HJT Log

Discussion in 'adware, spyware & hijack cleaning' started by BIGH2001, Dec 11, 2003.

Thread Status:
Not open for further replies.
  1. BIGH2001

    BIGH2001 Guest

    Hi, I've been hijacked! Here is my HJT log, can you please let me know what's wrong...Thanks! Harvey

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\System32\ibmpmsvc.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\LEXBCES.EXE
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\system32\LEXPPS.EXE
    C:\WINNT\System32\ati2evxx.exe
    C:\Program Files\NavNT\defwatch.exe
    C:\Program Files\NavNT\rtvscan.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\MsgSys.EXE
    C:\WINNT\Explorer.EXE
    C:\WINNT\system32\tp4serv.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
    C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
    C:\Program Files\CFGSAFE\AUTOCHK.EXE
    C:\Program Files\Locutus\SocketWatch\swatch.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
    C:\PROGRA~1\WINZIP\wzqkpick.exe
    C:\unzipped\hijackthis\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://if.searchcentrix.com/sidecat.jsp?p=98567&appid=21&id=17420815223194122
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search-click.com/search.html?p=37049
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search-click.com/?p=37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = C:\WINNT\search.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = C:\WINNT\search.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://www.pedo.ws/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search-click.com/?p=37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = C:\WINNT\search.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search-click.com/search.html?p=37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search-click.com/?p=37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search-click.com/search.html?p=37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://if.searchcentrix.com/sidecat.jsp?p=98567&appid=21&id=17420815223194122
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=socks.raleigh.ibm.com:1080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ibm.com;<local>
    R3 - URLSearchHook: SearchHookObject Class - {FD9BC004-8331-4457-B830-4759FF704C22} - C:\Documents and Settings\hbarbee\Application Data\iefeatsl\msiesh.dll
    O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-DFF7-EC6BF4D5FA7D} - C:\WINNT\gsim.dll
    O2 - BHO: iefeatsl module - {587DBF2D-9145-4c9e-92C2-1F953DA73773} - C:\Documents and Settings\hbarbee\Application Data\iefeatsl\iefeatsl.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
    O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.reg
    O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
    O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
    O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb02.exe
    O4 - HKLM\..\Run: [PrinTray] C:\WINNT\System32\spool\DRIVERS\W32X86\2\printray.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Online Service] C:\WINNT\svchost.exe
    O4 - HKLM\..\Run: [Belt] C:\WINNT\Belt.exe
    O4 - HKCU\..\Run: [AIM] C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
    O4 - HKCU\..\RunOnce: [iefeatslUpdate] rundll32 C:\DOCUME~1\hbarbee\APPLIC~1\iefeatsl\iefeatsl.new,UpdateDll
    O4 - Startup: PowerReg Scheduler.exe
    O4 - Startup: SocketWatch.lnk = C:\Program Files\Locutus\SocketWatch\swatch.exe
    O4 - Global Startup: AUTOCHK.LNK = C:\Program Files\CFGSAFE\AUTOCHK.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Yahoo! Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O12 - Plugin for .swf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npswf32.dll
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37965.870162037
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = unc.edu
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = unc.edu
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = unc.edu
     
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Hi BIGH2001,

    Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://if.searchcentrix.com/sidecat.jsp?p=98567&appid=21&id=17420815223194122
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search-click.com/search.html?p=37049
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search-click.com/?p=37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = C:\WINNT\search.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = C:\WINNT\search.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search-click.com/?p=37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = C:\WINNT\search.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search-click.com/search.html?p=37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search-click.com/?p=37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search-click.com/search.html?p=37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://if.searchcentrix.com/sidecat.jsp?p=98567&appid=21&id=17420815223194122

    R3 - URLSearchHook: SearchHookObject Class - {FD9BC004-8331-4457-B830-4759FF704C22} - C:\Documents and Settings\hbarbee\Application Data\iefeatsl\msiesh.dll
    O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-DFF7-EC6BF4D5FA7D} - C:\WINNT\gsim.dll
    O2 - BHO: iefeatsl module - {587DBF2D-9145-4c9e-92C2-1F953DA73773} - C:\Documents and Settings\hbarbee\Application Data\iefeatsl\iefeatsl.dll

    O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.reg

    O4 - HKLM\..\Run: [Online Service] C:\WINNT\svchost.exe
    O4 - HKLM\..\Run: [Belt] C:\WINNT\Belt.exe

    O4 - HKCU\..\RunOnce: [iefeatslUpdate] rundll32 C:\DOCUME~1\hbarbee\APPLIC~1\iefeatsl\iefeatsl.new,UpdateDll
    O4 - Startup: PowerReg Scheduler.exe

    Then reboot, preferably into safe mode and delete:
    c:\winnt\tour.reg
    C:\WINNT\Belt.exe

    Then download, unzip and run: http://www.spywareinfoforum.com/~merijn/files/cwshredder.zip

    That should do it.
     
  3. BIGH2001

    BIGH2001 Guest

    Pieter,

    Thanks so much! My homepage is now restored...Harvey
     
  4. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Glad we could help. :)

    Pieter
     
Thread Status:
Not open for further replies.