1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

HJT log - really would appreciate help

Discussion in 'Virus & Other Malware Removal' started by gwujess, Feb 21, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. gwujess

    gwujess Thread Starter

    Joined:
    Feb 21, 2004
    Messages:
    9
    Hi,

    I have been having a lot of problems with my computer related to spyware and such. Problems have included:

    -slowness
    -frequent resetting of my homepage
    -adding keys to my favorites
    -downloading programs without me knowing

    and so on

    Anyway, I ran a hijackthis log file and this is how it came out:


    I followed some tutorials and got rid of some things and now it looks like this:


    Any tips?
     
  2. Flrman1

    Flrman1

    Joined:
    Jul 26, 2002
    Messages:
    46,329
    Hi gwujess

    Welcome to TSG! :)

    Click here to download CWShredder. Close all browser windows, click on the cwshredder.exe then click "Fix" (Not "Scan only") and let it do it's thing.

    When it is finished restart your computer.

    To help prevent this from happening again, I strongly recommend you install the folowing patches for the vulnerabilities that this hijacker exploits:

    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms03-011.asp

    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS00-075.asp

    *Note: The simplest way to make sure you have all the security patches is to go to Windows update and install all "Critical Updates and Service Packs"



    Go here and download Adaware 6 Build 181

    Install the program and launch it.

    First in the main window look in the bottom right corner and click on Check for updates now and download the latest referencefiles.

    Make sure the following settings are made and on -------ON=GREEN

    From main window :Click Start then Activate in-depth scan (recommended)

    Click Use custom scanning options then click Customize and have these options selected: Under Drives and Folders put a check by Scan within archives and below that under Memory and Registry put a check by all the options there.

    Now click on the Tweak button in that same window. Under Scanning engine select Unload recognized processes during scanning and under Cleaning Engine select Let windows remove files in use at next reboot

    Click proceed to save your settings.

    Now to scan just click the Next button.

    When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)

    Restart your computer.


    Then go here and download Spybot Search & Destroy.

    Install the program and launch it.

    Before scanning press Online and Search for Updates .

    Put a check mark at and install all updates.

    Click Check for Problems and when the scan is finished let Spybot fix/remove all it finds marked in RED.

    Restart your computer.

    Come back here and post another Hijack This log and we'll get rid of what's left.
     
  3. gwujess

    gwujess Thread Starter

    Joined:
    Feb 21, 2004
    Messages:
    9
    Thanks so much for your help.

    I did the things you said and I already can gauge some improvement in my funcionality. Here is my new log:



    As a side note, this error message keeps popping up now:

    It comes up constantly...
     
  4. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,220
    First Name:
    Derek
    Run hijackthis, tick these entries listed below and ONLY these entries, double check to make sure, then make sure all browser & email windows are closed and press fix checked

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchexe.com/passthrough/in...//gweb.gwu.edu/
    O2 - BHO: BabeIE - {00000000-0000-0000-0000-000000000000} - C:\PROGRA~1\COMMON~2\ADDRES~1\cnbabe.dll (file missing)
    O2 - BHO: (no name) - {DF4D03D4-3E0E-0822-D176-38D29024AE2F} - C:\PROGRA~1\ADMINS~1\proxyproc.dll
    O3 - Toolbar: Bows platform up - {F1AC6C84-5B43-329B-946D-96F382521B03} - C:\PROGRA~1\ADMINS~1\proxyproc.dll
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
    O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pcsvc.exe
    O4 - HKLM\..\Run: [view bolt] C:\PROGRA~1\BODYDA~1\01 new great.exe
    O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\ADDRES~1\winnet.exe
    O4 - HKCU\..\Run: [Osus] C:\Documents and Settings\Jess\Application Data\acao.exe
    O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} (OTXMovie Class) - http://www.otxresearch.com/OTXMedia/OTXMedia.dll
    O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805...uditControl.cab


    Reboot into safe mode by following instructions here: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406
    then as some of the files or folders you need to delete may be hidden do this:
    Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files". Now click "Apply to all folders"
    Click "Apply" then "OK"

    Delete these files
    C:\Documents and Settings\Jess\Application Data\acao.exe

    and Delete these folders

    C:\PROGRAM FILES\BODYDA~1
    C:\Program Files\AutoUpdate
    C:\PROGRAM FILES\ADMINS~1
    C:\PROGRAM FILES \COMMON NAME
    C:\WINDOWS\system32\pcs

    then
    IF this is your mouse drivers or you know it's connected to the mouse leave them otherwise fix this entry
    O4 - HKLM\..\Run: [HorngTech4D] C:\PROGRA~1\MOUSES~1\bally4d.exe
    and then delete this folder along with the rest
    C:\PROGRAm files\MOUSES~1

    I strongly suspect this to be a LOP entry along with several of the others i've said to delete


    Reboot normally & post a new log
     
  5. Flrman1

    Flrman1

    Joined:
    Jul 26, 2002
    Messages:
    46,329
    Run Hijack This again and put a check by these. Close all windows except HijackThis and click "Fix checked"

    O2 - BHO: BabeIE - {00000000-0000-0000-0000-000000000000} - C:\PROGRA~1\COMMON~2\ADDRES~1\cnbabe.dll (file missing)

    O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"

    O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pcsvc.exe

    O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\ADDRES~1\winnet.exe

    O4 - HKCU\..\Run: [Osus] C:\Documents and Settings\Jess\Application Data\acao.exe

    O16 - DPF: {3B02AAA2-327C-40ED-A849-4BE819AE5385} (ImgSizer Control) - file://C:\Documents and Settings\Jess\Local Settings\Temp\~DlfnTmp0\imgSizer.ocx


    Restart to safe mode and delete:

    The C:\Program Files\AutoUpdate folder
    The C:\WINDOWS\system32\pcs folder
    The C:\Documents and Settings\Jess\Application Data\acao.exe file

    Some of the may be hidden files so click on My Computer. Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files". Now click "Apply to all folders"
    Click "Apply" then "OK"

    How to start your computer in safe mode.
     
  6. gwujess

    gwujess Thread Starter

    Joined:
    Feb 21, 2004
    Messages:
    9
    Thanks so much!

    I did all of the things you said and this is my new log:


    Again, thank you so much!
     
  7. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,220
    First Name:
    Derek
    A couple either got missed or came back

    Run hijackthis, tick these entries listed below and ONLY these entries, double check to make sure, then make sure all browser & email windows are closed and press fix checked


    O4 - HKLM\..\Run: [view bolt] C:\PROGRA~1\BODYDA~1\01 new great.exe
    O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\ADDRES~1\winnet.exe

    Reboot into safe mode
    then as some of the files or folders you need to delete may be hidden do this:
    Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files". Now click "Apply to all folders"
    Click "Apply" then "OK"

    Delete these files
    NONE
    and Delete these folders

    C:\PROGRAM FILES\BODYDA~1
    C:\PROGRAM FILES \COMMON NAME
     
  8. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Similar Threads - really appreciate help
  1. FatDaddy
    Replies:
    15
    Views:
    477
  2. bigwill2k
    Replies:
    3
    Views:
    282
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/205732

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice