
UNSOLVED
HIJACK THIS LOG
My friend is having a lot of complications on her computer and the AVG scan has deteted about 30 viruses. 4 viruses which cannot be healed or deleted. All the viurses are in the AVG vault. I also ran spybot and adware on her computer. Adware detected about 150 malware, but I wasnt sure which files to delete. I have included logs from AVG and hijackthis. Can someone let me know which files i need to delete from hijack this and AVG. I would greatly appreciate if seomone can help me out. thank you
This is the 4 files that AVG cannot delete:
C:\Program Files\INTERN~2\ACTALERT.EXE Trojan horse Downloader.Dyfica.2.I
C:\Program Files\INTERN~2\OPTIMIZE.EXE Trojan horse Downloader.Istbar.3.BE
C:\Program Files\ISTSVC\ISTSVC.EXE Trojan horse Downloader.Istbar.3.AW
C:\Program Files\LYCOS\IEAGENT\LOADER.EXE Trojan horse Downloader.Small.4.BQ
THIS IS THE COMPLETE TEST FROM AVG:
Results of Complete Test, date and time 6/7/2004 19:10:58 :
Testing C:\ serial E0F9-B620
C:\HIBERFIL.SYS Cannot open; not checked!
C:\Documents and Settings\GEORGE\NTUSER.DAT Cannot open; not checked!
C:\Documents and Settings\GEORGE\ntuser.dat.LOG Cannot open; not checked!
C:\Documents and Settings\GEORGE\Local Settings\Application Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
C:\Documents and Settings\GEORGE\Local Settings\Application Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
C:\Documents and Settings\LocalService\NTUSER.DAT Cannot open; not checked!
C:\Documents and Settings\LocalService\ntuser.dat.LOG Cannot open; not checked!
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
C:\Documents and Settings\NetworkService\NTUSER.DAT Cannot open; not checked!
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Cannot open; not checked!
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
C:\Program Files\INTERN~2\ACTALERT.EXE Trojan horse Downloader.Dyfica.2.I
C:\Program Files\INTERN~2\OPTIMIZE.EXE Trojan horse Downloader.Istbar.3.BE
C:\Program Files\ISTSVC\ISTSVC.EXE Trojan horse Downloader.Istbar.3.AW
C:\Program Files\LYCOS\IEAGENT\LOADER.EXE Trojan horse Downloader.Small.4.BQ
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP5\A0001683.EXE repaired
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP5\A0001684.DLL repaired
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP5\A0001685.EXE repaired
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP5\A0001686.EXE Trojan horse Downloader.Agent.AS
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP5\A0001687.EXE Trojan horse Downloader.Small.5.Y
C:\WINDOWS\SYSTEM32\AWKYGNNE.EXE Cannot open; not checked!
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Cannot open; not checked!
Test finished, duration 00:21:07.9 s
16341 objects tested, 9 found infected
THIS IS MY LOG FROM HIJACK THIS:
Logfile of HijackThis v1.97.7
Scan saved at 7:54:15 PM, on 6/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\AVGANT~1\avgserv.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\documents and settings\george\local settings\temp\GYk7.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\sysupd.exe
C:\AVGANT~1\avgcc32.exe
C:\ZoneAlarm\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\INHELPW.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hkcu
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hklm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://go.microsoft.com/fwlink/?LinkId=488
O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\spybot\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [GYk7] C:\documents and settings\george\local settings\temp\GYk7.exe
O4 - HKLM\..\Run: [zmwaixdfpj] C:\WINDOWS\System32\awkygnne.exe
O4 - HKLM\..\Run: [ijqf] C:\WINDOWS\ijqf.exe
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [AVG_CC] C:\AVGANT~1\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\ZoneAlarm\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [INHELPW] C:\WINDOWS\System32\INHELPW.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\spybot\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38145.726087963
Responses (0)
Solutions (0)
