My buddy wasn't able to download all these nifty progs so I had to upload it to him through AIM. He's no longer having problems staying in a web browser so I had him run HJT and send me his log file. Here's part of it.

O4 - HKLM\..\Run: [jf4] C:\documents and settings\dale davis\local settings\temp\jf4.exe
O4 - HKLM\..\Run: [F] C:\documents and settings\dale davis\local settings\temp\F.exe
----will have him clear his Temp folder again----

O4 - HKLM\..\Run: [r77i3sO] wmiwizc.exe
----what the heck is this?----
O4 - HKLM\..\Run: [ujlu8c9c] C:\WINDOWS\system32\ujlu8c9c.exe
----what the heck is this?----
O4 - HKLM\..\Run: [Mzaxht] C:\Program Files\Vshgtzb\Msbq.exe
----what the heck is this?----

Dani AI

Generated

The items shown in the startup list are classic signs of a recent, possibly transient infection: executables launched from a Temp folder, oddly named EXE files placed in System32, and a program buried inside a nonsense-named Program Files folder. is right to clear Temp, and is right that the full log will help — but do not remove things blindly. A cautious, repeatable cleanup is safer and faster than deleting without verification.

Recommended safe workflow:

  • Make a full HJT save and create a System Restore point or disk image first.
  • Do basic checks before deletion: verify each file location, view file Properties (Details/Digital Signatures) and check the publisher. Signed Microsoft files should not be removed.
  • Use Autoruns to disable suspicious startup entries (uncheck rather than delete) so the system can be tested without permanent registry edits; Autoruns download is here: Autoruns.
  • While disabled, boot to Safe Mode and move the suspicious files to quarantine (or upload them to VirusTotal for multi-engine scanning): VirusTotal. Then run a full scan with an up-to-date AV and an on-demand anti-malware scanner such as Malwarebytes: Malwarebytes.
  • If entries reappear or processes persist, run a rootkit check (specialized tools) and capture a fresh HJT/Autoruns log for review.

Notes and cautions: do not delete items from System32 without confirming they are malicious; use Process Explorer to inspect running processes first: Process Explorer. Keep copies of any files you remove until the machine is clean. If uncertain after these steps, post the full saved logs so the community can validate specific entries.

Recommended Answers

All 2 Replies

You should have him remove them all, reboot and post the entire log here after.

Will do, he should be online tomorrow. I'm trying to self-learn how to read HJT logs. It's pretty neat :)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.