Hi. I posted about this computer on one of my other posts, and now I am able to run it. So I figured that you guys could help me clean it out just like the other one! Here is my HJT log. Thanks so much for all the help!
Logfile of HijackThis v1.97.7 Scan saved at 2:34:24 PM, on 7/9/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Hi AG This line is related to the bridge error you mentioned in your other post. O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load You have a number of other problems too though.
I do not have the time to fully review your log right now, so I'm going to give you a series of steps to get you started and then ask you to post another log.
At this point I hope we will have Dealt with worm/trojan issues. Fixed Hosts file and searchsite redirect issues. Killed wintools. And dealt with some of the remaining issues.
At this point, please reboot and run and post a fresh hjt log and we will see what is left and the necessary steps to finish cleaning your system.
2. Download and run these two programs (Spybot S&D and Adaware) at the link below. Use Spybot first.
Most of the Internet baddies can be killed by a one-two punch with Spybot and Adaware assuming these three factors are achieved:
1. Latest version 2. Configured correctly for running options 3. New definitions from update feature
Chris has posted an excellent tutorial by dgosling on how to run Spybot S&D and also how to enable customized deep scanning functions for Adaware. Once you set these options they will be retained for future scans by Adaware.
Follow the directions in this detailed guide for Spybot and Adaware...print out the directions in the custom scan tutorial as a reference while you set these options for the custom setup of Adaware. These custom settings will be retained for future custom scans so don't go nuts thinking you have to do this every time you run it! It may take you five minutes to set them up, but it's worth it.
Please note the free Spybot 1.3 does have a slight bug...it detects some DSO exploits falsely. Hopefully an upgrade will fix this.The problem is not serious and should not deter people from using Spybot.
I also like to run Windows Disk Cleanup after cleaning with those two tools. Make sure you reboot if any reboot cleanup functions of Spybot and Adaware are advised by these tools (this may happen at the end of their cleanup).
Run Disk Cleanup: type cleanmgr at Start/Run. Scan all hard drives and check all categories at the end and click OK.
Texruss www.russelltexas.com Spyware Fighter Wilders Forum Slyware Warrior Tom Coyote Forum Expert Malware Responder Dell Forum
Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley.
Also...these longtime DellForum regulars have proven to me time and again their advice is excellent for malware questions in general, Windows operations, and many specific items in Hijackthis logs: jimw, ddeerrff, and msgale. Please follow their advice when they respond to your problems. They have a proven track record here.
BTW...clicking on people's usernames at the left will reveal information about them if they chose to have an open profile. My credentials are available for your perusal.
cghost
302 Posts
457
0
Posted July 12th, 2004 04:00
Hi AG
This line is related to the bridge error you mentioned in your other post.
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
You have a number of other problems too though.
I do not have the time to fully review your log right now, so I'm going to give you a series of steps to get you started and then ask you to post another log.
1)O4 - HKLM\..\Run: [Rundll16] C:\WINDOWS\rundll16.exe
This is a worm. Please run the online (housecall) virus scan from trendmicro.
http://uk.trendmicro-europe.com/consumer/products/housecall_pre.php
2)Please install hijackthis in its own directory, such as c:\hjt.
This is necessary to preserve its backups.
Then run hijackthis with browser windows closed and fix these items:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50038
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50038
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50038
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: 64.200.25.145 gator.com #cooklop
O1 - Hosts: 64.200.25.145 doubleclick.net #cooklop
O1 - Hosts: 64.200.25.145 www.doubleclick.net #cooklop
O1 - Hosts: 64.200.25.145 tripod.com #cooklop
O1 - Hosts: 64.200.25.145 www.tripod.com #cooklop
O1 - Hosts: 64.200.25.145 adultfriendfinder.com #cooklop
O1 - Hosts: 64.200.25.145 www.adultfriendfinder.com #cooklop
O1 - Hosts: 64.200.25.145 cj.com #cooklop
O1 - Hosts: 64.200.25.145 www.cj.com #cooklop
O1 - Hosts: 64.200.25.145 paypopup.com #cooklop
O1 - Hosts: 64.200.25.145 www.paypopup.com #cooklop
O1 - Hosts: 64.200.25.145 thehun.net #cooklop
O1 - Hosts: 64.200.25.145 www.thehun.net #cooklop
O1 - Hosts: 64.200.25.145 worldsex.com #cooklop
O1 - Hosts: 64.200.25.145 www.worldsex.com #cooklop
O1 - Hosts: 64.200.25.145 free6.com #cooklop
O1 - Hosts: 64.200.25.145 www.free6.com #cooklop
O1 - Hosts: 64.200.25.145 trafficmp.com #cooklop
O1 - Hosts: 64.200.25.145 www.trafficmp.com #cooklop
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: ay[2] = "3";
O1 - Hosts: var myRepeatArray = new Array();
O1 - Hosts: 280C52}&mSkip=1&rnd=5224", 600000, "TRUE");
O1 - Hosts: 1&rnd=12550", 600000, "TRUE");
O1 - Hosts: ˜JÞ ˆÞ
O1 - Hosts: �Þ
O1 - Hosts: {
O1 - Hosts: if (!Timeout) {
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - (no file)
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50038/QDow_AS2.cab
3)open Task Manager, click Processes tab. End the following processes:
WToolsS.exe
WToolsA.exe
WSup.exe
Close Task Manager.
Check the following items in Hijackthis - close ALL windows\browsers except Hijackthis and click "Fix checked":
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe
Then Boot to safe mode: Instructions here (http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam)
Make sure you can view hidden and system files: Instructions here (http://www.xtra.co.nz/help/0,,4155-1916458,00.html)
NOTE....even in safe mode you may have to open taskmanager and end task on some of them before you can delete them.
Delete the following files\folders IF still present:
C:\PROGRAM FILES\COMMON FILES\WINTOOLS
and
Empty your temporary internet files folder.
4) http://www.cjwd.demon.co.uk/spybot-adaware.html
Please run spybot and adaware as indicated.
At this point I hope we will have
Dealt with worm/trojan issues.
Fixed Hosts file and searchsite redirect issues.
Killed wintools.
And dealt with some of the remaining issues.
At this point, please reboot and run and post a fresh hjt log and we will see what is left and the necessary steps to finish cleaning your system.
Regards