• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
Sign in to follow this  
Followers 0
kenji

hxdefdrv.sys freaks me out

4 posts in this topic

From yesterday, I was bothered by a hacdef 084 trojan. I can't

download hijackthis or CWShredder to my PC. After renaming hijackthis,

I copied it to my pc. I scaned my pc and got the log as follows. It's really annoying that I can't download anti-trojan software anymore. My

OS is win2000. And the online virus scan indicated my pc was

infected by hxdefdrv.sys( trojan hacdef 084). Even after get rid of it,

the trojan reappear after reboot. This trojan really haunts me.

 

Any help will be appreciated!

 

---------------------------------------------------------

Logfile of HijackThis v1.97.7

Scan saved at 23:43:49, on 2004-5-19

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\spoolsv.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\system32\stisvc.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\Explorer.EXE

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

D:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\MSN Messenger\msnmsgr.exe

 

 

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FLASHGET\jccatch.dll (file missing)

O3 - Toolbar: ????? - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll (file missing)

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - Startup: NTUSER.DAT

O4 - Startup: ntuser.dat.LOG

O4 - Startup: ntuser.ini

O4 - Startup: AdobeWeb.log

O4 - Startup: ~

O4 - Global Startup: ntuser.pol

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

Share this post


Link to post
Share on other sites

There appears to be lines missing from the log - Please rerun HijackThis and when you save the log, click on "Edit" => "Select All" in notepad, then "Edit" => "Copy" and post the log in it's entirety.

 

Please make sure that you create a new directory c:\HJT and move the HijackThis.exe file into that directory and only run it from there.

 

In the mean time, the following should be deleted in HijackThis:

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FLASHGET\jccatch.dll (file missing)

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll (file missing)

 

I am not familiar with the following but they do not sit right with me:

O4 - Startup: NTUSER.DAT

O4 - Startup: ntuser.dat.LOG

O4 - Startup: ntuser.ini

O4 - Startup: AdobeWeb.log

O4 - Startup: ~

O4 - Global Startup: ntuser.pol

Delete them (After making sure you are running HijackThis from C:\HJT - In the event that we need to restore the entries after the fact).

Share this post


Link to post
Share on other sites

These entires:

O4 - Startup: NTUSER.DAT

O4 - Startup: ntuser.dat.LOG

O4 - Startup: ntuser.ini

O4 - Startup: AdobeWeb.log

O4 - Startup: ~

O4 - Global Startup: ntuser.pol

May be okay - I was informed that you are running the Japanese version of Windows so you can leave them be :)

Share this post


Link to post
Share on other sites

Due to no response, I am closing this thread.

 

If you need this topic reopened, please request this by sending the moderating team an email with the address of the thread. This applies only to the original topic starter. Everyone else please begin a New Topic.

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.
Sign in to follow this  
Followers 0