|
|
|
Hijack This
|
Original Message
|
Name: Pete
Date: October 7, 2003 at 19:53:01 Pacific
Subject: Hijack ThisOS: win 2000CPU/Ram: 4M CPU 1.80 GHz / 261,104 |
Comment: Here is a "Hijack This" logfile of my comp after a reboot. Can anyone tell me what I can remove safely? Also, does anyone know how I can save a logfile of a spybot scan? Thanks in advance for the help! Pete Logfile of HijackThis v1.97.2 Scan saved at 10:37:46 PM, on 10/7/2003 Platform: Windows 2000 SP3 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\System32\ibmpmsvc.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\Ati2evxx.exe C:\Program Files\Network Associates\VirusScan\avsynmgr.exe C:\Program Files\Cisco systems\VPN Client\cvpnd.exe C:\Program Files\1598_Fiberlink\Fgrd.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\System32\mspmspsv.exe C:\WINNT\system32\svchost.exe C:\Program Files\Network Associates\VirusScan\VsStat.exe C:\Program Files\Network Associates\VirusScan\Vshwin32.exe C:\Program Files\Network Associates\VirusScan\Avconsol.exe C:\Program Files\Network Associates\VirusScan\Webscanx.exe C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe C:\WINNT\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINNT\System32\PRPCUI.exe C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE C:\WINNT\System32\RunDll32.exe C:\WINNT\AGRSMMSG.exe C:\Program Files\VERITAS Software\Update Manager\sgtray.exe C:\WINNT\system32\dla\tfswctrl.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe C:\Program Files\WildTangent\Apps\GameChannel.exe C:\WINNT\wt\updater\wcmdmgr.exe C:\Documents and Settings\FowlerPT\Desktop\HijackThis.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ O1 - Hosts: 66.40.16.131 livesexlist.com O1 - Hosts: 66.40.16.131 lanasbigboobs.com O1 - Hosts: 66.40.16.131 thumbnailpost.com O1 - Hosts: 66.40.16.131 adult-series.com O1 - Hosts: 66.40.16.131 www.livesexlist.com O1 - Hosts: 66.40.16.131 www.lanasbigboobs.com O1 - Hosts: 66.40.16.131 www.thumbnailpost.com O1 - Hosts: 66.40.16.131 www.adult-series.com O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: DNSErr object - {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} - C:\WINNT\DNSErr.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe O4 - HKLM\..\Run: [TP4EX] tp4ex.exe O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [wcmdmgr] C:\WINNT\wt\updater\wcmdmgrl.exe -launch O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco systems\VPN Client\vpngui.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/hitthepros03/foxsports/wtinst.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{C2AD56C9-13C1-495A-B132-F9FDA022218A}: Domain = nielsenmedia.com O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = nielsenmedia.com,nmrlan.net,vnuusa.org,securityroot.net,enterprisenet.org O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = nielsenmedia.com,nmrlan.net,vnuusa.org,securityroot.net,enterprisenet.org
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: Nigel lew
Date: October 8, 2003 at 01:37:57 Pacific
Subject: Hijack This
|
Reply: (edit)My friend......Is that the first time you have run hijack....I have never seen so much poop.......you will need to likely do a number of things....getting rid of qtask atbootime can take a minute....Hijack really isnt equiped to handle that mess....Porn sites and the whole nine yards... You need to use a substantial reg cleaner, run adaware or spysweep has been working well lately for me.....even if you remove atboottime for instance something somewhere is going to add that reg value right after you delete......... I would recommend that you email me off list for a little more comprehensive explanation of your dilemma...I can tell you what you have been doing and where you have been....Do you have any kind of firewall or pop up blocker at all....You probably have porn dialers on your computer unless you are a member of a number of porn sites... feel free to give me a holler jnlew@comcast.net I likely have some freeware that will do alot of what you need.. Peace Nigel
Report Offensive Follow Up For Removal
|
|
Response Number 2
|
Name: Tom41
Date: October 8, 2003 at 01:52:05 Pacific
Subject: Hijack This |
Reply: (edit)Run HT again and check the following items. Next, close all browser Windows, and have HT fix all checked. O1 - Hosts: 66.40.16.131 livesexlist.com O1 - Hosts: 66.40.16.131 lanasbigboobs.com O1 - Hosts: 66.40.16.131 thumbnailpost.com O1 - Hosts: 66.40.16.131 adult-series.com O1 - Hosts: 66.40.16.131 www.livesexlist.com O1 - Hosts: 66.40.16.131 www.lanasbigboobs.com O1 - Hosts: 66.40.16.131 www.thumbnailpost.com O1 - Hosts: 66.40.16.131 www.adult-series.com O2 - BHO: DNSErr object - {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} - C:\WINNT\DNSErr.dll Spybot should create a report each time you scan unless you have disabled it.. It should be located at C:\Windows\Application Data\Spybot-S&D\Logs It may be in a different location in Win2K, so do a search for 'Logs'.
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name: Tom41
Date: October 8, 2003 at 01:58:29 Pacific
Subject: Hijack This |
Reply: (edit)"Hijack really isnt equiped to handle that mess....Porn sites and the whole nine yards..." Wrong!!!!! All of what mess?? Only 1 adult content BHO that creates those host file entries! This is what HT was designed for...
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: Pete
Date: October 8, 2003 at 21:46:36 Pacific
Subject: Hijack This |
Reply: (edit)OK. Thanks for the input guys. I've been using hijack this and ad aware. I've also tried cw shredder. I did a scan, fixed the items that Tom41 suggested, restarted and this is the logfile I received. Where are these popups coming from? And how do I avoid them? I've only been to a few of those sites, I don't have the memberships that were suggested. I definitely do not frequent these sites as much as the pop ups make it look like I do. The only popup I can remember right now is called spermatrix. (My start page has also been changed a few times... ugh..) What sucks is this is a work computer. Does anyone else know what I should do? I appreciate ALL the help. Thanks guys. Pete Logfile of HijackThis v1.97.2 Scan saved at 12:40:11 AM, on 10/9/2003 Platform: Windows 2000 SP3 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\System32\ibmpmsvc.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\Ati2evxx.exe C:\Program Files\Network Associates\VirusScan\avsynmgr.exe C:\Program Files\Cisco systems\VPN Client\cvpnd.exe C:\Program Files\1598_Fiberlink\Fgrd.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\System32\mspmspsv.exe C:\WINNT\system32\svchost.exe C:\Program Files\Network Associates\VirusScan\VsStat.exe C:\Program Files\Network Associates\VirusScan\Vshwin32.exe C:\Program Files\Network Associates\VirusScan\Avconsol.exe C:\Program Files\Network Associates\VirusScan\Webscanx.exe C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe C:\WINNT\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINNT\System32\PRPCUI.exe C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE C:\WINNT\System32\RunDll32.exe C:\WINNT\AGRSMMSG.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe C:\Program Files\VERITAS Software\Update Manager\sgtray.exe C:\WINNT\system32\dla\tfswctrl.exe C:\Documents and Settings\FowlerPT\My Documents\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe O4 - HKLM\..\Run: [TP4EX] tp4ex.exe O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco systems\VPN Client\vpngui.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/hitthepros03/foxsports/wtinst.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{C2AD56C9-13C1-495A-B132-F9FDA022218A}: Domain = nielsenmedia.com O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = nielsenmedia.com,nmrlan.net,vnuusa.org,securityroot.net,enterprisenet.org O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = nielsenmedia.com,nmrlan.net,vnuusa.org,securityroot.net,enterprisenet.org
Report Offensive Follow Up For Removal
|
Use following form to reply to current message:
|
|

|