Computing.Net > Forums > Security and Virus > HijackThis Log - Please Help

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

HijackThis Log - Please Help

Reply to Message Icon

Name: cave_jon_hotmail.com
Date: January 8, 2004 at 21:00:31 Pacific
OS: Windows XP - Home
CPU/Ram: 1.6 GHz P4/512 MB
Comment:

I am having a couple of problems that I believe
are spy-ware related. I have run Spybot-S&D 1.2
and Ad-aware 6.0 and cleaned everything they
could find, but I am still experiencing problems. I
have run a HijackThis scan and have included the
log file below.

I would appreciate it if someone could take a look
at this and let me know if they see anything that
needs to be removed. Many thanks.

Jon


Logfile of HijackThis v1.97.7
Scan saved at 7:36:02 PM, on 1/8/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1
(6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\EPSON\EBAPI\
SAgent2.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\
nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Real\
Update_OB\realsched.exe
D:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\
Main,Search Bar = about:blank
R3 - URLSearchHook: (no name) - _{CFBFAE00-
17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-
95BE-4956-B4C6-6BB168A70310} - (no file)
O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-
BEA1-786FA05C83AB} - C:\Program Files\
AproposClient\AproposPlugin.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-
B87D-784B7D6BE0B3} - C:\Program Files\
Adobe\Acrobat 5.0\Reader\ActiveX\
AcroIEHelper.ocx
O2 - BHO: (no name) - {2D0A4ACB-C2E4-4303-
8675-F0AC6B17691E} - C:\WINDOWS\System32\
drmv2iclt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-
A544-FADC6B084872} - C:\Program Files\Norton
SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-
3FFB-4238-8AD1-7859DF00B1D6} - C:\Program
Files\Norton SystemWorks\Norton AntiVirus\
NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-
876E-00A0C9082467} - C:\WINDOWS\system32\
msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\
Common Files\Real\Update_OB\realsched.exe" -
osboot
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-
D3488ABDDC6B} (QuickTime Object) - http://
www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {41F17733-B041-4099-A042-
B518BB6A408C} - http://a1540.g.akamai.net/7/
1540/52/20020713/qtinstall.info.apple.com/
samantha/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-
0050DA18DE71} (RdxIE Class) - http://
207.188.7.150/1111f926e81b4e5bf819/netzip/
RdxIE601.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-
0050048383FE} (OPUCatalog Class) - http://
office.microsoft.com/productupdates/content/
opuc.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-
00105A1F0D68} (InstallShield International Setup
Player) - http://admin.pressplay.com/duet/
registration/isetup.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-
00105AA9B6AE} (Symantec RuFSI Registry
Information Class) - http://security.symantec.com/
SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-
444553540000} (Shockwave Flash Object) - http:/
/download.macromedia.com/pub/shockwave/
cabs/flash/swflash.cab
O16 - DPF: {D7959311-BFA5-11D4-AC33-
0050DA92CB80} (VRmallViewer Class) - http://
download.humandream.com:8085/cabs/
VRmall.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-
00C04F6843FE} (Microsoft Office Tools on the
Web Control) - http://officeupdate.microsoft.com/
TemplateGallery/downloads/outc.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-
0060082AA75C} (GpcContainer Class) - https://
accordent.webex.com/client/latest/webex/
ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\
{F9943410-E418-45BA-85F3-F71741B33BDB}:
NameServer = 206.13.29.12



Sponsored Link
Ads by Google

Response Number 1
Name: Abnormal
Date: January 8, 2004 at 21:33:33 Pacific
Reply:

Fix these;
R3 - URLSearchHook: (no name) - _{CFBFAE00-
17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-
95BE-4956-B4C6-6BB168A70310} - (no file)
O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-
BEA1-786FA05C83AB} - C:\Program Files\
AproposClient\AproposPlugin.dll
O2 - BHO: (no name) - {2D0A4ACB-C2E4-4303-
8675-F0AC6B17691E} - C:\WINDOWS\System32\
drmv2iclt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\
Common Files\Real\Update_OB\realsched.exe" -
osboot
O16 - DPF: {56336BCB-3D8A-11D6-A00B-
0050DA18DE71} (RdxIE Class) - http://
207.188.7.150/1111f926e81b4e5bf819/netzip/
RdxIE601.cab

reboot and delete the Apropos Client folder.


0

Response Number 2
Name: cave_jon_hotmail.com
Date: January 9, 2004 at 17:57:44 Pacific
Reply:

Thank you for the feedback; it is greatly
appreciated. That seems to have fixed the
problem. Everything seems to be back to normal
now.

Computer Cops suggested that I also fix the
following items:

O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-
00105AA9B6AE} (Symantec RuFSI Registry
Information Class) - http://security.symantec.com/
SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-
0060082AA75C} (GpcContainer Class) - https://
accordent.webex.com/client/latest/webex/
ieatgpc.cab

And delete the following file after reboot:

C:\Program Files\Common Files\Real\
Update_OB\realsched.exe


The latest HijackThis log file is included below.

Thanks again!

Logfile of HijackThis v1.97.7
Scan saved at 5:46:40 PM, on 1/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1
(6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\EPSON\EBAPI\
SAgent2.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\
nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
D:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\
Main,Search Bar = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-
B87D-784B7D6BE0B3} - C:\Program Files\
Adobe\Acrobat 5.0\Reader\ActiveX\
AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-
A544-FADC6B084872} - C:\Program Files\Norton
SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-
3FFB-4238-8AD1-7859DF00B1D6} - C:\Program
Files\Norton SystemWorks\Norton AntiVirus\
NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-
876E-00A0C9082467} - C:\WINDOWS\system32\
msdxm.ocx
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-
D3488ABDDC6B} (QuickTime Object) - http://
www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {41F17733-B041-4099-A042-
B518BB6A408C} - http://a1540.g.akamai.net/7/
1540/52/20020713/qtinstall.info.apple.com/
samantha/us/win/QuickTimeInstaller.exe
O16 - DPF: {597C45C2-2D39-11D5-8D53-
0050048383FE} (OPUCatalog Class) - http://
office.microsoft.com/productupdates/content/
opuc.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-
00105A1F0D68} (InstallShield International Setup
Player) - http://admin.pressplay.com/duet/
registration/isetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-
444553540000} (Shockwave Flash Object) - http:/
/download.macromedia.com/pub/shockwave/
cabs/flash/swflash.cab
O16 - DPF: {D7959311-BFA5-11D4-AC33-
0050DA92CB80} (VRmallViewer Class) - http://
download.humandream.com:8085/cabs/
VRmall.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-
00C04F6843FE} (Microsoft Office Tools on the
Web Control) - http://officeupdate.microsoft.com/
TemplateGallery/downloads/outc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\
{F9943410-E418-45BA-85F3-F71741B33BDB}:
NameServer = 206.13.29.12


0

Response Number 3
Name: Abnormal
Date: January 9, 2004 at 19:52:07 Pacific
Reply:

There may be another 016 line to remove,
not sure. I did find your other post.

Follow the tips under my name, staying safe is all I ask for my help.


0

Response Number 4
Name: devilsknight
Date: January 28, 2004 at 11:29:14 Pacific
Reply:

Logfile of HijackThis v1.97.7
Scan saved at 2:25:35 PM, on 1/28/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\System32\QCONSVC.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINNT\system32\RunDll32.exe
C:\WINNT\System32\TpScrLk.exe
C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\DOCUME~1\leeson\LOCALS~1\Temp\pftD~tmp\Setup.exe
C:\DOCUME~1\leeson\LOCALS~1\Temp\pft10~tmp\Setup.exe
C:\DOCUME~1\leeson\LOCALS~1\Temp\pft13~tmp\Setup.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\leeson\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.quiksearchgenealogy.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.quiksearchgenealogy.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.quiksearchgenealogy.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.quiksearchgenealogy.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.quiksearchgenealogy.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.quiksearchgenealogy.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.quiksearchgenealogy.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.quiksearchgenealogy.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.quiksearchgenealogy.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.quiksearchgenealogy.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.quiksearchgenealogy.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.quiksearchgenealogy.com/
R3 - URLSearchHook: MailTo Class - {0FA33B6C-71BC-69D3-DB7A-472A4D6F3452} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\pubplace.dll
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.sheridanc.on.ca/"); (C:\Program Files\Netscape\Users\default\prefs.js)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.sheridanc.on.ca/"); (C:\Documents and Settings\leeson\Application Data\Mozilla\Profiles\default\m1vrgmgp.slt\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Microsoft Excel - {17DA0C9E-4A27-4ac5-BB75-5D24B8CDB972} - C:\DOCUME~1\leeson\APPLIC~1\MICROS~1\Office\Excel10.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINNT\system32\dla\tfswshx.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [AtiPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [IgfxTray] "C:\WINNT\System32\igfxtray.exe"
O4 - HKLM\..\Run: [TPHOTKEY] "C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe"
O4 - HKLM\..\Run: [BMMGAG] "RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor"
O4 - HKLM\..\Run: [BMMLREF] "C:\Program Files\ThinkPad\Utilities\BMMLREF.exe"
O4 - HKLM\..\Run: [TPKBDLED] "C:\WINNT\System32\TpScrLk.exe"
O4 - HKLM\..\Run: [TPKMAPMN] "C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe"
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [QCWLICON] "C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.exe"
O4 - HKLM\..\Run: [Smapp] "C:\Program Files\Analog Devices\SoundMAX\Smtray.exe"
O4 - HKLM\..\Run: [ATIModeChange] "Ati2mdxx.exe"
O4 - HKLM\..\Run: [QCTray] "C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe"
O4 - HKLM\..\Run: [Synchronization Manager] "mobsync.exe " /logon
O4 - HKLM\..\Run: [cuagent] "C:\PROGRA~1\COMMAN~1\COMMAN~1\cuagent.exe"
O4 - HKLM\..\Run: [dvprpt] "C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe"
O4 - HKLM\..\Run: [avtray] "C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe"
O4 - HKLM\..\Run: [CSAV_CheckViruses] "C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe"
O4 - HKLM\..\Run: [dla] "C:\WINNT\system32\dla\tfswctrl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "ctfmon.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.exe" /background
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
O4 - Global Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O4 - Global Startup: winlogon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37929.5344560185
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_03) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: HijackThis Log - Please Help

HijackThis log - please help www.computing.net/answers/security/hijackthis-log-please-help/9942.html

Hijackthis Log Please HELP! www.computing.net/answers/security/hijackthis-log-please-help/8684.html

drpeper (hijackthis log included) www.computing.net/answers/security/drpeper-hijackthis-log-included/9800.html