Start a Conversation

Unsolved

This post is more than 5 years old

1751

December 17th, 2004 20:00

Hijackthis Review

Logfile of HijackThis v1.99.0
Scan saved at 5:01:15 PM, on 12/17/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\WINDOWS\Cyb2k.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oneplace.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103253055625
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 

4.8K Posts

December 17th, 2004 20:00

SUMMERSRC,

What are we looking for?

Mike.

Message Edited by Midnight Star on 12-17-2004 04:28 PM

4 Posts

December 17th, 2004 21:00

I'm trying to get rid of spyware.
 
Adaware detects the IBIS toolbar every time it's run.   SPYBOT detects DSO every time it's run. 
 
 

4.8K Posts

December 18th, 2004 19:00

SummerSrc,

I don't see anything right off that's could be causing the IBIS detection. The DSO exploits could be false alarms. Can you post back information on what AdAware is reporting as IBIS 'hits'?

Mike.

 

4 Posts

December 19th, 2004 05:00

Mike,

Thanks for you response. 

I could not get rid of the IBIS spyware, later Macafee detected a virus.  I deleted instead of quarantening virus files damageing the operateing system and loseing internet access.   Dell tech support took me through the software repair option.    I recovered, ran spyware and still had IBIS spyware.   I was at a loss.  I went into the safe mode, ran adaware on boot up and have not seen IBIS since !!!!!!

However while Adaware full scan runs clean, SPYBOT still continously finds DSO Exploit 4-6 hits per run.

You may be right on when you said DSO Exploit could be a false alarm.  I am getting reports in similiar format as below.  Their are all in the same registry area, HKEY_USERS.    I checked the DSO box on the exclusion list in SPYBOT's settings and SPYBOT runs error free.

HKEY_USERS\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENT VERSION\INTERNET SETTINGS\ZONES\0\1004!=W=3

What action do you recommed I take ?
 
Thanks in advance

4 Posts

December 19th, 2004 11:00

All,

I found a website that provides a solution to my problem of DSO Exploit occuring every time I run SPYBOT.   I have chose to check disregard "DSO Exploit" on the SPYBOT settings option. 

The link below indicates SPYBOT will hive a fix for this problem on their next release. 

http://forums.net-integration.net/index.php?showtopic=15308

Thanks for your help.  I will consider this problem resolved.

 

 

December 27th, 2004 01:00

If you're new to computers and are unwilling to edit the winreg manually, you can download a program that will do it for you.  This program was specially designed to fix the DSO Exploit.
 
No Events found!

Top