Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Oct 2 2004, 09:41 PM
Post
#1
|
|
![]() New Member ![]() Group: New Member Posts: 7 Joined: 2-October 04 Member No.: 15,807 |
Logfile of HijackThis v1.98.2 Scan saved at 10:39:07 PM, on 10/2/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\WINDOWS\system32\spoolsv.exe D:\PROGRA~1\Grisoft\AVG6\avgserv.exe D:\WINDOWS\System32\nvsvc32.exe D:\WINDOWS\Explorer.EXE D:\WINDOWS\System32\svchost.exe D:\PROGRA~1\Grisoft\AVG6\avgcc32.exe D:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe D:\WINDOWS\System32\tbctray.exe D:\Program Files\Microsoft Office\Office10\WINWORD.EXE D:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe D:\Program Files\Internet Explorer\iexplore.exe D:\Program Files\Outlook Express\msimn.exe C:\program files\winrar\WinRAR.exe D:\DOCUME~1\Tom\LOCALS~1\Temp\Rar$EX00.842\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Inneret Splorer' R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar2.dll O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - D:\PROGRA~1\FlashFXP\IEFlash.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar2.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\system32\msdxm.ocx O4 - HKLM\..\Run: [AVG_CC] D:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RemoteControl] "D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [MSConfig] D:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [TraySantaCruz] D:\WINDOWS\System32\tbctray.exe O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINDOWS\System32\msjava.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab O16 - DPF: {29B2C103-AB53-4971-B765-FC1CE5D8B2D1} - http://www.silvercrk.com/php/hwspades_scec...907_5336879.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...l_v1-0-3-12.cab O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404...meInstaller.exe O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://mirror.worldwinner.com/games/v45/wo...jo/wordmojo.cab O16 - DPF: {A305FBA3-4A87-483D-A53B-138F9F635357} (PCInfo.CMClass) - http://ciscdb.sel.sony.com/support/pops/mdldetect/PCInfo.CAB O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab |
|
|
|
Oct 3 2004, 05:43 AM
Post
#2
|
|
![]() Advanced Member Group: Malware Expert Posts: 610 Joined: 2-April 04 Member No.: 3,658 Operating System: XP |
Hi welcome to TOM COYOTE FORUMS
First of all Your copy of HijackThis needs to be in a folder of it's own. When HJT fixes anything, it makes backups of the original files in the folder it is in. Since Temporary folders are emptied now and then (the files are DELETED), it would not be a good idea to have your backups there. Those backups would be VITAL to restoring your system if something went wrong in the FIX process! 1. Please go to you're 'My Documents' folder, right-click and select 'New > Folder' then name the folder 'HJT'. 2. Copy and paste HijackThis.exe to the new folder. Try doing the following online scans trendmicro http://housecall.trendmicro.com/ panda scan http://www.pandasoftware.com/activescan/ REPORT any virus or trojans found I do not see any real problem with your log other then the fact that you are running a lot of programs at the same time winword powerdvd internet explorer winrar outlook express Consider closing some of the programs? Please download and run Adaware & Spybot Then follow the instructions in the link below to run. Spybot Tutorial AdAware Tutorial You DO NOT have a firewall running a good one can be downloaded here Zone Alarm The following programs will protect your computer from any spyware or malware Adaware Spybot Spyware Blaster You had disabled some things using the msconfig utility Please ENABLE them. Do not reboot, run hijackthis again and generate a new log. POST the new log in this thread using 'Add Reply' This post has been edited by nellie2: Oct 3 2004, 10:42 AM |
|
|
|
Oct 3 2004, 06:32 AM
Post
#3
|
|
![]() Advanced Member Group: Malware Expert Posts: 610 Joined: 2-April 04 Member No.: 3,658 Operating System: XP |
What programs have you disabled ?
|
|
|
|
Oct 5 2004, 01:39 AM
Post
#4
|
|
![]() New Member ![]() Group: New Member Posts: 7 Joined: 2-October 04 Member No.: 15,807 |
the programs i disabled are:
nerocheck powerdvd hp share to web and nwiz.exe Logfile of HijackThis v1.98.2 Scan saved at 2:38:45 AM, on 10/5/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\WINDOWS\system32\spoolsv.exe D:\WINDOWS\Explorer.EXE D:\PROGRA~1\Grisoft\AVG6\avgserv.exe D:\WINDOWS\System32\nvsvc32.exe D:\PROGRA~1\Grisoft\AVG6\avgcc32.exe D:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe D:\WINDOWS\System32\tbctray.exe D:\WINDOWS\System32\svchost.exe D:\Program Files\Internet Explorer\iexplore.exe C:\program files\winrar\WinRAR.exe D:\DOCUME~1\Tom\LOCALS~1\Temp\Rar$EX00.212\HijackThis.exe D:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe D:\Program Files\Internet Explorer\iexplore.exe D:\Program Files\Microsoft Office\Office10\WINWORD.EXE C:\Phoenician Casino\casino.exe D:\Program Files\Ahead\Nero\nero.exe D:\Program Files\mozilla.org\Mozilla\mozilla.exe D:\Program Files\DC++\DCPlusPlus.exe D:\Program Files\Outlook Express\msimn.exe D:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\winrar\WinRAR.exe D:\Program Files\DVD Shrink\DVD Shrink 3.2.exe D:\Program Files\DVD Decrypter\DVDDecrypter.exe D:\Program Files\mIRC\mirc.exe D:\Program Files\QuickTime\QuickTimePlayer.exe D:\WINDOWS\System32\rundll32.exe D:\Program Files\Windows Media Player\wmplayer.exe D:\Program Files\Microsoft Office\Office10\EXCEL.EXE D:\Program Files\Microsoft Office\Office10\FRONTPG.EXE D:\Program Files\Microsoft Office\Office10\POWERPNT.EXE R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Inneret Splorer' R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar2.dll O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - D:\PROGRA~1\FlashFXP\IEFlash.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar2.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\system32\msdxm.ocx O4 - HKLM\..\Run: [AVG_CC] D:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [TraySantaCruz] D:\WINDOWS\System32\tbctray.exe O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINDOWS\System32\msjava.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE O16 - DPF: {29B2C103-AB53-4971-B765-FC1CE5D8B2D1} - http://www.silvercrk.com/php/hwspades_scec...907_5336879.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...l_v1-0-3-12.cab O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404...meInstaller.exe O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://mirror.worldwinner.com/games/v45/wo...jo/wordmojo.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {A305FBA3-4A87-483D-A53B-138F9F635357} (PCInfo.CMClass) - http://ciscdb.sel.sony.com/support/pops/mdldetect/PCInfo.CAB O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab I like multi tasking |
|
|
|
Oct 5 2004, 07:20 AM
Post
#5
|
|
![]() Advanced Member Group: Malware Expert Posts: 610 Joined: 2-April 04 Member No.: 3,658 Operating System: XP |
Hi
A lot of the programs are not running through their normal startup PLEASE do a REBOOT AND after that IMMEDIATELY run hijackthis get a NEW log and post it here using add reply You also need to have some PROTECTION against these malware Some good programs below GET THEM You DO NOT have a firewall running a good one can be downloaded here Zone Alarm The following programs will protect your computer from any spyware or malware Adaware Spybot Spyware Blaster |
|
|
|
Oct 23 2004, 05:37 PM
Post
#6
|
|
|
Classroom Admin Group: Administrator Posts: 3,651 Joined: 1-December 03 Member No.: 1,118 Operating System: XP home, Vista Ultimate, Vista Business |
Glad we could be of assistance. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address) Include your post user name and detail why you need it reopened with a valid link to your post. Any bad links or emails that are not from the original poster will be deleted without response. Any emails without the subject "Reopen" will be deleted without being looked at. If this is not your thread please start a New Topic. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
1 | ramsis | 45 | 6th January 2009 - 04:28 PM Last post by: ken545 |
|||
![]() |
2 | Mr. Kelley | 396 | 23rd December 2008 - 07:42 PM Last post by: LDTate |
|||
![]() |
5 | tmbMATRIX | 70 | 21st December 2008 - 09:55 AM Last post by: LDTate |
|||
![]() |
0 | jakrinda | 179 | 17th December 2008 - 08:53 PM Last post by: jakrinda |
|||
|
Time is now: 8th January 2009 - 11:03 PM |