firewall is active.  Better would be to install Zone Alarm's free firewall.  Then go to windowsupdate.microsoft.com and get all of your patches and service packs before you do anything else.  An unpatched system is vulnerable to 100's of attacks and you can get reinfected within minutes of going on line.
 
Ron
 
Following is my "cleaned system" post which might be of use to you so you don't get reinfected.
 
Make sure you have System Restore running (toggle it off and On today to get rid of any bad stuff it may have retained) and then you can just go back to an earlier time if you hit a bad site.  One way to make this more obvious is to check everything in your current HijackThis and Add to Ignore List then set up Hijackthis to run at boot and to show you if it finds anything new.
http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/systemrestore.mspx
 
To avoid going to a bad site you might want to install IE-SpyAd and SpywareBlaster and make the other changes recommended at:.
http://www.mvps.org/winhelp2002/restricted.htm
I used to recommend Spybot's Immunize system but have recently learned it is not as good as the one at:
http://www.mvps.org/winhelp2002/hosts.htm
Never hurts to do one of the free on line scans from Panda or Trend.  They take a while but are pretty good.
www.pandasoftware.com/activescan/activescan.asp?
http://housecall.trendmicro.com/
In addition to Microsoft AntiSpy
http://www.microsoft.com/athome/security/downloads/default.mspx
I like to run Spybot S&D. 
http://www.safer-networking.org/en/download/index.html
Also like to run AdAware once in a while. 
http://www.lavasoftusa.com/software/adaware/
Ron
No Events found!

Top