UNSOLVED

AGbasketball17

updated

22 years ago

0

3979

July 9th, 2004 17:00

Please, please, please help.

Hi. I posted about this computer on one of my other posts, and now I am able to run it. So I figured that you guys could help me clean it out just like the other one! Here is my HJT log. Thanks so much for all the help!

Logfile of HijackThis v1.97.7
Scan saved at 2:34:24 PM, on 7/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\WINDOWS\vlqxlioa.exe
C:\PROGRA~1\ACCELE~1\SYSTEM~1\sys_alert.exe
C:\WINDOWS\System32\YAHOOMSG.EXE
C:\Program Files\AIM\aim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\WinTools\WToolsA.exe
C:\Program Files\Common files\WinTools\WToolsS.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\Documents and Settings\Anthony.4DYWCP2SHUEER01\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50038
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50038
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50038
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: 64.200.25.145 gator.com #cooklop
O1 - Hosts: 64.200.25.145 doubleclick.net #cooklop
O1 - Hosts: 64.200.25.145 www.doubleclick.net #cooklop
O1 - Hosts: 64.200.25.145 tripod.com #cooklop
O1 - Hosts: 64.200.25.145 www.tripod.com #cooklop
O1 - Hosts: 64.200.25.145 adultfriendfinder.com #cooklop
O1 - Hosts: 64.200.25.145 www.adultfriendfinder.com #cooklop
O1 - Hosts: 64.200.25.145 cj.com #cooklop
O1 - Hosts: 64.200.25.145 www.cj.com #cooklop
O1 - Hosts: 64.200.25.145 paypopup.com #cooklop
O1 - Hosts: 64.200.25.145 www.paypopup.com #cooklop
O1 - Hosts: 64.200.25.145 thehun.net #cooklop
O1 - Hosts: 64.200.25.145 www.thehun.net #cooklop
O1 - Hosts: 64.200.25.145 worldsex.com #cooklop
O1 - Hosts: 64.200.25.145 www.worldsex.com #cooklop
O1 - Hosts: 64.200.25.145 free6.com #cooklop
O1 - Hosts: 64.200.25.145 www.free6.com #cooklop
O1 - Hosts: 64.200.25.145 trafficmp.com #cooklop
O1 - Hosts: 64.200.25.145 www.trafficmp.com #cooklop
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: ay[2] = "3";
O1 - Hosts: var myRepeatArray = new Array();
O1 - Hosts: 280C52}&mSkip=1&rnd=5224", 600000, "TRUE");
O1 - Hosts: 1&rnd=12550", 600000, "TRUE");
O1 - Hosts: ˜JÞ ˆÞ
O1 - Hosts: �Þ
O1 - Hosts: {
O1 - Hosts: if (!Timeout) {
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - (no file)
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Rule peak chin - {EF91288F-9C79-4FDC-D269-3063A5FC9423} - C:\PROGRA~1\BASEPI~1\thunk view.dll
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\System32\EXPLORER.EXE
O4 - HKLM\..\Run: [Rundll16] C:\WINDOWS\rundll16.exe
O4 - HKLM\..\Run: [WINSTA~1.EXE] C:\WINDOWS\System\WINSTA~1.EXE -b
O4 - HKLM\..\Run: [lohextzy] C:\WINDOWS\vlqxlioa.exe
O4 - HKLM\..\Run: [WinEssential] C:\WINDOWS\System32\Keyhost.exe
O4 - HKLM\..\Run: C:\WINDOWS\System32\hzhbxd.exe
O4 - HKLM\..\Run: C:\WINDOWS\System32\hzhbxd.exe
O4 - HKLM\..\Run: [] C:\WINDOWS\System32\
O4 - HKLM\..\Run: [oievetl] rundll32 C:\WINDOWS\System32:oievetl.dll,Init 1
O4 - HKLM\..\Run: [beios] C:\WINDOWS\System32\beios.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [eanth_system_patcher] C:\PROGRA~1\ACCELE~1\SYSTEM~1\sys_alert.exe /Startup
O4 - HKLM\..\Run: [WebScan] C:\Program Files\Acceleration Software\Anti-Virus\defscangui.exe -k
O4 - HKLM\..\Run: [eanth_critical_update_alert] C:\WINDOWS\TEMP\EANTH_~1.EXE /Startup
O4 - HKLM\..\Run: [Yahoo Messenger] YAHOOMSG.EXE
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [NSAgent] C:\Documents and Settings\Anthony.4DYWCP2SHUEER01\Local Settings\Temporary Internet Files\Content.IE5\HAZM4A1E\SaveKobeGameSetup06[1].exe
O4 - HKLM\..\RunOnce: [*oievetl] rundll32 C:\WINDOWS\System32:oievetl.dll,Init 1
O4 - HKCU\..\RunOnce: [Yahoo Messenger] YAHOOMSG.EXE
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50038/QDow_AS2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab

Thanks again,

AG

  • cghost

    302 Posts

    457

    0

    Posted July 12th, 2004 04:00

    Hi AG
    This line is related to the bridge error you mentioned in your other post.
    O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
    You have a number of other problems too though.

    I do not have the time to fully review your log right now, so I'm going to give you a series of steps to get you started and then ask you to post another log.

    1)O4 - HKLM\..\Run: [Rundll16] C:\WINDOWS\rundll16.exe
    This is a worm. Please run the online (housecall) virus scan from trendmicro.
    http://uk.trendmicro-europe.com/consumer/products/housecall_pre.php

    2)Please install hijackthis in its own directory, such as c:\hjt.
    This is necessary to preserve its backups.

    Then run hijackthis with browser windows closed and fix these items:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50038
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50038
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50038
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
    O1 - Hosts: 64.200.25.145 gator.com #cooklop
    O1 - Hosts: 64.200.25.145 doubleclick.net #cooklop
    O1 - Hosts: 64.200.25.145 www.doubleclick.net #cooklop
    O1 - Hosts: 64.200.25.145 tripod.com #cooklop
    O1 - Hosts: 64.200.25.145 www.tripod.com #cooklop
    O1 - Hosts: 64.200.25.145 adultfriendfinder.com #cooklop
    O1 - Hosts: 64.200.25.145 www.adultfriendfinder.com #cooklop
    O1 - Hosts: 64.200.25.145 cj.com #cooklop
    O1 - Hosts: 64.200.25.145 www.cj.com #cooklop
    O1 - Hosts: 64.200.25.145 paypopup.com #cooklop
    O1 - Hosts: 64.200.25.145 www.paypopup.com #cooklop
    O1 - Hosts: 64.200.25.145 thehun.net #cooklop
    O1 - Hosts: 64.200.25.145 www.thehun.net #cooklop
    O1 - Hosts: 64.200.25.145 worldsex.com #cooklop
    O1 - Hosts: 64.200.25.145 www.worldsex.com #cooklop
    O1 - Hosts: 64.200.25.145 free6.com #cooklop
    O1 - Hosts: 64.200.25.145 www.free6.com #cooklop
    O1 - Hosts: 64.200.25.145 trafficmp.com #cooklop
    O1 - Hosts: 64.200.25.145 www.trafficmp.com #cooklop
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: ay[2] = "3";
    O1 - Hosts: var myRepeatArray = new Array();
    O1 - Hosts: 280C52}&mSkip=1&rnd=5224", 600000, "TRUE");
    O1 - Hosts: 1&rnd=12550", 600000, "TRUE");
    O1 - Hosts: ˜JÞ ˆÞ
    O1 - Hosts: �Þ
    O1 - Hosts: {
    O1 - Hosts: if (!Timeout) {
    O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - (no file)
    O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50038/QDow_AS2.cab


    3)open Task Manager, click Processes tab. End the following processes:

    WToolsS.exe
    WToolsA.exe
    WSup.exe

    Close Task Manager.

    Check the following items in Hijackthis - close ALL windows\browsers except Hijackthis and click "Fix checked":

    R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL
    O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe


    Then Boot to safe mode: Instructions here (http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam)

    Make sure you can view hidden and system files: Instructions here (http://www.xtra.co.nz/help/0,,4155-1916458,00.html)

    NOTE....even in safe mode you may have to open taskmanager and end task on some of them before you can delete them.

    Delete the following files\folders IF still present:

    C:\PROGRAM FILES\COMMON FILES\WINTOOLS

    and
    Empty your temporary internet files folder.

    4) http://www.cjwd.demon.co.uk/spybot-adaware.html
    Please run spybot and adaware as indicated.

    At this point I hope we will have
    Dealt with worm/trojan issues.
    Fixed Hosts file and searchsite redirect issues.
    Killed wintools.
    And dealt with some of the remaining issues.

    At this point, please reboot and run and post a fresh hjt log and we will see what is left and the necessary steps to finish cleaning your system.

    Regards

  • Texruss

    2 Intern

    3447 Posts

    457

    0

    Posted July 13th, 2004 00:00

    AGbasketball17:

    Please follow these steps:

    1. Using Windows Explorer: (type explorer at Start/Run)

    Delete
    your HOSTS file in C:\Windows\System32\Drivers\HOSTS

    Info about HOSTS file here: http://russelltexas.com/malware/HOSTS.htm

    2. Download and run these two programs (Spybot S&D and Adaware) at the link below. Use Spybot first.

    Most of the Internet baddies can be killed by a one-two punch with Spybot and Adaware assuming these three factors are achieved:

    1. Latest version
    2. Configured correctly for running options
    3. New definitions from update feature

    Chris has posted an excellent tutorial by dgosling on how to run Spybot S&D and also how to enable customized deep scanning functions for Adaware. Once you set these options they will be retained for future scans by Adaware.

    Follow the directions in this detailed guide for Spybot and Adaware...print out the directions in the custom scan tutorial as a reference while you set these options for the custom setup of Adaware. These custom settings will be retained for future custom scans so don't go nuts thinking you have to do this every time you run it! It may take you five minutes to set them up, but it's worth it.

    http://www.cjwd.demon.co.uk/spybot-adaware.html

    Please note the free Spybot 1.3 does have a slight bug...it detects some DSO exploits falsely. Hopefully an upgrade will fix this.The problem is not serious and should not deter people from using Spybot.

    I also like to run Windows Disk Cleanup after cleaning with those two tools. Make sure you reboot if any reboot cleanup functions of Spybot and Adaware are advised by these tools (this may happen at the end of their cleanup).

    Run Disk Cleanup: type cleanmgr at Start/Run. Scan all hard drives and check all categories at the end and click OK.

    If you have any problems with Disk Cleanup completing...XP users can fix it here: 
    http://www2.whidbey.net/djdenham/DeleteOldFiles.htm

    3. Fix your Hijackthis folder (temp is bad) and download version 1.98 and post a new log. Delete the older 1.97 file.

    http://russelltexas.com/malware/downloadHJTzipfile.htm

    Proper HJT folder:  http://russelltexas.com/malware/createhjtfolder.htm 

    Texruss
    www.russelltexas.com
    Spyware Fighter Wilders Forum
    Slyware Warrior Tom Coyote Forum
    Expert Malware Responder Dell Forum

    Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley.

    Also...these longtime DellForum regulars have proven to me time and again their advice is excellent for malware questions in general, Windows operations, and many specific items in Hijackthis logs:  jimw, ddeerrff, and msgale. Please follow their advice when they respond to your problems. They have a proven track record here.

    BTW...clicking on people's usernames at the left will reveal information about them if they chose to have an open profile. My credentials are available for your perusal.