It is currently Tue Sep 01, 2026 4:05 pm


when you get the chance!help!

Discuss security related topics in here (Hacking, Cracking, and Protecting)
Do not post HJT Logs here

Moderator: PCguy

when you get the chance!help!

Postby complexity2000_98 » Wed Jun 09, 2004 5:21 pm

here is my log file from hijacker.exe..
Windows:2000
run:crazybrowser-like avant browser
deleted internet explorer

My largest problem is dealhelper...I can get most of
everything else off...Thanks For the Help
I have spybot,adaware, n cw shredder..
n nod32 virus scan-am willin to change or add
another if needed......Thank You

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\documents and settings\administrator\local settings\temp\hNZ3Q.exe
C:\WINNT\TimeSynchronize.exe
C:\WINNT\SM1BG.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINNT\system32\wintsvit.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Communities.com\ThePalace\Palace32.exe
C:\WINNT\system32\cidaemon.exe
C:\Program Files\Crazy Browser\Crazy Browser.exe
C:\WINNT\explorer.exe
E:\Ad-aware 6\Ad-aware.exe
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [hNZ3Q.exe] C:\documents and settings\administrator\local settings\temp\hNZ3Q.exe
O4 - HKLM\..\Run: [TimeSyncApp] C:\WINNT\TimeSynchronize.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINNT\SM1BG.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
O4 - HKLM\..\Run: [PCDRealtime] C:\WINNT\realtime.exe
O4 - HKLM\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\Windows Registry Repair Pro.exe -X
O4 - HKCU\..\Run: [Eols] C:\Documents and Settings\Administrator\Application Data\otrd.exe
O4 - HKCU\..\Run: [WCPI] C:\WINNT\system32\wintsvit.exe
O4 - HKCU\..\Run: [mydocs] C:\WINNT\system32\mydocs.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O9 - Extra button: AIM (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) -
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} -
complexity2000_98
Newbie
Newbie
 
Posts: 3
Joined: Wed Jun 09, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Wed Jun 09, 2004 8:07 pm

I've noticed in your log you have C:\WINNT\TimeSynchronize.exe running. TimeSynchronize product contains DealHelper bundled with it, DealHelper is an add-supported software that enables software publishers to offer software for free of charge in return for advertisements.

By downloading the DealHelper software, you gave permissions to DealHelper.com Inc. to display informational messages. The DealHelper software selects which ads and offers to display to individual users based on several factors, including: URLs associated with web pages visited by the user, search terms typed by the user into search engines, html content of the web pages viewed by the user.

Ad-aware now targets and removes 10 variants of Dealhelper. Before using HijackThis, please download, update (VERY IMPORTANT) and run Ad-aware. Setup Ad-aware to do a full scan. Instructions here:


Try this link for removal of Dealhelper:



After using these instructions post your HJT log here for brad to look at.
Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Wed Jun 09, 2004 11:52 pm

Do as Geekgirl suggests. Do the following to what remains:

Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following: (They may or may not be there)

hNZ3Q.exe
TimeSynchronize.exe
otrd.exe
wintsvit.exe
mydocs.exe


Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.) Close all other open Windows and have HiJackThis Fix:

O4 - HKLM\..\Run: [hNZ3Q.exe] C:\documents and settings\administrator\local settings\temp\hNZ3Q.exe
O4 - HKLM\..\Run: [TimeSyncApp] C:\WINNT\TimeSynchronize.exe
O4 - HKCU\..\Run: [Eols] C:\Documents and Settings\Administrator\Application Data\otrd.exe
O4 - HKCU\..\Run: [WCPI] C:\WINNT\system32\wintsvit.exe
O4 - HKCU\..\Run: [mydocs] C:\WINNT\system32\mydocs.exe
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} -

Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab) (You may have to boot to "Safe Mode" in order to delete some Files/Folders)

C:\documents and settings\administrator\local settings\temp\hNZ3Q.exe
C:\WINNT\TimeSynchronize.exe
C:\Documents and Settings\Administrator\Application Data\otrd.exe
C:\WINNT\system32\wintsvit.exe
C:\WINNT\system32\mydocs.exe

Now, empty your TEMP Folder / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

~fresh log file~

Postby complexity2000_98 » Thu Jun 10, 2004 3:01 am

Logfile of HijackThis v1.97.7
Scan saved at 9:50:43 PM, on 6/9/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\documents and settings\administrator\local settings\temp\hNZ3Q.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINNT\system32\mobsync.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
O4 - HKLM\..\Run: [PCDRealtime] C:\WINNT\realtime.exe
O4 - HKLM\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\Windows Registry Repair Pro.exe -X
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O9 - Extra button: AIM (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} -
O16 - DPF: {FE4BBEA8-1EFD-4B8A-BD1B-341CCDBEEAA6} -

Ok...Did all that..."deal helper" n "casprog" still wont go away
when i try to remove deal helper it says "log file missing" and when i try to remove "casprog" just a black screen comes up.
complexity2000_98
Newbie
Newbie
 
Posts: 3
Joined: Wed Jun 09, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Thu Jun 10, 2004 10:19 am

Do a search for uinst_cp.exe When found, delete it.
Are you saying they are still in Add/Remove Programs? Do you have any other sign of them?
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top


Return to Security

Who is online

Users browsing this forum: No registered users and 1 guest

cron