Hijack this log

Discussion in 'Malware Help (A Specialist Will Reply)' started by kasey1118, Mar 30, 2005.

  1. kasey1118

    kasey1118 Private E-2

    Please help me with my hijack log I am having some spywear problems
    I have tried running adaware and spybot, and I still have the problem I am using AVG 7.0 for my virus scan, .....I started using it about a month ago , before that I was using norton, I never had any problems like this before when I was using norton ....Thanks in advance for your help !
    kasey


    Logfile of HijackThis v1.99.1
    Scan saved at 9:38:18 AM, on 3/30/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Edit by chaslang: Unrequested inline log removed.
     
    Last edited by a moderator: Mar 30, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow forum guidelines on using and posting HijackThis logs.

    To help us to best help you, please follow the steps below closely and in the order given and do not skip anything. If you have any difficulty, please post back letting us know what steps you have completed, what you found while doing the scans if anything along with details about any problems you may have encountered in completing the steps. The more details you can provide the better. Don't be afraid to ask for additional help if you don't understand something!

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. kasey1118

    kasey1118 Private E-2

    Sorry about that ...I just completed all the steps I need too and found this but i dont understand how to get rid of it...please help

    Your computer is infected with at least one known virus or Trojan horse.
    C:\WINDOWS\cpbrkpie.ocx is infected with Adware.CouponAge
    C:\WINDOWS\ExeDialer.exe is infected with Packed.Dialer
    C:\WINDOWS\NDNuninstall5_64-1.exe is infected with Adware.NDotNet
    C:\WINDOWS\system32\EGCOMSERVICE2.dll is infected with Dialer.Inproc
    C:\WINDOWS\system32\EGCOMSERVICE_1048.dll is infected with Adware.InstantAccess
    C:\WINDOWS\system32\lsaagf.exe is infected with Adware.Envolo
    C:\WINDOWS\system32\Macromed\Shockwave 8\Xtras\download\TheGrooveAlliance\3DGrooveXtrav18\Groove.x32 is infected with Adware.Ezula
    C:\Program Files\Media Access\MediaAccC.dll is infected with Adware.WinTaskAd
    C:\Program Files\Media Access\MediaAccess.exe is infected with Adware.WinTaskAd
    C:\Program Files\Media Access\MediaAccK.exe is infected with Adware.WinTaskAd
    C:\Documents and Settings\User\Local Settings\Temp\AutoUpdate0\auto_update_uninstall.exe is infected with Adware.Envolo
    C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.zip-6c522c5b-6e04f4ae.zip is infected with Adware.Winpup
     
  4. Qwertyman66

    Qwertyman66 Private E-2

    How up to date are your definitions for Adaware, Spybot and AVG? I somehow managed to get the Adware.WinTaskAd a while back. Adaware removed it no problem. It might not be able to remove it if it is running, so check for the .exe files mentioned above in the running processes on the task manager and rerun adaware etc.
    Hope this helps.
     
  5. kasey1118

    kasey1118 Private E-2

    everything is up to date ...my avg, spybot and adaware dosent remove this .....
     
  6. Qwertyman66

    Qwertyman66 Private E-2

    OK then, this is beyond me. I will be interested to find out what the problem is, incase I am ever in your shoes.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please complete my previous instructions.
     
  8. kasey1118

    kasey1118 Private E-2

    I did complete all the instructions that you requested, and I am still stuck... I am kind of computer dumb, but I did everything you asked
     
  9. kasey1118

    kasey1118 Private E-2

    I am still having pop ups and I dont understand how to get rid of them
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not! Read from the point that says:


    After doing ALL of the above you still have a problem:

    and down. You did not follow those steps and post your HijackThis log.
     
  11. kasey1118

    kasey1118 Private E-2

    Ok I am sorry , I thought you had to be asked to post your log to post it
    Thanks again for all your help
    Kasey

    I have attached the log
    I am having popups that I can get rid of
    Thanks in advance for your help
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Isn't that what this line did:

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).

    You still did not follow directions though. You have two browser sessions running:
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    and you are running HijackThis from the ZIP file which is what I asked that you not do.
    C:\DOCUME~1\User\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    You must get HijackThis installed properly before continuing and you MUST remember to exit browsers before using HijackThis.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After installing HJT correctly as requested in my previous message, run the below steps.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\Media Access\MediaAccK.exe
    C:\Program Files\Media Access\MediaAccess.exe
    C:\WINDOWS\system32\wowcap32.exe
    C:\WINDOWS\system32\wjvodctr.exe
    C:\Program Files\CxtPls\CxtPls.exe

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.searchtraffic.com/search.php3?l=protect1&term=
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchtraffic.com/search.php3?l=protect1&term=
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
    O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
    O4 - HKLM\..\Run: [r7Fh3FX] wowcap32.exe
    O4 - HKCU\..\Run: [awwnRPb8e] wjvodctr.exe
    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/GamesUnlimited/ie/bridge-c40.cab
    O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} - http://otx.ifilm.com/OTXMedia/OTXMedia.dll
    O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
    O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872} (cpbrxpie Control) - http://a19.g.akamai.net/7/19/7125/4007/ftp.coupons.com/r3120/cpbrxpie.cab
    O16 - DPF: {99802379-7362-40E2-9D28-8A3B9AF880B7} - http://hotsearchbar.com/toolbar2/winhot32.cab
    O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} (AsyncDownloader Class) - http://survey.otxresearch.com/Preloader.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Media Access <-- the whole folder
    C:\Program Files\CxtPls <-- the whole folder
    C:\WINDOWS\system32\wowcap32.exe
    C:\WINDOWS\system32\wjvodctr.exe
    C:\Program Files\CxtPls
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds