Computing.Net > Forums > Security and Virus > hijackthis log file

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

hijackthis log file

Reply to Message Icon

Name: yanor
Date: September 18, 2003 at 13:54:07 Pacific
OS: Windows 2000 SP2
CPU/Ram: Pentium4 1.70 GHz
Comment:

hi,
I have installed the hijackthis software that you have recomended, and
I used it right after scanning & fixing everything with Spybot S&D.

Here is the log file, Iwould really appreciate if you could tell me what to do
with which entry, as the entries I understood (they were very few) I already
took care of.

I think it is worth mentioning that my problem may also be related to the
several worms and trojans that have infected my computer about a month ago
and I thought I took care of.
some problematic symptoms still have [related or unrelated I donnow) are:
the FIND option of windows isn't working [window doesn't open]
LiveUpdate (for NAV) is failing,
when looking in the explorer it seems like thare are no files in WINNT\system32
only subfolders (?)
and the worse is that the iexplorer has serious problem showing some internet
pages.

So here is the hijackthis logfile:
Logfile of HijackThis v1.97.2
Scan saved at 23:48:35, on 18/09/2003
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP2 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\System32\MsgSys.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Winamp3\winampa.exe
C:\WINNT\System32\gsicon.exe
C:\WINNT\System32\dslagent.exe
C:\Program Files\Inoculator\inoc.exe
C:\WINNT\System32\syscpy.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINNT\System32\internat.exe
D:\Babylon\32BIT\Babylon.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.microsoft.com/access/allinone.asp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ramgo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.microsoft.com/access/allinone.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.ramgo.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINNT\wsem214.dll
O3 - Toolbar: @msdxmLC.dll,-1@1037,&רדיו - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {54A85A38-A699-4AEC-8F88-AB542210C93B} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [Bilbulon] c:\program files\EcoSoft\Bilbulon\Bilbulon.exe
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [ICQ Lite] C:\le duc Aviel\תוכנות\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Inoculator] C:\Program Files\Inoculator\inoc.exe
O4 - HKLM\..\Run: [Syscpy] C:\WINNT\System32\syscpy.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Mail.com] C:\Program Files\mail.com\mcalert.exe -auto
O4 - Global Startup: Babylon Translator.lnk = D:\Babylon\32BIT\Babylon.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: ICQ Lite (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: JPM WowApplet - http://wow.bezeq.co.il/wownew/Shared/Applets/SyncApplet.cab
O16 - DPF: {00000000-DDBB-0704-0B53-2C8830E9FAEC} (IELoaderCtl Class) - http://freeload.cc/secure/ieloader.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} (preload control) - http://www.thepaymentcentre.com/build/preload.cab
O16 - DPF: {0878B424-1F95-4E26-B5AB-F0D349D89650} - ftp://download2.us4.outblaze.com/download/mail.com/emailalert/mail_mcea115.cab
O16 - DPF: {10000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/download/cabs/TURB8105/turbo.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2ABE804B-4D3A-41BF-A172-304627874B45} - http://akamai.downloadv3.com/binaries/DialHTML/EGDHTML.cab
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download2.abetterinternet.com/download/cabs/CGA18105/clean.cab
O16 - DPF: {486E48B5-ABF2-42BB-A327-2679DF3FB822} - http://akamai.downloadv3.com/binaries/IA/ia.cab
O16 - DPF: {4C759EC6-96BD-4551-A320-E61A1D68437F} - http://toolbar.globalwebsearch.com/toolbar/gws.cab
O16 - DPF: {5DA6A3EB-DEAA-45AD-B303-64A474879FA0} - http://toolbar.globalwebsearch.com/toolbar/gws.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/fr/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {7DBFDA8E-D33B-11D4-9269-00600868E56E} (WWWInstall Class) - http://www.edipole.fr/kits/WebInstall.dll
O16 - DPF: {8702D9E1-890B-4BF2-A233-FA44E582B2DE} (Dialer_activex Control) - http://vad.mainentrypoint.com/dialer/bin/CE10000/TEST/dialer_activex.cab
O16 - DPF: {94742E3F-D9A1-4780-9A87-2FFA43655DA2} - http://akamai.downloadv3.com/binaries/DialHTML/EGDHTML_pack.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D53B810F-6219-11D4-95B6-0040950375E7} - http://preview.erosconnect.com/dialer/goin/1/dialer_activex.cab
O16 - DPF: {E2F2B9D0-96B9-4B25-B90C-636ECB207D18} - http://www.getweathercast.com/WUInstCAST.cab
O16 - DPF: {E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} - http://xbs.climaxbucks.com/mt/dialers/fc/UniDist.CAB
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = intra-net1
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB7A5CFE-C687-4E27-A296-D0CCC6C8F957}: NameServer = 212.117.129.3 212.117.128.6
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = intra-net1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = intra-net1


thanks
Yanor
PS - I have an "invisible" (empty, annoying) toolbar. I had 2, but I managed
to get rid of one of them using hijackthis - maybe this info might help somehow
:)



Sponsored Link
Ads by Google

Response Number 1
Name: Abnormal
Date: September 19, 2003 at 12:23:55 Pacific
Reply:

Did you try SpyBot and or Ad-Aware?
Below, showes up for me when posting.

DO NOT post a HiJackThis log before following these steps.



0
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: hijackthis log file

Help Globofind-HiJackThis Log File www.computing.net/answers/security/help-globofindhijackthis-log-file/18129.html

hijackthis log file problem www.computing.net/answers/security/hijackthis-log-file-problem/13957.html

hijackthis log file help www.computing.net/answers/security/hijackthis-log-file-help/10066.html