LJoL
Topic Starter
Sadly I know a bit more about PCs than a lot of folks which lets me do things the average user can't so I tend to close stuff down and also tend to delete new files that get suspiciously added to my Windows folders, as well remove malicious shortcuts & links manually so a lot of stuff that probably deserved to be listed got short-changed. For instance I've reguarly seen commercial ad and/or porn links/startups get added but I've always used my pc's search function to root out the causes and terminate them.
The reason this is sad is that it's a case of knowing a lot but also knowing too much causing me to do something that unintentionally hinders fixing the problem while attempting to fix another. I fear that there is something on my system really nasty that I just can't find since a lot of mysterious stuff has been going on. Hence why I am finally attempting to use this HiJackThis program and forum. Well.. that and anti-v software is less than useless on fixing this situation. I say less than useless as I once actually had my McAffee anti-v software get killed by a v that had to be manually contained and bagged.
Suspicious PC Behaviour:
* On login files that don't seem to do anything found in the process list. They don't seem to change the handling of the PC one way or another whether I leave them running or shut them down using the task manager's end process mode (sometimes they are even protected from doing so argh!). There are pproximately 15 of those. The file alchem found by Hijack this was one such entry. Also I should mention that semi recent additions to unclosable "critical operating system files" have been added to the list found running, most of which will be listed next. Having no clue what they do as my experience more lies in web based programs I'm going to list the ones that somehow hijack didn't find when doing its running processes check. csrss.exe, (one extra svchost.exe than was listed), WinCPUcheck.exe, wincmdermkr.exe, alg.exe, alchem.exe, cisvc.exe, winregos.exe, getipcheck.exe, tcpblind.exe, ie6tap.exe, (duplicate entries of the rundll32.exe file one of which is closable while the other is protected critical file), and a couple others which weren't found simply because I had unthinkingly ended their processes prior to scanning due to it having become something of a habit upon opening the pc.
* Clicking a link or failure to stop certain web pages from fully loading sometimes causing the entire browser to shut down completely. Primarily in Netscape 7.1 but also at times the IE 6 browser.
* Sudden popups of IE browser windows even though I only ever use that application for testing website appearance and compliability.
* Strange instances of the task manager suddenly reading 100% processor usage even when not doing anything and without any automated scripts being setup.
* Programs suddenly hanging leaving the last seen image frozen in place even though the program itself has since crashed/closed. This makes it impossible to do anything since the entire Windows GUI is unable to function. The sends of the keyboard get processed by the PC as shown by the processor lights going on and off but the on-screen display fails to recognize it. The only thing that can be seen to change is the mouse cursor which freely moves about but clicks give the same response as the keyboard. The only way out of this that I have found is to either use the pc-hibernate button on the keyboard then immediately move the mouse cursor, or to shut the pc completely.
* Strange reportings of memory usage levels of the HD. Most of the time showing several gig of free space available but every so often listing instead only a few MBs of space such as the worst time I ever saw which listed only 3 MBs of space left available for storage. If this stayed low I'd figure it to be a virus but as it only seems to flick on for a few seconds every few days to weeks I'm figuring it's more along the lines of spyware or possibly a worm.
I'm going to now post the Hijack log file. I made backups of everything I deleted from this list but I did check, and told the program to fix, everything except the GetRight application and the wupdate I believe. Since there are backups I can still recover something if I was mistaken about its legitimacy.
As for the Norton virus scan entries… I'm highly sceptical about them being legit since I've never installed that software since I bought the PC and the orig software put in by the manufacturer was ripped out to clean the slate for it.
Logfile of HijackThis v1.98.2
Scan saved at 5:07:33 AM, on 10/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\TEMP\~AceTemp\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.ht…count_id=145499
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.ht…count_id=145499
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.slotch.com/?&account;_id=145499
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us6.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.ht…count_id=145499
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://mppv2valueadds3.valueactive.com/MPP….htm#checkraise
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem219.dll
O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem301.dll
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\ISTbar\istbar.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [oeznnmx] C:\WINDOWS\System32\qarbpvmc.exe
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [tqxox] C:\WINDOWS\tqxox.exe
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: River Belle Poker - {83F8B625-1B04-4c35-8BA1-6DB4D7EDBADF} - C:\Program Files\riverbelleMPP\MPPoker.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O15 - Trusted Zone: http://www.riverbellepoker.com
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_211/w…OCX/FlashAX.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup151.cab
Looking at that log file scares me as I've never even visited any online gambling sites or those valueactive and abacast sites, and the files supposedly belonging to PowerScan, ISTsvc, and 180solutions don't even show up in my program files folder index but does show up to the hijack software. The messenger ones also are a bit of an eye opener might I add.
PS: And yes I know that most of the files listed by myself in the group not found by hijack sound bad and should be deleted immediately… but on the off-chance they aren't I didn't want to get too friendly with the delete option in my windows system files section. I am highly suspicious of the ones that almost scream hacker or spyware though such as the ie6tap, getipcheck, and winregos among others. If anyone out there can confirm that these are not supposed to be on my system I'd appreciate a shout-out so that I can get to work with deleting them or barring such a simple removal being possible a reg cleaner or resource hacker at removing them.
The reason this is sad is that it's a case of knowing a lot but also knowing too much causing me to do something that unintentionally hinders fixing the problem while attempting to fix another. I fear that there is something on my system really nasty that I just can't find since a lot of mysterious stuff has been going on. Hence why I am finally attempting to use this HiJackThis program and forum. Well.. that and anti-v software is less than useless on fixing this situation. I say less than useless as I once actually had my McAffee anti-v software get killed by a v that had to be manually contained and bagged.
Suspicious PC Behaviour:
* On login files that don't seem to do anything found in the process list. They don't seem to change the handling of the PC one way or another whether I leave them running or shut them down using the task manager's end process mode (sometimes they are even protected from doing so argh!). There are pproximately 15 of those. The file alchem found by Hijack this was one such entry. Also I should mention that semi recent additions to unclosable "critical operating system files" have been added to the list found running, most of which will be listed next. Having no clue what they do as my experience more lies in web based programs I'm going to list the ones that somehow hijack didn't find when doing its running processes check. csrss.exe, (one extra svchost.exe than was listed), WinCPUcheck.exe, wincmdermkr.exe, alg.exe, alchem.exe, cisvc.exe, winregos.exe, getipcheck.exe, tcpblind.exe, ie6tap.exe, (duplicate entries of the rundll32.exe file one of which is closable while the other is protected critical file), and a couple others which weren't found simply because I had unthinkingly ended their processes prior to scanning due to it having become something of a habit upon opening the pc.
* Clicking a link or failure to stop certain web pages from fully loading sometimes causing the entire browser to shut down completely. Primarily in Netscape 7.1 but also at times the IE 6 browser.
* Sudden popups of IE browser windows even though I only ever use that application for testing website appearance and compliability.
* Strange instances of the task manager suddenly reading 100% processor usage even when not doing anything and without any automated scripts being setup.
* Programs suddenly hanging leaving the last seen image frozen in place even though the program itself has since crashed/closed. This makes it impossible to do anything since the entire Windows GUI is unable to function. The sends of the keyboard get processed by the PC as shown by the processor lights going on and off but the on-screen display fails to recognize it. The only thing that can be seen to change is the mouse cursor which freely moves about but clicks give the same response as the keyboard. The only way out of this that I have found is to either use the pc-hibernate button on the keyboard then immediately move the mouse cursor, or to shut the pc completely.
* Strange reportings of memory usage levels of the HD. Most of the time showing several gig of free space available but every so often listing instead only a few MBs of space such as the worst time I ever saw which listed only 3 MBs of space left available for storage. If this stayed low I'd figure it to be a virus but as it only seems to flick on for a few seconds every few days to weeks I'm figuring it's more along the lines of spyware or possibly a worm.
I'm going to now post the Hijack log file. I made backups of everything I deleted from this list but I did check, and told the program to fix, everything except the GetRight application and the wupdate I believe. Since there are backups I can still recover something if I was mistaken about its legitimacy.
As for the Norton virus scan entries… I'm highly sceptical about them being legit since I've never installed that software since I bought the PC and the orig software put in by the manufacturer was ripped out to clean the slate for it.
Logfile of HijackThis v1.98.2
Scan saved at 5:07:33 AM, on 10/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\TEMP\~AceTemp\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.ht…count_id=145499
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.ht…count_id=145499
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.slotch.com/?&account;_id=145499
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us6.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.ht…count_id=145499
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://mppv2valueadds3.valueactive.com/MPP….htm#checkraise
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem219.dll
O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem301.dll
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\ISTbar\istbar.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [oeznnmx] C:\WINDOWS\System32\qarbpvmc.exe
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [tqxox] C:\WINDOWS\tqxox.exe
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: River Belle Poker - {83F8B625-1B04-4c35-8BA1-6DB4D7EDBADF} - C:\Program Files\riverbelleMPP\MPPoker.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O15 - Trusted Zone: http://www.riverbellepoker.com
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_211/w…OCX/FlashAX.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup151.cab
Looking at that log file scares me as I've never even visited any online gambling sites or those valueactive and abacast sites, and the files supposedly belonging to PowerScan, ISTsvc, and 180solutions don't even show up in my program files folder index but does show up to the hijack software. The messenger ones also are a bit of an eye opener might I add.
PS: And yes I know that most of the files listed by myself in the group not found by hijack sound bad and should be deleted immediately… but on the off-chance they aren't I didn't want to get too friendly with the delete option in my windows system files section. I am highly suspicious of the ones that almost scream hacker or spyware though such as the ie6tap, getipcheck, and winregos among others. If anyone out there can confirm that these are not supposed to be on my system I'd appreciate a shout-out so that I can get to work with deleting them or barring such a simple removal being possible a reg cleaner or resource hacker at removing them.