There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Malware Removal & HijackThis Logs
Tag Cloud
audio blue screen boot bsod computer connection crash dell drivers dvd email error excel firefox freeze graphics harddrive hard drive hardware hijackthis install internet itunes keyboard laptop malware monitor motherboard network outlook outlook 2007 problem registry cleaner registry cleaners router screen slow sound trojan upgrade usb video virus vista windows windows 7 windows vista windows xp wireless word
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Security & Malware Removal > Malware Removal & HijackThis Logs >
Solved: w2000 hjt for checkup - smitrem and other (New)

Tip: Click Here to Update All Your PC's Outdated Drivers
[ Sponsored Link ]

Closed Thread
 
Thread Tools
ucurl's Avatar
Senior Member with 1,555 posts.
 
Join Date: Jan 2004
Location: Markham ON Canada
Experience: Generalist - Above average all round knowledge
18-Feb-2006, 01:03 PM #1
Cool Solved: w2000 hjt for checkup - smitrem and other
Win2000 with problems founr Smitrem on startup
Ran smitrem fix utility, Ran ewido, Unable to connect to internet from reg mode.
Have not been unable to get to control panel to uninstall some programs (very slow)

Have been able to load and run Grisoft AVG and Adaware

Saved hjt this log for review - see below
There is a bunch of crap in there which I haven't been able to deal with yet.

I've just been able access the internet via safe with networking.
Next step.. going to run Housecall and download Kaspersky to see what they catch
then take a better look at the hjt log.

Directions appreciate... (Nothing to do on this saturday but fix pc's)

Original Log (Ooops...Thanks MFDnSC for the catch)

Logfile of HijackThis v1.99.1
Scan saved at 11:43:51 AM, on 2/18/2006
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINNT\explorer.exe
C:\Utilities\hijack this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Yahoo!
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [iedll] C:\WINNT\iedll.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Reboot.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - C:\WINNT\System32\dcom_12.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
__________________
Ucurl - Experienced in problem investigation and resolutions..... on the prowl once again!!
I use/recommend AVG, Malwarebytes, Advanced Windows Care 3, Cleanup and other tools to combat Malware and fix troubled PC's.

Last edited by ucurl : 18-Feb-2006 02:20 PM.
MFDnNC's Avatar
Distinguished Member with 49,032 posts.
 
Join Date: Sep 2004
18-Feb-2006, 01:39 PM #2
No Log!
ucurl's Avatar
Senior Member with 1,555 posts.
 
Join Date: Jan 2004
Location: Markham ON Canada
Experience: Generalist - Above average all round knowledge
18-Feb-2006, 02:28 PM #3
OriginaL log posted in first message.
Still unable to connect to internet via reg mode

I've since updated and ran ewido again and ran cwshredder.
Ewido caught the 021 line dcom_12.dll
cwshedder caught iedll.

I've also cleaned up
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [iedll] C:\WINNT\iedll.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Reboot.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - C:\WINNT\System32\dcom_12.dll

*** Looking into LSP fix issue
I've run the LSPFix utility and found the following:
rnr20.dll tcpip
winrnr.dll NTDS
nwprovaw.dll NWLINK IPX/SPx/NetBio
msafd.dll
rsupsp.dl
--- not sure what to remove... but propbably one of these

***** New HJT Log ***

Logfile of HijackThis v1.99.1
Scan saved at 1:54:51 PM, on 2/18/2006
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\explorer.exe
C:\Utilities\hijack this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Yahoo!
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
__________________
Ucurl - Experienced in problem investigation and resolutions..... on the prowl once again!!
I use/recommend AVG, Malwarebytes, Advanced Windows Care 3, Cleanup and other tools to combat Malware and fix troubled PC's.
MFDnNC's Avatar
Distinguished Member with 49,032 posts.
 
Join Date: Sep 2004
18-Feb-2006, 02:44 PM #4
You have both McAfee and AVG - remove one - only One active AV on a system

Leave the LSP's alone

What errors are you getting
ucurl's Avatar
Senior Member with 1,555 posts.
 
Join Date: Jan 2004
Location: Markham ON Canada
Experience: Generalist - Above average all round knowledge
18-Feb-2006, 02:51 PM #5
I've tried to unload the Mcafee using add/remove but I get a windows installer error msg. (Windows installer service could not be accessesd)
I'm not sure how upto date their version is .. I'd like to uninstall it completely..
ran avg to see what virusesit finds ... it found (two)
When I try to access the internet via the normal window mode it hangs (progress bar half way)

I get a lot of messages "Not responding" when trying to access folders or programs.
(control pannel specifically)

I've run sfc /scannow and appeared to have restored soome of the original programs (thought that might help)
Ran hoster and restored it to original
__________________
Ucurl - Experienced in problem investigation and resolutions..... on the prowl once again!!
I use/recommend AVG, Malwarebytes, Advanced Windows Care 3, Cleanup and other tools to combat Malware and fix troubled PC's.

Last edited by ucurl : 18-Feb-2006 02:57 PM.
MFDnNC's Avatar
Distinguished Member with 49,032 posts.
 
Join Date: Sep 2004
18-Feb-2006, 03:04 PM #6
ucurl's Avatar
Senior Member with 1,555 posts.
 
Join Date: Jan 2004
Location: Markham ON Canada
Experience: Generalist - Above average all round knowledge
18-Feb-2006, 03:21 PM #7
Thanks..
Ran and it prompted me for cd and directory 386 files (i have and loaded) then prompted for Service pack 3 disk which I don't have. Issue may be related to a service pack update on this pc. Still haninging trying to get into control panel.
Still searching for answers....
__________________
Ucurl - Experienced in problem investigation and resolutions..... on the prowl once again!!
I use/recommend AVG, Malwarebytes, Advanced Windows Care 3, Cleanup and other tools to combat Malware and fix troubled PC's.
MFDnNC's Avatar
Distinguished Member with 49,032 posts.
 
Join Date: Sep 2004
18-Feb-2006, 03:45 PM #8
Get SP4 - maybe that will clear it up
ucurl's Avatar
Senior Member with 1,555 posts.
 
Join Date: Jan 2004
Location: Markham ON Canada
Experience: Generalist - Above average all round knowledge
18-Feb-2006, 08:56 PM #9
Thanks.. downloaded and installed sp4 (downloaded using safe with networking) and no change.
IE appears to be a problem, Still getting msg on many programs "not responding"

Still searching
MFDnNC's Avatar
Distinguished Member with 49,032 posts.
 
Join Date: Sep 2004
19-Feb-2006, 11:45 AM #10
<<Still getting msg on many programs>>

I thought you said the problem is with IE

Do this......

Go to the link below and download the trial version of SpySweeper:

SpySweeper http://www.webroot.com/consumer/prod...rc=4129&ac=tsg

* Click the Free Trial link under "SpySweeper" to download the program.
* Install it. Once the program is installed, it will open.
* It will prompt you to update to the latest definitions, click Yes.
* Once the definitions are installed, click Options on the left side.
* Click the Sweep Options tab.
* Under What to Sweep please put a check next to the following:
o Sweep Memory
o Sweep Registry
o Sweep Cookies
o Sweep All User Accounts
o Enable Direct Disk Sweeping
o Sweep Contents of Compressed Files
o Sweep for Rootkits

o Please UNCHECK Do not Sweep System Restore Folder.

* Click Sweep Now on the left side.
* Click the Start button.
* When it's done scanning, click the Next button.
* Make sure everything has a check next to it, then click the Next button.
* It will remove all of the items found.
* Click Session Log in the upper right corner, copy everything in that window.
* Click the Summary tab and click Finish.
* Paste the contents of the session log you copied into your next reply.
Also post a new Hijack This log.
ucurl's Avatar
Senior Member with 1,555 posts.
 
Join Date: Jan 2004
Location: Markham ON Canada
Experience: Generalist - Above average all round knowledge
20-Feb-2006, 09:56 PM #11
Marking Resolved.
I'm ok now.. cannot really pin point what fixed it. (I did a number of things all about the same time... in and out of watching the Daytona 500, Olympics, Hockey games and other distractions)
Downloaded SP4 as said before .. then ran sfc /scannnow again, also downloaded more win critical updates, re-ran adaware, spybots and grissoft. (also ran reg cleaner on a few old installed programs and removed them)
Rebooted a number of times and finally got to control panel, then to add remove programs and removed McAfee enterprise (old version) which appeared to be hanging the system behind the scenes. This appeared to give me better response and I was able to do more.

Appears ok now - HJT was clean, Reinstalled latest Grisoft, Zone Alarm and MS Anti-Spyware.
I think the sp4 and the sfc and updating the win updates corrected it - thanks for that direction.

Thanks again...I'm good to go.
__________________
Ucurl - Experienced in problem investigation and resolutions..... on the prowl once again!!
I use/recommend AVG, Malwarebytes, Advanced Windows Care 3, Cleanup and other tools to combat Malware and fix troubled PC's.
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 12:53 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
Powered by Cermak Technologies, Inc.