1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: hjt - log

Discussion in 'Virus & Other Malware Removal' started by tasputin, Jan 31, 2005.

Thread Status:
Not open for further replies.
Advertisement
  1. tasputin

    tasputin Thread Starter

    Joined:
    Jan 25, 2005
    Messages:
    11
    Hi,

    I think a friend of mine has a bad virus. When he surfs the net he gets re-directed to some webpage that he did not ask for.

    Any advice or help would be very much apreciated.

    Here is the hjt log:

    Logfile of HijackThis v1.99.0
    Scan saved at 22:51:01, on 30/01/2005
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\System32\ibmpmsvc.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINNT\System32\QCONSVC.EXE
    C:\WINNT\System32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\System32\tp4serv.exe
    C:\WINNT\System32\ltmsg.exe
    C:\WINNT\System32\S3Tray2.exe
    C:\ARCHIV~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\ARCHIV~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
    C:\Archivos de programa\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\WINNT\System32\rundll32.exe
    C:\WINNT\System32\icp.exe
    C:\WINNT\System32\p6.exe
    C:\WINNT\System32\miniport_mp.exe
    C:\WINNT\System32\performcl.exe
    C:\ARCHIV~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    C:\WINNT\System32\ctfmon.exe
    C:\WINNT\System32\wuauclt.exe
    C:\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://a-search.biz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://a-search.biz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://a-search.biz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://a-search.biz/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: DgnWebIE - {2843DAC1-05EF-11D2-95BA-0060083493D6} - C:\Archivos de programa\Dragon Systems\NaturallySpeaking\Program\web_ie.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\ARCHIV~1\FLASHGET\jccatch.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\ARCHIV~1\FLASHGET\fgiebar.dll
    O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
    O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
    O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
    O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.reg
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [TPHOTKEY] C:\ARCHIV~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
    O4 - HKLM\..\Run: [TPTRAY] C:\ARCHIV~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
    O4 - HKLM\..\Run: [FineReader7NewsReaderPro] C:\Archivos de programa\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Archivos de programa\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
    O4 - HKLM\..\Run: [Internet Content Publisher] icp.exe
    O4 - HKLM\..\Run: [MSNPluginSrvcs] p6.exe
    O4 - HKLM\..\Run: [MiniPortRt] C:\WINNT\System32\miniport_mp.exe
    O4 - HKLM\..\Run: [PerformCl] C:\WINNT\System32\performcl.exe
    O4 - HKLM\..\RunServices: [Internet Content Publisher] icp.exe
    O4 - HKLM\..\RunServices: [MSNPluginSrvcs] p6.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\System32\ctfmon.exe
    O4 - HKCU\..\Run: [LiteServe] E:\pendiente\programas basicos\LiteServe\liteserve.exe
    O4 - HKCU\..\Run: [Internet Content Publisher] icp.exe
    O4 - HKCU\..\Run: [MSNPluginSrvcs] p6.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: Descargar TODO con FlashGet - C:\Archivos de programa\FlashGet\jc_all.htm
    O8 - Extra context menu item: Descargar usando FlashGet - C:\Archivos de programa\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FLASHGET\flashget.exe
    O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FLASHGET\flashget.exe
    O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1106609009218
    O16 - DPF: {B5DD9A64-5C4B-4A48-BE56-97C1A8F85708} - http://204.177.92.198/quickdl/livevideo/fastvideoplayer.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{20DEE1E3-8ADB-4002-BF47-0208EB85FA98}: NameServer = 194.65.100.117
    O17 - HKLM\System\CS1\Services\Tcpip\..\{20DEE1E3-8ADB-4002-BF47-0208EB85FA98}: NameServer = 194.65.100.117
    O23 - Service: Servicio del administrador de discos lógicos - Unknown - C:\WINNT\System32\dmadmin.exe
    O23 - Service: Registro de sucesos - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Fax - Unknown - C:\WINNT\system32\fxssvc.exe
    O23 - Service: IBM PM Service - Unknown - C:\WINNT\System32\ibmpmsvc.exe
    O23 - Service: Servicio COM de grabación de CD de IMAPI - Unknown - C:\WINNT\System32\imapi.exe
    O23 - Service: Escritorio remoto compartido de NetMeeting - Unknown - C:\WINNT\System32\mnmsrvc.exe
    O23 - Service: DDE de red - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: DSDM de DDE de red - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: Plug and Play - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: QCONSVC - Unknown - C:\WINNT\System32\QCONSVC.EXE
    O23 - Service: Administrador de sesión de Ayuda de escritorio remoto - Unknown - C:\WINNT\system32\sessmgr.exe
    O23 - Service: Sistema de ayuda de tarjeta inteligente - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Tarjeta inteligente - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Registros y alertas de rendimiento - Unknown - C:\WINNT\system32\smlogsvc.exe
    O23 - Service: Telnet - Unknown - C:\WINNT\System32\tlntsvr.exe
    O23 - Service: Administrador de utilidades - Unknown - C:\WINNT\System32\UtilMan.exe
    O23 - Service: Instantáneas de volumen - Unknown - C:\WINNT\System32\vssvc.exe
    O23 - Service: Adaptador de rendimiento de WMI - Unknown - C:\WINNT\System32\wbem\wmiapsrv.exe
     
  2. Flrman1

    Flrman1

    Joined:
    Jul 26, 2002
    Messages:
    46,329
    Click here and download reglook.zip. Unzip the file and doubleclick on the runme.bat file. Let it run and then copy and paste the log it produces back here.

    Download and extract (unzip) the contents of the zip file to c:\reglook. Then double-click on therunme.bat file found in the reglook folder . When the program has completed running it will open a notepad that contains some information. Copy the contents of that notepad and paste it back here please.

    Also post another Hijack This log please.
     
  3. tasputin

    tasputin Thread Starter

    Joined:
    Jan 25, 2005
    Messages:
    11
    Hi there,

    here is the log's you asked for. Thamk you.

    A reg_look by IMM
    ----------------------------------------
    Handle OK.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    (key has 0 subkeys and 7 value entries - last modified 15:50(UTC) 18/05/2003)
    [AppInit_DLLs] = "" (REG_SZ)
    ----------------------------------------
    Handle OK.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon



    Logfile of HijackThis v1.99.0
    Scan saved at 23:44:17, on 01/02/2005
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\System32\ibmpmsvc.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\system32\spoolsv.exe
    C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINNT\System32\QCONSVC.EXE
    C:\WINNT\System32\svchost.exe
    C:\WINNT\System32\tp4serv.exe
    C:\WINNT\System32\ltmsg.exe
    C:\WINNT\System32\S3Tray2.exe
    C:\ARCHIV~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\ARCHIV~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
    C:\Archivos de programa\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\WINNT\System32\rundll32.exe
    C:\WINNT\System32\icp.exe
    C:\WINNT\System32\p6.exe
    C:\WINNT\System32\miniport_mp.exe
    C:\WINNT\System32\performcl.exe
    C:\WINNT\System32\ctfmon.exe
    C:\ARCHIV~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    C:\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://a-search.biz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://a-search.biz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://a-search.biz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://a-search.biz/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: DgnWebIE - {2843DAC1-05EF-11D2-95BA-0060083493D6} - C:\Archivos de programa\Dragon Systems\NaturallySpeaking\Program\web_ie.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\ARCHIV~1\FLASHGET\jccatch.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\ARCHIV~1\FLASHGET\fgiebar.dll
    O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
    O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
    O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
    O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.reg
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [TPHOTKEY] C:\ARCHIV~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
    O4 - HKLM\..\Run: [TPTRAY] C:\ARCHIV~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
    O4 - HKLM\..\Run: [FineReader7NewsReaderPro] C:\Archivos de programa\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Archivos de programa\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
    O4 - HKLM\..\Run: [Internet Content Publisher] icp.exe
    O4 - HKLM\..\Run: [MSNPluginSrvcs] p6.exe
    O4 - HKLM\..\Run: [MiniPortRt] C:\WINNT\System32\miniport_mp.exe
    O4 - HKLM\..\Run: [PerformCl] C:\WINNT\System32\performcl.exe
    O4 - HKLM\..\RunServices: [Internet Content Publisher] icp.exe
    O4 - HKLM\..\RunServices: [MSNPluginSrvcs] p6.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\System32\ctfmon.exe
    O4 - HKCU\..\Run: [LiteServe] E:\pendiente\programas basicos\LiteServe\liteserve.exe
    O4 - HKCU\..\Run: [Internet Content Publisher] icp.exe
    O4 - HKCU\..\Run: [MSNPluginSrvcs] p6.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: Descargar TODO con FlashGet - C:\Archivos de programa\FlashGet\jc_all.htm
    O8 - Extra context menu item: Descargar usando FlashGet - C:\Archivos de programa\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FLASHGET\flashget.exe
    O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FLASHGET\flashget.exe
    O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1106609009218
    O16 - DPF: {B5DD9A64-5C4B-4A48-BE56-97C1A8F85708} - http://204.177.92.198/quickdl/livevideo/fastvideoplayer.cab
    O23 - Service: Servicio del administrador de discos lógicos - Unknown - C:\WINNT\System32\dmadmin.exe
    O23 - Service: Registro de sucesos - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Fax - Unknown - C:\WINNT\system32\fxssvc.exe
    O23 - Service: IBM PM Service - Unknown - C:\WINNT\System32\ibmpmsvc.exe
    O23 - Service: Servicio COM de grabación de CD de IMAPI - Unknown - C:\WINNT\System32\imapi.exe
    O23 - Service: Escritorio remoto compartido de NetMeeting - Unknown - C:\WINNT\System32\mnmsrvc.exe
    O23 - Service: DDE de red - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: DSDM de DDE de red - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: Plug and Play - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: QCONSVC - Unknown - C:\WINNT\System32\QCONSVC.EXE
    O23 - Service: Administrador de sesión de Ayuda de escritorio remoto - Unknown - C:\WINNT\system32\sessmgr.exe
    O23 - Service: Sistema de ayuda de tarjeta inteligente - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Tarjeta inteligente - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Registros y alertas de rendimiento - Unknown - C:\WINNT\system32\smlogsvc.exe
    O23 - Service: Telnet - Unknown - C:\WINNT\System32\tlntsvr.exe
    O23 - Service: Administrador de utilidades - Unknown - C:\WINNT\System32\UtilMan.exe
    O23 - Service: Instantáneas de volumen - Unknown - C:\WINNT\System32\vssvc.exe
    O23 - Service: Adaptador de rendimiento de WMI - Unknown - C:\WINNT\System32\wbem\wmiapsrv.exe


    (key has 4 subkeys and 31 value entries - last modified 22:30(UTC) 01/02/2005)
    [Userinit] = "C:\WINNT\system32\userinit.exe," (REG_SZ)
    ----------------------------------------
    Handle OK.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\boot
    (key has 0 subkeys and 5 value entries - last modified 15:50(UTC) 18/05/2003)
    [Shell] = "SYS:Microsoft\Windows NT\CurrentVersion\Winlogon" (REG_SZ)
    ----------------------------------------
     
  4. Flrman1

    Flrman1

    Joined:
    Jul 26, 2002
    Messages:
    46,329
    Download TDS-3 from http://tds.diamondcs.com.au/index.php?page=download

    This is a Trial version so you will have to do the update manually.
    The automatic update only works with the registered version which costs $49.

    Update it following the instructions here:
    http://tds.diamondcs.com.au/index.php?page=update

    Under the "Manual Update" right click on the radius.td3 file and choose "Save target as".
    Then in the "Save in" box browse to the C:\Program Files\TDS3 folder
    (provided that is the location of your TDS-3 directory)and save it there.
    A prompt will appear telling you that there is already a radius.td3 file there "do you want to overwrite it" click Yes.

    Run the "full System scan" , preferably in safe mode.

    Note: Temporarily disable your Antivirus program.
    Launch TDS-3 and click on "System Testing" then "Full System Scan" and the scan will begin.

    TDS-3 does not automatically remove infected files that it finds. It will display what it has found in the lower portion of the main window and it will either say "Positive Identification etc...." or "Suspicious File". Anything with a positive identification you should right click and delete. Don't do anything with the suspicious ones yet. Right click on any suspicious entry found and choose "Save as Text" then go to the TDS-3 folder (usually C:\Program Files\TDS) and look for a scandump.txt file. Open the scandump.txt file and copy and paste it's contents here. Once we see the scandump file we can determine what to do with the suspicious ones. Many times the suspicious files are harmless.
     
  5. tasputin

    tasputin Thread Starter

    Joined:
    Jan 25, 2005
    Messages:
    11
    Hi,

    Sorry for not replying sooner.

    My friend decided to reinstal windows XP...it was very bad.

    Now it is ok.

    Thank you very much for your help.
     
  6. Flrman1

    Flrman1

    Joined:
    Jul 26, 2002
    Messages:
    46,329
    Thanks for letting us know! (y)

    I'm closing this thread.

    Anyone else with a similar problem please start a "New Thread".
     
  7. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/325218

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice