Help with my log!

Discussion in 'Malware Help (A Specialist Will Reply)' started by bani, Jul 20, 2005.

  1. bani

    bani Private E-2

    Hi, I think my computer has some probs. There are several extra buttons on IE and also extra options on toolbar. Here attached is my log. Could you please help to suggest anything I need to remove? Thanks a lot.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. HJT logs should only be posted when requested. You must follow the steps in the sticky READ ME FIRST sticky.

    Please run the steps below.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem, boot into normal mode and make sure you follow these directions:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. bani

    bani Private E-2

    I had followed the steps. I had run spyware doctor before running the hijackthis. I tried other ways, but cant remove the extra buttons and options on my tool bar. And also the extra option on my tool bar is not in my language. I dont know what it is. What else I need to do? Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete the steps in my previous message. I said if still having a problem after running the READ ME FIRST, to post a HijackThis log as an attachment.
     
  5. bani

    bani Private E-2

    o.k. I have run several different virus and spyware removal programs. I ran in safe mode and found a "advertisement" virus, which I quarantined. Still, the extra buttons on my IE still exist. If you click on these buttons they all have the same result: direct link to op99.com??? I am pulling my hair out here!! It would be greatly appreciated if you guys could help me out! Thx
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not install HijackThis as requested. You are running it directly out of the ZIP file (using WinRAR). This is exactly what we request that you not do because you will not get any backups this way.

    Also you have multiple browsers running and we request that they be closed before using HJT.

    The below lines illustrate what I am talking about:
    C:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.663\HijackThis.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    Please install HijackThis.exe properly before continuing and remember to exit browsers from now on.

    Do you know what the below is for:

    O2 - BHO: ltmenu Class - {78C21EFD-53BA-406C-AF1A-33A38ABD3958} - C:\Program Files\LtUcx\1002\c0.dll

    Is it for a chat room?

    Do you use a program name Perfect Disk Defragmenter or similar? I'm wondering about the below line:
    O4 - HKCU\..\Run: [dfrgsnap] C:\Windows\System32\dfrgsnap.exe
     
    Last edited: Jul 23, 2005
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looking further into your log I see you never ran all the steps of the READ ME FIRST. Definitely step 1 of cleaning was not run. I quote what it says there:
     
  8. bani

    bani Private E-2

    hi, me again, I have completed 'step 1' under the 'scaning and cleaning steps'.
    I performed the cleaning in safe and normal modes, with some probs found, which i deleted---I have done the alternate scans: trojanscan, trend micro's, a squared, and avast, (unable to do ads spy), in safe and norm modes, in which some probs were found and fixed. I still have the extra buttons....I want to kill the hijackers....or my cpu. I dont know what c:\programfiles\ltucx\1002\c0.dll is?? or the other one..(not chat room).. you asked about. I now have installed and ran 'hijack this' as instructed. Everything was definatly closed before I ran hjt. Please take another look and see what you think. Thx
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about my other question:

     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also do you recognize the below O16 line:

    O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://202.101.62.196:1995/talk.cab

    Seems to be for:
    Code:
    [url="http://samspade.org/t/whois?a=202.101.62.196;server=auto"][color=#0000ff]202.101.62.196[/color][/url] = [  ] 
     
      inetnum:	  [url="http://samspade.org/t/whois?a=202.101.62.195;server=auto"][color=#0000ff]202.101.62.195[/color][/url] - [url="http://samspade.org/t/whois?a=202.101.62.196;server=auto"][color=#0000ff]202.101.62.196[/color][/url] 
      netname:	  NETPIG-IT 
      descr:		  Shanghai NETPIG IT Co .Ltd 
      country:	  CN 
      admin-c:	   [url="http://samspade.org/t/whois?a=DWJ4-AP;server=whois.apnic.net"][color=#0000ff]DWJ4-AP[/color][/url] 
      tech-c:		   [url="http://samspade.org/t/whois?a=WJ194-AP;server=whois.apnic.net"][color=#0000ff]WJ194-AP[/color][/url] 
      mnt-by:		   [url="http://samspade.org/t/whois?a=MAINT-CHINANET-SH;server=whois.apnic.net"][color=#0000ff]MAINT-CHINANET-SH[/color][/url] 
      changed:	  [email="idc@sh163.net"][color=#0000ff]idc@sh163.net[/color][/email]
     20030423 
      status:		  ASSIGNED NON-PORTABLE 
      source:		  APNIC 
      person:	   Dai Wen Jing 
      address:	  333 Wusheng Road Shanghai  200003 
      country:	  CN 
      phone:		86-21-63270333-4376 
      fax-no:	   86-21-63592785 
      e-mail:	   [email="idc@sh163.net"][color=#0000ff]idc@sh163.net[/color][/email]
     
      
     
  11. bani

    bani Private E-2

    O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://202.101.62.196:1995/talk.cab
    ==> I dont recognize this. I guess it is sth I dont want. And the extra buttons all lead me to a website http://op99.com/2000/, I dont know if there is any connection btw these two.

    O4 - HKCU\..\Run: [dfrgsnap] C:\Windows\System32\dfrgsnap.exe
    ==>I have 'powerquest partitionmagic' installed in my computer. Maybe it is this one. I never used though.

    Thanks so much for reading my log. Please tell me what I need to do. Thanks.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Fix the O16 line using HJt and then reboot. Tell me if anything changes.

    You should also click Tools and look at Manage Addons to see if there is anything in there you do not recognize.

    I do not think dfrgsnap.exe if related to Partition Magic. Check the files properties.

    I would like to get some more info on the dfrgsnap.exe file. Locate it again using Windows Explorer and then right click on it and select Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important Item is the company name. If there is no Version tab, tell me that too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds