![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Mar 2005
Posts: 1
OS: Windows XP
|
Here is my HijackThis Log. Please help!
====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 3/2/05 Get updates at http://www.greyknight17.com/download.htm#programs ***Security Programs Detected*** C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Logfile of HijackThis v1.99.1 Scan saved at 11:52:39 AM, on 3/7/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe C:\Program Files\Java\j2re1.4.2_04\bin\jucheck.exe C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe C:\WINDOWS\isrvs\desktop.exe C:\Program Files\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.carrollcc.edu/library/default.asp R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.carrollcc.edu/library/default.asp O1 - Hosts: 69.20.16.183 auto.search.msn.com O1 - Hosts: 69.20.16.183 search.netscape.com O1 - Hosts: 69.20.16.183 ieautosearch O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe O4 - HKLM\..\Run: [ScreenPrint32] C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe -startup O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe O4 - HKLM\..\Run: [dtovlhla] c:\windows\system32\dtovlhla.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1109957028729 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = carrollcc.edu O17 - HKLM\Software\..\Telephony: DomainName = carrollcc.edu O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = carrollcc.edu O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll O20 - Winlogon Notify: OptimalLayout - C:\WINDOWS\system32\gpjsl3171.dll O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe" /ServiceStart (file missing) End of KRC HijackThis Analyzer Log. ==================================================================== |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Manager, The Conversation Pit/Analyst, Security Team
|
Hi and welcome to TSF.
I am currently reviewing your log. Please note that this is under the supervision of an expert analyst, and I will be back with a fix for your problem a.s.a.p Please be patient with me during this time.
__________________
"If you aren't a liberal when you're 20, you have no heart. If you aren't a conservative when you are 50, you have no brain"
|
|
|
|
|
#3 (permalink) |
|
TSF Enthusiast
|
Hello and welcome to TSF-
You have a very serious infection on your system. This will take some serious work to remove. If you follow my instructions precisely, we can remove it for you. We are going to do this in two steps. Step One: Remove all the 'other' badguys first. Step Two: remove the nasty ieautosearch bug. that’s the really nasty one. We will be using several anti-spyware, anti-adware and anti-hijack programs. I recommend that you keep these programs on your system permanently. Only use HijackThis under the guidance of an expert! Accidentally deleting something can disable your operating system. Print out these instructions so you may reference them without any programs open. It is very important that no programs (especially internet browsers) are running when implementing these fixes. [You may leave your firewall and virusscanner running, of course.] ---------------------------------------------------------------- * Your HiJackThis program is in an unusual location. It is important that this program reside in a permanent folder, where we can store logs. I recommend c:/program files/HJT/. You should save each log with a name that you can recognize, like HJT 9-20-04a.log. The 'a' is in case we make multiple logs in one day. HiJackThis is a single file program. So you may freely cut/paste it to whereever you want and it will not affect HiJackThis's functionality. ---------------------------------------------------------------- Show Hidden Files instructions (WinXP) Doubleclick My Computer | Tools | Folder Options | View tab Select Show Hidden Files and Folders Uncheck Hide extensions for known file types Uncheck Hide protected operating system files (Recommended) Select Apply to All Folders | Yes | Apply | OK ---------------------------------------------------------------- Turn off System Restore instructions (WinXP) Rightclick My Computer | Properties | System Restore | check “Turn off System Restore”, <Apply>, <OK>. Reboot. When we have confirmed that your log file is clean, you may renable System Restore and create a new restore point. ---------------------------------------------------------------- Repair Winsock instructions Download WinsockFix to some permanent directory, like c:/program files/winsockfix/ and doubleclick it. ---------------------------------------------------------------- Reboot in Safe Mode instructions. During reboot, tap the F8 key. Select Safe Mode. ---------------------------------------------------------------- Open HiJackThis | Config | Misc Tools | Open process manager. Select the following and click <Kill process> for each one if they are still listed (they may not be, and that's ok): C:\WINDOWS\isrvs\desktop.exe ---------------------------------------------------------------- Open HiJackThis | Scan, Put a check next to the following items. O1 - Hosts: 69.20.16.183 auto.search.msn.com O1 - Hosts: 69.20.16.183 search.netscape.com O1 - Hosts: 69.20.16.183 ieautosearch O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe O4 - HKLM\..\Run: [dtovlhla] c:\windows\system32\dtovlhla.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...b?1109957028729 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll O20 - Winlogon Notify: OptimalLayout - C:\WINDOWS\system32\gpjsl3171.dll Confirm that you have only the ones above checked, then press <Fix checked> Close HJT ---------------------------------------------------------------- Open Windows Explorer Now delete the following files (or delete the whole folder if no specific file is given): C:\WINDOWS\isrvs\ C:\WINDOWS\farmmext.exe c:\windows\system32\dtovlhla.exe C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll C:\WINDOWS\isrvs\mfiltis.dll C:\WINDOWS\system32\gpjsl3171.dll c:\windows\system32\dolsp.dll ---------------------------------------------------------------- * Empty the c:/windows/temp/ folder. Note: only empty the contents of the folder, leave the folder there. * Empty your C:/Documents and Settings/LocalService/Local Settings/Temp/ * Empty your C:/Documents and Settings/<All other usernames including Default User and Administrator>/Local Settings/Temp/ * Now empty your Recycle Bin. * Reboot in Normal Mode. ---------------------------------------------------------------- You should run an online virus scan. Select one or more of the following. Online virus scans can be superior to PC scans because some malware can infect your PC virus scanner. Select Autoclean if you use TrendMicro's Housecall. Panda at http://www.pandasoftware.com/actives..._principal.htm Housecall at http://housecall.trendmicro.com/ RAV Antivirus at http://www.ravantivirus.com/scan Reboot. When you are done, post a new HJT log.
__________________
Ich kann auf Deutsch helfen. Mach ein' post und PM mich. Peebs85 kann auch Deutsch. If I help you, please donate to upgrade our outgrown server. I will donate my time to helping you for free, but the server is not free. Please send donations to Jason Connors (TSF owner), 4410 Grandwood Lane, New Port Richey, FL 34653. Even if its only a dollar. Thank you. |
|
|
| Thread Tools | |
|
|